Overview
Freshpaint is a HIPAA-compliant customer data infrastructure platform designed for healthcare organizations. It captures web behavior events and routes them to analytics, marketing, and CRM tools while enforcing patient data governance rules.
What This Script Does
The Freshpaint script captures user interaction events on web pages including page views, clicks, form interactions, and custom events. It collects browser metadata, session information, and page context. Freshpaint's governance layer can redact or filter protected health information (PHI) before forwarding data to connected third-party destinations. The script sets cookies or uses localStorage for visitor identification and session tracking. Data is sent to Freshpaint's servers where governance rules are applied before distribution to configured analytics and marketing platforms.
Consent & Compliance
- Consent Category: Analytics
- Cookies/Storage: Sets first-party cookies for visitor identification and session tracking. Uses localStorage for event queuing.
- GDPR/ePrivacy: Requires consent. Despite HIPAA compliance features, Freshpaint collects behavioral data and sets non-essential cookies for analytics purposes. HIPAA compliance does not exempt the script from ePrivacy consent requirements.
- CCPA: Behavioral data collection constitutes personal information. While Freshpaint acts as a service provider, downstream data routing to marketing platforms may trigger sharing obligations.
Should You Block This Without Consent?
Yes. Freshpaint collects behavioral analytics data and sets tracking cookies. While its HIPAA governance features are valuable for healthcare organizations, the underlying data collection mechanism requires consent under GDPR/ePrivacy. Block until analytics consent is granted.
Is Freshpaint GDPR compliant?
Freshpaint typically loads analytics trackers, which are not strictly necessary for your site to work. Under the GDPR and the ePrivacy Directive, non-essential cookies and trackers must stay blocked until a visitor gives clear opt-in consent. So Freshpaint can be fully GDPR compliant, but only if your site holds its scripts until consent is granted and lets visitors decline just as easily. Compliance depends on how your site loads Freshpaint, not on Freshpaint itself.
Consent Categories
Also Known As
Industries
Tracked Domains (2)
cdn.freshpaint.ioAnalyticscdn.freshpaint.io is an analytics domain operated by Freshpaint, used to measure visits, sessions, and on-site behavior.
perfalytics.comAnalyticsperfalytics.com is an analytics domain operated by Freshpaint, used to measure visits, sessions, and on-site behavior.
Frequently Asked Questions
Related Vendors

Manage consent for Freshpaint
ConsentStack automatically detects and manages Freshpaint trackers so your site stays compliant with global privacy regulations.