Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
WePay, a JPMorgan Chase company, is an integrated payments provider offering iframe and hosted checkout, tokenization through wepay.js and onboarding for software platforms.
WePay is an integrated payments provider owned by JPMorgan Chase in the United States. It serves software platforms and independent software vendors with iframe and hosted checkout, tokenization and merchant onboarding, and the legacy product is being migrated into Chase.
The checkout loads wepay.js and hosted fields and sets functional cookies to operate the flow and fraud cookies to protect transactions. Payment details are tokenized so that card data does not pass through the platform server, and onboarding collects business and identity information for verification.
Strictly necessary checkout cookies are generally exempt from the consent rule in the ePrivacy Directive because they deliver a service the user requested. Processing rests on contract for payments, on legal obligations for financial rules, and on legitimate interests for fraud prevention.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Consent is not needed for the strictly necessary checkout and fraud cookies, but any analytics or marketing cookies a platform adds around the WePay flow require prior consent. Keep these categories clearly separated in the consent banner.
WePay processes data in the United States as part of JPMorgan Chase, so European platforms carry out a transfer to a third country. This should be covered by Standard Contractual Clauses, a transfer impact assessment and supplementary safeguards, reviewed alongside the migration into Chase.
Sign the applicable data processing agreement, document the US transfer and the legal bases, and describe the necessary checkout and fraud cookies in your cookie policy. Track the migration into Chase so that contracts and privacy notices stay accurate as the product changes.
Websites using WePay must obtain user consent under GDPR regulations.
DPIA considerations
A DPIA should consider that WePay processes payment and onboarding data in the US as part of JPMorgan Chase, and that the legacy product is being migrated into Chase. Assess the US transfer, the fraud processing and any change of controller or processor arising from the migration.
Sample consent text
We use WePay, a Chase company, to process your payment securely. Strictly necessary cookies that complete the checkout and support fraud prevention are always active. Any analytics or marketing cookies are set only with your consent, which you can withdraw at any time.
Third-party domains contacted
wepay.comapi.wepay.comstatic.wepay.comstage.wepay.comcdn.wepay.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| Checkout session cookie | Third-party | Session | Maintains the state of the WePay iframe and hosted checkout during the session |
| Fraud prevention cookie | Third-party | 1 year | Supports fraud detection and protects the integrity of payment transactions |
| Functional preference cookie | Third-party | 1 year | Stores functional settings and security preferences for the WePay interface |
| Onboarding session cookie | Third-party | Session | Keeps state during merchant onboarding and identity verification flows |
WePay uses cookies for user preferences — inform visitors with a consent banner.
WePay sets functional cookies needed to operate the iframe and hosted checkout and fraud cookies that help protect transactions. The exact set depends on the integration and whether the legacy WePay product or the Chase platform is used.
Consent is not required for the strictly necessary checkout and fraud cookies, which are exempt because they deliver a service the user requested. Consent is required for any analytics or marketing cookies a platform adds around the WePay checkout.
Processing rests on performance of a contract under Article 6(1)(b) for completing payments, legal obligation under Article 6(1)(c) for financial and anti money laundering rules, and legitimate interests under Article 6(1)(f) for fraud prevention.
Yes. WePay processes data in the United States as part of JPMorgan Chase, so European platforms carry out a transfer to a third country. This should be covered by Standard Contractual Clauses and supplementary safeguards, reviewed alongside the migration into Chase.
A DPIA is advisable because WePay processes payment and onboarding data in the US and the legacy product is being migrated into Chase. The assessment should cover the US transfer, fraud processing and any change of controller or processor from the migration.
Sign the applicable data processing agreement, document the US transfer and the legal bases, and describe the necessary checkout and fraud cookies in your cookie policy. Keep any added analytics behind consent and track the migration into Chase.
Alternatives for platform and integrated payments include Stripe Connect, Adyen for Platforms, Square and PayPal for Marketplaces. Each differs in server locations, cookie behaviour and transfer mechanisms that should be reviewed individually.
Add a WePay entry that lists the necessary checkout and fraud cookies with their purposes and durations, the US transfer and the safeguards in place. Note the migration into Chase and keep the entry current as your integration moves to the Chase platform.