Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Sezzle is a buy now pay later provider that embeds a JavaScript widget on merchant pages to show installment options and runs fraud scoring and conversion analytics.
Sezzle is a buy now pay later provider operated by Sezzle Inc. in Minneapolis, United States. It lets shoppers split a purchase into interest free installments and integrates with online stores through an embedded JavaScript widget shown on product and checkout pages.
The widget loads scripts from Sezzle domains and sets functional cookies, fraud and security cookies, and in some configurations marketing cookies. It can collect the products viewed, pages accessed, device characteristics used for fraud scoring, and conversion events, which it sends to Sezzle servers in the United States.
Under the ePrivacy Directive, storing or reading non essential cookies requires prior consent. The core payment service relies on performance of a contract, fraud prevention rests on legitimate interests, and the analytics and marketing tracking carried by the widget needs consent under Article 6(1)(a) of the GDPR.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Merchants should load the non essential parts of the widget only after the visitor accepts marketing and analytics cookies in a consent banner. Strictly necessary functions that are required to complete a payment the user requested can run without consent, but tracking that profiles the user must remain blocked until consent is given.
Because Sezzle processes data in the United States, merchants based in the European Economic Area carry out a transfer to a third country. This should be covered by Standard Contractual Clauses, a transfer impact assessment, and supplementary safeguards documented in the records of processing.
List Sezzle in your cookie policy, gate its tracking behind consent, sign a data processing agreement, and keep the transfer documentation current. Review what the widget loads on each page and remove any tracking that is not necessary for the chosen payment journey.
Websites using Sezzle must obtain user consent under GDPR regulations.
DPIA considerations
A DPIA is recommended where the Sezzle widget feeds analytics or marketing profiling, because it combines browsing data, purchase intent and device fingerprinting for fraud scoring. Assess the US data transfer, the scope of fraud related profiling, and whether less intrusive measures meet the same goal.
Sample consent text
We use Sezzle to offer buy now pay later options at checkout. With your consent, Sezzle may set cookies and collect device and browsing data to display installment plans and to measure performance. You can accept or decline these non essential functions at any time.
Third-party domains contacted
widget.sezzle.comsezzle.comapi.sezzle.comgateway.sezzle.comcheckout.sezzle.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| Functional widget cookie | Third-party | Session | Maintains the state of the Sezzle widget and the installment selection during the session |
| Fraud and security cookie | Third-party | 1 year | Recognises previously approved devices and supports fraud prevention and risk scoring |
| Device recognition cookie | Third-party | 13 months | Identifies the device to reduce repeated verification and protect against account takeover |
| Analytics and conversion cookie | Third-party | 2 years | Measures widget impressions, clicks and completed conversions for performance reporting |
| Marketing cookie | Third-party | 1 year | Supports marketing measurement and audience signals where this function is enabled |
Sezzle uses cookies for user preferences — inform visitors with a consent banner.
Sezzle sets functional cookies for the widget, fraud and security cookies for device recognition and risk scoring, and in some setups marketing cookies. The exact set depends on the integration and the merchant configuration.
Consent is required for the analytics and marketing tracking carried by the widget. The core payment functions the user requests and fraud prevention do not rely on consent, but non essential tracking must be blocked until the visitor agrees.
The payment service relies on performance of a contract under Article 6(1)(b), fraud prevention and risk scoring rely on legitimate interests under Article 6(1)(f), and analytics and marketing tracking rely on consent under Article 6(1)(a).
Yes. Sezzle Inc. processes data in the United States, so European merchants carry out a transfer to a third country. This should be covered by Standard Contractual Clauses, a transfer impact assessment and supplementary safeguards.
A DPIA is recommended where the widget feeds analytics or marketing profiling, because it combines browsing data, purchase intent and device fingerprinting used for fraud scoring. The assessment should also weigh the US transfer.
List Sezzle in your cookie policy, gate its non essential tracking behind a consent banner, sign a data processing agreement, and document the US transfer. Load only the widget functions needed for the chosen payment journey.
Alternatives include other buy now pay later providers such as Klarna, Afterpay, Affirm and PayPal Pay in 4. Each has its own cookie footprint, server locations and transfer arrangements that should be assessed separately.
Add a Sezzle entry that names the cookie categories, their purposes and durations, the US transfer and the safeguards in place. Update your consent management platform so the widget loads only after consent and keep the entry current as the integration changes.