Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Scalapay is an Italian Buy Now Pay Later (BNPL) provider that splits purchases into interest-free installments, primarily serving the fashion and lifestyle e-commerce sector across Italy and France. It embeds a checkout widget on merchant sites and uses a marketing and conversion tracking pixel. Because Scalapay processes consumer financial data, conducts soft credit checks and deploys tracking pixels, its integration triggers both GDPR consent obligations and sector-specific requirements under the EU Consumer Credit Directive and PSD2.
Scalapay is an Italian Buy Now Pay Later (BNPL) fintech that enables consumers to split purchases into three or four interest-free installments. Founded in 2019 and headquartered in Milan, it focuses on fashion, beauty and lifestyle e-commerce across Italy, France, Spain, Portugal, Germany and Australia. Merchants embed the Scalapay checkout widget via a JavaScript snippet loaded from cdn.scalapay.com or widget.scalapay.com, which displays installment previews on product pages and handles the payment flow at checkout. The service is regulated as a consumer credit provider, meaning its data processing obligations extend beyond general GDPR requirements to include sector-specific rules under the EU Consumer Credit Directive and PSD2.
Scalapay collects consumer identity data (name, email, phone, address), order data (items, amounts, merchant ID) and payment schedule data. During eligibility assessment it performs a soft credit check, consulting credit bureau data that does not leave a visible mark on the consumer's credit file but still constitutes processing of financial personal data. The Scalapay marketing pixel (loaded from widget.scalapay.com) collects page-view and conversion events, enabling Scalapay to measure its contribution to sales and retarget customers across partner sites. Cookies include a payment session identifier, a fraud-prevention device token and marketing measurement cookies. The payment session cookie is essential for the checkout to function; all others require consent.
Core payment processing relies on contractual necessity (Art. 6(1)(b) GDPR), as it is necessary to execute the installment agreement. Soft-credit checks can be justified under legitimate interests (Art. 6(1)(f)) where the controller demonstrates a proportionate need for creditworthiness verification, but many practitioners use consent to be safe. Marketing pixel processing and retargeting require consent under both Art. 6(1)(a) GDPR and the ePrivacy Directive. Italian merchants must also comply with the Garante per la protezione dei dati personali's cookie guidelines, which follow EDPB guidance but impose additional notification and record-keeping obligations. The Italian Codice Privacy (D.Lgs. 196/2003 as amended by D.Lgs. 101/2018) applies in parallel with GDPR for Italian data subjects.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Because Scalapay offers deferred payment plans, merchants integrating it as a payment option may take on co-disclosure obligations under the EU Consumer Credit Directive (2008/48/EC) and its successor (2023/2225/EU). These require pre-contractual information to be provided to consumers, including the APR (even if 0%), total credit amount and repayment schedule, before the consumer commits. The forthcoming Consumer Credit Directive II increases transparency requirements for BNPL. Under PSD2, Scalapay itself holds the necessary payment institution or e-money institution authorisation; merchants simply integrate the widget. However, merchants must ensure their checkout flow does not obscure the credit nature of the transaction.
The checkout widget itself may load without consent if it is limited to rendering installment pricing information using only essential session cookies. However, the marketing pixel on widget.scalapay.com and any retargeting or analytics cookies must be gated behind prior consent. In practice, many merchants load the full widget script conditionally after consent, which is the safest approach. The CMP consent layer must categorise Scalapay under both 'Payments' (essential, no consent needed for core checkout) and 'Marketing' or 'Analytics' (consent required for the pixel). Consent records must be stored with timestamps, and withdrawal must be honoured by blocking subsequent pixel requests.
Merchants should: (1) separate the Scalapay installment preview widget (can be treated as functional) from the marketing pixel (requires consent) and load them independently; (2) include Scalapay in the privacy notice with a description of soft-credit processing, legal basis and data sharing with credit bureaus; (3) sign and keep current the Scalapay DPA and review its sub-processor list; (4) display the required EU Consumer Credit pre-contractual information (SECCI form equivalent) before the consumer finalises payment; (5) offer clear information about the soft credit check in the checkout flow; (6) conduct a DPIA if operating at scale or processing financial data that could reveal consumer vulnerability; and (7) update cookie policy tables to list Scalapay cookies separately with their purpose, duration and legal basis.
Websites using Scalapay must obtain user consent under GDPR regulations.
DPIA considerations
A Data Protection Impact Assessment is strongly recommended before deploying Scalapay, particularly where soft-credit data is processed or where the marketing pixel tracks purchasing behaviour at scale. Key risk areas include: (1) combination of consumer identity, order and payment data creating detailed financial profiles; (2) soft-credit enquiry data, which may indirectly reveal financial vulnerability; (3) marketing pixel data (loaded from widget.scalapay.com) enabling cross-site behavioural profiling if linked with Scalapay's own customer database; (4) processing under both GDPR and the Italian Codice Privacy (D.Lgs. 196/2003), which has additional requirements such as the Garante's cookie guidelines; (5) EU Consumer Credit Directive obligations around pre-contractual disclosure and creditworthiness assessment. The DPIA should map all data flows through the Scalapay widget, identify the legal basis for each processing purpose, and evaluate whether Scalapay's sub-processor chain exposes data outside the EEA.
Sample consent text
We offer Scalapay as a Buy Now Pay Later payment option. By selecting Scalapay at checkout, you consent to Scalapay S.r.l. processing your personal, order and payment data to assess your eligibility, arrange your installment plan and communicate with you about your payments. Scalapay may conduct a soft credit check, which will not affect your credit score. Scalapay also places tracking cookies and a marketing pixel on our site via widget.scalapay.com. You can accept or decline the marketing pixel separately; payment-related cookies are necessary for the checkout to function. For more information see our Privacy Policy and Scalapay's Privacy Policy at scalapay.com/privacy.
Third-party domains contacted
scalapay.comcdn.scalapay.comintegration.scalapay.comwidget.scalapay.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| scalapay_session | functional | Session | Essential payment session cookie that maintains the BNPL checkout state, order reference and authentication context during the Scalapay installment payment flow. Required for the payment to complete. |
| scalapay_device | functional | 1 year | Device fingerprint token used by Scalapay's fraud prevention system to identify and authenticate returning devices, reducing false-positive declines and detecting fraudulent transactions. |
| scp_track | marketing | 1 year | Marketing and conversion tracking cookie loaded from widget.scalapay.com. Tracks page views, product impressions and completed purchases to attribute sales to Scalapay and enable retargeting of consumers who viewed but did not complete an installment checkout. |
| scp_analytics | analytics | 6 months | Analytics cookie measuring widget rendering performance, installment plan selection rates and checkout funnel drop-off points to help Scalapay improve its merchant integration experience. |
| scp_ab | functional | 30 days | A/B testing cookie used to assign users to different Scalapay widget UI variants (e.g. 3 vs 4 installment display) and measure which presentation drives higher BNPL adoption rates. |
Scalapay uses cookies for user preferences — inform visitors with a consent banner.
Scalapay sets a payment session cookie that is essential for the BNPL checkout flow to function correctly, a device fingerprint cookie for fraud prevention, and marketing measurement cookies loaded via widget.scalapay.com that track page views and conversion events. The session and fraud-prevention cookies are necessary and can be placed without consent, but the marketing and analytics cookies require an affirmative opt-in from the user before they are set. Merchants should audit which of these cookies are loaded by the Scalapay widget snippet on their specific integration.
Consent is required for the marketing pixel and retargeting cookies that Scalapay loads via widget.scalapay.com; these cannot be placed before the user opts in under the ePrivacy Directive and GDPR. The core payment session cookie that enables the BNPL checkout may be treated as strictly necessary and does not require prior consent. Merchants in Italy must also comply with the Garante's specific cookie guidance. The safest approach is to load the full Scalapay snippet only after marketing consent is granted, while pre-rendering installment pricing using a server-side Scalapay API call if needed.
The core payment and installment arrangement processing relies on contractual necessity (Art. 6(1)(b) GDPR), as it is required to execute the purchase agreement. The soft-credit check uses legitimate interests (Art. 6(1)(f)), with some controllers preferring explicit consent for extra certainty. Marketing pixel processing and retargeting require consent (Art. 6(1)(a) GDPR). Fraud prevention relies on legitimate interests. Italian merchants must also account for the Italian Codice Privacy which requires specific notice and consent procedures for automated creditworthiness assessments.
Scalapay's core processing is EU-based, headquartered in Milan with operations in France. However, fraud-scoring engines, analytics sub-processors or payment rail partners may involve data flows outside the EEA. Merchants should request and review Scalapay's current sub-processor list and DPA to identify any third-country transfers. Where transfers exist, verify the legal mechanism (Standard Contractual Clauses or adequacy decision) and disclose them in your privacy notice. As of current knowledge, there is no primary US transfer like some US-based BNPL competitors, but sub-processor chains must be verified.
A DPIA is strongly recommended and may be mandatory if your use involves large-scale processing of consumer financial data, automated creditworthiness assessments, or profiling that could affect access to goods or services. The combination of consumer identity, purchase history and soft-credit data creates a financial profile that triggers multiple Art. 35 GDPR risk factors. The assessment should map Scalapay's data flows, evaluate the legitimacy of each processing purpose, consider the impact on financially vulnerable consumers, and document residual risk mitigations.
Separate the payment widget (essential function) from the marketing pixel (consent required) and load them on different consent triggers. Display EU Consumer Credit pre-contractual information (APR, total amount, repayment schedule) before the consumer commits to the installment plan. Include Scalapay in your privacy notice describing the soft-credit check, legal basis and data retention. Sign the Scalapay DPA and add it to your records of processing. Implement a mechanism for users to opt out of marketing tracking without losing access to the payment option. Update your cookie policy table with all Scalapay cookies.
European alternatives include Klarna (Sweden, strong GDPR track record), Alma (France, EU-regulated), and Paidy alternatives for specific markets. Some checkout-native BNPL solutions offered directly by payment processors (Stripe Afterpay-style, Adyen BNPL) may share infrastructure that is already covered by your existing DPA with those processors, potentially simplifying compliance documentation. The key differentiators for privacy are: EU data residency, minimal marketing tracking, transparent sub-processor lists, and pre-built GDPR consent tooling for merchants.
In your cookie policy, add a Scalapay section listing the payment session cookie (essential, session duration), the device fraud-prevention cookie (essential, 1 year), and widget.scalapay.com marketing cookies (analytics/marketing, 1 year, consent required). In your privacy notice, add Scalapay as a data processor/joint controller (verify your arrangement with Scalapay) and describe the soft-credit check, the data shared, the legal basis, retention period and the consumer's right to object or withdraw consent. Link to Scalapay's own privacy policy. Update both documents whenever Scalapay revises its DPA or sub-processor list.