FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. E-commerce
  4. Yampi Checkout
Y

Yampi Checkout

PreferencesWebsite

Related services

24nettbutikk

24nettbutikk is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. 24nettbutikk supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, 24nettbutikk ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Preferences

2ClickShop

2ClickShop is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 2ClickShop integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 2ClickShop helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences

4-Tell

4-Tell is a marketing platform that equips businesses with tools to amplify their digital presence and drive customer acquisition. It supports audience segmentation, campaign automation, and cross-channel engagement. 4-Tell provides real-time analytics and reporting dashboards for performance measurement and strategy optimization. By combining data intelligence with marketing execution, 4-Tell helps deliver the right message to the right audience at the right time.

Preferences

42stores

42stores is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 42stores integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 42stores helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences

4Partners

4Partners is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 4Partners integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 4Partners helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences
4

4Partners CMS

4Partners CMS is a powerful content management system (CMS) designed to help businesses and developers build, manage, and publish digital content with ease. It offers a flexible architecture that supports custom content types, templates, and workflows, making it ideal for websites of any scale. With 4Partners CMS, teams can streamline content creation, improve collaboration, and deliver engaging web experiences. Its extensible plugin ecosystem and API-first approach ensure seamless integration with.

Preferences
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does Yampi Checkout do?

Yampi Checkout is a Brazilian e-commerce checkout solution that lets merchants accept payments through a hosted or embedded flow integrated with multiple payment gateways. It includes cart management, one-page checkout, abandoned cart recovery, A/B testing, and detailed conversion analytics. Yampi is widely used by Brazilian retailers on Shopify, WooCommerce, Nuvemshop, and other platforms. Because the infrastructure is hosted in Brazil, any use targeting EU customers raises a third-country transfer issue under the GDPR.

What Yampi Checkout is and how it works

Yampi Checkout is a SaaS checkout product developed by Yampi, a Brazilian e-commerce platform headquartered in São Paulo. It replaces the native checkout of platforms such as Shopify, WooCommerce, Nuvemshop or Magento with an optimised cart, one-page payment, and post-purchase flow. Merchants connect Yampi to one or several payment gateways (Cielo, Stone, PagSeguro, Stripe, Mercado Pago) and offer Pix, boleto, card and digital wallets.

The checkout runs either as a redirect to seguro.yampi.com.br or as an embedded iframe. It includes abandoned cart recovery, A/B testing, upsells, and a backend that the merchant uses to monitor conversion in real time.

Data and cookies collected

Yampi sets several first-party cookies. A session cookie keeps the cart linked to the visitor, a CSRF token protects checkout forms, and a customer identifier links anonymous browsing sessions to subsequent logged-in or paid sessions. In addition, Yampi may set A/B testing cookies, conversion tracking cookies, and an e-mail-capture cookie used to send abandoned cart messages.

Personal data collected typically includes name, e-mail, CPF or other tax identifier, billing and shipping address, phone number, IP address, device information, and the full order content. Some merchants enable Facebook Pixel, Google Ads or TikTok Pixel inside Yampi: those further extend the cookie footprint to advertising networks.

GDPR and ePrivacy implications

Strictly necessary cookies (cart session, CSRF) do not require consent under Article 5(3) of the ePrivacy Directive. However, the A/B testing, conversion tracking, e-mail capture for abandoned cart, and any advertising pixels enabled on top of Yampi do require informed prior consent. The legal basis differs accordingly: contract performance for the checkout itself, consent for marketing features.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Data transfers to Brazil

Yampi hosts its infrastructure on cloud providers located in Brazil. Brazil benefits from a modern data protection regime (LGPD) but has not yet been granted an adequacy decision by the European Commission as of 2026. EU controllers must therefore implement appropriate safeguards: Standard Contractual Clauses, a transfer impact assessment, and supplementary measures such as encryption in transit and at rest.

Consent and DPIA

The non-essential cookies set by Yampi must be blocked until the visitor opts in. The abandoned cart e-mail flow requires either consent or, in B2B contexts, a soft opt-in covered by an existing customer relationship. A DPIA is recommended because the processing combines profiling for conversion optimisation, marketing remarketing, and a transfer to a third country.

Practical compliance steps

Sign a data processing addendum with Yampi including SCCs, disable A/B testing and abandoned cart capture for users who refuse marketing, document the subprocessors used by the platform, configure your consent banner to gate the non-essential Yampi cookies, and reference Yampi explicitly in your privacy policy with a clear statement on the transfer to Brazil.

GDPR consent category

Preferences

Websites using Yampi Checkout must obtain user consent under GDPR regulations.

Legal basisconsent_for_marketing_and_analytics_cookies_contract_for_session_cookies
Risk levelmedium
Applicable regulationsGDPR, ePrivacy Directive, LGPD

DPIA considerations

A DPIA is recommended whenever Yampi is used on stores that target EU residents, because the combination of marketing cookies, conversion tracking, abandoned cart e-mails, and a transfer to Brazil increases the overall risk. The DPIA should cover the consent mechanism, the SCCs signed with Yampi, the retention periods of cart and transaction logs, and the safeguards applied to e-mail-based remarketing.

Sample consent text

We use Yampi Checkout to operate our cart, payment, and abandoned cart recovery. Some cookies are strictly necessary for the checkout to function; others (A/B testing, conversion tracking, marketing) require your consent. Your purchase data is processed in Brazil under Standard Contractual Clauses.

Technical details

Tracking methodfirst_party_cookies_and_javascript
Server locationBrazil
Data transferred outside the EUYampi hosts data on servers in Brazil. For EU users, this constitutes a transfer to a third country. Brazil benefits from a partial recognition through the LGPD framework, but no adequacy decision has been issued by the European Commission as of 2026. Standard Contractual Clauses and a transfer impact assessment are required.

Third-party domains contacted

yampi.com.brseguro.yampi.com.brcdn.yampi.ioapi.yampi.com.br

Cookies placed

NameTypeDurationPurpose
yampi_sessionhttpsessionMaintains the cart and checkout session for the visitor.
XSRF-TOKENhttpsessionCross-site request forgery protection for checkout forms.
_yampi_cidhttp12 monthsCustomer identifier that links anonymous browsing to subsequent paid sessions.
_yampi_abhttp90 daysA/B testing cookie used to assign and persist checkout experiments.
_yampi_cart_recoveryhttp30 daysStores the e-mail and cart contents used for abandoned cart recovery messages.
_yampi_convhttp30 daysConversion attribution cookie set after a successful purchase.

Yampi Checkout uses cookies for user preferences — inform visitors with a consent banner.

Get started freeScan your site

Frequently asked questions

What cookies does Yampi Checkout set?

Yampi sets a session cookie and a CSRF token (strictly necessary), a customer identifier that links browsing to purchase, an A/B testing cookie, a cart recovery cookie that stores e-mail and cart content, and a conversion attribution cookie. Advertising pixels (Meta, Google, TikTok) can be enabled by the merchant on top.

Is consent required for Yampi Checkout?

Yes for the non-essential layers. Cart session and CSRF cookies are exempt, but A/B testing, conversion tracking, abandoned cart e-mail capture, and any advertising pixels require informed prior consent. Block these cookies until the visitor opts in through your consent management platform.

What is the legal basis?

Two distinct legal bases apply. Article 6(1)(b) GDPR (performance of a contract) covers the checkout, payment, and order fulfilment. Article 6(1)(a) GDPR (consent) covers A/B testing, conversion tracking, abandoned cart marketing, and advertising pixels enabled inside Yampi.

Does Yampi transfer data outside the EU?

Yes. Yampi operates from Brazil, so EU customer data is transferred to a third country. As of 2026 Brazil does not benefit from an EU adequacy decision, so the transfer must rely on Standard Contractual Clauses, a transfer impact assessment, and supplementary measures such as encryption.

Is a DPIA required?

A DPIA is strongly recommended when Yampi is deployed on stores that target EU customers, because the processing combines large-scale profiling (A/B testing, conversion tracking, remarketing) with a transfer to a non-adequate third country. The DPIA should document risks, safeguards, and the consent design.

How do I implement Yampi compliantly?

Sign a data processing addendum with SCCs, configure your consent banner to block A/B testing and marketing cookies until opt-in, disable abandoned cart e-mail capture for visitors who refuse marketing, document Yampi as a subprocessor in your records, and inform customers in your privacy policy about the transfer to Brazil.

What are the alternatives to Yampi for EU merchants?

EU-based or EU-hosted checkout solutions include Shopify Checkout (with EU data residency options), Mollie, Adyen, Stripe Checkout (EU), Bold Commerce, or building a custom checkout on top of headless commerce. These options reduce or eliminate the third-country transfer concern for European customers.

How should I update my cookie policy for Yampi?

List each Yampi cookie with its name, type, duration, and purpose. Mark cart session and CSRF as strictly necessary, and A/B testing, conversion tracking, cart recovery, and any advertising pixels as subject to consent. Mention Yampi by name as a processor, reference the SCCs for the Brazil transfer, and refresh the page when Yampi updates its subprocessor list.