FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. E-commerce
  4. Braintree
B

Braintree

Essential

Related services

24nettbutikk

24nettbutikk is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. 24nettbutikk supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, 24nettbutikk ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Preferences

2ClickShop

2ClickShop is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 2ClickShop integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 2ClickShop helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences

4-Tell

4-Tell is a marketing platform that equips businesses with tools to amplify their digital presence and drive customer acquisition. It supports audience segmentation, campaign automation, and cross-channel engagement. 4-Tell provides real-time analytics and reporting dashboards for performance measurement and strategy optimization. By combining data intelligence with marketing execution, 4-Tell helps deliver the right message to the right audience at the right time.

Preferences

42stores

42stores is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 42stores integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 42stores helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences

4Partners

4Partners is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 4Partners integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 4Partners helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences
4

4Partners CMS

4Partners CMS is a powerful content management system (CMS) designed to help businesses and developers build, manage, and publish digital content with ease. It offers a flexible architecture that supports custom content types, templates, and workflows, making it ideal for websites of any scale. With 4Partners CMS, teams can streamline content creation, improve collaboration, and deliver engaging web experiences. Its extensible plugin ecosystem and API-first approach ensure seamless integration with.

Preferences
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does Braintree do?

Braintree is the merchant payment processing platform of PayPal Holdings, offering credit card, PayPal, Venmo, Apple Pay, Google Pay and SEPA Direct Debit in a single integration.

What is Braintree?

Braintree is the merchant payment processing platform owned by PayPal Holdings Inc., headquartered in Chicago. It offers a single integration for card payments, PayPal, Venmo, Apple Pay, Google Pay, SEPA Direct Debit, Bancontact, iDEAL, Sofort, Klarna and many other local European payment methods. Merchants integrate Braintree through Hosted Fields (PCI scope reduced iframes), the Drop in UI or the GraphQL API. Behind the scenes, Braintree handles tokenisation, 3DS2 Strong Customer Authentication, fraud detection (Kount, ThreatMetrix) and the Vault for recurring payments.

What data and cookies does Braintree collect?

Braintree drops first party cookies on the merchant domain (BraintreeJS_ for the SDK state) and third party cookies on braintreegateway.com and paypal.com when PayPal or Venmo buttons are displayed (LANG, tsrce, x-pp-s, l7_az, ts, ts_c, _ga linked to paypal.com). The advanced fraud detection scripts (collector.js, data collector) fingerprint device attributes such as user agent, screen resolution, plug ins, fonts, IP and behavioural signals. Card data is tokenised and transmitted directly from the iframe to Braintree without ever touching the merchant server.

GDPR and ePrivacy implications

Payment cookies that are strictly necessary to complete the transaction requested by the user fall under the exemption of article 5(3) ePrivacy. The fraud detection scripts, however, go beyond what is strictly necessary in many cases and typically require consent, except where they can be justified by overriding legitimate interest in preventing payment fraud. CNIL and EDPB guidance distinguishes essential anti fraud features (allowed under legitimate interest) from broad behavioural profiling (which needs consent). Braintree and the merchant are independent controllers for the payment processing.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Consent management with Braintree

Load the Braintree Hosted Fields and Drop in UI without prior consent because they are strictly necessary to complete the payment. Load the advanced fraud detection collector.js only after the user has consented to the relevant purpose, or document a legitimate interest assessment that limits the data collected to what is necessary for fraud prevention. Do not preload PayPal Smart Buttons before consent if they trigger third party cookies on paypal.com beyond what is needed for the checkout.

Data transfers, PCI DSS and the EU gateway

Braintree provides an EU gateway hosted in Ireland (payments-eu.braintree-api.com), but card data and fraud signals can still be processed in the United States by PayPal Holdings for PCI DSS, anti money laundering, dispute management and risk scoring. Transfers rely on EU Standard Contractual Clauses and on the PayPal DPF certification. Document the transfer mechanism in your records of processing activities and clearly inform users in your privacy notice.

Practical compliance checklist

Sign the Braintree merchant agreement and the PayPal DPA with EU SCCs. Activate the EU gateway when possible. Trigger Hosted Fields and Drop in UI without consent (strictly necessary). Wrap the advanced fraud detector behind a CMP gate or document a legitimate interest assessment. List Braintree cookies in your cookie policy as Functional or Fraud Prevention. Identify PayPal (Europe) Sarl & Cie, S.C.A and PayPal Inc. as independent controllers in your privacy notice with the US transfer disclosure.

GDPR consent category

Essential

Websites using Braintree must obtain user consent under GDPR regulations.

Legal basisPerformance of a contract (article 6(1)(b) GDPR) for the actual payment processing, combined with legitimate interest for fraud prevention. Strictly necessary status applies to checkout cookies, but the fraud detection scripts that fingerprint the device usually require consent under article 5(3) ePrivacy.
Risk levelmedium
Applicable regulationsGDPR, ePrivacy Directive, TTDSG, PCI DSS, PSD2 Strong Customer Authentication, AMLD5, French Data Protection Act, UK GDPR and PECR

DPIA considerations

A DPIA is recommended whenever Braintree is paired with the advanced fraud detection scripts (Kount, ThreatMetrix), when merchants store cardholder data through the Vault feature for recurring billing, or when 3DS2 risk based authentication processes a broad set of behavioural signals.

Sample consent text

We use Braintree by PayPal to process your payments and to detect fraudulent transactions. Braintree sets cookies on your device to secure the checkout and to fingerprint suspicious behaviour. Payment cookies are strictly necessary, but the advanced fraud scripts that profile your device only run if you grant consent.

Technical details

Tracking methodHosted Fields JavaScript SDK, Drop in UI and direct API calls. First party fraud detection cookies plus optional PayPal Pay Later and Venmo widgets
Server locationUnited States headquarters (Chicago) with EU gateway in Dublin (payments-eu.braintree-api.com)
Data transferred outside the EUBraintree is a subsidiary of PayPal Holdings Inc. headquartered in the United States. An EU gateway exists in Ireland, but card data and fraud signals can be processed in the US for PCI DSS, fraud detection and dispute management. Transfers rely on EU SCCs and on the PayPal DPF certification.

Third-party domains contacted

braintreegateway.combraintree-api.compayments-eu.braintree-api.compaypal.compaypalobjects.comvenmo.com

Cookies placed

NameTypeDurationPurpose
BraintreeJS_*FunctionalSessionMaintains the Hosted Fields and Drop in UI state on the merchant domain during checkout. Strictly necessary for the payment to complete.
tsFunctional3 yearsPayPal session cookie used by Braintree when PayPal buttons are loaded. Helps recognise the user during the PayPal flow.
ts_cFunctional3 yearsPayPal companion cookie to ts, used together for session continuity in the PayPal checkout.
l7_azFunctional30 minutesLoad balancer routing cookie on paypal.com used during the checkout to keep the user on the same backend instance.
tsrceFunctional3 daysPayPal traffic source cookie set when Smart Buttons are displayed for analytics and attribution.
x-pp-sFunctionalSessionPayPal session identifier used during the PayPal Smart Button flow.

Braintree is an essential service, but transparency matters. Manage all your consent with FlowConsent.

Get started freeScan your site

Frequently asked questions

What cookies does Braintree set?

Braintree sets first party cookies on the merchant domain to maintain the Hosted Fields state, plus third party cookies on braintreegateway.com and paypal.com (LANG, tsrce, x-pp-s, l7_az, ts, ts_c) when PayPal or Venmo buttons render. Advanced fraud detection (collector.js) also creates a device fingerprint stored in browser storage.

Is consent required for Braintree?

Hosted Fields and Drop in UI cookies are strictly necessary and exempt from consent under article 5(3) ePrivacy. The advanced fraud detection scripts and the PayPal Smart Buttons usually require consent unless a documented legitimate interest assessment supports them.

What is the legal basis for Braintree?

Performance of a contract (article 6(1)(b) GDPR) for the actual payment processing. Legitimate interest (article 6(1)(f) GDPR) for essential anti fraud measures. Consent (article 6(1)(a) GDPR) for non essential profiling, marketing buttons and behavioural anti fraud.

What about US data transfers?

Braintree provides an EU gateway in Ireland but card and fraud data can be processed in the United States by PayPal Holdings. Transfers rely on EU SCCs and on the PayPal DPF certification.

Do I need a DPIA for Braintree?

A DPIA is recommended when activating the advanced fraud detection (Kount, ThreatMetrix), when running 3DS2 risk based authentication with broad behavioural signals, or when storing card data in the Vault for recurring payments at significant scale.

How do I implement Braintree compliantly?

Load Hosted Fields without consent. Load the advanced fraud collector only after consent or under a documented legitimate interest. Sign the Braintree merchant agreement and the PayPal DPA with EU SCCs. Activate the EU gateway when possible. Inform users in the privacy notice with the right balance between transparency and security.

What are the alternatives to Braintree in Europe?

Stripe Connect, Adyen, Mollie (Dutch, EU only), Worldline, Checkout.com, GoCardless for SEPA, Klarna for BNPL, or local providers such as Lemonway and Lyra Network. Most offer similar PCI DSS compliance and 3DS2 support but with different EU footprints.

How do I document Braintree in my cookie policy?

List the BraintreeJS_ first party cookies and the third party cookies on braintreegateway.com and paypal.com with their domain, duration and purpose. Categorise payment cookies as Strictly Necessary and fraud detection cookies as Fraud Prevention. Identify PayPal (Europe) Sarl & Cie, S.C.A and PayPal Inc. as independent controllers in the privacy notice with the transfer disclosure.