FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. E-commerce
  4. Piano

Piano

PreferencesWebsite

Related services

24nettbutikk

24nettbutikk is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. 24nettbutikk supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, 24nettbutikk ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Preferences

2ClickShop

2ClickShop is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 2ClickShop integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 2ClickShop helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences

4-Tell

4-Tell is a marketing platform that equips businesses with tools to amplify their digital presence and drive customer acquisition. It supports audience segmentation, campaign automation, and cross-channel engagement. 4-Tell provides real-time analytics and reporting dashboards for performance measurement and strategy optimization. By combining data intelligence with marketing execution, 4-Tell helps deliver the right message to the right audience at the right time.

Preferences

42stores

42stores is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 42stores integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 42stores helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences

4Partners

4Partners is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 4Partners integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 4Partners helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences
4

4Partners CMS

4Partners CMS is a powerful content management system (CMS) designed to help businesses and developers build, manage, and publish digital content with ease. It offers a flexible architecture that supports custom content types, templates, and workflows, making it ideal for websites of any scale. With 4Partners CMS, teams can streamline content creation, improve collaboration, and deliver engaging web experiences. Its extensible plugin ecosystem and API-first approach ensure seamless integration with.

Preferences
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does Piano do?

Piano is a subscription, paywall and audience activation platform that combines analytics, identity, consent management and content monetisation in one JavaScript SDK.

What is Piano

Piano (piano.io) is a subscription, paywall and audience activation platform used heavily by publishers and media groups. It bundles Piano ID (identity and account management), Piano Composer (paywall and offer orchestration), Piano DMP (audience segments), Piano Analytics (after the acquisition of AT Internet) and a Consent Management Platform certified under the IAB TCF v2.2. Everything is deployed through a single tp.js JavaScript SDK.

What cookies and data Piano collects

Piano writes __utp (anonymous Piano user identifier), __pat and __pvi cookies for paywall behaviour, __qca for engagement and many segment cookies depending on the modules enabled. Through Piano ID the platform stores the logged in identifier and a session token. The CMP module writes a consent string in line with TCF v2.2 and a separate consent identifier. Server side Piano receives IP, user agent, page URL, reading behaviour, subscription status and account data.

GDPR and ePrivacy implications

The paywall and identity functions are strictly necessary for paid content delivery and rely on contract performance. Audience activation, DMP segments, advertising integrations and behavioural personalisation are not strictly necessary and require consent under Art. 5(3) ePrivacy and Art. 6(1)(a) GDPR. The CMP module itself is exempt from consent for the recording of the consent decision.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Consent and legal basis

Configure the Piano CMP to ask explicit consent for advertising, profiling and audience activation purposes. Keep paywall and identity flows under contract performance. Surface a granular opt out for DMP segments. Mind the EDPB position that legitimate interest is not acceptable for cross site advertising trackers; rely on consent.

Data transfers and hosting

Piano operates data centers in Amsterdam and Paris for EU customers, in addition to Philadelphia, Denver, Hong Kong and Sydney. Choosing the EU region keeps reader data within the EU at rest. Piano Inc. remains US headquartered and may access data from the US for global support; rely on the EU US Data Privacy Framework and the Piano Standard Contractual Clauses for any transfer.

Practical compliance steps

Pick the EU data center, segment the consent purposes by module (paywall, analytics, advertising, DMP), expose a clear withdraw mechanism, audit which third parties receive data via the CMP and turn off any integration that exceeds the declared purposes. Train editorial and product teams on the limits of segmentation, and add Piano to your records of processing activities as both processor and joint controller (CMP module).

GDPR consent category

Preferences

Websites using Piano must obtain user consent under GDPR regulations.

Legal basisConsent (Art. 6(1)(a) GDPR) for advertising and profiling features; contract performance (Art. 6(1)(b) GDPR) for paywall and subscription flows
Risk levelhigh
Applicable regulationsGDPR, ePrivacy Directive, EU US Data Privacy Framework, IAB TCF v2.2 (for the CMP module), CNIL cookie guidelines

DPIA considerations

A DPIA is recommended when Piano combines paywall, identity and DMP modules, when audience segments are enriched with third party data, when minors are addressed, or when AI driven offer personalisation is enabled.

Sample consent text

We use Piano to deliver paywalls, personalised offers and audience analytics. Piano writes cookies on your device and shares your IP address, account identifier and reading behaviour with Piano Inc. in the United States. We only load Piano modules that require consent if you accept.

Technical details

Tracking methodJavaScript SDK for paywalls, audience activation, consent management and customer journey orchestration
Server locationUnited States (Piano Inc., Philadelphia) with EU data centers in Amsterdam and Paris
Data transferred outside the EUPiano Inc. is headquartered in the United States. EU customers can opt into Piano data centers in Amsterdam and Paris, but Piano Inc. operates the platform globally and support may access data from the US. Transfers rely on the EU US Data Privacy Framework and Piano Standard Contractual Clauses.

Third-party domains contacted

tinypass.compiano.iocdn.tinypass.combuy.tinypass.comexperience.piano.io

Cookies placed

NameTypeDurationPurpose
__utpfirst_party1 yearAnonymous Piano user identifier used for paywall and analytics
__patfirst_party1 yearStores paywall state and offer access for the visitor
__pvifirst_party1 yearVisit identifier used to count page views against the paywall meter
__qcafirst_party1 yearEngagement and quintile cookie used by audience modules
__tacfirst_party1 yearStores the encoded TCF v2.2 consent string for downstream vendors

Piano uses cookies for user preferences — inform visitors with a consent banner.

Get started freeScan your site

Frequently asked questions

Which cookies does Piano set?

Piano writes __utp (anonymous user identifier), __pat and __pvi (paywall behaviour), __qca (engagement), the TCF v2.2 consent string and several segment cookies for DMP. Piano ID adds an authentication cookie when the reader logs in.

Is consent required for Piano?

Partially. The paywall and the Piano ID login are strictly necessary and exempt. Audience activation, DMP segments, advertising integrations and behavioural personalisation require prior consent under Art. 5(3) ePrivacy and the GDPR.

Which GDPR legal basis applies?

Contract performance for paywall and identity. Consent for DMP, advertising integrations and audience activation. Legitimate interest is not acceptable for cross site advertising trackers.

Are there transfers to the United States?

Piano Inc. is US headquartered. EU data centers in Amsterdam and Paris reduce the residency footprint, but support and global operations may access data from the US. Rely on the EU US Data Privacy Framework and Piano Standard Contractual Clauses.

Do I need a DPIA?

Recommended when Piano combines paywall, identity and DMP, when audience segments are enriched with third party data, when minors are addressed, or when AI driven offer personalisation is enabled.

How do I implement Piano compliantly?

Pick the EU region, declare each module separately in the CMP, expose granular controls, audit downstream vendors loaded via the CMP, and review every TCF purpose to ensure it matches the modules actually in use.

Are there alternatives to Piano?

For paywalls: Poool (France), Tinypass legacy, Laterpay (Germany), Stripe Subscriptions backed by your own implementation. For audience analytics: AT Internet historic (now Piano Analytics), Matomo, Plausible. For CMP: Didomi, Axeptio, Sourcepoint.

How do I update my cookie policy?

List Piano cookies per module (paywall, identity, DMP, CMP, integrations) with purpose, lifetime and controller. Specify that the CMP module is governed by IAB TCF v2.2 and explain the EU US Data Privacy Framework basis for any transfer.