FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. E-commerce
  4. Afterpay

Afterpay

PreferencesWebsite

Related services

24nettbutikk

24nettbutikk is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. 24nettbutikk supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, 24nettbutikk ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Preferences

2ClickShop

2ClickShop is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 2ClickShop integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 2ClickShop helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences

4-Tell

4-Tell is a marketing platform that equips businesses with tools to amplify their digital presence and drive customer acquisition. It supports audience segmentation, campaign automation, and cross-channel engagement. 4-Tell provides real-time analytics and reporting dashboards for performance measurement and strategy optimization. By combining data intelligence with marketing execution, 4-Tell helps deliver the right message to the right audience at the right time.

Preferences

42stores

42stores is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 42stores integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 42stores helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences

4Partners

4Partners is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 4Partners integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 4Partners helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences
4

4Partners CMS

4Partners CMS is a powerful content management system (CMS) designed to help businesses and developers build, manage, and publish digital content with ease. It offers a flexible architecture that supports custom content types, templates, and workflows, making it ideal for websites of any scale. With 4Partners CMS, teams can streamline content creation, improve collaboration, and deliver engaging web experiences. Its extensible plugin ecosystem and API-first approach ensure seamless integration with.

Preferences
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does Afterpay do?

Afterpay is a buy now pay later (BNPL) provider owned by Block, Inc. (also operator of Clearpay in the UK and EU). It lets shoppers split purchases into four interest free instalments. Merchants embed an Afterpay JavaScript SDK and price widget on product and checkout pages. Even before checkout, the widget loads scripts, sets cookies and transmits visitor and product data to Afterpay servers, which raises specific GDPR and ePrivacy obligations.

What is Afterpay

Afterpay is a buy now pay later (BNPL) service operated by Afterpay Pty Ltd, a wholly owned subsidiary of Block, Inc. (the parent company of Square and Cash App). In the United Kingdom and most of Europe the same service runs under the Clearpay brand. Shoppers split a purchase into four equal instalments paid every two weeks, with no interest and limited fees. Merchants integrate Afterpay through a JavaScript SDK that renders price widgets on product pages, a checkout button and a redirect flow to portal.afterpay.com or portal.clearpay.com where the consumer is identified and the credit decision is made.

What data and cookies Afterpay collects

The Afterpay widget sets first party and third party cookies for cart state, anti fraud signalling and analytics. It collects IP address, User Agent, viewed product pages, basket value, currency, merchant ID and a device fingerprint used by the fraud engine. At checkout, Afterpay collects name, address, email, phone, date of birth, payment method and, depending on the country, partial identifiers used for soft credit checks. Block, Inc. and its underwriting partners may consult external credit bureaus and fraud databases as part of the decision.

GDPR and ePrivacy implications

The Afterpay SDK loaded on product and category pages places cookies before checkout, which triggers Article 5(3) of the ePrivacy Directive. Those cookies are not strictly necessary for the user to access the merchant site, so consent is required before they are set. The processing of payment, identity and credit data during checkout itself can be based on the performance of a contract under Article 6(1)(b) GDPR, with fraud prevention typically grounded on legitimate interest under Article 6(1)(f). Automated decisions for credit scoring are subject to Article 22 GDPR safeguards.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Is consent required

Yes, for the widget, the price calculator and any analytics or marketing cookies set on category and product pages. The merchant should block the Afterpay SDK behind a consent gate and only load it once the user has accepted at least the functional or marketing category, depending on the cookies set. Inside the actual checkout, where the user has chosen Afterpay as the payment method, the strictly necessary processing of the order can proceed under contract, but transparency notices about the data shared with Block must still be provided.

Data transfers to the United States and Australia

Block, Inc. is headquartered in the United States and operates global infrastructure on AWS. The Australian entity also processes some data in Australia. Block self certified under the EU US Data Privacy Framework, which provides an adequacy decision for transfers to certified Block entities. For categories of data outside the DPF scope, Block relies on the new Standard Contractual Clauses with the related Transfer Impact Assessment. Merchants must list Block, Inc. and Afterpay Pty Ltd as recipients in their privacy policy and explain the transfer mechanism.

Practical compliance steps

Gate the Afterpay SDK behind the consent manager so the script only loads after the relevant categories are accepted. Sign a data processing or controller to controller agreement with Block, depending on the contractual setup in your country. Update the privacy policy with the categories of data shared, the transfer mechanism (DPF and SCCs) and the user rights regarding automated decisions. List the afterpay.com and clearpay.com domains and cookies in the cookie policy. Implement an opt out path that does not block the rest of the checkout when Afterpay is refused.

GDPR consent category

Preferences

Websites using Afterpay must obtain user consent under GDPR regulations.

Legal basisContract (Art. 6(1)(b) GDPR) for checkout, plus consent (Art. 6(1)(a) GDPR) for analytics, marketing widgets and fraud cookies set client side
Risk levelhigh
Applicable regulationsGDPR, ePrivacy Directive, PSD2, Consumer Credit Directive 2008/48/EC, TTDSG

DPIA considerations

A DPIA may be required when Afterpay is combined with credit scoring, fraud profiling or cross border data flows at scale. The processing involves financial data, automated decision making for credit assessment and transfers to the US and Australia, all of which are factors highlighted by EU DPAs as triggers for a formal DPIA under Art. 35 GDPR.

Sample consent text

We use Afterpay (Clearpay) to display payment options and process buy now pay later orders. This sets cookies and shares your IP address and purchase data with Block, Inc. in the United States. Do you accept?

Technical details

Tracking methodJavaScript SDK and iframe widget (afterpay.js), redirect to portal.afterpay.com for checkout flow, server to server API calls for order capture
Server locationUnited States and Australia (Block, Inc. and Afterpay Pty Ltd, regional infrastructure in EU via AWS for European merchants)
Data transferred outside the EUPersonal data is transferred to Block, Inc. in the United States and to Afterpay Pty Ltd in Australia. Block relies on EU Standard Contractual Clauses and the EU US Data Privacy Framework certification. Australia is recognised as a jurisdiction with an EU adequacy assessment for credit reporting under specific conditions.

Third-party domains contacted

afterpay.comstatic.afterpay.comjs.afterpay.comportal.afterpay.comapi.afterpay.comclearpay.comportal.clearpay.comjs.clearpay.comstatic.clearpay.co.uk

Cookies placed

NameTypeDurationPurpose
ap_sso_sessionthird partySessionMaintains the authenticated session between portal.afterpay.com and the merchant site during a BNPL transaction.
ap_segment_idthird party13 monthsAnonymous segmentation identifier used by Afterpay analytics and fraud engine to recognise repeat devices across merchants.
afterpay_device_idthird party1 yearDevice fingerprint identifier used by Afterpay risk and credit decisioning to detect fraud and duplicate accounts.
_ap_sessionthird partySessionShort lived session cookie for the widget rendering and checkout redirect flow.
cf_clearancethird party30 daysCloudflare bot mitigation cookie set on Afterpay domains to validate that the request comes from a real browser.
OptanonConsentthird party1 yearOneTrust consent state cookie set on afterpay.com when the user visits Afterpay owned pages, recording the cookie preferences.

Afterpay uses cookies for user preferences — inform visitors with a consent banner.

Get started freeScan your site

Frequently asked questions

What cookies does Afterpay set on a merchant site?

The widget sets cookies such as ap_sso_session for portal authentication, ap_segment_id for fraud and analytics segmentation, and a fraud device fingerprint id used for risk scoring. Additional measurement cookies (Google Analytics, internal counters) may be loaded depending on the merchant integration. All non strictly necessary cookies must be gated behind consent.

Is consent required for Afterpay in the EU?

For the product page widget, the price calculator and any marketing cookies the answer is yes: these are set before payment and are not strictly necessary. Inside checkout, after the user has chosen Afterpay, the strictly necessary processing can proceed under contract, but the consent banner should still surface the data sharing in a transparent way.

What is the legal basis for processing personal data with Afterpay?

Three bases coexist: contract (Art. 6(1)(b) GDPR) for completing the BNPL order, legitimate interest (Art. 6(1)(f)) for fraud prevention and credit risk, and consent (Art. 6(1)(a)) for non essential cookies, marketing and combined profiling. Where automated credit decisions are taken, Article 22 GDPR safeguards (human review, contestability) apply.

Are there data transfers to the United States with Afterpay?

Yes. Block, Inc. is a US controller and operates infrastructure on AWS globally. Block is self certified under the EU US Data Privacy Framework. Where data falls outside the DPF, transfers rely on Standard Contractual Clauses plus a Transfer Impact Assessment. Some processing also occurs in Australia at Afterpay Pty Ltd.

Do I need a DPIA before integrating Afterpay?

Often yes. The combination of credit scoring, automated decisions, large scale processing of payment data and international transfers ticks several factors on the EDPB criteria. A DPIA is the safest path even for medium sized merchants, especially when Afterpay is combined with other tracking on the same checkout funnel.

How do I integrate Afterpay in a GDPR compliant way?

Load the Afterpay SDK only after consent for the relevant category, sign the appropriate data processing or controller agreement with Block, update the privacy policy with recipient and transfer information, and add Afterpay cookies and domains to your cookie policy. Make sure the BNPL choice is one option among others and that the user can complete the checkout without it.

What are the alternatives to Afterpay?

EU based BNPL providers (Klarna, Alma, Scalapay, Cofidis 4xCB) offer comparable services with EU data processing in many cases. They still require care, but the transfer risk is typically lower. Traditional payment methods (cards, SEPA Direct Debit, PayPal) remain available for users who refuse BNPL or related tracking.

How should I update my cookie policy for Afterpay?

Add Afterpay (Clearpay) under the Marketing or Functional category as appropriate. List the cookies (ap_sso_session, ap_segment_id, device fingerprint identifiers), the provider (Afterpay Pty Ltd and Block, Inc.), the purpose (order processing, fraud prevention, analytics) and the transfer mechanism (DPF or SCC). Update the policy whenever Afterpay changes its cookie list.