FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. E-commerce
  4. Square

Square

PreferencesWebsite

Related services

24nettbutikk

24nettbutikk is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. 24nettbutikk supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, 24nettbutikk ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Preferences

2ClickShop

2ClickShop is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 2ClickShop integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 2ClickShop helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences

4-Tell

4-Tell is a marketing platform that equips businesses with tools to amplify their digital presence and drive customer acquisition. It supports audience segmentation, campaign automation, and cross-channel engagement. 4-Tell provides real-time analytics and reporting dashboards for performance measurement and strategy optimization. By combining data intelligence with marketing execution, 4-Tell helps deliver the right message to the right audience at the right time.

Preferences

42stores

42stores is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 42stores integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 42stores helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences

4Partners

4Partners is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 4Partners integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 4Partners helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences
4

4Partners CMS

4Partners CMS is a powerful content management system (CMS) designed to help businesses and developers build, manage, and publish digital content with ease. It offers a flexible architecture that supports custom content types, templates, and workflows, making it ideal for websites of any scale. With 4Partners CMS, teams can streamline content creation, improve collaboration, and deliver engaging web experiences. Its extensible plugin ecosystem and API-first approach ensure seamless integration with.

Preferences
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does Square do?

Square is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. Square integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, Square helps organizations maintain robust websites that meet user expectations and technical requirements.

Square, the payments brand of Block, Inc., was founded in 2009 by Jack Dorsey and Jim McKelvey. Originally famous for its card reader dongle, Square is now a full commerce platform covering point of sale, online checkout, invoicing, payroll and lending. European merchants are contractually engaged with Square Up Europe Ltd in Dublin and Square UK Ltd in London, with payment processing performed on US infrastructure.

What Square does

Square offers in person card readers, the Square Terminal, the Square Register, the Web Payments SDK (tokenised card collection for any website), the Checkout API (hosted payment pages), Square Online (e commerce builder) and recurring billing. It also includes anti fraud, 3D Secure, Strong Customer Authentication under PSD2, dispute management and tax reporting.

Data and cookies set

The Square Web Payments SDK loads JavaScript from web.squarecdn.com and may set cookies including __cf_bm (Cloudflare bot management) and a fraud risk fingerprint cookie. Square Online sites set additional analytics and marketing cookies such as _ga and _fbp. Square collects card BIN, last four digits, billing address, IP, user agent and device fingerprint for risk scoring.

GDPR and ePrivacy implications

Payment processing is performed on the legal basis of contract (Art. 6(1)(b) GDPR) and legal obligations (AML, tax). The fraud detection cookie may be considered strictly necessary for the security exemption of Art. 5(3) ePrivacy. Marketing and analytics cookies set by Square Online require ePrivacy consent. SCA under PSD2 requires the customer to authenticate with two factors for most online card payments above 30 EUR.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Data transfers to the United States

Although Square Up Europe Ltd is contractually established in Dublin, the underlying systems (authorisation, fraud, settlement, support) run on Block, Inc. infrastructure in the United States. Block, Inc. is self certified under the EU US Data Privacy Framework. Document the transfer mechanism and the Transfer Impact Assessment for the payment processing and the supporting systems.

Practical compliance steps

Use the Square Web Payments SDK rather than collecting card data on your own servers to keep PCI DSS scope minimal. Enable 3D Secure 2 for SCA compliance. Sign the Square DPA. Block marketing and analytics cookies behind a CMP category. Mention Block Inc. and Square Up Europe Ltd in your privacy notice with the EU US DPF transfer mechanism. Configure retention of payment records (typically 10 years for tax).

GDPR consent category

Preferences

Websites using Square must obtain user consent under GDPR regulations.

Legal basisPerformance of a contract (Art. 6(1)(b) GDPR) for the payment itself. Legal obligation (Art. 6(1)(c)) for anti money laundering and tax recordkeeping. Consent (Art. 6(1)(a) GDPR and Art. 5(3) ePrivacy Directive) for the marketing and analytics cookies set by the Square Web SDK or by Square Online sites.
Risk levelmedium
Applicable regulationsGDPR, PSD2, ePrivacy Directive, TDDDG, LSSI CE, CCPA/CPRA, EU US Data Privacy Framework, PCI DSS Level 1, AML Directive, EBA RTS on SCA

Technical details

Tracking methodPayment processing platform. Square Web Payments SDK and Checkout API are loaded via JavaScript and iframe to handle card collection on the merchant website. Square also operates Square Online (e commerce site builder) and embedded buy buttons that set tracking cookies.
Server locationBlock, Inc. (parent of Square), San Francisco, California, United States. Payment data is processed on PCI DSS Level 1 certified US infrastructure with regional acquiring partners in the United Kingdom (Square UK Ltd) and Ireland (Square Up Europe Ltd) for European merchants.
Data transferred outside the EUEuropean merchants are contractually engaged with Square Up Europe Ltd (Dublin, Ireland) but payment authorisation, fraud detection and back office systems run on Block Inc. infrastructure in the United States. Transfers from the EU rely on the EU US Data Privacy Framework or on Standard Contractual Clauses with supplementary measures.

Third-party domains contacted

squareup.comweb.squarecdn.compci-connect.squareup.comsquare.sitecash.appblock.xyz

Cookies placed

NameTypeDurationPurpose
__cf_bmthird_party30 minutesCloudflare bot management cookie used by Square to distinguish humans from automated traffic on web.squarecdn.com.
sq_fidthird_partySessionDevice fingerprint cookie used by Square for fraud detection on online payments.
_gathird_party2 yearsGoogle Analytics identifier set by Square Online stores for visitor analytics.
_fbpthird_party3 monthsMeta Pixel identifier set by Square Online when the merchant has enabled Facebook advertising.

Square uses cookies for user preferences — inform visitors with a consent banner.

Get started freeScan your site

Frequently asked questions

Which cookies does Square set?

The Square Web Payments SDK sets a Cloudflare bot management cookie (__cf_bm, 30 minutes), a fraud fingerprint cookie and a session cookie on web.squarecdn.com. Square Online sites set additional cookies including _ga and _fbp. Strictly necessary cookies do not require consent; analytics and marketing ones do.

Is consent required to use Square?

Consent is not required for the strictly necessary payment cookies and the security cookie. Consent is required for the marketing and analytics cookies set by Square Online and for any newsletter subscription or remarketing flow.

What is the legal basis for processing payment data?

Contract (Art. 6(1)(b) GDPR) for processing the payment itself. Legal obligation (Art. 6(1)(c)) for anti money laundering and tax recordkeeping. Legitimate interest (Art. 6(1)(f)) for fraud detection. Consent (Art. 6(1)(a)) for marketing and analytics.

Is data transferred to the United States?

Yes. Although the EU contracting entity is Square Up Europe Ltd in Dublin, the back end systems are operated by Block, Inc. in the US. Transfers rely on the EU US Data Privacy Framework (Block is certified) or on Standard Contractual Clauses with supplementary measures.

Do I need a DPIA for Square?

A DPIA is recommended when handling card data at scale, recurring payments, card on file, or sensitive verticals (health, gambling). The DPIA covers the lawful basis, PCI DSS scope, SCA flow, fraud detection, US transfers and retention.

How do I implement Square correctly?

Use the Web Payments SDK with tokenisation to minimise PCI DSS scope. Enable 3D Secure 2 for SCA compliance. Sign the Square DPA. Block analytics and marketing cookies behind a CMP category. Document Block Inc. and Square Up Europe Ltd as sub processors and the EU US transfer mechanism in your records of processing.

Which alternatives to Square should I consider?

EU based payment processors: Adyen (Netherlands), Mollie (Netherlands), Stripe Ireland (with US back end), Worldline (France), Lyra (France), GoCardless (UK). For SMB: SumUp (UK/Germany), Klarna Checkout (Sweden), Viva Wallet (Greece).

How do I update the cookie policy when Square changes?

Subscribe to the Square trust centre. When sub processors, certifications, payment flows or cookies change, update your cookie table, privacy notice and records of processing, and bump the consent banner version. Re run your PCI DSS self assessment annually.