FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. E-commerce
  4. FastSpring

FastSpring

PreferencesWebsite

Related services

24nettbutikk

24nettbutikk is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. 24nettbutikk supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, 24nettbutikk ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Preferences

2ClickShop

2ClickShop is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 2ClickShop integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 2ClickShop helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences

4-Tell

4-Tell is a marketing platform that equips businesses with tools to amplify their digital presence and drive customer acquisition. It supports audience segmentation, campaign automation, and cross-channel engagement. 4-Tell provides real-time analytics and reporting dashboards for performance measurement and strategy optimization. By combining data intelligence with marketing execution, 4-Tell helps deliver the right message to the right audience at the right time.

Preferences

42stores

42stores is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 42stores integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 42stores helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences

4Partners

4Partners is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 4Partners integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 4Partners helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences
4

4Partners CMS

4Partners CMS is a powerful content management system (CMS) designed to help businesses and developers build, manage, and publish digital content with ease. It offers a flexible architecture that supports custom content types, templates, and workflows, making it ideal for websites of any scale. With 4Partners CMS, teams can streamline content creation, improve collaboration, and deliver engaging web experiences. Its extensible plugin ecosystem and API-first approach ensure seamless integration with.

Preferences
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does FastSpring do?

FastSpring is a US based merchant of record (MoR) payment platform widely used by software and SaaS companies to outsource billing, EU VAT collection, fraud prevention and global tax compliance. The hosted checkout, served from fastspring.com and onfastspring.com, sets only strictly necessary first party cookies and routes transactions through Bright Market LLC, the legal seller of record. As the merchant of record FastSpring handles VAT, invoicing and chargebacks on behalf of the publisher.

What is FastSpring?

FastSpring is a US based payment platform incorporated as Bright Market LLC in Santa Barbara, California. It operates as a merchant of record (MoR) for software, SaaS and digital products: when a customer pays through FastSpring, Bright Market LLC is the legal seller of record on the invoice, collects EU VAT and other sales taxes, handles refunds, chargebacks and dispute management and remits the net revenue to the publisher.

Publishers integrate FastSpring with the Popup Storefront (an overlay on their site), the Web Storefront (a hosted product page) or the Embedded Storefront (a checkout in an iframe). The Storefront.js library and the Order API allow advanced flows such as price localisation, subscription management and B2B quoting.

Cookies and data collected

On the hosted FastSpring checkout, only strictly necessary first party cookies are set on fastspring.com and onfastspring.com: a session cookie that maintains the cart, a CSRF protection token and a fraud risk score cookie. FastSpring also collects billing data (name, email, address, country, payment method) needed to complete the purchase. When the publisher uses the Library API to display localised prices on its own page, geo IP lookups happen server side without setting cookies on the publisher domain.

As a merchant of record, FastSpring also stores enough billing information to produce a compliant invoice with EU VAT, to honour refund requests and to deal with payment scheme rules. Card data is tokenised through PCI DSS Level 1 processors; FastSpring never exposes raw PAN to the publisher.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

GDPR and ePrivacy implications

Because FastSpring acts as the merchant of record, it is a controller for the invoicing and tax remittance data and a processor for the publisher''s customer data. Strictly necessary cookies set on the hosted checkout are exempt from prior consent under Art. 5(3) ePrivacy and the EDPB ePrivacy guidance. The customer''s explicit choice to start a purchase is the legal basis for the processing of the payment data.

International data transfers

FastSpring processes EU customer data on AWS US East regions. The FastSpring DPA incorporates the EU Standard Contractual Clauses (modules 2 and 3) and the UK International Data Transfer Addendum, and FastSpring is self certified under the EU US Data Privacy Framework. EU customers can request additional information on access controls and on the categories of sub processors used.

Practical compliance steps

Sign the FastSpring DPA from your account. List FastSpring (Bright Market LLC) in your privacy notice as merchant of record and processor, mention the US transfer with SCCs and DPF, and add it to your Article 30 register. No cookie banner update is needed for the hosted checkout itself, but any third party analytics that you wire to FastSpring events (Google Analytics, GA4 ecommerce, Meta CAPI) must remain in the consent gated tag manager.

GDPR consent category

Preferences

Websites using FastSpring must obtain user consent under GDPR regulations.

Legal basisContract performance (Art. 6(1)(b) GDPR) for processing payment data necessary to complete the purchase the user has initiated. Legal obligation (Art. 6(1)(c)) for EU VAT collection and reporting, AML and tax record keeping, since FastSpring is the merchant of record. Strictly necessary cookies on the hosted checkout are exempt from consent under Art. 5(3) ePrivacy.
Risk levellow
Applicable regulationsGDPR, UK GDPR, ePrivacy Directive 2002/58/EC, EU US Data Privacy Framework, EU VAT Directive (Council Directive 2006/112/EC), PSD2, AMLD5, PCI DSS, US CCPA/CPRA

DPIA considerations

A DPIA is not normally required for standard SaaS subscription billing through FastSpring. It can become relevant for products that combine billing with extensive customer profiling, regulated industry data or special category data tied to subscription tiers.

Sample consent text

Payments and invoicing on this site are handled by FastSpring (Bright Market LLC, United States), our merchant of record. FastSpring processes your payment data and EU VAT under contract and legal obligations on its US infrastructure. International transfers to the United States are covered by Standard Contractual Clauses and the EU US Data Privacy Framework.

Technical details

Tracking methodMerchant of record (MoR) SaaS payment platform: hosted checkout (Popup, Embedded, Web Storefront) loaded from fastspring.com / onfastspring.com, with the Storefront.js library and the Order API; first party session, CSRF and fraud cookies are set on the hosted checkout domain; product listings and price localisation can be rendered on the publisher domain via the Library API
Server locationUnited States (FastSpring, doing business as Bright Market LLC, Santa Barbara, California, headquarters); production hosted on AWS US East regions; static assets and the checkout web app served from Cloudflare and AWS CloudFront with EU edge presence
Data transferred outside the EUFastSpring (Bright Market LLC) is established in the United States. EU customer payment data and billing addresses are processed on AWS US East. FastSpring is self certified under the EU US Data Privacy Framework and the FastSpring DPA includes the EU Standard Contractual Clauses (modules 2 and 3) and the UK International Data Transfer Addendum. As a merchant of record, FastSpring handles EU VAT collection and reporting for the seller.

Third-party domains contacted

fastspring.comonfastspring.comsbl.onfastspring.comd1f8f9xcsvx3ha.cloudfront.net

Cookies placed

NameTypeDurationPurpose
fs_sessionfirst_partySessionStrictly necessary session cookie on the FastSpring hosted checkout used to maintain the customer cart and the in progress order.
fs_csrffirst_partySessionCSRF protection token used to validate the payment form submission on the FastSpring hosted checkout.
fs_riskfirst_party30 minutesStrictly necessary fraud risk cookie used by FastSpring for transaction risk scoring during the checkout.
fs_localefirst_party1 yearFunctional cookie used by the FastSpring hosted checkout to remember the customer's language and currency preference between sessions.

FastSpring uses cookies for user preferences — inform visitors with a consent banner.

Get started freeScan your site

Frequently asked questions

What cookies does FastSpring set?

On the hosted FastSpring checkout only strictly necessary first party cookies are set on fastspring.com and onfastspring.com: a session cookie (fs_session) keeping the cart, a CSRF protection token (fs_csrf) and a risk score cookie (fs_risk). When the customer pays with a card, the underlying card processor may add its own short lived risk cookies.

Do I need consent to use FastSpring on my website?

No, the cookies on the hosted FastSpring checkout are strictly necessary under Art. 5(3) ePrivacy and are exempt from prior consent. The customer has actively initiated the purchase, which is the legal basis for processing the payment data under Art. 6(1)(b) GDPR. Optional analytics on the publisher domain (GA4 ecommerce, Meta CAPI) must stay behind a consent gated tag manager.

What is the legal basis for processing payments through FastSpring?

Contract performance (Art. 6(1)(b) GDPR) for processing the data necessary to complete the transaction. Legal obligation (Art. 6(1)(c)) for EU VAT, AML and tax record keeping, since FastSpring is the merchant of record. Strictly necessary cookies are exempt under Art. 5(3) ePrivacy.

Does FastSpring transfer data to third countries?

Yes. Bright Market LLC is established in the United States and processes EU customer data on AWS US East. The FastSpring DPA includes the EU Standard Contractual Clauses and the UK IDTA, and FastSpring is self certified under the EU US Data Privacy Framework. A Transfer Impact Assessment should review US surveillance laws.

Do I need a DPIA for FastSpring?

Standard SaaS billing through FastSpring does not normally require a DPIA. A DPIA may be appropriate when FastSpring is combined with extensive customer profiling, regulated industries or special category data tied to subscription tiers.

How do I implement FastSpring compliantly?

Sign the FastSpring DPA, mention FastSpring (Bright Market LLC) as merchant of record and processor in your privacy notice, document the US transfer with SCCs and DPF, and add the service to your Article 30 register. Use the hosted checkout to keep the payment data scope minimal and avoid loading any optional analytics outside the consent gated tag manager.

Are there alternatives to FastSpring for EU SaaS?

Other merchant of record platforms include Paddle (UK with EU AWS), Lemon Squeezy (US with DPF), 2Checkout / Verifone (US and EU). For non MoR EU options, Stripe Billing (Ireland), Mollie subscriptions (Netherlands), Adyen subscriptions (Netherlands) and Chargebee Billing (US with EU residency on enterprise).

How should I update my cookie and privacy policy for FastSpring?

For most setups no banner update is needed because the hosted checkout sets only strictly necessary cookies under Art. 5(3) ePrivacy. Update the privacy notice to mention FastSpring as merchant of record, the US transfer with SCCs and DPF and the role of FastSpring as a separate controller for VAT and tax remittance.