FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. E-commerce
  4. Recurly

Recurly

PreferencesWebsite

Related services

24nettbutikk

24nettbutikk is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. 24nettbutikk supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, 24nettbutikk ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Preferences

2ClickShop

2ClickShop is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 2ClickShop integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 2ClickShop helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences

4-Tell

4-Tell is a marketing platform that equips businesses with tools to amplify their digital presence and drive customer acquisition. It supports audience segmentation, campaign automation, and cross-channel engagement. 4-Tell provides real-time analytics and reporting dashboards for performance measurement and strategy optimization. By combining data intelligence with marketing execution, 4-Tell helps deliver the right message to the right audience at the right time.

Preferences

42stores

42stores is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 42stores integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 42stores helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences

4Partners

4Partners is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 4Partners integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 4Partners helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences
4

4Partners CMS

4Partners CMS is a powerful content management system (CMS) designed to help businesses and developers build, manage, and publish digital content with ease. It offers a flexible architecture that supports custom content types, templates, and workflows, making it ideal for websites of any scale. With 4Partners CMS, teams can streamline content creation, improve collaboration, and deliver engaging web experiences. Its extensible plugin ecosystem and API-first approach ensure seamless integration with.

Preferences
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does Recurly do?

Recurly is a US based subscription billing and recurring revenue platform headquartered in San Francisco that powers subscription lifecycle, dunning, revenue recognition and recurring invoicing for SaaS, streaming and digital media companies. Recurly.js tokenises card and bank input in a PCI compliant iframe loaded from js.recurly.com. Recurly is a processor (not a merchant of record), processing happens on AWS US East with optional EU residency on AWS Frankfurt for enterprise plans.

What is Recurly?

Recurly is a subscription billing platform incorporated as Recurly Inc. in San Francisco, California, founded in 2009. It powers recurring revenue for SaaS companies, streaming services, digital publishers and consumer subscription brands. Recurly handles plans and add ons, free trials, taxes (with TaxJar or Avalara), dunning, revenue recognition, churn analytics and customer self service portals. It connects to Stripe, Braintree, Adyen, Worldpay and many other payment gateways as the underlying processor.

Cookies and data collected

Recurly.js is loaded from js.recurly.com on the seller''s subscription or checkout page. It opens an iframe served from api.recurly.com that captures the card or bank account input directly in the PCI scope of Recurly, returns a token to the seller''s frontend and never exposes the raw PAN. The iframe sets first party Recurly cookies (recurly_session, recurly_csrf, recurly_risk) used to maintain the in progress checkout and to score risk. Server side, Recurly stores subscription metadata, invoices and tokenised card references.

GDPR and ePrivacy implications

Recurly is a processor for the seller under Art. 28 GDPR. The strictly necessary cookies on the Recurly.js iframe are exempt from prior consent under Art. 5(3) ePrivacy because they are needed for the requested payment service. The seller remains the controller for the subscription data and the merchant for VAT, although Recurly can compute and remit taxes when integrated with TaxJar or Avalara.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

International data transfers

By default, Recurly processes EU subscription data on AWS US East 1 and US West 2. EU data residency on AWS Frankfurt (eu central 1) is available as a contractual add on. The Recurly DPA incorporates the EU Standard Contractual Clauses (modules 2 and 3) and the UK International Data Transfer Addendum, and Recurly is self certified under the EU US Data Privacy Framework. A Transfer Impact Assessment should evaluate US surveillance laws.

Practical compliance steps

Sign the Recurly DPA, request EU data residency if available on your plan, mention Recurly as a processor in your privacy notice and Article 30 record, document the US transfer with SCCs and DPF and run a Transfer Impact Assessment. Keep card data off your servers by using Recurly.js. No cookie banner update is needed for the hosted iframe itself, but optional analytics on the same page must remain in a consent gated tag manager.

GDPR consent category

Preferences

Websites using Recurly must obtain user consent under GDPR regulations.

Legal basisContract performance (Art. 6(1)(b) GDPR) for processing the subscription, recurring billing, dunning and refund data necessary to deliver the service the customer has subscribed to. Legal obligation (Art. 6(1)(c)) for tax record keeping. Strictly necessary cookies on the Recurly.js iframe are exempt from prior consent under Art. 5(3) ePrivacy.
Risk levelmedium
Applicable regulationsGDPR, UK GDPR, ePrivacy Directive 2002/58/EC, EU US Data Privacy Framework, PSD2, PCI DSS Level 1, SOC 2 Type II, ISO/IEC 27001, US CCPA/CPRA

DPIA considerations

A DPIA is not normally required for using Recurly as a billing processor. It can become appropriate when Recurly subscription data is combined with extensive customer profiling, dynamic pricing, AI driven dunning or special category data tied to subscription tiers.

Sample consent text

Recurring payments on this site are powered by Recurly (Recurly Inc., United States). Recurly tokenises your card and bank input in a PCI compliant iframe, processes subscription data on AWS US East and supports an EU residency option on AWS Frankfurt. International transfers are covered by Standard Contractual Clauses and the EU US Data Privacy Framework. Recurly is our processor, not the merchant of record.

Technical details

Tracking methodSubscription billing and recurring revenue platform: Recurly.js loaded from js.recurly.com tokenises credit card and bank account input on the seller's own page, opens a hosted PCI compliant iframe and exchanges encrypted payloads with the Recurly API; sets first party Recurly session and CSRF cookies on the hosted checkout pages; integrates with Stripe Elements, Braintree, Adyen and Worldpay as underlying gateways
Server locationUnited States (Recurly Inc., San Francisco, California, headquarters); production hosted on AWS US East 1 and US West 2 by default; EU data residency on AWS Frankfurt (eu central 1) is available as a paid add on for enterprise customers
Data transferred outside the EURecurly Inc. is established in the United States and processes most subscription data on AWS US East. EU data residency on AWS Frankfurt is available contractually for enterprise plans. The Recurly DPA incorporates the EU Standard Contractual Clauses (modules 2 and 3) and the UK International Data Transfer Addendum, and Recurly is self certified under the EU US Data Privacy Framework. Recurly is not a merchant of record: the seller remains the merchant for VAT and tax purposes.

Third-party domains contacted

recurly.comjs.recurly.comapi.recurly.comapp.recurly.com

Cookies placed

NameTypeDurationPurpose
recurly_sessionthird_partySessionStrictly necessary session cookie set on the Recurly hosted iframe to keep the in progress checkout while the customer is entering payment data.
recurly_csrfthird_partySessionCSRF protection token used to validate the payment form submission on the Recurly hosted iframe.
recurly_riskthird_party30 minutesStrictly necessary fraud risk cookie used by Recurly for transaction risk scoring during the checkout.

Recurly uses cookies for user preferences — inform visitors with a consent banner.

Get started freeScan your site

Frequently asked questions

What cookies does Recurly set?

Recurly.js loads an iframe served from api.recurly.com that sets strictly necessary first party cookies on the Recurly hosted domain: recurly_session (session cookie keeping the checkout), recurly_csrf (CSRF protection) and recurly_risk (fraud risk score during the transaction).

Do I need consent to use Recurly?

No. The Recurly.js iframe cookies are strictly necessary to deliver the payment service the customer has initiated and are exempt from prior consent under Art. 5(3) ePrivacy. The customer's active choice to subscribe is the legal basis under Art. 6(1)(b) GDPR.

What is the legal basis for using Recurly?

Contract performance (Art. 6(1)(b) GDPR) for subscription billing data. Legal obligation (Art. 6(1)(c)) for tax records on the seller side. Strictly necessary cookies are exempt under Art. 5(3) ePrivacy.

Does Recurly transfer data to third countries?

Yes. Recurly Inc. is established in the United States and processes EU subscription data on AWS US East 1 and US West 2 by default. EU residency on AWS Frankfurt is available as an enterprise add on. The Recurly DPA includes the EU SCCs and the UK IDTA, and Recurly is self certified under the EU US Data Privacy Framework.

Do I need a DPIA for Recurly?

Standard subscription billing through Recurly does not normally require a DPIA. It can become appropriate when Recurly subscription data is combined with extensive customer profiling, dynamic pricing, AI driven dunning or special category data tied to subscription tiers.

How do I implement Recurly compliantly?

Sign the Recurly DPA, request EU residency if your plan allows it, integrate Recurly.js to keep card data outside your servers, mention Recurly as a processor in your privacy notice and Article 30 record, document the US transfer with SCCs and DPF and run a Transfer Impact Assessment.

Are there alternatives to Recurly?

Subscription billing alternatives include Stripe Billing (Ireland and US with DPF), Chargebee (US with EU residency), Zuora (US with EU residency), Paddle (UK MoR), Maxio / SaaSOptics (US), Adyen Subscriptions (Netherlands) and Mollie subscriptions (Netherlands).

How should I update my cookie and privacy policy for Recurly?

You do not need a banner update for the hosted Recurly.js iframe (strictly necessary cookies). In your privacy notice describe Recurly as your subscription billing processor, the US storage on AWS, the SCCs and DPF and the EU residency option for enterprise plans.