FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. E-commerce
  4. Gumroad

Gumroad

PreferencesWebsite

Related services

24nettbutikk

24nettbutikk is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. 24nettbutikk supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, 24nettbutikk ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Preferences

2ClickShop

2ClickShop is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 2ClickShop integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 2ClickShop helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences

4-Tell

4-Tell is a marketing platform that equips businesses with tools to amplify their digital presence and drive customer acquisition. It supports audience segmentation, campaign automation, and cross-channel engagement. 4-Tell provides real-time analytics and reporting dashboards for performance measurement and strategy optimization. By combining data intelligence with marketing execution, 4-Tell helps deliver the right message to the right audience at the right time.

Preferences

42stores

42stores is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 42stores integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 42stores helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences

4Partners

4Partners is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 4Partners integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 4Partners helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences
4

4Partners CMS

4Partners CMS is a powerful content management system (CMS) designed to help businesses and developers build, manage, and publish digital content with ease. It offers a flexible architecture that supports custom content types, templates, and workflows, making it ideal for websites of any scale. With 4Partners CMS, teams can streamline content creation, improve collaboration, and deliver engaging web experiences. Its extensible plugin ecosystem and API-first approach ensure seamless integration with.

Preferences
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does Gumroad do?

Gumroad is a US based merchant of record platform that lets creators sell ebooks, digital downloads, software, memberships and online courses. Creators either link to a Gumroad hosted product page or embed an overlay loaded from gumroad.com on their own site. As the merchant of record, Gumroad collects EU VAT, handles refunds and routes payments through Stripe and PayPal. The embed sets non strictly necessary cookies, so EU sites must gate it behind consent and document the US transfer.

What is Gumroad?

Gumroad is a US based platform incorporated as Gumroad Inc. in San Francisco, California, founded in 2011 by Sahil Lavingia. It targets independent creators who want to sell digital goods (ebooks, courses, software, music, art assets), physical goods and recurring memberships. Gumroad operates as the merchant of record (MoR): when a buyer checks out, Gumroad Inc. is the legal seller of record on the invoice, collects EU VAT and other sales taxes, handles refunds and remits the net revenue to the creator.

Creators can either send buyers to a hosted Gumroad page (creator.gumroad.com or gumroad.com/l/PRODUCT) or use the Gumroad overlay, a JavaScript snippet that opens the checkout in an iframe on the creator''s own site.

Cookies and data collected

When the Gumroad overlay is embedded on a third party site, gumroad.js loads from gumroad.com. The overlay opens an iframe to gumroad.com that sets first party Gumroad cookies (_gumroad_session, _gumroad_guid for cart attribution, a CSRF token) and Cloudflare bot management cookies. The Stripe checkout step adds __stripe_mid and __stripe_sid; if the buyer uses PayPal, paypal_* cookies are loaded. Gumroad''s own site also runs Google Analytics 4, Microsoft Clarity and Segment for product analytics.

GDPR and ePrivacy implications

Embedding the Gumroad overlay loads cookies before any action by the visitor, which triggers Art. 5(3) ePrivacy and requires prior consent in the EU. On the Gumroad hosted checkout itself, strictly necessary cookies needed to complete the purchase rely on contract performance and are exempt from prior consent. As merchant of record, Gumroad is a separate controller for VAT, invoicing and refunds.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Consent and implementation

For EU traffic, replace the overlay with a button that opens the hosted Gumroad page in a new tab until the visitor has accepted the functional or marketing category in your CMP. Once consent is given, load gumroad.js and let the overlay open. The buyer''s interaction with the Gumroad checkout itself is on Gumroad''s domain, with its own privacy notice and cookie controls.

International data transfers

All Gumroad processing happens on AWS US East. The Gumroad DPA incorporates the EU Standard Contractual Clauses (modules 2 and 3) and references the EU US Data Privacy Framework. Stripe and PayPal apply their own transfer mechanisms (Ireland based EU entities with SCCs to the US, DPF certifications).

Practical compliance steps

Sign the Gumroad DPA from your account. Gate the overlay behind a CMP toggle and use a static link to the hosted page until consent is given. List Gumroad, Stripe and PayPal in your privacy notice and Article 30 record. Mention the merchant of record relationship and the US transfer with SCCs and DPF. Update your customer service expectations: buyers contact Gumroad for refunds and VAT receipts.

GDPR consent category

Preferences

Websites using Gumroad must obtain user consent under GDPR regulations.

Legal basisConsent (Art. 6(1)(a) GDPR and Art. 5(3) ePrivacy) for the Gumroad overlay loaded on the creator's own site, because the iframe sets non strictly necessary cookies before any action by the visitor. Contract performance (Art. 6(1)(b)) for the purchase the buyer initiates on the Gumroad hosted page itself. Legal obligation (Art. 6(1)(c)) for EU VAT collection and reporting, since Gumroad is the merchant of record.
Risk levelmedium
Applicable regulationsGDPR, UK GDPR, ePrivacy Directive 2002/58/EC, EU US Data Privacy Framework, EU VAT (OSS / MOSS), PSD2, PCI DSS, US CCPA/CPRA

DPIA considerations

A DPIA is not normally required for a typical creator using Gumroad. It can become relevant for creators running large catalogs with extensive analytics, audience profiling, course completion tracking and AI driven recommendation on the same customer base.

Sample consent text

Sales on this site are powered by Gumroad (Gumroad Inc., United States), our merchant of record for digital goods. The Gumroad overlay sets functional and analytics cookies, opens an iframe to gumroad.com, processes payments through Stripe and PayPal and remits EU VAT on our behalf. International transfers to the US are covered by Standard Contractual Clauses and the EU US Data Privacy Framework.

Technical details

Tracking methodMerchant of record platform for digital creators: hosted product pages on gumroad.com and an embeddable overlay loaded from gumroad.com/js/gumroad.js or gumroad.com/js/gumroad embed.js; the overlay opens an iframe to gumroad.com that hosts the checkout; first party Gumroad session and CSRF cookies are set on gumroad.com, payments are routed through Stripe and PayPal
Server locationUnited States (Gumroad Inc., San Francisco, California, headquarters); production hosted on AWS US East regions; static assets and the storefront served from AWS CloudFront and Cloudflare with EU edge presence
Data transferred outside the EUGumroad Inc. is established in the United States and processes EU customer data on AWS US East. Gumroad is the merchant of record for digital goods and is registered for EU VAT through the MOSS / OSS scheme. The Gumroad DPA incorporates the EU Standard Contractual Clauses (modules 2 and 3) and references the EU US Data Privacy Framework. Payment processors (Stripe, PayPal) apply their own SCCs and DPF certifications.

Third-party domains contacted

gumroad.compublic-files.gumroad.comstatic.gumroad.comjs.stripe.comwww.paypal.com

Cookies placed

NameTypeDurationPurpose
_gumroad_sessionthird_party2 weeksGumroad session cookie set on gumroad.com to keep an authenticated session and an in progress checkout.
_gumroad_guidthird_party1 yearGumroad attribution and recognition identifier used to attribute purchases to the originating link or affiliate.
__cf_bmthird_party30 minutesCloudflare bot management cookie set on gumroad.com to distinguish humans from automated traffic.
__stripe_midthird_party1 yearStripe machine identifier loaded during the Gumroad Stripe checkout step for fraud prevention.
__stripe_sidthird_party30 minutesStripe session identifier loaded during the Gumroad Stripe checkout step for fraud detection.

Gumroad uses cookies for user preferences — inform visitors with a consent banner.

Get started freeScan your site

Frequently asked questions

What cookies does Gumroad set?

When the Gumroad overlay loads, it sets first party Gumroad cookies on gumroad.com (_gumroad_session, _gumroad_guid for cart attribution, a CSRF token) and Cloudflare bot management cookies (__cf_bm, _cfuvid). The Stripe checkout step adds __stripe_mid, __stripe_sid and m. If the buyer chooses PayPal, paypal_* cookies are loaded.

Do I need consent to load the Gumroad overlay?

Yes. The overlay loads gumroad.js before the visitor does anything, which puts non strictly necessary cookies on the device. Art. 5(3) ePrivacy requires prior consent in the EU. Until consent is given, replace the overlay with a static button linking to the hosted Gumroad page in a new tab.

What is the legal basis for using Gumroad?

Consent (Art. 6(1)(a) GDPR and Art. 5(3) ePrivacy) for loading the overlay and its cookies on your own site. Contract performance (Art. 6(1)(b)) for processing the purchase on the hosted Gumroad page. Legal obligation (Art. 6(1)(c)) for EU VAT collection and reporting, since Gumroad is the merchant of record.

Does Gumroad transfer data to third countries?

Yes. Gumroad Inc. is established in the United States and processes EU customer data on AWS US East. The Gumroad DPA incorporates the EU Standard Contractual Clauses (modules 2 and 3) and references the EU US Data Privacy Framework. Stripe and PayPal apply their own transfer mechanisms.

Do I need a DPIA for Gumroad?

A DPIA is not normally required for a single creator selling a few products through Gumroad. It can be appropriate when Gumroad is combined with extensive customer profiling, audience emails, course completion tracking and AI recommendations on the same customer base.

How do I implement Gumroad compliantly?

Sign the Gumroad DPA, gate the overlay behind a CMP toggle, use a static link to the hosted page until consent is given, mention Gumroad, Stripe and PayPal in your privacy notice, document the US transfer with SCCs and DPF, add Gumroad to your Article 30 record and direct refund and VAT receipt requests to Gumroad as merchant of record.

Are there alternatives to Gumroad?

EU friendly creator commerce platforms include Lemon Squeezy (US with DPF, see our dedicated page), Paddle (UK MoR), Podia, Kajabi (US), Teachable (US), SendOwl (UK), Tipeee (France), Lemonway and Stripe Checkout / Payment Links for self managed setups. EU sellers without MoR can also use Mollie (Netherlands) or Adyen (Netherlands).

How should I update my cookie and privacy policy for Gumroad?

List the Gumroad and Stripe cookies in your cookie policy under their categories. In your privacy notice describe Gumroad as your merchant of record for digital goods, the overlay, the iframe to gumroad.com, the US transfer with SCCs and DPF and the role of Stripe and PayPal as separate processors.