FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. E-commerce
  4. GoKwik

GoKwik

PreferencesWebsite

Related services

24nettbutikk

24nettbutikk is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. 24nettbutikk supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, 24nettbutikk ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Preferences

2ClickShop

2ClickShop is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 2ClickShop integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 2ClickShop helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences

4-Tell

4-Tell is a marketing platform that equips businesses with tools to amplify their digital presence and drive customer acquisition. It supports audience segmentation, campaign automation, and cross-channel engagement. 4-Tell provides real-time analytics and reporting dashboards for performance measurement and strategy optimization. By combining data intelligence with marketing execution, 4-Tell helps deliver the right message to the right audience at the right time.

Preferences

42stores

42stores is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 42stores integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 42stores helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences

4Partners

4Partners is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 4Partners integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 4Partners helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences
4

4Partners CMS

4Partners CMS is a powerful content management system (CMS) designed to help businesses and developers build, manage, and publish digital content with ease. It offers a flexible architecture that supports custom content types, templates, and workflows, making it ideal for websites of any scale. With 4Partners CMS, teams can streamline content creation, improve collaboration, and deliver engaging web experiences. Its extensible plugin ecosystem and API-first approach ensure seamless integration with.

Preferences
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does GoKwik do?

GoKwik is an Indian conversion intelligence platform built for direct to consumer e commerce stores on Shopify, Magento and custom stacks. The SDK loaded from sdk.gokwik.co writes first party cookies on the merchant's domain, scores cash on delivery risk, runs address intelligence and renders a one click hosted checkout overlay. Data is processed on AWS Mumbai. For EU stores, the transfer to India relies on Standard Contractual Clauses and requires consent for the non strictly necessary tracking cookies.

What is GoKwik?

GoKwik is an Indian conversion intelligence platform, incorporated as GoKwik Solutions Pvt. Ltd. in Gurugram, Haryana, that targets direct to consumer (D2C) e commerce merchants. It bundles a one click hosted checkout (KwikCheckout), an address intelligence layer (KwikPass) and a cash on delivery (COD) risk engine on top of a merchant''s Shopify, Magento or custom storefront. The SDK loaded from sdk.gokwik.co replaces the native checkout, identifies returning customers across stores in the GoKwik network and prevents fraudulent COD orders using device, network and behaviour signals.

Cookies and data collected

On a typical Shopify or Magento store, GoKwik writes first party cookies on the merchant domain (gk_visitor, gk_session, gk_kwikpass) and a localStorage object with the GoKwik visitor ID, a returning customer hash, the chosen shipping pincode and the COD risk band. The SDK transmits shipping address fragments, phone number hashes, IP, user agent, device fingerprint and prior order patterns to api.gokwik.co for scoring. KwikPass also enables cross store checkout, so the same shopper hash can be recognised across multiple GoKwik powered storefronts.

GDPR and ePrivacy implications

Under the GDPR, GoKwik is a processor for the merchant (controller) when running the checkout flow, and a controller for its cross store network. The COD risk engine and KwikPass are forms of automated decision making under Art. 22 GDPR because they can decline cash on delivery or trigger upfront payment requirements. Under Art. 5(3) ePrivacy, gk_visitor and gk_kwikpass are not strictly necessary for the requested page view, so they require consent before they are set.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Consent and implementation

EU merchants should gate the GoKwik SDK behind a CMP. A pragmatic option is to load only a stub before consent (the Add to cart button stays native), then load the full SDK after the analytics or marketing category is accepted. Inside the checkout itself, strictly necessary data processing required to complete the order may rely on contract performance, but the cross store recognition and COD risk profiling need consent or a strong legitimate interest balancing test.

International data transfers

GoKwik processes data on AWS Mumbai. India is not covered by an EU adequacy decision. The GoKwik DPA includes the EU Standard Contractual Clauses (modules 2 and 3) and aligns with India''s Digital Personal Data Protection Act, 2023. EU merchants should run a Transfer Impact Assessment that looks at Indian access laws (CERT IN, the IT Act, the DPDP Act exemptions), encryption in transit and at rest and the residual risk for EU customers.

Practical compliance steps

Sign the GoKwik DPA, gate the SDK behind a CMP, separate strictly necessary checkout data from cross store profiling in your privacy notice, give EU customers a meaningful right to object to automated COD scoring, document the international transfer to India with SCCs and a TIA, list gokwik.co and sdk.gokwik.co in your Content Security Policy and complete a DPIA that covers fraud scoring and cross store recognition.

GDPR consent category

Preferences

Websites using GoKwik must obtain user consent under GDPR regulations.

Legal basisContract performance (Art. 6(1)(b) GDPR) for the data processed during the checkout the customer has initiated. Consent (Art. 6(1)(a) GDPR and Art. 5(3) ePrivacy) for the non strictly necessary cookies (fraud and COD scoring fingerprint, attribution cookies, returning customer recognition) that the SDK sets before the customer reaches the checkout step.
Risk levelhigh
Applicable regulationsGDPR, UK GDPR, ePrivacy Directive 2002/58/EC, India Digital Personal Data Protection Act 2023, US CCPA/CPRA (when serving US shoppers), PCI DSS

DPIA considerations

A DPIA is recommended whenever an EU merchant deploys GoKwik because the SDK combines device fingerprinting, COD fraud scoring (a form of profiling under Art. 4(4) GDPR) and a transfer to India, a third country without an adequacy decision. The DPIA should cover fraud scoring, attribution profiling and the international transfer.

Sample consent text

This store uses GoKwik (GoKwik Solutions Pvt. Ltd., India) to power its checkout, address intelligence and cash on delivery risk scoring. GoKwik sets functional and analytics cookies, sends data to AWS Mumbai and uses Standard Contractual Clauses for the transfer outside the EEA. Some features only run after you give consent for analytics.

Technical details

Tracking methodCheckout, address intelligence and COD intelligence platform for D2C e commerce: a JavaScript SDK loaded from sdk.gokwik.co (and gokwik.co subdomains) on the merchant's Shopify, Magento or custom store; the SDK writes first party cookies for user identification, fraud scoring, COD risk decisioning and checkout state, exchanges encrypted payloads with the GoKwik backend and renders a one click hosted checkout overlay
Server locationIndia (GoKwik Solutions Pvt. Ltd., Gurugram, Haryana, headquarters); production hosted on AWS Asia Pacific Mumbai (ap south 1) with multi AZ replication; data lake and machine learning workloads in the same region
Data transferred outside the EUGoKwik Solutions Pvt. Ltd. is established in India. India has not received a European Commission adequacy decision under the GDPR. EU customer data processed through a GoKwik powered checkout (shipping addresses, phone numbers, payment hashes, device fingerprints) is transferred to AWS Mumbai. The GoKwik DPA incorporates the EU Standard Contractual Clauses (modules 2 and 3) and references compliance with India's Digital Personal Data Protection Act, 2023.

Third-party domains contacted

gokwik.cosdk.gokwik.coapi.gokwik.copay.gokwik.co

Cookies placed

NameTypeDurationPurpose
gk_visitorfirst_party1 yearGoKwik long lived visitor identifier used to recognise returning shoppers on the merchant store and to attribute conversions.
gk_sessionfirst_partySessionGoKwik session state cookie used to keep the checkout step, cart contents and chosen shipping information.
gk_kwikpassfirst_party6 monthsKwikPass cross store recognition hash used to identify the shopper across multiple GoKwik powered merchant stores for one click checkout.
gk_cod_riskfirst_party30 daysCOD risk band cookie used to remember the customer's cash on delivery risk classification for faster checkout decisioning on subsequent visits.

GoKwik uses cookies for user preferences — inform visitors with a consent banner.

Get started freeScan your site

Frequently asked questions

What cookies does GoKwik set?

GoKwik writes first party cookies on the merchant domain: gk_visitor (a long lived visitor identifier), gk_session (session state), gk_kwikpass (KwikPass cross store recognition hash) and a small localStorage object with the COD risk band, the shipping pincode and the returning customer hash. Cloudflare bot management cookies may also be set on gokwik.co subdomains.

Do I need consent to use GoKwik?

Yes. The gk_visitor and gk_kwikpass cookies and the device fingerprint used for COD scoring are not strictly necessary for the page the EU visitor first sees. Art. 5(3) ePrivacy requires consent before they are set. The full SDK should only load after the analytics or marketing category has been accepted in your CMP.

What is the legal basis for using GoKwik?

Contract performance (Art. 6(1)(b) GDPR) for the data needed to complete the checkout the customer has initiated. Consent (Art. 6(1)(a) GDPR and Art. 5(3) ePrivacy) for the tracking cookies and the fraud scoring. Legitimate interest can support some fraud prevention work but rarely covers cross store profiling and automated COD refusals.

Does GoKwik transfer data to third countries?

Yes. GoKwik is established in India and processes data on AWS Mumbai. India has no EU adequacy decision. The GoKwik DPA includes the EU Standard Contractual Clauses (modules 2 and 3) and references the Indian Digital Personal Data Protection Act 2023. EU merchants should complete a Transfer Impact Assessment.

Do I need a DPIA for GoKwik?

Yes, in most EU deployments. GoKwik combines device fingerprinting, behavioural scoring (COD risk and cross store recognition), automated decisions on payment options and an international transfer to India. The combination meets at least two of the Art. 35 GDPR criteria.

How do I implement GoKwik compliantly?

Sign the GoKwik DPA, gate the SDK behind a CMP, give customers a meaningful way to object to automated COD scoring, document the India transfer with SCCs and TIA, separate strictly necessary checkout data from cross store profiling in the privacy notice, and complete a DPIA covering fraud scoring and cross store recognition.

Are there alternatives to GoKwik?

EU friendly checkout and fraud platforms include Mollie Checkout (Netherlands), Adyen Risk Hub (Netherlands), Stripe Radar + Stripe Link (Ireland and US with DPF), Klarna Authentication (Sweden), Riskified (Israel with EU servers), Bolt Checkout (US) and Shop Pay (Shopify). For COD specific markets the EU has fewer direct equivalents.

How should I update my cookie and privacy policy for GoKwik?

List gk_visitor, gk_session and gk_kwikpass in your cookie policy as analytics or marketing cookies, with their durations. In your privacy notice, describe GoKwik as your checkout and fraud prevention provider, the data sent to AWS Mumbai, the use of automated COD decisions, the international transfer to India with SCCs and the customer's rights including the right to object to profiling.