FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. Personalization
  4. Overheat
O

Overheat

Analytics

Related services

A

AB Tasty

AB Tasty is a digital analytics solution that helps businesses measure and understand their online performance through comprehensive data collection and analysis. It provides visitor tracking, behavioral insights, and conversion metrics across websites and applications. AB Tasty supports custom event tracking, audience segmentation, and automated reporting. With intuitive dashboards and visualization tools, AB Tasty enables informed decisions that improve experience and drive results.

Analytics
A

ABLyft

ABLyft is an analytics and measurement platform providing deep insights into digital ecosystem performance. It tracks user interactions, measures campaign effectiveness, and identifies optimization opportunities across web and mobile. ABLyft offers customizable dashboards, automated alerts, and data export capabilities. By transforming raw data into actionable intelligence, ABLyft empowers organizations to optimize strategy and maximize return on investment.

Analytics
A

Acquia Personalization

Acquia Personalization is a digital analytics solution that helps businesses measure and understand their online performance through comprehensive data collection and analysis. It provides visitor tracking, behavioral insights, and conversion metrics across websites and applications. Acquia Personalization supports custom event tracking, audience segmentation, and automated reporting. With intuitive dashboards and visualization tools, Acquia Personalization enables informed decisions that improve.

Analytics
A

Adobe Target

Adobe Target is an analytics and measurement platform providing deep insights into digital ecosystem performance. It tracks user interactions, measures campaign effectiveness, and identifies optimization opportunities across web and mobile. Adobe Target offers customizable dashboards, automated alerts, and data export capabilities. By transforming raw data into actionable intelligence, Adobe Target empowers organizations to optimize strategy and maximize return on investment.

Analytics
A

Algolia DocSearch

Algolia DocSearch is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. Algolia DocSearch supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, Algolia DocSearch ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Preferences
B

Bloomreach Discovery

Bloomreach Discovery is a digital analytics solution that helps businesses measure and understand their online performance through comprehensive data collection and analysis. It provides visitor tracking, behavioral insights, and conversion metrics across websites and applications. Bloomreach Discovery supports custom event tracking, audience segmentation, and automated reporting. With intuitive dashboards and visualization tools, Bloomreach Discovery enables informed decisions that improve experience.

Analytics
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does Overheat do?

Overheat is a European privacy-focused session recording and heatmap tool designed as a GDPR-compliant alternative to Hotjar. It captures user interactions to help website owners understand how visitors navigate their site. With EU-based infrastructure and privacy-by-design principles, Overheat eliminates the third-country transfer risk associated with US-based analytics tools. Consent is still required before session recordings begin under the ePrivacy Directive.

What is Overheat?

Overheat is a European privacy-focused session recording and heatmap analytics tool that provides website owners with visual insights into how visitors interact with their pages. It records mouse movements, clicks, scroll depth, and navigation patterns to create heatmaps and session replays. Overheat is specifically designed as a GDPR-compliant alternative to US-based tools like Hotjar and Microsoft Clarity, with EU-based data storage and privacy-by-design features such as automatic masking of sensitive input fields.

What data does Overheat collect?

Overheat records mouse movements, click positions, scroll depth, page navigation sequences, and session duration. It may also capture form interaction data (fields focused, not necessarily values). IP addresses and browser information are collected. Sensitive form fields such as passwords and payment inputs are automatically masked. Session recordings are stored on EU-based servers.

GDPR compliance and EU advantage

Overheat''s EU data storage eliminates the primary GDPR risk associated with US-based session recording tools. No transfer mechanism is required. The privacy-by-design approach including automatic form field masking reduces the risk of inadvertently capturing sensitive personal data in recordings. The ePrivacy Directive still requires consent before session recording begins, as recording user behaviour constitutes non-essential data collection regardless of storage location.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Consent requirements

Consent is required before Overheat scripts load and session recording begins. The consent notice should explain that session recordings and heatmaps are used to improve the website, describe the data captured, and confirm EU data storage. Given the EU location, no US transfer disclosure is needed. Users who decline must not have their sessions recorded.

Data location and transfers

All data is processed in the EU. No transfer mechanism required. This makes Overheat suitable for organisations with strict data localisation requirements who need session recording analytics.

Practical compliance steps

Obtain ePrivacy consent before Overheat loads. Verify automatic form field masking is active. Update your privacy policy to describe Overheat as a processor with EU data storage. Sign a DPA with Overheat. Configure session recording sampling rates and retention periods to minimise data collection. Document the processing in your RoPA noting the EU data location.

GDPR consent category

Analytics

Websites using Overheat must obtain user consent under GDPR regulations.

Legal basisConsent (Art. 6(1)(a) GDPR) for session recordings and heatmap tracking as these involve systematic observation of individual user behaviour. Legitimate interest (Art. 6(1)(f)) may apply to aggregate, anonymised heatmap data with a documented balancing test.
Risk levelmedium
Applicable regulationsGDPR, ePrivacy Directive

DPIA considerations

A DPIA is advisable when Overheat session recordings capture sensitive user interactions at scale, such as form completions, health-related page visits, or financial account pages. The EU data location significantly reduces risk compared to US-based alternatives.

Sample consent text

We use Overheat to record and analyse how visitors use our website through session recordings and heatmaps. Overheat collects interaction data including mouse movements, clicks, and scroll behaviour. Data is processed in the EU. Please accept to enable session recording and heatmap analytics.

Technical details

Tracking methodJavaScript snippet, session recording, heatmap tracking, click and scroll event capture, first-party cookies
Server locationEuropean Union (Overheat is a European privacy-focused analytics tool)
Cookieless tracking availableYes

Third-party domains contacted

overheat.iocdn.overheat.io

Cookies placed

NameTypeDurationPurpose
oh_sessionsessionSessionSession identifier used to maintain the active session recording and associate interaction events
oh_uidpersistent1 yearVisitor identifier used to stitch sessions across page loads for complete session replay

Overheat collects user analytics data — you legally need a consent banner. Try FlowConsent free.

Get started freeScan your site

Frequently asked questions

What does Overheat record?

Overheat records mouse movements, click positions, scroll depth, page navigation sequences, and session duration. Sensitive form fields such as passwords and payment inputs are automatically masked. Recordings are stored on EU-based servers.

Does Overheat require consent under GDPR?

Yes. Session recording and heatmap tracking are non-essential and require prior ePrivacy consent regardless of EU data location. Users who decline must not have their sessions recorded.

What is the legal basis for using Overheat?

Consent (Art. 6(1)(a)) is required for session recordings and individual heatmap tracking. Legitimate interest may apply to aggregate, anonymised heatmap data with a documented balancing test.

Does Overheat transfer data outside the EU?

No. All data is processed within the EU. No GDPR Chapter V transfer mechanism is required — a major advantage over US-based tools like Hotjar or FullStory.

Do I need a DPIA for Overheat?

Advisable when recordings capture sensitive interactions at scale (health, finance, legal pages). The EU data location significantly reduces the risk profile versus US alternatives.

How do I implement Overheat compliantly?

Obtain ePrivacy consent before loading. Verify automatic form masking is active. Sign a DPA with Overheat. Update your privacy policy noting EU data storage. Configure retention periods and document the processing in your RoPA.

How does Overheat compare to Hotjar for GDPR compliance?

Overheat stores all data in the EU, eliminating the US transfer risk. Hotjar requires SCCs; Overheat does not. Both require ePrivacy consent. For EU organisations, Overheat is the simpler compliance choice.

How do I add Overheat to my cookie policy?

List the Overheat session cookie under analytics, note the EU data storage, reference Overheat as processor, and link to their privacy policy. No third-country transfer disclosure is required.