FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. Other
  4. Affirm

Affirm

Other

Related services

AccuWeather

AccuWeather is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. AccuWeather supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, AccuWeather ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Other
A

Acuity Scheduling

Acuity Scheduling is a user preference and personalization service that helps websites deliver customized experiences based on individual visitor settings and choices. It manages preferences for content display, communication channels, and interaction styles. Acuity Scheduling integrates with website platforms to remember and apply user choices consistently across sessions. With privacy-compliant preference storage, Acuity Scheduling enhances satisfaction by ensuring tailored browsing experiences for every visitor.

Preferences

Algolia

Algolia is a versatile web technology that supports digital platforms with specialized functionality and enhanced capabilities. It provides robust tools and services that integrate with modern websites and applications seamlessly. Algolia is designed to improve operational efficiency, user experience, and digital performance. Trusted by developers and businesses alike, Algolia offers reliable solutions that scale with organizational needs and evolving web standards.

Other
A

AppDynamics

AppDynamics is an analytics and measurement platform providing deep insights into digital ecosystem performance. It tracks user interactions, measures campaign effectiveness, and identifies optimization opportunities across web and mobile. AppDynamics offers customizable dashboards, automated alerts, and data export capabilities. By transforming raw data into actionable intelligence, AppDynamics empowers organizations to optimize strategy and maximize return on investment.

Analytics
A

Apple App Store

Apple App Store is a comprehensive e-commerce platform that provides businesses with all the tools needed to build, manage, and grow an online store. From product catalog management and secure payment processing to inventory tracking and order fulfillment, Apple App Store delivers a complete commerce solution. It features responsive storefront themes, SEO-optimized product pages, and powerful marketing tools to help merchants increase visibility and drive sales across channels.

Other
A

Apple iCloud Mail

Apple iCloud Mail is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. Apple iCloud Mail supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, Apple iCloud Mail ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Other
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does Affirm do?

Affirm is a US based buy now pay later (BNPL) and point of sale financing provider operated by Affirm Holdings, Inc. Merchants embed the affirm.js script to display monthly payment estimates on product pages and open a hosted credit application at checkout. The widget transmits visitor and transaction data to Affirm servers in the United States, which triggers full GDPR and ePrivacy obligations for EU merchants.

What is Affirm

Affirm is a buy now pay later and point of sale lending platform operated by Affirm Holdings, Inc., a publicly listed company headquartered in San Francisco. Unlike short instalment products, Affirm offers loans ranging from a few weeks to several years, with disclosed interest and a hard or soft credit check depending on the offer. Merchants integrate Affirm through affirm.js, which renders the As low as monthly payment widget on product pages and opens a hosted credit application flow at checkout.

What data Affirm collects

On product pages, Affirm collects IP address, User Agent, page URL, basket value and merchant ID through the widget script, and sets analytics and fraud cookies. During the credit application, Affirm collects name, date of birth, address, phone, email, the last four digits of a social security number or a national identifier, employment data and bank verification. Affirm queries credit bureaus and fraud databases to issue the lending decision and shares the outcome with the merchant.

GDPR and ePrivacy implications

Affirm cookies set on category and product pages are not strictly necessary and require consent under Article 5(3) of the ePrivacy Directive. The credit application performed at checkout falls under Article 6(1)(b) GDPR as it is necessary to enter into a contract requested by the data subject. Automated credit scoring is subject to Article 22 GDPR safeguards: the user must be informed, can ask for human intervention and can contest the decision. Cross border transfers to the US trigger Chapter V obligations.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Is consent required

For the marketing widget and any analytics cookies dropped before checkout, yes: gate the affirm.js script behind the consent manager. Inside the checkout, when the user has actively chosen Affirm as the financing option, the application processing can run under contract. The privacy notice must still clearly describe what data goes to Affirm and that an automated decision will be taken.

Data transfers to the United States

Affirm Holdings, Inc. is a US controller and processes data on US infrastructure. Affirm self certified under the EU US Data Privacy Framework, which provides an adequacy decision for transfers to Affirm. Affirm also publishes Standard Contractual Clauses for international customers and clarifies how it handles requests for access by US authorities under FISA 702. Merchants must reference these mechanisms in their privacy policy and inform users of the international nature of the processing.

Practical compliance steps

Gate the Affirm widget behind your consent manager, document the integration in your record of processing, conduct a DPIA covering automated decisions and US transfers, and sign the appropriate agreement with Affirm (controller to controller for the lending decision, processor terms for analytics passed through the merchant). Update the privacy policy with the categories of data, the legal bases, the SCC or DPF mechanism and the user rights regarding Article 22.

GDPR consent category

Other

Websites using Affirm must obtain user consent under GDPR regulations.

Legal basisContract (Art. 6(1)(b) GDPR) for credit application and checkout, consent (Art. 6(1)(a)) for the marketing widget on product pages and any analytics cookies it loads, legitimate interest (Art. 6(1)(f)) for fraud prevention
Risk levelhigh
Applicable regulationsGDPR, ePrivacy Directive, Consumer Credit Directive 2008/48/EC, TTDSG, ECOA (US), TILA (US)

DPIA considerations

A DPIA is recommended whenever Affirm is integrated. The processing involves automated credit decisions, financial data, fraud profiling and systematic transfers of personal data to the United States, three of the nine WP29 criteria for high risk processing. Document the necessity and proportionality of the integration, and the safeguards implemented (consent gate, transfer mechanism, retention).

Sample consent text

We use Affirm to display payment plans and process credit applications. This sets cookies and shares your IP address and transaction data with Affirm Holdings, Inc. in the United States. Do you accept?

Technical details

Tracking methodJavaScript SDK (affirm.js), iframe widget for monthly payment estimates, redirect or modal for credit application, server to server API for capture and refund
Server locationUnited States (Affirm Holdings, Inc., San Francisco) with global delivery through AWS edges
Data transferred outside the EUPersonal data (IP address, device fingerprint, contact and financial information at checkout) is transferred to Affirm Holdings, Inc. in the United States. Affirm relies on EU US Data Privacy Framework certification and Standard Contractual Clauses. Affirm offers BNPL primarily in North America; European merchants embedding the widget for US shoppers must still document the transfer.

Third-party domains contacted

affirm.comcdn-assets.affirm.comapi.affirm.comtracker.affirm.comwww.affirm.comcdn1.affirm.comsift.com

Cookies placed

NameTypeDurationPurpose
_affirm_sessionthird partySessionMaintains the user session between the merchant site and the Affirm hosted application flow.
affirm_sift_session_idthird party1 yearSift fraud detection session identifier used by Affirm to score risk on incoming credit applications.
mp_<token>_mixpanelthird party1 yearMixpanel analytics cookie set on affirm.com to measure the funnel of the credit application.
_gathird party2 yearsGoogle Analytics first party cookie set on affirm.com to track usage of Affirm marketing and merchant facing pages.
csrftokenthird party1 yearCross site request forgery protection token used during the hosted credit application flow.

This service may collect user data. Ensure GDPR compliance with FlowConsent.

Get started freeScan your site

Frequently asked questions

What cookies does Affirm set?

The widget sets cookies such as _affirm_session, affirm_sift_session_id (a fraud session identifier provided by Sift), and various analytics cookies (Mixpanel, Google Analytics) on Affirm domains. These cookies are not strictly necessary on a merchant site and require consent under the ePrivacy rules.

Do I need consent for the Affirm widget?

Yes, for the As low as widget rendered on category and product pages, and for any analytics cookies the script triggers. Inside the checkout, once the user has chosen Affirm, processing can run under contract, but the consent layer should already have classified those cookies as marketing or functional.

What is the legal basis for Affirm processing?

Contract (Art. 6(1)(b) GDPR) for the credit application, legitimate interest (Art. 6(1)(f)) for fraud prevention via Sift and risk modelling, and consent (Art. 6(1)(a)) for non essential cookies and marketing widgets. Automated decision making requires the Article 22 safeguards.

Are personal data transferred to the US with Affirm?

Yes. Affirm is a US controller and processes everything in the United States. Affirm is self certified under the EU US Data Privacy Framework and offers Standard Contractual Clauses. Both should be referenced in the merchant's privacy policy together with the list of recipients.

Is a DPIA needed for Affirm?

Yes in most cases. Automated credit scoring on potentially every customer that lands on a product page meets several DPIA criteria. A DPIA should cover the data flows, the credit decisioning logic, the user rights under Article 22, and the safeguards for cross border transfers.

How do I implement Affirm correctly?

Block affirm.js until consent is granted, route the financing flow through a dedicated path that the user actively chooses, sign the relevant contractual instruments with Affirm, and update the privacy policy. Provide a clear notice when the user is about to be subject to an automated credit decision and explain how to request human review.

What are the alternatives to Affirm in Europe?

For European merchants, Klarna, Alma, Scalapay, Riverty and Cofidis offer regulated BNPL services with stronger EU presence. They still come with their own privacy obligations but often process data within the EU. Traditional financing solutions through partner banks remain available for high value purchases.

How should I describe Affirm in my cookie policy?

Add an entry under Marketing or Functional. List the relevant cookies (_affirm_session, affirm_sift_session_id, analytics cookies), the provider (Affirm Holdings, Inc., San Francisco, USA), the purpose (rendering the widget, fraud prevention, analytics), and the transfer mechanism (EU US Data Privacy Framework or SCC).