Overview
Wistia is a business video hosting platform built specifically for marketing and sales teams. Unlike YouTube or Vimeo, Wistia is designed for branded video hosting with deep engagement analytics, email capture, and CRM integrations. Its player embeds on websites with full analytics tracking of viewer behavior, making it a hybrid functional and marketing analytics tool.
What This Script Does
Wistia's embed loads a JavaScript player library that handles video playback and transmits engagement data to Wistia's analytics infrastructure.
Script Files and Domains
fast.wistia.com/embed/medias/{media-id}.jsonp— Initial embed configuration request.fast.wistia.com/assets/external/E-v1.js— The Wistia player JavaScript library. Approximately 100–200KB.embedwistia-a.akamaihd.net— Akamai CDN delivering video media segments.pipestone.wistia.com— Analytics event ingestion endpoint receiving viewer engagement data.distillery.wistia.com— Additional asset delivery endpoint.
Cookies and Storage Set
wistia-video-progress-{media-id}— localStorage key storing playback progress for each video. Allows users to resume from where they left off. Scoped to the host page, not shared cross-domain._wpt— Wistia Player Token cookie. Used for identifying viewers across sessions for returning viewer recognition and engagement analytics continuity. Persists for 1 year.wistiaid— Wistia visitor identifier cookie. Links viewing sessions to a persistent anonymous visitor ID for engagement analytics and email capture integration. Persists for 1 year.- Heatmap and viewing session data is stored in Wistia's platform linked to the visitor ID.
Data Collected Per Viewing Session
- Video play initiation, pause, resume, and completion events
- Watch percentage: seconds watched, percentage of total duration, rewatch events
- Engagement score: Wistia's proprietary metric combining completion rate, rewatch behavior, and interaction engagement
- Play rate: percentage of page loads on which the video was played (aggregate, not per-session)
- Viewer heatmaps: color-coded visualization of watched vs. skipped vs. rewatched seconds
- Click events on calls-to-action (CTAs) embedded in the player
- Turnstile/email capture form completions (if configured) — email address submitted within the player
- Geographic data derived from IP address (country, region)
Email Capture (Turnstile) Wistia's Turnstile feature pauses video playback at a configured timestamp and presents an email input form. Submitted email addresses are stored in Wistia and forwarded to connected integrations (HubSpot, Marketo, Salesforce, Mailchimp). This transforms the video embed into a lead generation tool.
Wistia Integrations Viewer engagement data can be synced to HubSpot (updating contact records with viewing history), Marketo (triggering lead scoring workflows), Pardot, and Salesforce. This downstream data sharing extends Wistia's privacy impact beyond the immediate viewing session.
Consent & Compliance
Consent category: Functional / Analytics / Marketing
- GDPR/ePrivacy: The
wistiaidand_wptpersistent cookies identify individual viewers across sessions, constituting personal data processing requiring consent under ePrivacy. When Turnstile email capture is active, the video embed becomes a lead generation tool requiring explicit marketing consent. When engagement data is synced to marketing automation platforms, the processing purpose shifts from functional to marketing. At minimum, analytics consent is required. Marketing consent is required if Turnstile, CRM sync, or audience retargeting features are in use. - CCPA/CPRA: Viewer engagement profiles, viewing history, and email capture data constitute personal information. Data forwarded to HubSpot, Marketo, or Salesforce represents data sharing with third-party service providers.
- IAB TCF: Wistia is not a standard IAB TCF vendor, but the use of persistent visitor identification cookies falls under Purpose 1 (Store and/or access information on a device) of the TCF framework.
- EU-US Data Privacy Framework: Wistia is a US company headquartered in Boston. It relies on SCCs and DPF for EU-to-US data transfers.
Should You Block This Without Consent?
Conditional. If Wistia is used purely for video playback without viewer identification cookies, CRM sync, or email capture, a functional basis may apply and blocking may not be required. However, Wistia's default configuration enables persistent viewer identification (wistiaid), engagement analytics, and the Turnstile lead capture feature — all of which require consent. In practice, Wistia should be blocked until at least analytics consent is granted. If email capture or CRM integration is active, marketing consent is required before the player loads.
Consent Categories
Also Known As
Industries
Tracked Domains (2)
wistia.comAnalyticswistia.netAnalyticsFrequently Asked Questions
Does Wistia require cookie consent?
Conditional. Wistia's default configuration sets wistiaid and _wpt persistent visitor identification cookies, requiring at least analytics consent under ePrivacy. If Turnstile email capture or CRM sync is active, marketing consent is required. Video playback without visitor tracking cookies or CRM integration may qualify under functional consent.
What cookies does Wistia set?
Wistia sets wistiaid (persistent visitor ID, 1 year) and _wpt (player token for returning viewer recognition, 1 year) as first-party cookies. LocalStorage stores wistia-video-progress-{media-id} for playback resumption. Engagement data — watch percentage, heatmaps, CTA clicks — is sent to pipestone.wistia.com and linked to the visitor ID.
How does ConsentStack handle Wistia?
ConsentStack detects Wistia through scripts from fast.wistia.com and the E-v1.js player library. Classified as functional and analytics, with marketing added when Turnstile or CRM sync is active. ConsentStack blocks the player until appropriate consent is granted, preventing wistiaid and _wpt cookies from being set before the consent gate clears.
Related Vendors
Manage consent for Wistia
ConsentStack automatically detects and manages Wistia trackers so your site stays compliant with global privacy regulations.