FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. E-commerce
  4. Patreon

Patreon

PreferencesWebsite

Related services

24nettbutikk

24nettbutikk is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. 24nettbutikk supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, 24nettbutikk ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Preferences

2ClickShop

2ClickShop is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 2ClickShop integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 2ClickShop helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences

4-Tell

4-Tell is a marketing platform that equips businesses with tools to amplify their digital presence and drive customer acquisition. It supports audience segmentation, campaign automation, and cross-channel engagement. 4-Tell provides real-time analytics and reporting dashboards for performance measurement and strategy optimization. By combining data intelligence with marketing execution, 4-Tell helps deliver the right message to the right audience at the right time.

Preferences

42stores

42stores is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 42stores integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 42stores helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences

4Partners

4Partners is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 4Partners integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 4Partners helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences
4

4Partners CMS

4Partners CMS is a powerful content management system (CMS) designed to help businesses and developers build, manage, and publish digital content with ease. It offers a flexible architecture that supports custom content types, templates, and workflows, making it ideal for websites of any scale. With 4Partners CMS, teams can streamline content creation, improve collaboration, and deliver engaging web experiences. Its extensible plugin ecosystem and API-first approach ensure seamless integration with.

Preferences
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does Patreon do?

Patreon is a US based membership platform headquartered in San Francisco that lets creators run paid recurring memberships, drip content and patron only communities. Creators set up tiers on patreon.com and either link to their public Patreon page or embed a join button and tier widgets on their own site. The embed sets non strictly necessary cookies, and Patreon acts as the merchant of record for digital memberships in the EU, collecting EU VAT on the creator's behalf. EU sites must gate the embed behind consent and document the US transfer.

What is Patreon?

Patreon is a US based membership platform incorporated as Patreon Inc., founded in 2013 by Jack Conte and Sam Yam, with headquarters in San Francisco. Creators (musicians, podcasters, illustrators, news outlets, software developers) set up a Patreon page, define monthly or annual tiers and publish exclusive posts, audio, video or downloads for their paying patrons. Patreon hosts the public page, the patron portal, the messaging and the audio/video player.

For most EU patrons paying for digital memberships, Patreon is the merchant of record: Patreon collects the EU VAT, issues the receipt and pays the creator the net revenue. Payments are routed through Stripe and PayPal.

Cookies and data collected

When a Patreon embed is on the creator''s own site, JavaScript loads from c.patreon.com or c10.patreonusercontent.com. The embed opens an iframe to patreon.com that sets first party Patreon cookies (session, csrf, patreon device id, patreon language preference) and Cloudflare bot management cookies. Stripe and PayPal flows during checkout add __stripe_mid, __stripe_sid, m and paypal_* cookies. Patreon itself runs Google Analytics 4, Optimizely, Sentry and Segment on patreon.com.

GDPR and ePrivacy implications

Loading the Patreon embed sets non strictly necessary cookies before the visitor acts, which triggers Art. 5(3) ePrivacy and requires prior consent in the EU. Once the visitor joins on patreon.com, the membership processing is on contract performance and Patreon acts as a separate controller for the VAT and tax data. Patreon also processes patron messages, posts and rewards on the creator''s behalf, with creators acting as joint controllers for that content.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Consent and implementation

For EU traffic, replace the embed by a plain link to the public Patreon page until the visitor has accepted the functional or marketing category in your CMP. Once consent is given, the Patreon embed and the join button can load. Once on patreon.com, the patron is subject to Patreon''s own privacy notice and cookie controls.

International data transfers

Patreon processes EU patron data on Google Cloud US and AWS US East. The Patreon DPA includes the EU Standard Contractual Clauses (modules 2 and 3) and the UK IDTA, and Patreon is self certified under the EU US Data Privacy Framework. Onward transfers happen to Stripe and PayPal, which apply their own SCCs and DPF certifications.

Practical compliance steps

Sign the Patreon DPA from your creator settings. Gate the embed behind a CMP. List Patreon, Stripe and PayPal in your privacy notice and Article 30 record. Document the US transfer with SCCs and DPF. Update your terms so refunds, VAT receipts and disputes go through Patreon as merchant of record for digital memberships in the EU.

GDPR consent category

Preferences

Websites using Patreon must obtain user consent under GDPR regulations.

Legal basisConsent (Art. 6(1)(a) GDPR and Art. 5(3) ePrivacy) for the Patreon embed widget and join button loaded on the creator's own site, because they set non strictly necessary cookies before any visitor action. Contract performance (Art. 6(1)(b)) for the membership the patron subscribes to on patreon.com. Legal obligation (Art. 6(1)(c)) for EU VAT, AML and tax record keeping, since Patreon is the merchant of record for digital memberships.
Risk levelmedium
Applicable regulationsGDPR, UK GDPR, ePrivacy Directive 2002/58/EC, EU US Data Privacy Framework, EU VAT Directive (Council Directive 2006/112/EC), PSD2, PCI DSS, US CCPA/CPRA

DPIA considerations

A DPIA is not normally required for a creator with a small Patreon. It can become relevant for media operations using Patreon alongside extensive analytics, profiling, course completion tracking and AI driven content delivery on the same audience.

Sample consent text

Memberships on this site are powered by Patreon (Patreon Inc., United States), our merchant of record for digital memberships in the EU. The Patreon embed sets functional and analytics cookies, opens a page on patreon.com, processes payments through Stripe and PayPal and remits EU VAT on our behalf. International transfers to the US are covered by Standard Contractual Clauses and the EU US Data Privacy Framework.

Technical details

Tracking methodMembership and recurring revenue platform: hosted public pages on patreon.com, an embeddable join button loaded from c10.patreonusercontent.com / c.patreon.com, plus tag based widgets that display Patron tiers; first party Patreon session, CSRF and identification cookies are set on patreon.com, Stripe and PayPal handle the payment iframe and recurring billing
Server locationUnited States (Patreon Inc., San Francisco, California, headquarters); production hosted on Google Cloud Platform US regions and AWS US East; static assets and patron media served from Cloudflare and Patreon's own usercontent CDN with EU edge presence
Data transferred outside the EUPatreon Inc. is established in the United States. Personal data of patrons (names, emails, address for physical rewards, payment metadata, message history) is processed on GCP US and AWS US East. Patreon is self certified under the EU US Data Privacy Framework, and its DPA incorporates the EU Standard Contractual Clauses (modules 2 and 3) and the UK International Data Transfer Addendum. As merchant of record for digital memberships in the EU, Patreon also collects EU VAT on behalf of creators.

Third-party domains contacted

patreon.comc.patreon.comc10.patreonusercontent.comjs.stripe.comwww.paypal.com

Cookies placed

NameTypeDurationPurpose
session_idthird_party2 weeksPatreon functional session cookie set on patreon.com to keep an authenticated patron session and the in progress membership flow.
csrf_tokenthird_partySessionCSRF protection token for Patreon API calls during the membership and payment flow.
patreon_device_idthird_party1 yearPersistent Patreon device identifier used to recognise the same browser across sessions and to detect suspicious sign in attempts.
__cf_bmthird_party30 minutesCloudflare bot management cookie set on patreon.com to distinguish humans from automated traffic.
__stripe_midthird_party1 yearStripe machine identifier loaded during the Patreon Stripe checkout step for fraud prevention.
__stripe_sidthird_party30 minutesStripe session identifier loaded during the Patreon Stripe checkout step for fraud detection.

Patreon uses cookies for user preferences — inform visitors with a consent banner.

Get started freeScan your site

Frequently asked questions

What cookies does Patreon set?

When the Patreon embed loads, it sets first party Patreon cookies on patreon.com (session_id, csrf_token, patreon_device_id, locale) and Cloudflare bot management cookies (__cf_bm, _cfuvid). The Stripe checkout adds __stripe_mid, __stripe_sid and m; PayPal adds paypal_* cookies. Patreon's own site runs Google Analytics 4, Optimizely, Sentry and Segment.

Do I need consent to load the Patreon embed?

Yes. The embed sets non strictly necessary cookies before any visitor action, so Art. 5(3) ePrivacy requires prior consent in the EU. Use a CMP to gate the embed and rely on a plain link to the public Patreon page until consent is given.

What is the legal basis for using Patreon?

Consent (Art. 6(1)(a) GDPR and Art. 5(3) ePrivacy) for the embed cookies. Contract performance (Art. 6(1)(b)) for the membership processing on patreon.com. Legal obligation (Art. 6(1)(c)) for EU VAT collection, since Patreon is the merchant of record for digital memberships in the EU.

Does Patreon transfer data to third countries?

Yes. Patreon Inc. is established in the United States and processes EU patron data on Google Cloud US and AWS US East. The Patreon DPA incorporates the EU Standard Contractual Clauses and the UK IDTA, and Patreon is self certified under the EU US Data Privacy Framework. Stripe and PayPal apply their own SCCs and DPF certifications.

Do I need a DPIA for Patreon?

A DPIA is not normally required for a small creator using Patreon as a tip jar. It can become appropriate for media operations using Patreon alongside extensive analytics, profiling, course completion tracking and AI content delivery on the same audience.

How do I implement Patreon compliantly?

Sign the Patreon DPA, gate the embed behind a CMP, list Patreon, Stripe and PayPal in your privacy notice and Article 30 record, document the US transfer with SCCs and DPF, and direct refund, VAT receipt and dispute requests to Patreon as merchant of record.

Are there alternatives to Patreon?

EU friendly alternatives include Steady (Germany), Tipeee (France), Liberapay (France, non profit), Ko fi (UK), Buy Me a Coffee (US), Substack (US with DPF), Beehiiv (US with DPF) and self managed setups based on Stripe Billing or Mollie subscriptions.

How should I update my cookie and privacy policy for Patreon?

List the Patreon, Cloudflare, Stripe and PayPal cookies in your cookie policy with their categories and durations. In your privacy notice describe Patreon as your membership platform and merchant of record, the embed, the iframe to patreon.com, the US transfer with SCCs and DPF and the role of Stripe and PayPal as separate processors.