Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Stripe.js is a JavaScript library loaded from js.stripe.com used to securely handle payment card data and power Stripe Radar, Stripe's fraud detection and prevention system. It sets two cookies: __stripe_mid (1 year) and __stripe_sid (30 minutes), and collects a device and behavioural fingerprint used to score transactions for fraud risk. On payment pages, Stripe.js is considered strictly necessary for processing the transaction. However, loading it site-wide on all pages for always-on fraud fingerprinting is legally contested under the ePrivacy Directive and GDPR, and may require a legitimate interest balancing test or consent depending on national interpretation.
Stripe.js is a JavaScript library provided by Stripe Inc. and loaded from js.stripe.com. It enables merchants to securely collect and tokenise payment card information directly in the browser, ensuring that raw card data never touches the merchant's servers. Beyond payment form handling, Stripe.js powers Stripe Radar, Stripe's machine-learning fraud detection and prevention system, by collecting device and behavioural signals that are used to score each transaction for fraud risk. Stripe.js is a foundational component of Stripe's payment infrastructure and is typically required for any site processing card payments via Stripe.
Stripe.js sets two named cookies: __stripe_mid, a machine identifier cookie with a duration of one year, and __stripe_sid, a session identifier cookie lasting 30 minutes. In addition to these cookies, Stripe.js collects an extensive device and behavioural fingerprint including browser type and version, installed plugins, screen resolution, time zone, mouse movement patterns, keystroke timing, and other signals. This fingerprint is used by Stripe Radar to build a fraud risk score for each transaction. Importantly, Stripe recommends loading Stripe.js on every page of a site (not just checkout pages) so that it can observe user behaviour from early in the session.
On payment pages, the __stripe_mid and __stripe_sid cookies and the Radar fingerprinting are strongly arguable as strictly necessary for the payment processing service that the user has explicitly requested: the ePrivacy Directive Art. 5(3) exemption applies. However, loading Stripe.js site-wide on non-payment pages (e.g. homepages, blog posts, product listings) before any purchase intent is expressed is a different matter. This broader deployment collects fingerprinting data outside the payment context, which is harder to justify as strictly necessary and is legally contested. Several EU data protection authorities have signalled that always-on fraud fingerprinting beyond the payment page context may require consent or at minimum a rigorous legitimate interest assessment.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
For payment-page-only deployment, the legal basis is legitimate interest (Art. 6(1)(f) GDPR) and performance of a contract (Art. 6(1)(b)), since fraud detection is a legitimate interest that is necessary and proportionate to protecting payment transactions. For site-wide deployment, a legitimate interest balancing test must document that the interests of Stripe and the merchant in fraud prevention outweigh user privacy interests and that the data subject would reasonably expect this processing. Data is transferred to Stripe Inc. in the United States. Stripe uses Standard Contractual Clauses (SCCs) as the transfer mechanism and provides a Data Processing Addendum. A DPA with Stripe is required under GDPR Art. 28.
The compliance risk for Stripe.js is rated medium. When confined to payment pages, the risk is relatively low and the strictly necessary or legitimate interest basis is defensible. The risk increases when Stripe.js is loaded site-wide, because the fraud fingerprinting then occurs on all pages including those unrelated to payment, widening the scope of personal data collection. Merchants that embed Stripe.js globally should document their legitimate interest assessment, inform users of this processing in their privacy policy, and consider whether a DPIA is warranted.
To comply with GDPR and ePrivacy when using Stripe.js: sign a Data Processing Addendum with Stripe; disclose Stripe.js in your privacy policy including the cookies set, the fraud detection purpose, and the US data transfer via SCCs; if loading Stripe.js site-wide, document and publish a legitimate interest assessment for the broader fingerprinting; consider restricting Stripe.js to payment-related pages to minimise risk; add __stripe_mid and __stripe_sid to your cookie policy under a security or strictly necessary category (if payment-page only) or flag them for a LIA (if site-wide); and review Stripe's DPA and sub-processor list periodically.
Websites using Stripe.js must obtain user consent under GDPR regulations.
DPIA considerations
A DPIA should be considered if Stripe.js is loaded site-wide across all pages, given that device fingerprinting for fraud detection outside the payment context may constitute systematic processing of personal data at scale. The combination of behavioural signals collected by Stripe Radar (mouse movements, timing, browser characteristics) may constitute profiling. Document the scope of Stripe.js deployment, the data flows to Stripe in the US, and the legal basis for each deployment context (payment page vs. all pages). Review Stripe's Data Processing Agreement and sub-processor list.
Third-party domains contacted
js.stripe.comm.stripe.comm.stripe.networkapi.stripe.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| __stripe_mid | functional | 1 year | Stripe machine identifier cookie set by js.stripe.com. Used by Stripe Radar to assign a persistent machine identity to a browser for fraud detection scoring. Persists across sessions. |
| __stripe_sid | functional | 30 minutes | Stripe session identifier cookie set by js.stripe.com. Used by Stripe Radar to track a single browsing session for fraud risk assessment during the payment flow. |
Stripe.js is an essential service, but transparency matters. Manage all your consent with FlowConsent.
Stripe.js sets two cookies: __stripe_mid (machine identifier, duration 1 year) and __stripe_sid (session identifier, duration 30 minutes). These cookies are used by Stripe Radar, Stripe's fraud detection system, to link behavioural signals collected across a user's browser session to a stable machine identity. In addition to these cookies, Stripe.js collects a device fingerprint including browser characteristics, plugins, screen resolution, and interaction patterns.
On payment pages specifically, the __stripe_mid and __stripe_sid cookies and the fraud fingerprinting are defensible as strictly necessary under the ePrivacy Directive, since they are required to process the payment transaction the user explicitly initiated. No consent banner is typically required for payment-page-only deployment. However, if Stripe.js is loaded site-wide across all pages (as Stripe recommends for better fraud detection), the broader fingerprinting on non-payment pages is legally contested and may require a legitimate interest assessment or, under stricter national interpretations, consent.
For payment-page-only use: legitimate interest (Art. 6(1)(f)) and performance of a contract (Art. 6(1)(b)) GDPR. Fraud detection for payment security is a proportionate and necessary legitimate interest. For site-wide use: a legitimate interest balancing test is required documenting that fraud prevention interests outweigh user privacy interests and that users would reasonably expect this processing. A Data Processing Agreement with Stripe under Art. 28 GDPR is required in all cases.
Yes. Stripe Inc. is headquartered in the United States and processes transaction and fraud-detection data there. Stripe uses Standard Contractual Clauses (SCCs) as the GDPR-compliant transfer mechanism for EEA-to-US transfers. Stripe provides a Data Processing Addendum covering these transfers. You must disclose this US transfer in your privacy policy and reference the SCCs as the applicable safeguard.
A DPIA should be considered if Stripe.js is loaded site-wide on all pages, because the systematic collection of device fingerprints and behavioural signals from all visitors (not just those making payments) may constitute high-risk processing. The combination of persistent identifiers (__stripe_mid lasting 1 year) and behavioural profiling across sessions broadens the data processing scope. For payment-page-only deployment, a DPIA is generally not required.
Best practices: sign Stripe's Data Processing Addendum; if possible, load Stripe.js only on payment-related pages rather than site-wide; disclose Stripe.js in your privacy policy including the cookies set, fraud detection purpose, and US transfer via SCCs; if loading site-wide, document and publish a legitimate interest balancing test; add __stripe_mid and __stripe_sid to your cookie notice under "Security" or "Strictly Necessary" (payment pages) or "Functional" (site-wide with LIA); and review Stripe's DPA and sub-processor list periodically.
Several EU-based payment processors offer alternatives where fraud detection does not require site-wide JavaScript fingerprinting. Mollie (Netherlands), Adyen (Netherlands), and Klarna (Sweden) are EU-based processors. However, most modern fraud prevention systems use some form of device intelligence. Mollie and Adyen offer robust EU data residency options. The compliance risk can also be reduced by confining any payment processor's JavaScript to checkout pages only.
In your cookie policy, list __stripe_mid and __stripe_sid under a "Security" or "Strictly Necessary" category if Stripe.js is loaded only on payment pages, explaining that they are required to process your payment securely and detect fraud. If Stripe.js is loaded site-wide, you may need to categorise them differently and explain the broader legitimate interest basis. Include: cookie name, purpose (payment security and fraud detection via Stripe Radar), duration, that data is processed by Stripe Inc. in the US under SCCs, and a link to Stripe's privacy policy.