Pendo
Product analytics plus in-app guides, keyed to the visitor ID you pass it — identity-linked by design. US SaaS with an EU hosting option.
verified 2026-07-11 · grade set per the published methodology
How the grade breaks down
How little it collects, and whether collection is purpose-bound.
Whether it respects GPC, consent state, and tracking-prevention signals.
Cookieless vs. persistent IDs, cross-site linkage, fingerprinting risk.
Where data lives and whether it is shared with third parties.
How verifiable and documented its real behavior is.
At a glance
Pendo combines product analytics with in-app guides and surveys, and its data model is identity-based: the operator passes a visitor ID at install time (commonly an internal user ID or email), and every click and pageview the agent auto-collects is linked to that identity in Pendo’s cloud. The agent does not record typed form input by default, but auto-collected click data plus operator-supplied metadata can amount to a detailed per-user behavioral record. An EU hosting option exists alongside the default US environment. Consent gating and GPC honoring are not automatic — the operator must hold the agent back until consent is granted — and because guides inject content, the tool writes to the page as well as reading from it. The grade reflects an identity-resolved SaaS default that requires consent in most jurisdictions; what the operator passes as visitor metadata largely determines how much personal data ends up in Pendo.
Sources & basis for grade
Grades reflect documented behavior, vendor documentation, and ad.rip scans as of the date above. Each assessment is reproducible and vendors may request correction.
- Pendo agent / data-collection documentation
- Pendo privacy & security documentation (EU hosting option)
- Pendo DPA / sub-processor list