Overview
Deel is a global payroll, HR, and compliance platform that enables companies to hire employees and contractors across more than 150 countries without establishing a local legal entity. The platform serves as an employer of record, managing employment contracts, payroll processing, tax withholding, benefits administration, and compliance with local labour law. Deel operates primarily as a standalone SaaS application — its web presence on third-party websites is minimal, limited to optional integration components such as careers embeds or referral attribution widgets.
Deel holds EU-US Data Privacy Framework certification and offers a comprehensive Data Processing Agreement for GDPR-compliant data processing.
What This Script Does
When Deel scripts appear on third-party websites, they are typically one of two components:
1. Careers embed widget Deel offers companies a careers page embed that displays open contractor or employee roles sourced from the company's Deel account. The widget loads from Deel's CDN and renders job listings with title, location, type, and department filters.
- Scripts loaded:
embed.deel.comor similar CDN subdomain - Cookies set: Session-scoped functional cookies to preserve filter state (department, location). These are scoped to the widget interaction and expire with the session. No persistent tracking cookies are set on the host domain.
- Data collected: No visitor behavioural data is collected on the host site. Applicants who click a listing are redirected to
app.deel.comwhere application data (name, email, resume) is collected under Deel's privacy policy.
2. Referral attribution snippet Partners and affiliates may embed a Deel referral snippet to track sign-ups attributed to their referral link.
- Cookies set:
deel_ref— First-party persistent cookie set on click-through from a referral link. Stores the referral attribution identifier to credit sign-ups to the referring partner. Expiry: typically 30 days. - Data collected: Referral source identifier and timestamp. No browsing behaviour on the host site is tracked beyond the initial referral click event.
Core platform (app.deel.com): Within Deel's own application, standard SaaS authentication cookies, CSRF tokens, and session management cookies are used exclusively as first-party cookies on Deel's domain. These are not present on third-party websites.
Consent & Compliance
Consent category: Functional
When embedded on third-party websites, Deel scripts serve functional purposes — displaying available roles or recording a referral attribution tied to a user's deliberate click action. Neither use case involves behavioural profiling, cross-site tracking, or advertising.
Under GDPR and ePrivacy, session cookies for the careers widget qualify as strictly necessary for delivering the functional component. Referral attribution cookies serve a purpose directly connected to the user's deliberate action and have minimal privacy impact. No consent is typically required for these functional interactions, though referral cookies persisting beyond the session may warrant disclosure in a privacy notice.
Under CCPA/CPRA, the minimal data collected through third-party embeds does not typically trigger opt-out obligations. Data collection escalates only when an applicant voluntarily submits information on Deel's own platform, governed by Deel's privacy notice.
Deel holds EU-US Data Privacy Framework certification for US-bound data transfers and provides Standard Contractual Clauses through its DPA.
Should You Block This Without Consent?
No. Deel's third-party script presence is functional and minimal. The careers widget uses only session-scoped cookies for UI state. Referral snippets set a short-lived attribution cookie tied to a deliberate user action. Neither component performs behavioural tracking or advertising profiling on the host site.
Is Deel GDPR compliant?
Deel typically loads functional trackers, which are not strictly necessary for your site to work. Under the GDPR and the ePrivacy Directive, non-essential cookies and trackers must stay blocked until a visitor gives clear opt-in consent. So Deel can be fully GDPR compliant, but only if your site holds its scripts until consent is granted and lets visitors decline just as easily. Compliance depends on how your site loads Deel, not on Deel itself.
Consent Categories
Also Known As
Industries
Tracked Domains (1)
deel.comFunctionaldeel.com is a functional domain operated by Deel, used to run site features like chat, video, embeds, and preferences.
Frequently Asked Questions
Related Vendors
Manage consent for Deel
ConsentStack automatically detects and manages Deel trackers so your site stays compliant with global privacy regulations.