FlowConsent
ServicesHow it worksPricingBlogDocumentation
ServicesHow it worksPricingBlogDocumentationLog inTry FlowConsent
Log inTry FlowConsent
FlowConsent

GDPR-compliant consent, EU-hosted, live in under ten minutes — without a cookie wall.

EU-HOSTED·RGPD·SOC 2
Product
  • Services
  • How it works
  • Pricing
  • Extension
Company
  • Blog
  • Documentation
  • Solutions
  • FlowConsent App
Legal
  • Privacy Policy
  • Terms of Service
  • Legal notice
  • Cookies
© 2026 FlowConsent by BeBranded. All rights reserved.
FrancaisDeutschEspanol
All systems operational

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. Analytics
  4. Moneris Payment Gateway
M

Moneris Payment Gateway

AnalyticsWebsite

Related services

34SP.com

34SP.com is a digital analytics solution that helps businesses measure and understand their online performance through comprehensive data collection and analysis. It provides visitor tracking, behavioral insights, and conversion metrics across websites and applications. 34SP.com supports custom event tracking, audience segmentation, and automated reporting. With intuitive dashboards and visualization tools, 34SP.com enables informed decisions that improve experience and drive results.

Analytics
5

51.LA

51.LA is a digital analytics solution that helps businesses measure and understand their online performance through comprehensive data collection and analysis. It provides visitor tracking, behavioral insights, and conversion metrics across websites and applications. 51.LA supports custom event tracking, audience segmentation, and automated reporting. With intuitive dashboards and visualization tools, 51.LA enables informed decisions that improve experience and drive results.

Analytics

52Degrees

52Degrees is an analytics and measurement platform providing deep insights into digital ecosystem performance. It tracks user interactions, measures campaign effectiveness, and identifies optimization opportunities across web and mobile. 52Degrees offers customizable dashboards, automated alerts, and data export capabilities. By transforming raw data into actionable intelligence, 52Degrees empowers organizations to optimize strategy and maximize return on investment.

Analytics
A

a3 Lazy Load

a3 Lazy Load is a comprehensive e-commerce platform that provides businesses with all the tools needed to build, manage, and grow an online store. From product catalog management and secure payment processing to inventory tracking and order fulfillment, a3 Lazy Load delivers a complete commerce solution. It features responsive storefront themes, SEO-optimized product pages, and powerful marketing tools to help merchants increase visibility and drive sales across channels.

Analytics
A

Able CDP

Able CDP is a digital analytics solution that helps businesses measure and understand their online performance through comprehensive data collection and analysis. It provides visitor tracking, behavioral insights, and conversion metrics across websites and applications. Able CDP supports custom event tracking, audience segmentation, and automated reporting. With intuitive dashboards and visualization tools, Able CDP enables informed decisions that improve experience and drive results.

Analytics
A

Abralytics

Abralytics is an analytics and measurement platform providing deep insights into digital ecosystem performance. It tracks user interactions, measures campaign effectiveness, and identifies optimization opportunities across web and mobile. Abralytics offers customizable dashboards, automated alerts, and data export capabilities. By transforming raw data into actionable intelligence, Abralytics empowers organizations to optimize strategy and maximize return on investment.

Analytics
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does Moneris Payment Gateway do?

Moneris is a major Canadian payment gateway that processes cardholder data under PCI DSS, with checkout scripts that may set cookies and pixels.

What Moneris is

Moneris is a major Canadian payment gateway and processor used by merchants to accept card payments online and in store. It offers hosted tokenization, which keeps payment details on Moneris systems while the customer stays on the merchant website. By handling the sensitive card data itself, Moneris helps merchants reduce their own exposure to cardholder information. It operates under the strict requirements of the Payment Card Industry Data Security Standard.

What data and cookies it collects

During checkout Moneris processes cardholder data such as the card number, expiry and security code, along with transaction amounts and identifiers. Its hosted payment pages and scripts may set cookies and use pixel tags, including a cookie that links a browser to tokenized card numbers, and in some deployments the Offlinx cookie. This information is personal data under the GDPR and includes financial details that are particularly sensitive. The card number itself is also regulated cardholder data under PCI DSS.

GDPR and ePrivacy implications

Processing payment data to fulfil an order generally rests on the performance of a contract under the GDPR, so consent is not required for the payment itself. However, any cookies that are not strictly necessary, such as marketing or analytics cookies set at checkout, still require prior consent under Art. 5(3) of the ePrivacy Directive. The merchant and Moneris must clarify their respective controller and processor roles and put an appropriate agreement in place. Transparency about the financial processing and the parties involved is essential.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Consent requirements

The payment processing does not need consent because it is necessary to perform the contract with the customer. Strictly necessary checkout cookies that simply make the payment work are also exempt from the consent rule. Any additional cookies used for marketing, fraud profiling beyond what is necessary, or analytics must be gated behind a consent banner. Where the Offlinx cookie or similar advertising features are present, they must remain off until the visitor opts in.

International data transfers

Moneris processes data in Canada, which benefits from a partial EU adequacy decision covering commercial activity under PIPEDA, so transfers from the EU to Canada require no additional safeguards. This is an important nuance that distinguishes Moneris from United States based providers. However, Moneris states it may transfer personal data onward to the United States and the Philippines, and those onward transfers need Standard Contractual Clauses, a transfer impact assessment and supplementary measures. The merchant should confirm where data actually flows and document the safeguards accordingly.

Practical compliance steps

Confirm the controller and processor roles with Moneris and conclude a data processing agreement that addresses cardholder data and onward transfers. Rely on hosted tokenization to keep card data out of your own systems and stay within PCI DSS scope. Gate any non essential checkout cookies behind a consent banner and disclose Moneris clearly in the privacy and cookie policies. Map the data flows to Canada, the United States and the Philippines, and document the adequacy decision and the clauses used.

GDPR consent category

Analytics

Websites using Moneris Payment Gateway must obtain user consent under GDPR regulations.

Legal basisPerformance of a contract under Art. 6(1)(b) GDPR for processing the payment, with prior consent under Art. 5(3) ePrivacy Directive for any non essential cookies set during checkout
Risk levelhigh
Applicable regulationsGDPR, ePrivacy Directive, PCI DSS, EU adequacy decision for Canada (PIPEDA)

DPIA considerations

Although payment processing relies on contract rather than consent, the sensitivity of cardholder data and the volume of transactions can still warrant a data protection impact assessment, especially where fraud scoring or profiling is involved. Assess the data flows to Moneris in Canada and any onward transfers to the United States or the Philippines, the PCI DSS scope and the cookies set at checkout. Document the lawful basis, the transfer mechanisms and the security measures protecting the payment data.

Sample consent text

We process your payment through Moneris, a Canadian payment provider, to complete your order securely. Card data is handled under PCI DSS and Canada benefits from an EU adequacy decision. Optional cookies set during checkout run only after you accept them.

Technical details

Tracking methodPayment gateway with hosted tokenization and a checkout iframe or script that processes cardholder data and may set pixels and cookies during the payment flow
Server locationCanada (Moneris processing infrastructure, covered by the EU adequacy decision for Canada under PIPEDA)
Data transferred outside the EUCardholder and transaction data is processed in Canada, which benefits from a partial EU adequacy decision covering commercial activity under PIPEDA, so transfers to Canada need no additional safeguards. Moneris also states it may transfer personal data onward to the United States and the Philippines, and those onward transfers require Standard Contractual Clauses, a transfer impact assessment and supplementary measures.

Third-party domains contacted

moneris.comwww3.moneris.comgateway.moneris.comesqa.moneris.com

Cookies placed

NameTypeDurationPurpose
moneris_tokenthird partySessionLinks the customer browser to tokenized card numbers during hosted tokenization so the payment can be completed securely.
Offlinxthird party2 yearsAdvertising and behavioural cookie used by Moneris on participating merchant sites, which requires consent and can be opted out.
JSESSIONIDthird partySessionMaintains the secure session on the Moneris hosted payment page so the checkout flow works correctly.

Moneris Payment Gateway collects user analytics data — you legally need a consent banner. Try FlowConsent free.

Get started freeScan your site

Frequently asked questions

Which cookies does Moneris set?

During hosted checkout Moneris may set a session cookie such as JSESSIONID and a token cookie that links the browser to tokenized card numbers, both used to complete the payment securely. On participating merchant sites it may also set the Offlinx advertising cookie. The payment cookies are strictly necessary, while advertising cookies like Offlinx require consent.

Is consent required to use Moneris?

Consent is not required for the payment processing itself or for the strictly necessary cookies that make checkout work, because these rest on contract and the ePrivacy exemption. Consent is required for any non essential cookies, such as the Offlinx advertising cookie or analytics scripts set at checkout. Those must stay blocked until the visitor opts in.

What is the legal basis for the processing?

The lawful basis for processing payment data is the performance of a contract under Art. 6(1)(b) GDPR, since the payment is needed to fulfil the order. Compliance with legal obligations may also apply to record keeping and fraud prevention. Any non essential cookies require consent under Art. 5(3) of the ePrivacy Directive.

Does Moneris transfer data to the United States?

Moneris processes data primarily in Canada, which has an EU adequacy decision for commercial data under PIPEDA, so EU to Canada transfers need no extra safeguards. However Moneris states it may transfer personal data onward to the United States and the Philippines. Those onward transfers require Standard Contractual Clauses, a transfer impact assessment and supplementary measures.

Is a DPIA needed for Moneris?

A data protection impact assessment may be warranted because cardholder data is sensitive and processing volumes are typically high, particularly where fraud scoring or profiling occurs. The assessment should consider the Canada adequacy decision, the onward transfers and the PCI DSS controls. Document the safeguards even where the core payment relies on contract.

How do I implement Moneris compliantly?

Use hosted tokenization so cardholder data stays with Moneris and your PCI DSS scope is reduced. Conclude a data processing agreement, define controller and processor roles and record the transfer position for Canada and any onward countries. Block non essential checkout cookies behind a consent banner and keep your security measures and documentation current.

Are there alternatives to Moneris?

European payment service providers such as Adyen, Stripe Europe or Worldline can keep payment processing within the EU or EEA and simplify the transfer analysis. Other adequacy covered or framework certified providers may also be suitable depending on the markets served. Any alternative still needs PCI DSS compliance, a clear lawful basis and proper handling of checkout cookies.

How should I update my cookie policy for Moneris?

Distinguish the strictly necessary payment cookies, which do not need consent, from advertising cookies like Offlinx, which do. Name Moneris as a Canadian payment provider and note the adequacy decision plus any onward transfers to the United States and the Philippines. Explain how visitors can opt out of advertising cookies and keep the policy aligned with the live checkout configuration.