Tracker library

Intercom: what it is, what it sets, and how to gate it.

Live chat and in-app messaging, classified as functional because a visitor who opens a chat expects the chat to work, but it is not automatically consent-exempt.

Vendor
Intercom
Scanner category
functional
Consent category
Functional
Control
Custom script or container tag

What it is

Intercom provides a messenger widget and ties conversations to a visitor or user record. The scanner classifies it as functional: the site would visibly lose a feature without it, which is the test the catalogue applies.

Functional is not the same as necessary. Necessary means strictly necessary for a service the visitor explicitly requested. A chat widget that loads on every page before anyone has asked for support is closer to a convenience than a requirement, and several regulators have said so about chat and similar widgets.

What a scan matches

A verification scan drives a real browser and records the outbound requests observed during its configured journeys, so Intercom is identified by request hosts and paths rather than by source-code claims. Requests on unvisited paths, after unperformed interactions or solely on the server remain outside that observation.

  • intercom.io
  • intercomcdn.com
  • intercomassets.com

Cookies are classified by name before domain because many analytics and advertising tags write first-party cookies through the page, which places a vendor-related identifier on your domain. Matching known names helps attribute those values without assuming that every first-party cookie came from your own application.

CookieWhat it is for
intercom-*Session and device identifiers for the messenger, matched by prefix

Controlling it with consent

No named adapter. Attach it to the functional category, or (the pattern many sites prefer) load the launcher lazily and only initialise the messenger when a visitor actually clicks it.

Where Intercom is used to identify signed-in users, that identity flow is separate from the widget and needs its own consideration.

No named adapter: choose the appropriate control

The product ships named adapters for Google Tag Manager, Google Analytics, the Meta and TikTok pixels, and Klaviyo. Choose the control route that fits this technology: a custom HTTPS script declaration for a browser loader, an individual consent condition inside a tag manager, a platform or app setting, or a click-to-load placeholder for a frame. Server-side integrations need their own enforcement because a browser runtime cannot stop them.

What breaks if it is refused: the chat widget. That is a real cost, and it is the reason a click-to-load pattern is often the better answer than a hard gate.

Verifying it

Before consent there should be no intercom- cookie. Then check whether the widget loads at all, and decide deliberately whether a visitor who refused functional should still be able to reach support.

  • Before a choice: optional tracking endpoints and optional identifiers are absent; any intentionally loaded necessary or functional surface matches the control model described above
  • After rejecting optional categories: optional activity remains absent and the refusal persists across a reload
  • After granting the relevant category: the expected loader or embed appears and the feature behaves normally
  • After withdrawing: new optional activity stops; where the vendor supports a consent signal, verify that the signal is sent as well as checking network behavior

Common questions

Is live chat strictly necessary?

Rarely, in the legal sense. It is a service the visitor may want rather than one they asked for by loading the page. The functional category exists for exactly this middle ground.

Can I load chat only when someone clicks?

Yes, and it is a good pattern. The click is an explicit request for the service, which strengthens the necessity argument and improves page performance at the same time.

Sources and verification

Verified on . Product-behaviour statements were checked against the current implementation and tests. The links below are the verification basis recorded for this article. They support the stated facts, not a legal conclusion for every site or configuration; recheck changing vendor behaviour before relying on it in production.

See what your own site is loading

A browser scan reports the requests and storage it observed during the sampled journey. Use configured workspace scans to compare the states and pages that matter to your implementation.