FlowConsent
ServicesHow it worksPricingBlogDocumentation
ServicesHow it worksPricingBlogDocumentationLog inTry FlowConsent
Log inTry FlowConsent
FlowConsent

GDPR-compliant consent, EU-hosted, live in under ten minutes — without a cookie wall.

EU-HOSTED·RGPD·SOC 2
Product
  • Services
  • How it works
  • Pricing
  • Extension
Company
  • Blog
  • Documentation
  • Solutions
  • FlowConsent App
Legal
  • Privacy Policy
  • Terms of Service
  • Legal notice
  • Cookies
© 2026 FlowConsent by BeBranded. All rights reserved.
FrancaisDeutschEspanol
All systems operational

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. E-commerce
  4. Scalapay

Scalapay

PreferencesWebsite

Related services

24nettbutikk

24nettbutikk is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. 24nettbutikk supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, 24nettbutikk ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Preferences

2ClickShop

2ClickShop is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 2ClickShop integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 2ClickShop helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences

4-Tell

4-Tell is a marketing platform that equips businesses with tools to amplify their digital presence and drive customer acquisition. It supports audience segmentation, campaign automation, and cross-channel engagement. 4-Tell provides real-time analytics and reporting dashboards for performance measurement and strategy optimization. By combining data intelligence with marketing execution, 4-Tell helps deliver the right message to the right audience at the right time.

Preferences

42stores

42stores is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 42stores integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 42stores helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences

4Partners

4Partners is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 4Partners integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 4Partners helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences
4

4Partners CMS

4Partners CMS is a powerful content management system (CMS) designed to help businesses and developers build, manage, and publish digital content with ease. It offers a flexible architecture that supports custom content types, templates, and workflows, making it ideal for websites of any scale. With 4Partners CMS, teams can streamline content creation, improve collaboration, and deliver engaging web experiences. Its extensible plugin ecosystem and API-first approach ensure seamless integration with.

Preferences
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does Scalapay do?

Scalapay is an Italian Buy Now Pay Later (BNPL) provider that splits purchases into interest-free installments, primarily serving the fashion and lifestyle e-commerce sector across Italy and France. It embeds a checkout widget on merchant sites and uses a marketing and conversion tracking pixel. Because Scalapay processes consumer financial data, conducts soft credit checks and deploys tracking pixels, its integration triggers both GDPR consent obligations and sector-specific requirements under the EU Consumer Credit Directive and PSD2.

What Scalapay Is and How It Works

Scalapay is an Italian Buy Now Pay Later (BNPL) fintech that enables consumers to split purchases into three or four interest-free installments. Founded in 2019 and headquartered in Milan, it focuses on fashion, beauty and lifestyle e-commerce across Italy, France, Spain, Portugal, Germany and Australia. Merchants embed the Scalapay checkout widget via a JavaScript snippet loaded from cdn.scalapay.com or widget.scalapay.com, which displays installment previews on product pages and handles the payment flow at checkout. The service is regulated as a consumer credit provider, meaning its data processing obligations extend beyond general GDPR requirements to include sector-specific rules under the EU Consumer Credit Directive and PSD2.

Data Collected, Cookies and Tracking Pixels

Scalapay collects consumer identity data (name, email, phone, address), order data (items, amounts, merchant ID) and payment schedule data. During eligibility assessment it performs a soft credit check, consulting credit bureau data that does not leave a visible mark on the consumer's credit file but still constitutes processing of financial personal data. The Scalapay marketing pixel (loaded from widget.scalapay.com) collects page-view and conversion events, enabling Scalapay to measure its contribution to sales and retarget customers across partner sites. Cookies include a payment session identifier, a fraud-prevention device token and marketing measurement cookies. The payment session cookie is essential for the checkout to function; all others require consent.

GDPR Legal Basis and Italian Codice Privacy

Core payment processing relies on contractual necessity (Art. 6(1)(b) GDPR), as it is necessary to execute the installment agreement. Soft-credit checks can be justified under legitimate interests (Art. 6(1)(f)) where the controller demonstrates a proportionate need for creditworthiness verification, but many practitioners use consent to be safe. Marketing pixel processing and retargeting require consent under both Art. 6(1)(a) GDPR and the ePrivacy Directive. Italian merchants must also comply with the Garante per la protezione dei dati personali's cookie guidelines, which follow EDPB guidance but impose additional notification and record-keeping obligations. The Italian Codice Privacy (D.Lgs. 196/2003 as amended by D.Lgs. 101/2018) applies in parallel with GDPR for Italian data subjects.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Consumer Credit Directive and PSD2 Obligations

Because Scalapay offers deferred payment plans, merchants integrating it as a payment option may take on co-disclosure obligations under the EU Consumer Credit Directive (2008/48/EC) and its successor (2023/2225/EU). These require pre-contractual information to be provided to consumers, including the APR (even if 0%), total credit amount and repayment schedule, before the consumer commits. The forthcoming Consumer Credit Directive II increases transparency requirements for BNPL. Under PSD2, Scalapay itself holds the necessary payment institution or e-money institution authorisation; merchants simply integrate the widget. However, merchants must ensure their checkout flow does not obscure the credit nature of the transaction.

Consent Requirements and CMP Implementation

The checkout widget itself may load without consent if it is limited to rendering installment pricing information using only essential session cookies. However, the marketing pixel on widget.scalapay.com and any retargeting or analytics cookies must be gated behind prior consent. In practice, many merchants load the full widget script conditionally after consent, which is the safest approach. The CMP consent layer must categorise Scalapay under both 'Payments' (essential, no consent needed for core checkout) and 'Marketing' or 'Analytics' (consent required for the pixel). Consent records must be stored with timestamps, and withdrawal must be honoured by blocking subsequent pixel requests.

Practical Compliance Steps for Merchants

Merchants should: (1) separate the Scalapay installment preview widget (can be treated as functional) from the marketing pixel (requires consent) and load them independently; (2) include Scalapay in the privacy notice with a description of soft-credit processing, legal basis and data sharing with credit bureaus; (3) sign and keep current the Scalapay DPA and review its sub-processor list; (4) display the required EU Consumer Credit pre-contractual information (SECCI form equivalent) before the consumer finalises payment; (5) offer clear information about the soft credit check in the checkout flow; (6) conduct a DPIA if operating at scale or processing financial data that could reveal consumer vulnerability; and (7) update cookie policy tables to list Scalapay cookies separately with their purpose, duration and legal basis.

GDPR consent category

Preferences

Websites using Scalapay must obtain user consent under GDPR regulations.

Legal basisContractual necessity (Art. 6(1)(b) GDPR) for core BNPL payment processing; explicit consent (Art. 6(1)(a)) for marketing pixel, retargeting cookies and soft-credit inquiry communications; legitimate interests (Art. 6(1)(f)) for fraud prevention. Italian Codice Privacy supplements GDPR for Italian data subjects.
Risk levelhigh
Applicable regulations{GDPR,PSD2,"ePrivacy Directive","Italian Codice Privacy (D.Lgs. 196/2003 as amended)","EU Consumer Credit Directive (2008/48/EC)","Italian Consumer Credit Regulations"}

DPIA considerations

A Data Protection Impact Assessment is strongly recommended before deploying Scalapay, particularly where soft-credit data is processed or where the marketing pixel tracks purchasing behaviour at scale. Key risk areas include: (1) combination of consumer identity, order and payment data creating detailed financial profiles; (2) soft-credit enquiry data, which may indirectly reveal financial vulnerability; (3) marketing pixel data (loaded from widget.scalapay.com) enabling cross-site behavioural profiling if linked with Scalapay's own customer database; (4) processing under both GDPR and the Italian Codice Privacy (D.Lgs. 196/2003), which has additional requirements such as the Garante's cookie guidelines; (5) EU Consumer Credit Directive obligations around pre-contractual disclosure and creditworthiness assessment. The DPIA should map all data flows through the Scalapay widget, identify the legal basis for each processing purpose, and evaluate whether Scalapay's sub-processor chain exposes data outside the EEA.

Sample consent text

We offer Scalapay as a Buy Now Pay Later payment option. By selecting Scalapay at checkout, you consent to Scalapay S.r.l. processing your personal, order and payment data to assess your eligibility, arrange your installment plan and communicate with you about your payments. Scalapay may conduct a soft credit check, which will not affect your credit score. Scalapay also places tracking cookies and a marketing pixel on our site via widget.scalapay.com. You can accept or decline the marketing pixel separately; payment-related cookies are necessary for the checkout to function. For more information see our Privacy Policy and Scalapay's Privacy Policy at scalapay.com/privacy.

Technical details

Tracking methodJavaScript checkout widget, marketing and conversion tracking pixel, first-party and third-party cookies, server-side payment API
Server locationEU (Italy and France primary); payment processing via EU-based payment processors
Data transferred outside the EUScalapay may share consumer and order data with EU-based payment processors and, for fraud scoring, with third-party risk engines that may operate outside the EEA. Soft-credit data may be shared with Italian credit bureaus. Marketing pixel data (widget.scalapay.com) may be processed by analytics sub-processors; verify current sub-processor list with Scalapay DPA.

Third-party domains contacted

scalapay.comcdn.scalapay.comintegration.scalapay.comwidget.scalapay.com

Cookies placed

NameTypeDurationPurpose
scalapay_sessionfunctionalSessionEssential payment session cookie that maintains the BNPL checkout state, order reference and authentication context during the Scalapay installment payment flow. Required for the payment to complete.
scalapay_devicefunctional1 yearDevice fingerprint token used by Scalapay's fraud prevention system to identify and authenticate returning devices, reducing false-positive declines and detecting fraudulent transactions.
scp_trackmarketing1 yearMarketing and conversion tracking cookie loaded from widget.scalapay.com. Tracks page views, product impressions and completed purchases to attribute sales to Scalapay and enable retargeting of consumers who viewed but did not complete an installment checkout.
scp_analyticsanalytics6 monthsAnalytics cookie measuring widget rendering performance, installment plan selection rates and checkout funnel drop-off points to help Scalapay improve its merchant integration experience.
scp_abfunctional30 daysA/B testing cookie used to assign users to different Scalapay widget UI variants (e.g. 3 vs 4 installment display) and measure which presentation drives higher BNPL adoption rates.

Scalapay uses cookies for user preferences — inform visitors with a consent banner.

Get started freeScan your site

Frequently asked questions

What cookies does Scalapay set on my website?

Scalapay sets a payment session cookie that is essential for the BNPL checkout flow to function correctly, a device fingerprint cookie for fraud prevention, and marketing measurement cookies loaded via widget.scalapay.com that track page views and conversion events. The session and fraud-prevention cookies are necessary and can be placed without consent, but the marketing and analytics cookies require an affirmative opt-in from the user before they are set. Merchants should audit which of these cookies are loaded by the Scalapay widget snippet on their specific integration.

Is consent required to integrate Scalapay on a European e-commerce site?

Consent is required for the marketing pixel and retargeting cookies that Scalapay loads via widget.scalapay.com; these cannot be placed before the user opts in under the ePrivacy Directive and GDPR. The core payment session cookie that enables the BNPL checkout may be treated as strictly necessary and does not require prior consent. Merchants in Italy must also comply with the Garante's specific cookie guidance. The safest approach is to load the full Scalapay snippet only after marketing consent is granted, while pre-rendering installment pricing using a server-side Scalapay API call if needed.

What legal basis applies to Scalapay's data processing?

The core payment and installment arrangement processing relies on contractual necessity (Art. 6(1)(b) GDPR), as it is required to execute the purchase agreement. The soft-credit check uses legitimate interests (Art. 6(1)(f)), with some controllers preferring explicit consent for extra certainty. Marketing pixel processing and retargeting require consent (Art. 6(1)(a) GDPR). Fraud prevention relies on legitimate interests. Italian merchants must also account for the Italian Codice Privacy which requires specific notice and consent procedures for automated creditworthiness assessments.

Does Scalapay transfer consumer data outside the EU?

Scalapay's core processing is EU-based, headquartered in Milan with operations in France. However, fraud-scoring engines, analytics sub-processors or payment rail partners may involve data flows outside the EEA. Merchants should request and review Scalapay's current sub-processor list and DPA to identify any third-country transfers. Where transfers exist, verify the legal mechanism (Standard Contractual Clauses or adequacy decision) and disclose them in your privacy notice. As of current knowledge, there is no primary US transfer like some US-based BNPL competitors, but sub-processor chains must be verified.

Do I need a DPIA to use Scalapay?

A DPIA is strongly recommended and may be mandatory if your use involves large-scale processing of consumer financial data, automated creditworthiness assessments, or profiling that could affect access to goods or services. The combination of consumer identity, purchase history and soft-credit data creates a financial profile that triggers multiple Art. 35 GDPR risk factors. The assessment should map Scalapay's data flows, evaluate the legitimacy of each processing purpose, consider the impact on financially vulnerable consumers, and document residual risk mitigations.

How do I implement Scalapay in a GDPR-compliant way?

Separate the payment widget (essential function) from the marketing pixel (consent required) and load them on different consent triggers. Display EU Consumer Credit pre-contractual information (APR, total amount, repayment schedule) before the consumer commits to the installment plan. Include Scalapay in your privacy notice describing the soft-credit check, legal basis and data retention. Sign the Scalapay DPA and add it to your records of processing. Implement a mechanism for users to opt out of marketing tracking without losing access to the payment option. Update your cookie policy table with all Scalapay cookies.

Are there privacy-friendlier alternatives to Scalapay for BNPL in Europe?

European alternatives include Klarna (Sweden, strong GDPR track record), Alma (France, EU-regulated), and Paidy alternatives for specific markets. Some checkout-native BNPL solutions offered directly by payment processors (Stripe Afterpay-style, Adyen BNPL) may share infrastructure that is already covered by your existing DPA with those processors, potentially simplifying compliance documentation. The key differentiators for privacy are: EU data residency, minimal marketing tracking, transparent sub-processor lists, and pre-built GDPR consent tooling for merchants.

How should I update my cookie policy and privacy notice for Scalapay?

In your cookie policy, add a Scalapay section listing the payment session cookie (essential, session duration), the device fraud-prevention cookie (essential, 1 year), and widget.scalapay.com marketing cookies (analytics/marketing, 1 year, consent required). In your privacy notice, add Scalapay as a data processor/joint controller (verify your arrangement with Scalapay) and describe the soft-credit check, the data shared, the legal basis, retention period and the consumer's right to object or withdraw consent. Link to Scalapay's own privacy policy. Update both documents whenever Scalapay revises its DPA or sub-processor list.