
Appcues and GDPR
CertReports found no public GDPR evidence for Appcues as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.
Evidence
- Kind
- listing
- Issued or listed
- 6 Mar 2018
- Expires or valid through
- 1 Apr 2027
- Scope
- Appcues processes four different categories of data, which reflect the different levels of sensitivity in context. We never sell this data to third parties. In limited cases, we provide it to third-party services for usage strictly within the Appcues product or business; for example, to provide analytics graphs on the Appcues dashboard. Type 1: End-user PII This is the most sensitive type of data that Appcues collects. Examples: Any user profile data passed to Appcues by the customer, using the `Appcues.identify()` SDK function Browser information that is collected by default in the Appcues SDK (e.g., OS, device type, browser language, user agent) Browsing history data that is collected by default in the Appcues SDK (e.g., current page URL, current page title) We reiterate that like all data we collect, end-user PII is never sold to third parties. Customers may opt out of browser and browser history information by contacting Appcues Support. This data is used in the targeting and customization of Appcues content. Type 2: End-user Appcues Data This data pertains to how end users are interacting with Appcues content; for example, whether a flow was shown to a given user, whether a user has clicked away a tooltip, etc. This category also includes user responses to in-Appcues forms or surveys. Though this category usually does not contain PII, we caution that form or survey responses may add PII to this data. End-user Appcues data is provided to service providers for usage within the Appcues platform. Customers may also configure Appcues to send this data upstream to other services via Segment. Data in this category is used in the targeting and customization of Appcues content, as well as displaying analytics on the Appcues dashboard. It is this data stream which is available for CSV download on the Appcues dashboard. Type 3: Customer PII Customer PII is collected by the Appcues dashboard, for example the name and email address of each of a customer's team members who are authorized to use the Appcues platform. Appcues does not store financial data about customers (e.g., credit card information), choosing instead to employ a dedicated payments processor. Data of this type is used mainly in the Appcues dashboard and editor, and within the Appcues business. Type 4: Customer Aggregate Data This category includes customer-wide statistics such as active user count, number of Appcues flows shown, how many Appcues flows are published at a time, etc. This data does not contain PII. Data in this category is used mainly in the Appcues dashboard and editor, customer emails, and within the Appcues business.
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | Appcues: Active: EU-US Certification, SW-US Certification, UK Extension Certification | Live pagesha256 beb661d904 |
What GDPR means, and what it does not
"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.
Read the GDPR guide and browse all vendors with evidenceQuestions buyers ask
Is Appcues GDPR compliant?
There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.
How does CertReports verify this?
Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.
Alternatives with GDPR evidence
Similar vendors (shared product tags or the Marketing category) whose GDPR row is verified or vendor-stated, ranked by similarity.
No Marketing vendor has GDPR evidence in the index yet.