FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. E-commerce
  4. Payhip

Payhip

PreferencesWebsite

Related services

24nettbutikk

24nettbutikk is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. 24nettbutikk supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, 24nettbutikk ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Preferences

2ClickShop

2ClickShop is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 2ClickShop integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 2ClickShop helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences

4-Tell

4-Tell is a marketing platform that equips businesses with tools to amplify their digital presence and drive customer acquisition. It supports audience segmentation, campaign automation, and cross-channel engagement. 4-Tell provides real-time analytics and reporting dashboards for performance measurement and strategy optimization. By combining data intelligence with marketing execution, 4-Tell helps deliver the right message to the right audience at the right time.

Preferences

42stores

42stores is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 42stores integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 42stores helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences

4Partners

4Partners is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 4Partners integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 4Partners helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences
4

4Partners CMS

4Partners CMS is a powerful content management system (CMS) designed to help businesses and developers build, manage, and publish digital content with ease. It offers a flexible architecture that supports custom content types, templates, and workflows, making it ideal for websites of any scale. With 4Partners CMS, teams can streamline content creation, improve collaboration, and deliver engaging web experiences. Its extensible plugin ecosystem and API-first approach ensure seamless integration with.

Preferences
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does Payhip do?

Payhip is a UK based merchant of record platform run by Payhip Ltd in London. Creators use it to sell ebooks, digital downloads, courses, memberships and software, either on a hosted Payhip page or via an embed button or storefront on their own site. As merchant of record, Payhip collects EU VAT and other sales taxes and routes payments through Stripe and PayPal. The UK adequacy decision makes the main data flow EU friendly, but consent is still required for the embed and onward transfers must be documented.

What is Payhip?

Payhip is a UK based platform operated by Payhip Ltd in London that lets creators and small businesses sell digital products (ebooks, music, design assets, software), courses, memberships and physical goods. Sellers either send buyers to a hosted Payhip page (payhip.com/SELLER/PRODUCT) or embed a Buy button or full storefront on their own site through payhip.com/embed.js.

As merchant of record (MoR) for digital products, Payhip is the legal seller on the invoice, collects EU VAT and remits the net revenue. Payments are routed through Stripe and PayPal in the background. Payhip competes with Gumroad, Lemon Squeezy, Sellfy and SendOwl.

Cookies and data collected

When the Payhip embed is on the seller''s site, embed.js loads from payhip.com. The embed opens an iframe to payhip.com that sets first party Payhip cookies (payhip_session, payhip_csrf, payhip_locale, an attribution cookie) and Cloudflare bot management cookies. Stripe and PayPal flows add __stripe_mid, __stripe_sid and paypal_* cookies. Payhip''s own dashboard uses Google Analytics 4 and Sentry.

GDPR and ePrivacy implications

Embedding the Payhip widget loads cookies before the visitor acts, which triggers Art. 5(3) ePrivacy and requires prior consent in the EU. Once the customer initiates the purchase on the hosted checkout, the strictly necessary cookies are exempt and the payment processing relies on contract performance. As merchant of record, Payhip is a separate controller for VAT and tax data.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Consent and implementation

For EU traffic, replace the embed with a static link to the hosted Payhip product page until the visitor has accepted the functional or marketing category in your CMP. The hosted checkout itself can run without a banner because the cookies are strictly necessary, but the privacy notice should describe Payhip, Stripe and PayPal.

International data transfers

Payhip processes data on AWS Europe London and Ireland. The UK has an EU adequacy decision under Art. 45 GDPR, so the data flow to Payhip is treated like an intra EEA transfer. Onward transfers occur to Stripe (Ireland and US, with SCCs and DPF) and PayPal (Luxembourg and US, with SCCs and DPF).

Practical compliance steps

Sign the Payhip DPA from your seller dashboard. Gate the embed behind a CMP. List Payhip, Stripe and PayPal in your privacy notice and Article 30 record. Document UK adequacy and the onward transfers. Update your terms so refunds, VAT receipts and disputes go through Payhip as merchant of record.

GDPR consent category

Preferences

Websites using Payhip must obtain user consent under GDPR regulations.

Legal basisConsent (Art. 6(1)(a) GDPR and Art. 5(3) ePrivacy) for the Payhip embed loaded on the seller's own site, because it sets non strictly necessary cookies before any visitor action. Contract performance (Art. 6(1)(b)) for the purchase the customer completes on the hosted Payhip checkout. Legal obligation (Art. 6(1)(c)) for EU VAT collection and reporting, since Payhip is the merchant of record.
Risk levellow
Applicable regulationsGDPR, UK GDPR, ePrivacy Directive 2002/58/EC, EU US Data Privacy Framework (via Stripe / PayPal), EU VAT Directive (Council Directive 2006/112/EC), PSD2, PCI DSS

DPIA considerations

A DPIA is not normally required for a small creator using Payhip. It can become relevant for media operations using Payhip memberships and courses alongside extensive analytics, profiling and AI tooling on the same customer base.

Sample consent text

Sales and memberships on this site are powered by Payhip (Payhip Ltd, United Kingdom), our merchant of record for digital products and memberships. The Payhip embed sets functional and analytics cookies, opens an iframe to payhip.com, processes payments through Stripe and PayPal and remits EU VAT on our behalf. The UK benefits from an EU adequacy decision.

Technical details

Tracking methodMerchant of record platform for digital products and memberships: hosted product pages on payhip.com and an embeddable button or storefront loaded from payhip.com/embed.js; opens a checkout iframe to payhip.com that sets first party Payhip session, CSRF and locale cookies; payments are routed through Stripe and PayPal, with Payhip Ltd as the legal seller of record
Server locationUnited Kingdom (Payhip Ltd, London, England, headquarters); production hosted on AWS Europe London (eu west 2) and Ireland (eu west 1); static assets and the embed served from AWS CloudFront with EU edge presence
Data transferred outside the EUPayhip Ltd is established in the United Kingdom. The UK benefits from a European Commission adequacy decision under the GDPR. Customer data is processed on AWS Europe London and Ireland. Onward transfers occur for payments through Stripe (Ireland and US) and PayPal (Luxembourg and US), each covered by their own SCCs and EU US Data Privacy Framework. As merchant of record, Payhip collects EU VAT on behalf of sellers.

Third-party domains contacted

payhip.comwww.payhip.comcdn.payhip.comjs.stripe.comwww.paypal.com

Cookies placed

NameTypeDurationPurpose
payhip_sessionthird_party2 weeksPayhip session cookie set on payhip.com to keep an authenticated session and the in progress checkout.
payhip_csrfthird_partySessionCSRF protection token for Payhip API calls during the checkout flow.
payhip_localethird_party1 yearFunctional cookie used by Payhip to remember the buyer's language and currency preference between visits.
payhip_attributionthird_party6 monthsAttribution cookie used to track which seller link or affiliate brought the buyer to the Payhip checkout.
__cf_bmthird_party30 minutesCloudflare bot management cookie set on payhip.com to distinguish humans from automated traffic.

Payhip uses cookies for user preferences — inform visitors with a consent banner.

Get started freeScan your site

Frequently asked questions

What cookies does Payhip set?

When the Payhip embed loads, it sets first party Payhip cookies on payhip.com (payhip_session, payhip_csrf, payhip_locale, an attribution cookie) and Cloudflare bot management cookies. The Stripe step adds __stripe_mid and __stripe_sid; PayPal flows add paypal_* cookies.

Do I need consent to load the Payhip embed?

Yes. The embed sets non strictly necessary cookies before the visitor takes any action, so Art. 5(3) ePrivacy requires prior consent in the EU. Use a CMP to gate the embed and link to the hosted product page until consent is given.

What is the legal basis for using Payhip?

Consent (Art. 6(1)(a) GDPR and Art. 5(3) ePrivacy) for the embed cookies. Contract performance (Art. 6(1)(b)) for the purchase on the hosted Payhip checkout. Legal obligation (Art. 6(1)(c)) for EU VAT collection since Payhip is the merchant of record for digital products.

Does Payhip transfer data to third countries?

Primarily no. Payhip Ltd processes data in the United Kingdom and on AWS Europe London and Ireland. The UK has an EU adequacy decision under Art. 45 GDPR. Onward transfers happen for payments through Stripe and PayPal, covered by their own SCCs and EU US Data Privacy Framework.

Do I need a DPIA for Payhip?

Not for a small creator. A DPIA can be appropriate for media operations using Payhip memberships and courses alongside extensive analytics, profiling and AI tools on the same customer base.

How do I implement Payhip compliantly?

Sign the Payhip DPA, gate the embed behind a CMP, list Payhip, Stripe and PayPal in your privacy notice and Article 30 record, mention the UK adequacy decision and the onward transfers, and update your terms so refunds, VAT receipts and disputes go through Payhip.

Are there alternatives to Payhip?

EU friendly merchant of record alternatives include Paddle (UK), Lemon Squeezy (US with DPF), Gumroad (US with DPF), FastSpring (US), Sellfy (Latvia, EU) and SendOwl (UK). Non MoR EU options include Stripe Checkout and Mollie subscriptions.

How should I update my cookie and privacy policy for Payhip?

List the Payhip, Cloudflare, Stripe and PayPal cookies in your cookie policy with their categories and durations. In your privacy notice describe Payhip as your merchant of record, the embed, the iframe to payhip.com, the UK adequacy and the onward transfer to Stripe and PayPal in the US.