Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Cleverbridge is a Cologne based ecommerce and subscription billing platform that handles checkout, recurring payments, tax and fraud prevention for software and digital goods vendors. When its hosted checkout or cart is used, it sets cookies for session management, fraud prevention and conversion attribution and processes buyer and order data. Under the GDPR and the ePrivacy Directive, its non essential cookies require prior consent.
Cleverbridge is an ecommerce, subscription billing and payments platform founded in 2005 and headquartered in Cologne, Germany, with offices in the United States and Japan. It provides software and SaaS companies with a hosted checkout, global payment processing, recurring billing, tax handling and fraud prevention. Vendors send buyers to a Cleverbridge cart or embed its checkout in their store.
When the Cleverbridge checkout loads it sets cookies for session management, fraud prevention and conversion attribution and reads device data such as IP address and browser. To process an order or subscription, Cleverbridge handles identity, contact, billing and payment data and screens transactions for fraud. Some cookies are persistent identifiers used to recognise the device and attribute the sale.
The attribution and analytics cookies are not strictly necessary, so storing them is governed by Article 5(3) of the ePrivacy Directive and requires consent. Cleverbridge often acts as merchant of record or reseller, which affects whether it is a controller or processor, so the roles and the lawful basis for each purpose must be defined.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Block Cleverbridge non essential cookies until the buyer accepts them through a Consent Management Platform, while cookies strictly necessary to complete a requested purchase may load. Log consent, make refusal as easy as acceptance, and ensure the checkout does not set tracking identifiers before opt in.
Cleverbridge processes personal data primarily in the European Union, with some processing in the United States. Transfers to the US must rely on Standard Contractual Clauses or the EU US Data Privacy Framework, supported by a Transfer Impact Assessment. Because the main processing is in the EU, the transfer exposure is lower than for non EU providers.
List the Cleverbridge cookies and domains in your cookie policy and gate non essential ones behind consent. Clarify whether Cleverbridge acts as your processor or as merchant of record and controller, sign the appropriate terms, and document your transfer safeguards. Review the integration when Cleverbridge updates its checkout.
Websites using Cleverbridge must obtain user consent under GDPR regulations.
DPIA considerations
Cleverbridge processes identity, contact, billing and payment data and screens transactions for fraud. Key DPIA considerations: (1) attribution and analytics cookies are persistent identifiers needing consent; (2) Cleverbridge often acts as reseller or merchant of record, which affects whether it is a controller or processor; (3) some processing may occur in the United States, requiring transfer safeguards; (4) the lawful basis for each purpose must be defined. A DPIA is advisable in case of extensive profiling or large volumes of payment data.
Sample consent text
We use Cleverbridge to process your order and payments. The Cleverbridge checkout sets cookies and processes your identity, billing and payment data, and screens the transaction for fraud. You can withdraw your consent to non essential cookies at any time through our cookie settings.
Third-party domains contacted
cleverbridge.comsecure.cleverbridge.comcdn.cleverbridge.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| cb_session | Functional | Session | Maintains the buyer session through the Cleverbridge checkout. |
| _cb_attr | Attribution / Analytics | 1 year | Persistent identifier used to attribute completed orders and recognise returning devices. |
| cb_fraud | Security | 6 months | Supports device recognition and fraud screening during checkout. |
Cleverbridge uses cookies for user preferences — inform visitors with a consent banner.
Cleverbridge sets cookies for session management, fraud prevention and conversion attribution when its checkout loads. The attribution and analytics cookies are persistent identifiers that are not strictly necessary, so they require consent, while a narrow set needed to complete a requested purchase may be treated as essential.
Yes for the non essential cookies. The attribution and analytics cookies Cleverbridge sets need prior consent under the GDPR and the ePrivacy Directive, so they should not load until the buyer accepts. Cookies strictly necessary to process a requested purchase can rely on a different basis.
Consent under Article 6(1)(a) GDPR covers the attribution cookies, while processing needed to complete a purchase relies on contract under Article 6(1)(b). Fraud prevention may rely on legitimate interest. Whether Cleverbridge is your processor or an independent controller as merchant of record changes who relies on which basis.
Cleverbridge processes data mainly in the EU, with some processing in the United States. US transfers must use Standard Contractual Clauses or the EU US Data Privacy Framework with a Transfer Impact Assessment, but because the core processing stays in the EU the transfer exposure is comparatively low.
A DPIA may not be mandatory for a standard checkout, but it is advisable if you combine Cleverbridge with extensive profiling or process large volumes of payment data. Document the purposes, the controller roles, fraud screening and transfer safeguards to demonstrate accountability.
Add Cleverbridge through a CMP that blocks non essential cookies until consent, keep purchase essential cookies separate, and confirm whether it acts as your processor or as merchant of record. Sign the relevant terms, disclose cookies and recipients, and document transfer safeguards.
Other merchant of record and billing platforms include Paddle, FastSpring, Digital River and 2Checkout (Verifone). Paddle and Cleverbridge are EU friendly options that can simplify transfer compliance. All set checkout and tracking cookies, so consent gating and clear roles remain the priority.
Describe the Cleverbridge cookies, their purpose and duration, list the Cleverbridge domains, and state that data is processed in the EU and, to a limited extent, the US. Clarify the controller roles in your privacy notice and keep both aligned with the integration.