FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. Security
  4. Apruvd

Apruvd

EssentialWebsite

Related services

Accertify

Accertify is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. Accertify supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, Accertify ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Essential

adCAPTCHA

adCAPTCHA is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. adCAPTCHA supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, adCAPTCHA ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Essential
A

Akamai Bot Manager

Akamai Bot Manager is an AI-powered chatbot platform that enables businesses to automate customer conversations across websites, messaging apps, and social channels. It provides natural language processing, conversation flow builders, and backend integration to handle inquiries, qualify leads, and provide support. Akamai Bot Manager reduces response times and costs while maintaining high-quality conversational experiences that scale with your business needs.

Essential
A

Akamai Web Application Protector

Akamai Web Application Protector is a comprehensive web security solution that protects websites and applications from cyber threats including DDoS attacks, SQL injection, and cross-site scripting. It provides web application firewall (WAF) capabilities, real-time threat detection, and automated incident response. Akamai Web Application Protector offers SSL/TLS encryption, bot management, and security monitoring. With compliance reporting and vulnerability scanning, Akamai Web Application Protector.

Essential
A

Alibaba Cloud Verification Code

Alibaba Cloud Verification Code is a web hosting and cloud infrastructure provider delivering reliable, scalable hosting solutions for websites and applications of all sizes. It offers shared, VPS, and dedicated server options with SSD storage, global CDN, and automated backups. Alibaba Cloud Verification Code provides one-click deployment, managed databases, and 24/7 monitoring. With high uptime guarantees and developer-friendly tools, Alibaba Cloud Verification Code ensures optimal performance at scale.

Essential

Alliance Auth

Alliance Auth is an identity and authentication platform providing secure login, single sign-on (SSO), and multi-factor authentication for websites and applications. It supports social login, passwordless authentication, and user management with enterprise-grade security. Alliance Auth simplifies identity implementation for developers while ensuring compliance. With adaptive authentication and anomaly detection, Alliance Auth protects user accounts while maintaining a frictionless experience.

Essential
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does Apruvd do?

Managed fraud prevention and chargeback guarantee service from Apruvd LLC (United States) that combines machine learning, device fingerprinting and manual review to approve or decline e commerce transactions.

What Apruvd is

Apruvd is a managed fraud prevention service that screens e commerce transactions and provides a chargeback guarantee. The merchant calls the Apruvd API at checkout; Apruvd combines machine learning, device fingerprinting and a manual review team to decide whether to approve, decline or hold the order.

What data is processed

Apruvd processes the buyer''s name, billing and shipping address, e mail, phone, IP, device fingerprint, order value, basket content, BIN range and payment method metadata. It cross references this against its risk graph of historical fraud patterns and known networks of fraudsters.

GDPR and ePrivacy implications

Fraud prevention can rely on contract (Article 6(1)(b) GDPR) or legitimate interest (Article 6(1)(f)) provided the processing is strictly proportionate. The fingerprinting script may still trigger Article 5(3) ePrivacy if it stores or reads information on the device for purposes beyond what is strictly necessary for the requested service. Automated decisions producing legal effects fall under Article 22, with a right to human intervention.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Consent requirements

Consent is generally not required because fraud screening is necessary to perform the contract and protect both parties. However the fingerprinting and risk signal collection must be disclosed in the privacy notice, with an explanation of the logic and the right to contest an automated decision. Marketing reuse of fraud data would require consent.

International data transfers

Apruvd processes data primarily in the United States. Transfers rely on Standard Contractual Clauses and the EU US Data Privacy Framework. Document the transfer impact assessment, especially since fraud signals can be combined and shared across merchants in the network.

Practical compliance steps

Sign the DPA, run a DPIA, describe Apruvd as a processor in your privacy notice, explain the automated decision logic in plain language, expose a contact point for human review under Article 22, restrict the data fields sent to the strict minimum, define retention for risk scores and align with PCI DSS scoping for any payment data shared.

GDPR consent category

Essential

Websites using Apruvd must obtain user consent under GDPR regulations.

Legal basisArticle 6(1)(b) GDPR (contract performance, fraud screening required to complete the payment) and Article 6(1)(f) (legitimate interest in preventing fraud, chargebacks and money laundering). Pure marketing or profiling uses of fraud signals would require consent.
Risk levelhigh
Applicable regulationsGDPR, ePrivacy Directive, PSD2, AMLD, German TTDSG, French CNIL guidance on fraud prevention, Spanish LOPDGDD, PCI DSS

DPIA considerations

A DPIA is required because fraud screening involves systematic evaluation of personal aspects (Article 35(3)(a) GDPR) and may lead to automated decisions with legal or significant effects (Article 22). Document the logic, the human review fallback, retention of risk signals and data subject rights.

Sample consent text

To protect both you and our store from payment fraud we use Apruvd (Apruvd LLC, United States) to analyse the transaction, including device, IP and order data. Apruvd may approve, decline or send the order for manual review. You can request human intervention and explanation under Article 22 GDPR.

Technical details

Tracking methodJavaScript fingerprinting snippet, server side transaction screening API, device and behavioural signals, IP reputation, optional first party session cookies
Server locationUnited States (primary), with some monitoring in EU regions
Data transferred outside the EUApruvd LLC is based in the United States. Transaction data, billing addresses, IP addresses and device signals are transmitted to the US backend. Transfers rely on Standard Contractual Clauses and the EU US Data Privacy Framework.

Third-party domains contacted

apruvd.comjs.apruvd.comapi.apruvd.comfingerprint.apruvd.com

Cookies placed

NameTypeDurationPurpose
apruvd_didhttp1 yearStores a pseudonymous device identifier computed from the fingerprinting script to recognise the device across orders.
apruvd_sessionhttpSessionStores the session ID used during the fraud scoring API call at checkout.
apruvd_riskhttp30 daysCaches the latest risk score for the device to avoid redundant API calls during the same browsing window.

Apruvd is an essential service, but transparency matters. Manage all your consent with FlowConsent.

Get started freeScan your site

Frequently asked questions

Which cookies does Apruvd set?

Apruvd sets a small set of strictly necessary cookies for the checkout fraud check: apruvd_did (device ID derived from fingerprinting), apruvd_session (session ID) and apruvd_risk (cached risk score). No advertising cookie is set.

Is user consent required?

Not for the fraud scoring itself when it is strictly necessary to complete the payment under Article 6(1)(b) GDPR. The fingerprinting and cookies do however need to be disclosed in the privacy notice. Reuse for marketing would require consent.

What is the legal basis?

Article 6(1)(b) GDPR (contract performance) and Article 6(1)(f) (legitimate interest in fraud prevention). Article 22 GDPR applies whenever the score automatically rejects an order, and the merchant must offer a human review channel.

Does Apruvd transfer data to the US?

Yes. Apruvd LLC is based in the United States. Transfers are covered by Standard Contractual Clauses and the EU US Data Privacy Framework as described in the Apruvd DPA. A transfer impact assessment is recommended.

Do I need a DPIA?

Yes. Automated decision making, large scale evaluation of personal aspects and cross merchant risk graphs all trigger Article 35 GDPR. The DPIA must cover the logic, model bias controls, retention of signals and Article 22 safeguards.

How do I implement Apruvd compliantly?

Sign the DPA, run a DPIA, send only the data fields required for scoring, disclose Apruvd in the privacy notice, set up a human review process for declined orders, configure retention, restrict admin access and align PCI DSS controls for shared payment data.

What are the alternatives?

Other fraud and chargeback services include Signifyd, Riskified, Forter, Kount, Sift, Stripe Radar, Adyen RevenueProtect, NoFraud and ClearSale. EU based options or those with EU residency reduce transfer complexity.

How do I update the cookie policy?

List Apruvd as a processor under the security and fraud prevention category, describe the strictly necessary cookies it sets, the data sent to its API, the retention of risk scores, link to its privacy policy and refresh the entry whenever the integration changes.