Criteo

Criteo

Specializes in commerce media retargeting, serving personalized product ads to users who have previously browsed or purchased from retail sites. The Criteo OneTag fires on product and confirmation pages to log catalog item views and conversions. Syncs user identifiers with retailers to power cross-site product recommendations.

Overview

Criteo is a global commerce media company specializing in retargeting — delivering personalized product ads to users who have previously browsed or purchased from retail and e-commerce sites. Founded in Paris in 2005 and listed on NASDAQ, Criteo operates one of the largest retargeting networks globally, processing billions of shopping signals daily across more than 22,000 advertiser clients. Its script — the Criteo OneTag — fires on product detail, cart, and order confirmation pages to capture browsing and purchase intent signals that fuel its cross-site product recommendation engine. Criteo's demand-side platform (DSP) then serves personalized carousel ads displaying the exact products a user viewed, on thousands of publisher sites.

What This Script Does

Script Files and Domains

The Criteo OneTag loads from static.criteo.net/js/ld/publishertag.prebid.js or sslwidget.criteo.com/p. Tracking beacons fire to dis.eu.criteo.com (EU data endpoint), dis.us.criteo.com (US data endpoint), and gum.criteo.com (cookie sync). RTB bid requests originate from bidder.criteo.com.

Cookies Set

  • uid — Criteo's primary cross-site user identifier. Persistent, 13-month expiry. Third-party cookie set on criteo.com domain. The backbone of Criteo's retargeting system — this cookie links browsing sessions across all Criteo partner sites.
  • optout — Stores user opt-out preference if the user has opted out via privacy.criteo.com.
  • gcuid — Google Click User ID, set when Criteo integrates with Google's cookie matching infrastructure.
  • cto_bundle — Criteo's publisher-side user sync token, used to maintain user identity in environments where third-party cookies are blocked (e.g., Safari ITP). Set as a first-party cookie on the publisher's domain.
  • cto_tld_test — A temporary test cookie used to determine the highest-level domain on which first-party cookies can be set.

OneTag Events

The OneTag fires structured events on key pages:

  • viewHome — Homepage visits
  • viewList — Category/search results pages (with category and keyword data)
  • viewItem — Product detail pages (with product ID, price, availability)
  • viewCart — Shopping cart pages (with item list, quantities, values)
  • trackTransaction — Order confirmation pages (with order ID, items, revenue)

Each event includes the retailer's product catalog identifiers, enabling Criteo to match viewed products against its cached product feed and render accurate carousel ads.

Identifier Sync and Identity Graph

Criteo participates in cookie syncing with Google (DoubleClick), Amazon, The Trade Desk, and other major ad platforms via gum.criteo.com, exchanging user identifiers to expand its retargeting reach. Criteo also maintains a Universal Login Graph built from hashed email addresses captured from retailer login events, enabling cross-device retargeting even when third-party cookies are unavailable.

Header Bidding

Criteo participates in Prebid.js header bidding auctions via the criteo_fastbid adapter. The script evaluates publisher ad inventory and submits real-time bids containing Criteo's retargeting user ID.

Consent & Compliance

Category: Marketing

Criteo is a registered IAB TCF 2.2 vendor (Vendor ID 91). TCF purposes exercised: Purpose 1 (Store/access information on device), Purpose 2 (Select basic ads), Purpose 3 (Create personalised ads profile), Purpose 4 (Select personalised ads), Purpose 5 (Create personalised content profile), Purpose 6 (Select personalised content), Purpose 7 (Measure ad performance). Special Purpose 1 (security, fraud prevention) and Special Feature 1 (precise geolocation) are also declared.

Under GDPR, Criteo requires explicit consent for all tracking and retargeting operations. The French CNIL fined Criteo €40 million in June 2023 for violations including collecting behavioral data without valid consent and failing to verify that consent signals received from publishers were freely given and informed. This is one of the largest CNIL enforcement actions against an ad tech company and directly confirms the GDPR status of Criteo's tracking operations.

Criteo is headquartered in Paris (EU) with major operations in the US. EU data is processed on dis.eu.criteo.com endpoints. Criteo is registered under the EU-US Data Privacy Framework for transatlantic transfers.

Under CCPA/CPRA, Criteo's behavioral data sharing with demand partners constitutes sale or sharing of personal information.

Should You Block This Without Consent?

Yes. Criteo is an advertising retargeting platform that sets persistent third-party cookies, builds cross-site behavioral profiles from browsing and purchase data, and syncs identifiers with dozens of ad partners. The CNIL's €40 million fine in 2023 confirms regulators' view that Criteo tracking without valid consent is unlawful. Block the OneTag entirely until explicit marketing consent is obtained.

Visit website

Consent Categories

Marketing

Also Known As

Criteo OneTagCriteo retargetingCriteo pixelcommerce media retargetingCriteo cookieCriteo GDPR

Industries

Business and Consumer ServicesMarketing and Advertising

Tracked Domains (2)

criteo.comMarketing
criteo.netMarketing

Frequently Asked Questions

Does Criteo require explicit consent under GDPR?

Yes. Criteo is IAB TCF 2.2 Vendor ID 91 and requires consent for all retargeting and profiling. The French CNIL issued a 40 million euro fine in June 2023 confirming that Criteo tracking without valid consent is unlawful under GDPR and direct evidence of enforcement risk.

What cookies does the Criteo OneTag set?

The primary cookie is uid, a persistent 13-month cross-site identifier stored on criteo.com. The cto_bundle cookie is set as a first-party cookie on the publisher domain to maintain identity in Safari ITP environments where third-party cookies are unavailable.

How does ConsentStack handle Criteo on my website?

ConsentStack blocks the Criteo OneTag until the visitor grants marketing consent. It passes a valid TCF 2.2 consent string to Criteo so the platform receives a compliant signal. Revoking consent suppresses the OneTag on all subsequent page loads, stopping retargeting data collection.

Related Vendors

Google Ads
Google Ads
Google Ads is Google's advertising platform for search, display, and remarketing campaigns. Conversion tracking scripts fire on advertiser landing pages to measure actions taken after ad clicks. The remarketing tag builds audience lists for retargeting users across Google's ad network.
Google
Google
Google is the dominant provider of web analytics, advertising, and infrastructure tools. Scripts like Google Analytics, Tag Manager, Ads, and reCAPTCHA collect behavioral data, manage tag firing, serve targeted ads, and detect bots. Sets persistent cookies to track users and correlate activity across sites.
Microsoft Dynamics 365
Microsoft Dynamics 365
Microsoft Dynamics 365 is a suite of CRM and ERP applications that integrates with websites through tracking scripts and embedded forms. Web tracking code captures visitor behavior, page views, and form submissions to build customer profiles and score leads. Sets cookies to identify returning visitors and attribute marketing touchpoints across sessions.
Microsoft
Microsoft
Runs Clarity (session recording and heatmaps), the Microsoft Advertising UET tag (conversion tracking), and Bing's remarketing pixel. Clarity injects a recording script that captures mouse movements, clicks, and rage clicks. The UET tag fires conversion events to tie ad clicks to on-site actions across Microsoft's ad network.
Microsoft Advertising UET Tag
Microsoft Advertising UET Tag
Microsoft Advertising UET Tag is the Universal Event Tracking pixel for Microsoft's ad platform, formerly Bing Ads. The JavaScript tag fires on advertiser websites to track page views, conversions, and custom events for campaign optimization. Sets cookies to identify visitors across sessions and attribute conversions to Microsoft Search and Audience Network ad clicks.
LinkedIn Ads
LinkedIn Ads
LinkedIn Ads is LinkedIn's advertising platform for B2B marketing and professional audience targeting. Conversion tracking scripts and pixels fire on advertiser websites to measure sign-ups, downloads, and purchases driven by LinkedIn ad campaigns. Sets cookies for audience matching, retargeting list building, and cross-device attribution reporting.

Manage consent for Criteo

ConsentStack automatically detects and manages Criteo trackers so your site stays compliant with global privacy regulations.