FlowConsent
ServicesHow it worksPricingBlogDocumentation
ServicesHow it worksPricingBlogDocumentationLog inTry FlowConsent
Log inTry FlowConsent
FlowConsent

GDPR-compliant consent, EU-hosted, live in under ten minutes — without a cookie wall.

EU-HOSTED·RGPD·SOC 2
Product
  • Services
  • How it works
  • Pricing
  • Extension
Company
  • Blog
  • Documentation
  • Solutions
  • FlowConsent App
Legal
  • Privacy Policy
  • Terms of Service
  • Legal notice
  • Cookies
© 2026 FlowConsent by BeBranded. All rights reserved.
FrancaisDeutschEspanol
All systems operational

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. E-commerce
  4. Stripe.js
S

Stripe.js

Essential

Related services

24nettbutikk

24nettbutikk is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. 24nettbutikk supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, 24nettbutikk ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Preferences

2ClickShop

2ClickShop is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 2ClickShop integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 2ClickShop helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences

4-Tell

4-Tell is a marketing platform that equips businesses with tools to amplify their digital presence and drive customer acquisition. It supports audience segmentation, campaign automation, and cross-channel engagement. 4-Tell provides real-time analytics and reporting dashboards for performance measurement and strategy optimization. By combining data intelligence with marketing execution, 4-Tell helps deliver the right message to the right audience at the right time.

Preferences

42stores

42stores is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 42stores integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 42stores helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences

4Partners

4Partners is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 4Partners integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 4Partners helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences
4

4Partners CMS

4Partners CMS is a powerful content management system (CMS) designed to help businesses and developers build, manage, and publish digital content with ease. It offers a flexible architecture that supports custom content types, templates, and workflows, making it ideal for websites of any scale. With 4Partners CMS, teams can streamline content creation, improve collaboration, and deliver engaging web experiences. Its extensible plugin ecosystem and API-first approach ensure seamless integration with.

Preferences
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does Stripe.js do?

Stripe.js is a JavaScript library loaded from js.stripe.com used to securely handle payment card data and power Stripe Radar, Stripe's fraud detection and prevention system. It sets two cookies: __stripe_mid (1 year) and __stripe_sid (30 minutes), and collects a device and behavioural fingerprint used to score transactions for fraud risk. On payment pages, Stripe.js is considered strictly necessary for processing the transaction. However, loading it site-wide on all pages for always-on fraud fingerprinting is legally contested under the ePrivacy Directive and GDPR, and may require a legitimate interest balancing test or consent depending on national interpretation.

What is Stripe.js?

Stripe.js is a JavaScript library provided by Stripe Inc. and loaded from js.stripe.com. It enables merchants to securely collect and tokenise payment card information directly in the browser, ensuring that raw card data never touches the merchant's servers. Beyond payment form handling, Stripe.js powers Stripe Radar, Stripe's machine-learning fraud detection and prevention system, by collecting device and behavioural signals that are used to score each transaction for fraud risk. Stripe.js is a foundational component of Stripe's payment infrastructure and is typically required for any site processing card payments via Stripe.

Cookies and Data Collected by Stripe.js

Stripe.js sets two named cookies: __stripe_mid, a machine identifier cookie with a duration of one year, and __stripe_sid, a session identifier cookie lasting 30 minutes. In addition to these cookies, Stripe.js collects an extensive device and behavioural fingerprint including browser type and version, installed plugins, screen resolution, time zone, mouse movement patterns, keystroke timing, and other signals. This fingerprint is used by Stripe Radar to build a fraud risk score for each transaction. Importantly, Stripe recommends loading Stripe.js on every page of a site (not just checkout pages) so that it can observe user behaviour from early in the session.

ePrivacy Directive and Consent Analysis

On payment pages, the __stripe_mid and __stripe_sid cookies and the Radar fingerprinting are strongly arguable as strictly necessary for the payment processing service that the user has explicitly requested: the ePrivacy Directive Art. 5(3) exemption applies. However, loading Stripe.js site-wide on non-payment pages (e.g. homepages, blog posts, product listings) before any purchase intent is expressed is a different matter. This broader deployment collects fingerprinting data outside the payment context, which is harder to justify as strictly necessary and is legally contested. Several EU data protection authorities have signalled that always-on fraud fingerprinting beyond the payment page context may require consent or at minimum a rigorous legitimate interest assessment.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

GDPR Legal Basis and Data Transfers to the US

For payment-page-only deployment, the legal basis is legitimate interest (Art. 6(1)(f) GDPR) and performance of a contract (Art. 6(1)(b)), since fraud detection is a legitimate interest that is necessary and proportionate to protecting payment transactions. For site-wide deployment, a legitimate interest balancing test must document that the interests of Stripe and the merchant in fraud prevention outweigh user privacy interests and that the data subject would reasonably expect this processing. Data is transferred to Stripe Inc. in the United States. Stripe uses Standard Contractual Clauses (SCCs) as the transfer mechanism and provides a Data Processing Addendum. A DPA with Stripe is required under GDPR Art. 28.

Risk Assessment for European Merchants

The compliance risk for Stripe.js is rated medium. When confined to payment pages, the risk is relatively low and the strictly necessary or legitimate interest basis is defensible. The risk increases when Stripe.js is loaded site-wide, because the fraud fingerprinting then occurs on all pages including those unrelated to payment, widening the scope of personal data collection. Merchants that embed Stripe.js globally should document their legitimate interest assessment, inform users of this processing in their privacy policy, and consider whether a DPIA is warranted.

Practical Compliance Steps for European Merchants

To comply with GDPR and ePrivacy when using Stripe.js: sign a Data Processing Addendum with Stripe; disclose Stripe.js in your privacy policy including the cookies set, the fraud detection purpose, and the US data transfer via SCCs; if loading Stripe.js site-wide, document and publish a legitimate interest assessment for the broader fingerprinting; consider restricting Stripe.js to payment-related pages to minimise risk; add __stripe_mid and __stripe_sid to your cookie policy under a security or strictly necessary category (if payment-page only) or flag them for a LIA (if site-wide); and review Stripe's DPA and sub-processor list periodically.

GDPR consent category

Essential

Websites using Stripe.js must obtain user consent under GDPR regulations.

Legal basisStrictly necessary (ePrivacy Directive Art. 5(3) exemption) and legitimate interest (GDPR Art. 6(1)(f)) when Stripe.js is loaded exclusively on payment pages as part of the payment processing flow. However, loading Stripe.js site-wide for always-on fraud fingerprinting on non-payment pages is legally contested: this broader deployment arguably requires a legitimate interest balancing test or, under stricter interpretations by some EU DPAs, user consent. Publishers should confine Stripe.js loading to payment-relevant pages where possible.
Risk levelmedium
Applicable regulationsGDPR (EU) 2016/679, ePrivacy Directive 2002/58/EC, SCCs for US data transfers, PCI DSS (payment card industry compliance)

DPIA considerations

A DPIA should be considered if Stripe.js is loaded site-wide across all pages, given that device fingerprinting for fraud detection outside the payment context may constitute systematic processing of personal data at scale. The combination of behavioural signals collected by Stripe Radar (mouse movements, timing, browser characteristics) may constitute profiling. Document the scope of Stripe.js deployment, the data flows to Stripe in the US, and the legal basis for each deployment context (payment page vs. all pages). Review Stripe's Data Processing Agreement and sub-processor list.

Technical details

Tracking methodJavaScript loaded from js.stripe.com. Sets cookies __stripe_mid (1 year) and __stripe_sid (30 minutes) for fraud detection via Stripe Radar. Collects device and behavioural fingerprint including browser characteristics, mouse movements, and timing data. When loaded site-wide (not just on payment pages), this fingerprinting occurs on pages before checkout begins.
Server locationUnited States (Stripe Inc.), with EU data residency options available via Stripe Privacy Controls
Data transferred outside the EUData is processed by Stripe Inc. in the United States. Stripe uses Standard Contractual Clauses (SCCs) under GDPR Art. 46 for EEA-to-US data transfers. A Data Processing Agreement is available from Stripe.

Third-party domains contacted

js.stripe.comm.stripe.comm.stripe.networkapi.stripe.com

Cookies placed

NameTypeDurationPurpose
__stripe_midfunctional1 yearStripe machine identifier cookie set by js.stripe.com. Used by Stripe Radar to assign a persistent machine identity to a browser for fraud detection scoring. Persists across sessions.
__stripe_sidfunctional30 minutesStripe session identifier cookie set by js.stripe.com. Used by Stripe Radar to track a single browsing session for fraud risk assessment during the payment flow.

Stripe.js is an essential service, but transparency matters. Manage all your consent with FlowConsent.

Get started freeScan your site

Frequently asked questions

What cookies does Stripe.js set?

Stripe.js sets two cookies: __stripe_mid (machine identifier, duration 1 year) and __stripe_sid (session identifier, duration 30 minutes). These cookies are used by Stripe Radar, Stripe's fraud detection system, to link behavioural signals collected across a user's browser session to a stable machine identity. In addition to these cookies, Stripe.js collects a device fingerprint including browser characteristics, plugins, screen resolution, and interaction patterns.

Is consent required for Stripe.js cookies?

On payment pages specifically, the __stripe_mid and __stripe_sid cookies and the fraud fingerprinting are defensible as strictly necessary under the ePrivacy Directive, since they are required to process the payment transaction the user explicitly initiated. No consent banner is typically required for payment-page-only deployment. However, if Stripe.js is loaded site-wide across all pages (as Stripe recommends for better fraud detection), the broader fingerprinting on non-payment pages is legally contested and may require a legitimate interest assessment or, under stricter national interpretations, consent.

What is the legal basis for Stripe.js under GDPR?

For payment-page-only use: legitimate interest (Art. 6(1)(f)) and performance of a contract (Art. 6(1)(b)) GDPR. Fraud detection for payment security is a proportionate and necessary legitimate interest. For site-wide use: a legitimate interest balancing test is required documenting that fraud prevention interests outweigh user privacy interests and that users would reasonably expect this processing. A Data Processing Agreement with Stripe under Art. 28 GDPR is required in all cases.

Does Stripe.js transfer data to the United States?

Yes. Stripe Inc. is headquartered in the United States and processes transaction and fraud-detection data there. Stripe uses Standard Contractual Clauses (SCCs) as the GDPR-compliant transfer mechanism for EEA-to-US transfers. Stripe provides a Data Processing Addendum covering these transfers. You must disclose this US transfer in your privacy policy and reference the SCCs as the applicable safeguard.

Do I need a DPIA for Stripe.js?

A DPIA should be considered if Stripe.js is loaded site-wide on all pages, because the systematic collection of device fingerprints and behavioural signals from all visitors (not just those making payments) may constitute high-risk processing. The combination of persistent identifiers (__stripe_mid lasting 1 year) and behavioural profiling across sessions broadens the data processing scope. For payment-page-only deployment, a DPIA is generally not required.

How do I implement Stripe.js in a GDPR-compliant way?

Best practices: sign Stripe's Data Processing Addendum; if possible, load Stripe.js only on payment-related pages rather than site-wide; disclose Stripe.js in your privacy policy including the cookies set, fraud detection purpose, and US transfer via SCCs; if loading site-wide, document and publish a legitimate interest balancing test; add __stripe_mid and __stripe_sid to your cookie notice under "Security" or "Strictly Necessary" (payment pages) or "Functional" (site-wide with LIA); and review Stripe's DPA and sub-processor list periodically.

Are there payment processors without site-wide fingerprinting for European merchants?

Several EU-based payment processors offer alternatives where fraud detection does not require site-wide JavaScript fingerprinting. Mollie (Netherlands), Adyen (Netherlands), and Klarna (Sweden) are EU-based processors. However, most modern fraud prevention systems use some form of device intelligence. Mollie and Adyen offer robust EU data residency options. The compliance risk can also be reduced by confining any payment processor's JavaScript to checkout pages only.

How do I describe Stripe.js cookies in my cookie policy?

In your cookie policy, list __stripe_mid and __stripe_sid under a "Security" or "Strictly Necessary" category if Stripe.js is loaded only on payment pages, explaining that they are required to process your payment securely and detect fraud. If Stripe.js is loaded site-wide, you may need to categorise them differently and explain the broader legitimate interest basis. Include: cookie name, purpose (payment security and fraud detection via Stripe Radar), duration, that data is processed by Stripe Inc. in the US under SCCs, and a link to Stripe's privacy policy.