FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. E-commerce
  4. Plug&Pay
P

Plug&Pay

PreferencesWebsite

Related services

24nettbutikk

24nettbutikk is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. 24nettbutikk supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, 24nettbutikk ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Preferences

2ClickShop

2ClickShop is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 2ClickShop integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 2ClickShop helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences

4-Tell

4-Tell is a marketing platform that equips businesses with tools to amplify their digital presence and drive customer acquisition. It supports audience segmentation, campaign automation, and cross-channel engagement. 4-Tell provides real-time analytics and reporting dashboards for performance measurement and strategy optimization. By combining data intelligence with marketing execution, 4-Tell helps deliver the right message to the right audience at the right time.

Preferences

42stores

42stores is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 42stores integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 42stores helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences

4Partners

4Partners is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 4Partners integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 4Partners helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences
4

4Partners CMS

4Partners CMS is a powerful content management system (CMS) designed to help businesses and developers build, manage, and publish digital content with ease. It offers a flexible architecture that supports custom content types, templates, and workflows, making it ideal for websites of any scale. With 4Partners CMS, teams can streamline content creation, improve collaboration, and deliver engaging web experiences. Its extensible plugin ecosystem and API-first approach ensure seamless integration with.

Preferences
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does plug pay do?

plug pay is a Brazilian payment orchestration and checkout platform that lets merchants accept credit cards, Pix and other local payment methods through a hosted checkout or a JavaScript SDK embedded in their site.

What is plug pay

plug pay is a Brazilian payment orchestration and checkout platform. Merchants embed its hosted checkout or its JavaScript SDK to accept credit cards, Pix, boleto and other local payment methods. The platform tokenizes card data and routes the transaction to the selected acquirer or sub acquirer.

Cookies and data collected

During checkout plug pay sets cookies such as pp_session for the active payment session, _plug_sid for visitor identification and _plug_pay_token to bind a tokenized card to the session. The SDK collects device fingerprint signals (user agent, screen size, time zone, IP address) for fraud scoring, plus the buyer name, email, billing address and chosen payment method.

GDPR and ePrivacy legal basis

The actual payment processing relies on Article 6(1)(b) GDPR as the execution of a contract. Antifraud signals fall under Article 6(1)(f) GDPR (legitimate interest in preventing payment fraud). Non strictly necessary cookies and analytics scripts loaded by the checkout require consent under Article 5(3) ePrivacy Directive and Section 25(1) TTDSG.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Data transfers to Brazil

plug pay is hosted on AWS in Brazil. Each transaction involves a transfer of personal data from the EU to Brazil. There is no European Commission adequacy decision for Brazil, so transfers must rely on Standard Contractual Clauses 2021/914 and a transfer impact assessment that takes Brazilian surveillance laws and the LGPD into account.

DPIA considerations

A DPIA under Article 35 GDPR is recommended because the processing involves financial data, automated fraud scoring and an international transfer. It should describe data minimisation, retention of card tokens, the antifraud logic, the rights of the buyer when a transaction is refused and the PCI DSS scope.

Compliance steps

Sign Standard Contractual Clauses with Plug Pagamentos, complete a transfer impact assessment, list plug pay in the privacy notice and cookie banner, block non essential cookies until consent, scope PCI DSS responsibilities and keep evidence of the antifraud legitimate interest balancing test.

GDPR consent category

Preferences

Websites using plug pay must obtain user consent under GDPR regulations.

Legal basisArticle 6(1)(b) GDPR (performance of a payment contract) for the core transaction processing, Article 6(1)(f) GDPR (legitimate interest in fraud prevention) for antifraud signals, and Article 6(1)(a) GDPR (consent) for non essential cookies and analytics scripts loaded by the checkout.
Risk levelhigh
Applicable regulationsGDPR, ePrivacy Directive, TTDSG, LOPDGDD, LGPD, PCI DSS, Schrems II, CNIL guidelines, EDPB transfer guidelines, Standard Contractual Clauses 2021/914

DPIA considerations

A DPIA is recommended whenever a European controller embeds plug pay, because the integration involves systematic processing of payment data, antifraud profiling, device fingerprinting and a transfer of personal data from the EU to Brazil. The DPIA must address the transfer impact assessment, the contractual safeguards in place, the retention of card tokens and the rights of the data subject when fraud rules block a transaction.

Sample consent text

To process your payment we send checkout data to plug pay in Brazil, which sets cookies on your device for the payment session and fraud prevention. Do you accept the use of plug pay to complete this order?

Technical details

Tracking methodServer side payment session management combined with first party browser cookies and JavaScript SDK for tokenized card capture. plug pay uses session, fraud and device fingerprint signals to authorise transactions through its Brazilian payment infrastructure.
Server locationBrazil. plug pay is operated by Plug Pagamentos, a Brazilian payment platform with infrastructure hosted on AWS regions inside Brazil (primarily sa east 1, São Paulo).
Data transferred outside the EUWhen plug pay is embedded by an EU controller, cardholder and transaction data are transferred from the EU to Brazil. Brazil is recognised by some controllers as offering adequate safeguards under the LGPD, but no European Commission adequacy decision exists. EU to Brazil transfers must therefore rely on Standard Contractual Clauses with a transfer impact assessment.

Third-party domains contacted

api.plugpay.com.brcheckout.plugpay.com.brjs.plugpay.com.brcdn.plugpay.com.brrisk.plugpay.com.br

Cookies placed

NameTypeDurationPurpose
pp_sessionsessionSessionMaintains the active payment session and ties the buyer to the merchant order while the checkout is open.
_plug_sidfirst_party1 yearPersistent visitor identifier used by plug pay to recognise returning buyers and stop duplicate or replay submissions.
_plug_pay_tokenfirst_party30 minutesHolds the short lived token that represents a tokenized payment instrument before the transaction is authorised.
_plug_fpfirst_party6 monthsStores a device fingerprint hash used in antifraud scoring to detect suspicious buyer behaviour.
_plug_localefirst_party1 yearStores the preferred language and currency for the hosted checkout interface.

plug pay uses cookies for user preferences — inform visitors with a consent banner.

Get started freeScan your site

Frequently asked questions

Which cookies does plug pay set at checkout?

plug pay sets first party cookies including pp_session for the live payment session, _plug_sid as a visitor identifier and _plug_pay_token to bind a tokenized card to the buyer. Additional antifraud cookies and localStorage entries are written by the JavaScript SDK during the order flow.

Is consent required to load the plug pay checkout?

Strictly necessary payment cookies do not require consent under the ePrivacy Directive. Analytics or marketing scripts loaded by the same checkout and any optional fingerprinting beyond fraud prevention require prior consent from the buyer.

What is the GDPR legal basis for plug pay?

Article 6(1)(b) GDPR covers the payment as part of the sales contract. Article 6(1)(f) GDPR covers antifraud signals under a documented legitimate interest. Article 6(1)(a) GDPR covers non essential analytics and marketing cookies loaded by the checkout.

Are payment data transferred outside the EU?

Yes. plug pay operates from Brazil, so every transaction transfers personal data from the EU to Brazil. There is no European Commission adequacy decision for Brazil, so Standard Contractual Clauses and a transfer impact assessment are required.

Is a DPIA required for plug pay?

Yes, a DPIA is recommended. The integration combines large scale payment processing, automated fraud scoring and an international transfer, which together meet several criteria of Article 35 GDPR and the EDPB lists of high risk processing.

How should plug pay be implemented correctly?

Sign SCCs and a data processing agreement, complete a transfer impact assessment, embed the SDK only on the pages that need it, block non essential cookies until consent, document antifraud rules and confirm the split of PCI DSS responsibilities with Plug Pagamentos.

What are the alternatives to plug pay?

In the EU, alternatives include Stripe, Adyen, Mollie and Worldline. Brazilian alternatives include Pagar.me, Stone and Cielo. Each option has its own hosting region, transfer mechanism and antifraud model that must be assessed before switching.

How do I update my cookie policy for plug pay?

List the strictly necessary payment cookies (pp_session, _plug_sid, _plug_pay_token), the antifraud and any analytics cookies, the controller relationship with Plug Pagamentos, the EU to Brazil transfer mechanism and a link to the plug pay privacy notice.