FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. E-commerce
  4. ProcessOut

ProcessOut

PreferencesWebsite

Related services

24nettbutikk

24nettbutikk is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. 24nettbutikk supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, 24nettbutikk ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Preferences

2ClickShop

2ClickShop is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 2ClickShop integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 2ClickShop helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences

4-Tell

4-Tell is a marketing platform that equips businesses with tools to amplify their digital presence and drive customer acquisition. It supports audience segmentation, campaign automation, and cross-channel engagement. 4-Tell provides real-time analytics and reporting dashboards for performance measurement and strategy optimization. By combining data intelligence with marketing execution, 4-Tell helps deliver the right message to the right audience at the right time.

Preferences

42stores

42stores is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 42stores integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 42stores helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences

4Partners

4Partners is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 4Partners integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 4Partners helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences
4

4Partners CMS

4Partners CMS is a powerful content management system (CMS) designed to help businesses and developers build, manage, and publish digital content with ease. It offers a flexible architecture that supports custom content types, templates, and workflows, making it ideal for websites of any scale. With 4Partners CMS, teams can streamline content creation, improve collaboration, and deliver engaging web experiences. Its extensible plugin ecosystem and API-first approach ensure seamless integration with.

Preferences
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does ProcessOut do?

ProcessOut is a smart payment routing and orchestration platform founded in Paris in 2015 and acquired by Checkout.com in 2020. It provides a vendor neutral API that lets merchants connect to multiple Payment Service Providers (Stripe, Adyen, Worldpay, PayPal, Braintree and more), route transactions dynamically to maximise authorisation rates, run A/B tests on PSPs, manage cards in a unified vault and benchmark payment performance through detailed analytics. ProcessOut targets mid market and enterprise merchants who want PSP independence and a single integration for the global payments stack.

What ProcessOut is

ProcessOut is a payment orchestration platform founded in Paris in 2015 by Cyril Chemla, Gregoire Lemercier and Jeremy Lejoux. The company joined the Checkout.com group in 2020 and continues to provide a vendor neutral layer above traditional Payment Service Providers. Through a single API, ProcessOut enables merchants to vault cards once, connect dozens of PSPs (Stripe, Adyen, Worldpay, Braintree, PayPal, Klarna, GoCardless and others), apply smart routing rules in real time, run controlled experiments on PSP performance and consolidate reporting in a unified analytics dashboard.

What data and cookies ProcessOut sets

In the checkout flow, ProcessOut sets technical cookies and tokens used by its hosted iFrame for tokenisation, anti CSRF protection and 3D Secure session continuity. It processes card primary account numbers (PAN), expiry, CVV, cardholder name, billing address, IP address, device fingerprint and transaction metadata. Card data is tokenised and stored in a PCI DSS Level 1 vault. On the merchant dashboard, additional cookies are used for authentication, preferences and product analytics.

GDPR and ePrivacy implications

ProcessOut acts as a processor or joint controller depending on the use case. Payment execution is grounded in contractual necessity, while fraud prevention relies on legal obligation. Smart routing decisions are profiling activities that must be documented, and customers retain rights to information, access, rectification, restriction and objection. Cookies set by the checkout iFrame are strictly necessary and exempt from consent, while cookies on the merchant dashboard are subject to standard consent rules.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Consent requirements

No consent is required to process the payment itself, since this is necessary to execute the contract. Consent is required for non essential analytics or marketing cookies that ProcessOut or your dashboard tooling sets. For storing card credentials for future purchases (card on file), you must rely on contract or explicit opt in from the customer at the checkout step.

Data transfers

ProcessOut hosts its core vault and routing engine in the European Union. As part of the Checkout.com group, some operational data flows through UK and US infrastructure. Most importantly, routing transactions to PSPs such as Stripe US, Braintree or PayPal involves transfers of cardholder data outside the EEA. Standard Contractual Clauses, the EU US Data Privacy Framework and an active transfer impact assessment are necessary, along with PSP specific contractual safeguards.

Practical compliance steps

Sign the ProcessOut and Checkout.com DPA, list the connected PSPs in your transparency notice with their respective transfer mechanisms, document the routing logic and profiling in the record of processing activities, perform a DPIA covering card vaulting and smart routing, limit cardholder data retention to the strict PCI DSS minimum, restrict dashboard access through SSO and MFA, and verify that the checkout iFrame loads no marketing cookies before consent.

GDPR consent category

Preferences

Websites using ProcessOut must obtain user consent under GDPR regulations.

Legal basisContractual necessity (Art. 6(1)(b) GDPR) for executing payments, legal obligation (Art. 6(1)(c) GDPR) for fraud prevention and anti money laundering, legitimate interest (Art. 6(1)(f) GDPR) for routing optimisation, consent (Art. 6(1)(a) GDPR) for analytics cookies on the merchant dashboard
Risk levelhigh
Applicable regulationsGDPR, ePrivacy Directive, PSD2, PCI DSS, AML, French Monetary and Financial Code

DPIA considerations

A DPIA is required because ProcessOut processes large volumes of cardholder data, performs profiling for fraud and routing, and triggers cross border transfers to downstream PSPs including in the United States. Key risks include scope of card vaulting, retention of failed transactions, exposure of identifying metadata to multiple PSPs, behavioural profiling for routing optimisation, sub processing by Checkout.com group entities and incident response across multiple acquirers.

Sample consent text

Payment on our website is processed by ProcessOut, a payment orchestration platform of the Checkout.com group. ProcessOut tokenises your card data and routes the transaction to the optimal acquirer, which may be located outside the European Union. Strictly necessary cookies set by the payment iFrame are exempt from consent. Analytics or marketing cookies will only be loaded after you accept in our consent banner.

Technical details

Tracking methodJavaScript SDK and iFrames hosted by ProcessOut for tokenisation, plus server side APIs for routing and analytics
Server locationEuropean Union (France, Paris) with infrastructure operated by Checkout.com after acquisition; additional regions in the United Kingdom and United States
Data transferred outside the EUProcessOut routes transactions to multiple Payment Service Providers (Stripe, Adyen, Worldpay, PayPal, Braintree, etc.) located in the EU, the UK and the United States. Card tokenisation occurs in EU regions but secondary routing and fraud analysis can involve US based PSPs and Checkout.com group infrastructure. Card data leaves the EEA when the chosen acquirer is outside Europe.

Third-party domains contacted

processout.comapi.processout.comjs.processout.comdashboard.processout.comcheckout.com

Cookies placed

NameTypeDurationPurpose
po_sessionsessionsessionStrictly necessary session cookie used by the ProcessOut checkout iFrame to maintain state between tokenisation, 3D Secure challenge and final authorisation.
__Host-po-csrfsessionsessionAnti CSRF token issued by the ProcessOut checkout iFrame to protect against cross site request forgery during card data submission.
po_device_idfirst_party13 monthsDevice fingerprint identifier used by ProcessOut for fraud scoring and dispute analytics. Considered strictly necessary for fraud prevention.
po_dashboard_sessionsessionsessionSession cookie for the ProcessOut merchant dashboard used to authenticate merchants between page loads.
_pendo / amplitudeanalyticsup to 13 monthsOptional product analytics cookies (Pendo, Amplitude) on the merchant dashboard. Loaded only after the merchant has accepted analytics in the dashboard preferences.

ProcessOut uses cookies for user preferences — inform visitors with a consent banner.

Get started freeScan your site

Frequently asked questions

What cookies does ProcessOut set?

The ProcessOut checkout iFrame sets strictly necessary cookies and tokens for tokenisation, CSRF protection and 3D Secure session management. The merchant dashboard at dashboard.processout.com sets authentication, preference and optional product analytics cookies. No marketing cookies are set on the public checkout flow.

Is consent required to use ProcessOut?

Consent is not required for the payment processing itself or for the strictly necessary cookies on the iFrame, since both are needed to execute the contract. Consent is required for optional analytics or marketing cookies on your site or on the merchant dashboard, and you must obtain explicit opt in to store a card for future purchases (card on file).

What is the legal basis for processing?

Contract for executing the payment, legal obligation for fraud prevention and anti money laundering controls, legitimate interest for transactional analytics and routing optimisation, and consent for non essential cookies and saving card credentials.

Does ProcessOut transfer data outside the EU?

Yes. While ProcessOut hosts its vault and routing engine in the EU, the Checkout.com group operates UK and US infrastructure, and routing to PSPs such as Stripe US, Braintree or PayPal involves transfers of cardholder data outside the EEA, covered by Standard Contractual Clauses and the EU US Data Privacy Framework.

Is a DPIA required?

Yes. The large volume of payment card data, the systematic profiling for smart routing and fraud, the cross border data flows and the use of a chain of sub processors trigger a mandatory DPIA under Article 35 GDPR.

How do we integrate ProcessOut compliantly?

Use the hosted iFrame so the PAN never touches your servers, sign the DPA with ProcessOut and Checkout.com, list all connected PSPs in the privacy notice, document the routing logic, complete a DPIA, restrict dashboard access through SSO and MFA, and align retention with PCI DSS requirements.

What are the alternatives to ProcessOut?

Alternatives include Primer, Spreedly, Gr4vy, IXOPAY and the orchestration offerings of large PSPs themselves (Stripe Connect, Adyen, Worldline). Each differs in PSP coverage, pricing model, vaulting capabilities and EU sovereignty.

How should we update the cookie policy?

Add an entry for ProcessOut as the payment orchestrator, listing the strictly necessary iFrame cookies, the optional dashboard analytics cookies and a clear note that the chosen acquirer may be outside the EU. Provide links to the privacy notices of Checkout.com and each connected PSP, and refresh the list whenever the routing configuration changes.