Overview
Livestorm is a browser-based video engagement platform used by businesses to host webinars, virtual conferences, and online product demos. Unlike desktop-installed conferencing tools, Livestorm is designed to be embedded directly on marketing and product websites, which means its registration widgets and video players load as third-party scripts on publisher pages. This makes it relevant to consent management whenever a site operator embeds a Livestorm event on their own domain.
What This Script Does
Livestorm embeds load scripts from app.livestorm.co or equivalent Livestorm infrastructure domains. The embed typically includes a registration widget that collects visitor name and email address, and a video player component for live or on-demand streams.
Cookies set by Livestorm scripts include a session identifier for maintaining registration state (ls_session, session-duration) and potentially a tracking cookie for measuring attendee engagement and conversion attribution (30–90 day persistence). Analytics events such as page view, widget impression, registration submit, and video play percentage are transmitted to Livestorm servers.
Client-side data collected includes page URL, referrer, device and browser metadata, and interaction events with the registration form and video player. For registered attendees, Livestorm processes name, email, and engagement data under its own privacy policy. From a site-owner perspective, the key concern is the tracking and analytics cookies that Livestorm may set on the embedding page for visitors who have not yet registered.
Consent & Compliance
Under GDPR and the ePrivacy Directive, Livestorm's session cookies that are strictly necessary for the registration widget to function may be exempt from consent requirements. However, analytics and marketing attribution cookies set to track conversion and engagement data require prior opt-in consent from EU visitors.
Under CCPA/CPRA, if Livestorm collects personal information from California residents via the embedded widget (names, emails, behavioral data), this constitutes data collection subject to disclosure requirements. Site owners must list Livestorm as a data processor and ensure opt-out rights are honored.
The consent category for Livestorm is mixed: the core registration and streaming functionality is functional, while engagement tracking and marketing attribution is marketing. Livestorm as a US-based service should be evaluated for EU-US Data Privacy Framework compliance in customer DPAs.
Should You Block This Without Consent?
Conditional. The video player and registration form serve a clear functional purpose and may be permitted under functional consent. The analytics and marketing attribution tracking cookies should be blocked until the visitor has provided consent. Configure your consent manager to load the Livestorm embed script only after functional consent is granted, and separately gate marketing tracking if distinguishable.
Is Livestorm GDPR compliant?
Livestorm typically loads functional and marketing trackers, which are not strictly necessary for your site to work. Under the GDPR and the ePrivacy Directive, non-essential cookies and trackers must stay blocked until a visitor gives clear opt-in consent. So Livestorm can be fully GDPR compliant, but only if your site holds its scripts until consent is granted and lets visitors decline just as easily. Compliance depends on how your site loads Livestorm, not on Livestorm itself.
Consent Categories
Also Known As
Industries
Tracked Domains (1)
livestorm.comFunctionallivestorm.com is a functional domain operated by Livestorm, used to run site features like chat, video, embeds, and preferences.
Frequently Asked Questions
Related Vendors
Manage consent for Livestorm
ConsentStack automatically detects and manages Livestorm trackers so your site stays compliant with global privacy regulations.