FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. E-commerce
  4. HeyLight

HeyLight

PreferencesWebsite

Related services

24nettbutikk

24nettbutikk is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. 24nettbutikk supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, 24nettbutikk ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Preferences

2ClickShop

2ClickShop is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 2ClickShop integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 2ClickShop helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences

4-Tell

4-Tell is a marketing platform that equips businesses with tools to amplify their digital presence and drive customer acquisition. It supports audience segmentation, campaign automation, and cross-channel engagement. 4-Tell provides real-time analytics and reporting dashboards for performance measurement and strategy optimization. By combining data intelligence with marketing execution, 4-Tell helps deliver the right message to the right audience at the right time.

Preferences

42stores

42stores is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 42stores integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 42stores helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences

4Partners

4Partners is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 4Partners integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 4Partners helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences
4

4Partners CMS

4Partners CMS is a powerful content management system (CMS) designed to help businesses and developers build, manage, and publish digital content with ease. It offers a flexible architecture that supports custom content types, templates, and workflows, making it ideal for websites of any scale. With 4Partners CMS, teams can streamline content creation, improve collaboration, and deliver engaging web experiences. Its extensible plugin ecosystem and API-first approach ensure seamless integration with.

Preferences
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does HeyLight do?

HeyLight is a European Buy Now Pay Later and consumer credit platform born from the 2024 merger of HeidiPay and Compass Banca, offering instalment plans for ecommerce checkout.

What HeyLight is and what it does

HeyLight is a European Buy Now Pay Later and consumer credit provider born in 2024 from the merger of HeidiPay in Switzerland and the BNPL division of Compass Banca, part of the Italian Mediobanca group. It offers instalment plans (3x, 4x, 6x, 12x and up to 84x) integrated into ecommerce checkouts through a JavaScript widget and an iframe payment flow, and it acts as a regulated credit provider supervised by national financial authorities in Italy, Switzerland and other EU markets.

Data and cookies collected by HeyLight

During a checkout HeyLight collects order details, applicant identity (name, email, postal address), fiscal code or national identifier, IBAN, an ID document for KYC, and signals used for credit scoring such as previous repayment history and device data. Session and CSRF cookies (heylight_session, hl_csrf) sustain the secure checkout, hl_consent stores cookie preferences, and hl_lang stores the language. Domains include heylight.com, pay.heylight.com, checkout.heylight.com, api.heylight.com and cdn.heylight.com.

GDPR and ePrivacy implications

HeyLight processes financial data, identity documents and KYC information at scale, and performs automated credit decisions which fall under Art. 22 GDPR. Strict information duties under Art. 13 GDPR apply, as do applicant rights to obtain a human review, contest the decision and understand the logic involved. The ePrivacy Directive applies to any non strictly necessary cookies set by the widget, while the EU Consumer Credit Directive 2023/2225 and PSD2 impose additional disclosures and security obligations.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Consent requirements and legal basis

Cookies that are strictly necessary for the checkout do not need consent. Marketing and analytics cookies, if loaded, require prior opt in consent under ePrivacy. The underlying credit assessment relies on contract performance (Art. 6(1)(b)), legal obligation (Art. 6(1)(c)) for KYC and AML, and legitimate interest (Art. 6(1)(f)) for fraud prevention. Special information must be given when the credit score relies on automated decision making, including the right to request human intervention.

Cross-border data transfers and practical compliance steps

Processing happens primarily in the EU (Italy) and Switzerland; Switzerland is covered by an EU adequacy decision so no additional transfer tools are needed. Merchants should: list HeyLight in the privacy notice and cookie banner, gate marketing cookies behind consent, run a DPIA covering automated credit decisions and KYC, sign a data processing or joint controller agreement as appropriate, document retention of credit files, and inform applicants about their Art. 22 rights and complaint channels with the national DPA.

GDPR consent category

Preferences

Websites using HeyLight must obtain user consent under GDPR regulations.

Legal basisContract performance (Art. 6(1)(b)) for credit assessment, legal obligation (Art. 6(1)(c)) for KYC/AML, legitimate interest (Art. 6(1)(f)) for fraud prevention, consent for marketing and analytics cookies
Risk levelhigh
Applicable regulationsGDPR, ePrivacy Directive, Italian Privacy Code, Swiss FADP, EU Consumer Credit Directive 2023/2225, AML and KYC directives, PSD2

DPIA considerations

A DPIA is strongly required. HeyLight performs automated credit scoring (Art. 22 GDPR), processes identity documents and fiscal codes for KYC and AML, handles financial behaviour data at large scale, and combines EU and Swiss processing. Assess profiling logic, applicant rights to human review, retention of credit files, security of ID documents and lawful basis for each processing purpose.

Sample consent text

By proceeding with HeyLight you agree that your personal and financial data will be processed to assess your creditworthiness, verify your identity under AML rules and provide instalment financing. Marketing and analytics cookies are set only with your consent.

Technical details

Tracking methodJavaScript checkout widget plus iframe payment flow collecting order data, applicant identity, fiscal code, IBAN, ID documents and credit scoring decisions
Server locationEuropean Union (Italy primary) and Switzerland
Data transferred outside the EULimited transfers between EU and Switzerland; Switzerland benefits from an EU adequacy decision so no additional safeguards required

Third-party domains contacted

heylight.compay.heylight.comcheckout.heylight.comapi.heylight.comcdn.heylight.comheidipay.comcompass.it

Cookies placed

NameTypeDurationPurpose
heylight_sessionfunctionalSessionMaintains the secure HeyLight checkout session and links the applicant to their pending credit application
hl_csrffunctionalSessionCross site request forgery token protecting the checkout and credit application forms
hl_consentfunctional12 monthsStores the cookie banner choices made by the visitor on HeyLight properties
hl_langpreferences6 monthsRemembers the language preference for the checkout interface
hl_device_idsecurity12 monthsDevice fingerprint identifier used for fraud prevention and risk based authentication
_gaanalytics13 monthsGoogle Analytics client identifier set on the marketing site, only after consent

HeyLight uses cookies for user preferences — inform visitors with a consent banner.

Get started freeScan your site

Frequently asked questions

Which cookies and identifiers does HeyLight set?

HeyLight sets functional cookies such as heylight_session for the checkout session, hl_csrf for cross site request forgery protection, hl_consent to record cookie choices and hl_lang for the language. Exact names depend on the integration and may also include short lived authentication tokens.

Is consent required before loading HeyLight?

The checkout itself can be loaded without consent because it is strictly necessary to perform the credit contract requested by the customer. Any marketing, advertising or analytics cookies added on top of the widget require prior opt in consent under the ePrivacy Directive.

What is the legal basis for processing?

Contract performance (Art. 6(1)(b)) covers the credit assessment, legal obligation (Art. 6(1)(c)) covers KYC and AML duties, and legitimate interest (Art. 6(1)(f)) covers fraud prevention. Marketing and analytics rely on consent. Automated credit decisions invoke Art. 22 GDPR with safeguards.

Does HeyLight transfer data outside the EU?

Processing takes place primarily in Italy (EU) and Switzerland. Switzerland is covered by an EU adequacy decision, so transfers between the two jurisdictions need no additional safeguards. There are no routine transfers to countries lacking an adequate level of protection.

Do I need a DPIA for HeyLight?

Yes, a DPIA is strongly recommended. Automated credit scoring under Art. 22 GDPR, large scale processing of financial data and identity documents for KYC, and combined EU and Swiss processing all meet the criteria of Art. 35 GDPR for mandatory assessment.

How do I implement HeyLight compliantly?

List HeyLight in the privacy notice and cookie banner, sign a DPA or joint controller agreement, gate any non strictly necessary cookies behind consent, inform applicants about automated decision making and their right to human intervention, retain KYC files securely and run a DPIA before launch.

Are there alternatives to HeyLight?

Yes. Other Buy Now Pay Later and consumer credit providers include Klarna (Sweden), Afterpay or Clearpay in Europe, Scalapay (Italy), Riverty (formerly AfterPay BE), Alma (France), Younited (France), Cetelem and PayPal Pay Later. Compliance posture, data location and product scope differ between providers.

How do I update my cookie policy for HeyLight?

Add a HeyLight entry naming the controller, list the cookies used (heylight_session, hl_csrf, hl_consent, hl_lang) with purpose and duration, indicate that processing takes place in the EU and Switzerland under an adequacy decision, and link to the HeyLight privacy notice for credit assessment and KYC details.