FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. E-commerce
  4. Apple Pay
A

Apple Pay

PreferencesWebsite

Related services

24nettbutikk

24nettbutikk is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. 24nettbutikk supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, 24nettbutikk ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Preferences

2ClickShop

2ClickShop is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 2ClickShop integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 2ClickShop helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences

4-Tell

4-Tell is a marketing platform that equips businesses with tools to amplify their digital presence and drive customer acquisition. It supports audience segmentation, campaign automation, and cross-channel engagement. 4-Tell provides real-time analytics and reporting dashboards for performance measurement and strategy optimization. By combining data intelligence with marketing execution, 4-Tell helps deliver the right message to the right audience at the right time.

Preferences

42stores

42stores is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 42stores integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 42stores helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences

4Partners

4Partners is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 4Partners integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 4Partners helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences
4

4Partners CMS

4Partners CMS is a powerful content management system (CMS) designed to help businesses and developers build, manage, and publish digital content with ease. It offers a flexible architecture that supports custom content types, templates, and workflows, making it ideal for websites of any scale. With 4Partners CMS, teams can streamline content creation, improve collaboration, and deliver engaging web experiences. Its extensible plugin ecosystem and API-first approach ensure seamless integration with.

Preferences
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does Apple Pay do?

Apple Pay is the contactless and online payment service of Apple, integrated with Safari and the iOS Wallet to let users pay with the card stored on their device.

What is Apple Pay?

Apple Pay is the contactless and online payment service of Apple. On the web, merchants integrate Apple Pay through the Apple Pay JS API on Safari or through a payment service provider (Stripe, Adyen, Braintree, Worldline). The user authorises the payment with Face ID, Touch ID or a passcode, and the device generates a tokenised payment credential bound to the merchant. The card number is never shared with the merchant or the publisher. For European users, Apple Distribution International in Ireland is the customer facing entity.

What data and cookies does Apple Pay collect?

Apple Pay on the web requires a domain verification file hosted on the merchant (well known apple-developer-merchantid-domain-association). The Apple Pay button does not drop tracking cookies on the publisher domain. A small number of strictly necessary cookies are set on apple.com when the user is signed in to their Apple account. The merchant receives the encrypted payment token, the billing address (if requested) and the shipping address (if requested), but not the underlying card details. Transaction signals like device location and Apple risk scores are processed inside Apple infrastructure to validate the payment.

GDPR and ePrivacy implications

Apple Pay is one of the most privacy friendly payment options for European publishers. The few cookies it sets are strictly necessary for the payment and fall under the article 5(3) ePrivacy exemption. The card data is tokenised on the device and never reaches the merchant in clear. Apple processes transaction signals as an independent controller under its own Apple privacy notice. The publisher acts as a controller for the order data it receives back from Apple Pay.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Consent management with Apple Pay

You can display the Apple Pay button without a separate consent because it does not set non essential cookies. Inform users about Apple Pay in your privacy notice and identify Apple Distribution International (for EEA) and Apple Inc. (for global flows) as independent controllers. Provide a link to the Apple privacy notice and to the Apple Pay specific privacy section.

Data residency and Apple DPF

Apple Distribution International (Cork, Ireland) is the EEA customer facing entity. Apple Inc. (Cupertino, California) operates the broader Apple Pay infrastructure. Some flows can involve Apple Inc. infrastructure in the United States. Transfers rely on EU SCCs and the Apple Inc. DPF certification under the EU US Data Privacy Framework.

Practical compliance checklist

Register your domain with Apple and host the domain verification file. Sign the Apple Pay Merchant Agreement through your payment service provider. Display the button without a separate consent. Inform users in your privacy notice that Apple Pay is used. Identify Apple Distribution International and Apple Inc. as controllers. Document any data you receive back from Apple Pay (billing and shipping addresses) in your records of processing activities.

GDPR consent category

Preferences

Websites using Apple Pay must obtain user consent under GDPR regulations.

Legal basisPerformance of a contract (article 6(1)(b) GDPR) for the payment processing, with a strictly necessary classification for the limited Apple cookies that the button may set. Apple Pay sets very few cookies and most data flows occur through native Wallet APIs, not through tracking cookies.
Risk levellow
Applicable regulationsGDPR, ePrivacy Directive, TTDSG, LOPDGDD, French Data Protection Act, UK GDPR and PECR, PCI DSS, PSD2 SCA, EMVCo Payment Tokenisation

DPIA considerations

Apple Pay is generally low risk because card data is tokenised on the device and never reaches the merchant or the publisher servers in clear. A DPIA may be appropriate when Apple Pay is paired with Apple Sign In, when the merchant runs subscriptions with stored Apple Pay tokens, or when the merchant aggregates transaction data with broader profiling.

Sample consent text

We use Apple Pay to let you check out with the card stored on your Apple device. Apple Pay does not share your card number with us, it generates a one time payment token signed by your device. Apple Pay sets only very limited technical cookies that are strictly necessary for the payment, so no separate consent is required for the button to display.

Technical details

Tracking methodApple Pay JavaScript SDK and Apple Pay JS API on Safari with native Wallet integration on iOS, very limited cookies and a domain verification file hosted on the merchant
Server locationApple Inc. (United States) and Apple Distribution International (Ireland) on Apple infrastructure
Cookieless tracking availableYes
Data transferred outside the EUApple Pay is operated by Apple Inc. (United States) and Apple Distribution International (Ireland) for EEA users. Card data is tokenised on the device and never shared in clear with the merchant. Some flows can involve Apple infrastructure in the United States. Transfers rely on Apple Inc. DPF certification and EU SCCs.

Third-party domains contacted

apple.comapple-pay-gateway.apple.comapple-pay-gateway-cert.apple.comsmp-device.apple.com

Cookies placed

NameTypeDurationPurpose
s_viStrictly Necessary2 yearsApple visitor identifier used by the Apple Pay backend on apple.com to maintain the merchant transaction context.
geoStrictly NecessarySessionStores the user country and region for the Apple Pay availability check.
dssidStrictly NecessarySessionApple session identifier used during the Apple Pay authentication and confirmation step.
dssfStrictly Necessary1 yearApple secure flag cookie used to protect the Apple Pay session against forged requests.

Apple Pay uses cookies for user preferences — inform visitors with a consent banner.

Get started freeScan your site

Frequently asked questions

What cookies does Apple Pay set?

Apple Pay sets very few cookies. A small number of strictly necessary cookies on apple.com (s_vi, geo, dssid, dssf) appear when the user is signed in to an Apple account. No tracking cookies are dropped on the publisher domain.

Is consent required to display the Apple Pay button?

No. The Apple Pay button does not set non essential cookies on the publisher domain. The strictly necessary cookies set on apple.com fall under the article 5(3) ePrivacy exemption.

What is the legal basis for Apple Pay?

Performance of a contract (article 6(1)(b) GDPR) for the payment, and legitimate interest (article 6(1)(f) GDPR) for the Apple side fraud prevention.

What about US data transfers?

Apple Distribution International is in Ireland but some flows involve Apple Inc. in the US. Transfers rely on EU SCCs and the Apple Inc. DPF certification.

Do I need a DPIA for Apple Pay?

Generally no. Apple Pay is low risk because card data never reaches the merchant. A DPIA may be appropriate when Apple Pay is paired with Apple Sign In, when subscriptions use Apple Pay tokens, or when transaction data feeds broader profiling.

How do I implement Apple Pay compliantly?

Register your domain with Apple. Host the merchant ID domain association file. Sign the Apple Pay Merchant Agreement via your PSP. Display the button without separate consent. Inform users in your privacy notice.

What are the alternatives to Apple Pay?

Google Pay, Amazon Pay, PayPal Express, Shop Pay, Klarna Pay Now, GoCardless, Stripe Link, Adyen, Mollie or local methods (Bancontact, iDEAL, Sofort, Bizum).

How do I document Apple Pay in my cookie policy?

Note that Apple Pay does not set tracking cookies on your domain. Identify Apple Distribution International and Apple Inc. as controllers in the privacy notice. Link to the Apple privacy notice and Apple Pay specific section.