Elavon

Elavon

Elavon scripts embed hosted payment forms for processing card transactions on merchant websites. Scripts handle card data within Elavon's PCI-compliant hosted environment, preventing direct handling of sensitive card data by the merchant. Session data is used for fraud prevention.

Overview

Elavon, a subsidiary of US Bancorp, is a major global payment processor serving merchants across retail, hospitality, healthcare, and e-commerce. When Elavon's scripts appear on merchant websites, they're powering the hosted payment form experience — secure card entry interfaces that process transactions through Elavon's PCI-compliant infrastructure without exposing sensitive card data to the merchant's servers.

Elavon's approach to web integration is conservative and security-focused, reflecting its banking heritage and the stringent requirements of payment card processing.

What This Script Does

Elavon's scripts handle secure payment processing on merchant checkout pages:

  • Hosted payment form rendering: Displays card entry fields within Elavon's hosted environment (typically iframes), capturing card number, expiration date, and CVV directly on Elavon's PCI-certified servers
  • Payment tokenization: Converts card details into secure tokens for transaction processing, allowing merchants to manage payments without directly handling card data
  • Transaction processing: Submits payment authorization requests through Elavon's processing network and returns approval or decline responses to the checkout flow
  • Session state management: Sets cookies to maintain the payment session, linking the customer's cart to the active transaction through the authorization cycle
  • Fraud prevention signals: Collects basic device and session data to support fraud screening for the transaction
  • 3D Secure support: Manages cardholder authentication flows when required by the card issuer or regional regulations

Consent & Compliance

Elavon's payment scripts operate in a clear compliance context:

  • GDPR: Payment processing for a customer-initiated purchase falls under "performance of a contract" (Article 6(1)(b)). Elavon/US Bancorp acts as a data processor for transaction data and provides standard DPAs.
  • ePrivacy Directive: Payment session cookies and fraud prevention data collection are strictly necessary for the requested service and exempt from consent requirements.
  • PCI DSS: Elavon maintains PCI DSS Level 1 certification. Hosted payment forms keep card data within Elavon's certified environment, minimizing merchant PCI scope.

Should You Block This Without Consent?

Elavon's scripts are essential to completing purchases on your site. They process payment transactions that customers explicitly initiated by proceeding to checkout. The session cookies maintain transaction state, and the fraud prevention measures protect both parties. Blocking these scripts would prevent customers from paying.

No.

Is Elavon GDPR compliant?

Elavon typically loads functional trackers, which are not strictly necessary for your site to work. Under the GDPR and the ePrivacy Directive, non-essential cookies and trackers must stay blocked until a visitor gives clear opt-in consent. So Elavon can be fully GDPR compliant, but only if your site holds its scripts until consent is granted and lets visitors decline just as easily. Compliance depends on how your site loads Elavon, not on Elavon itself.

Visit website

Consent Categories

Also Known As

elavonelavon paymentselavon hosted formelavon checkoutelavon pcielavon cookies

Industries

Computers Electronics and TechnologyFinanceProgramming and Developer SoftwareBusiness and Consumer Services

Tracked Domains (1)

elavon.comEssential

elavon.com is an essential domain operated by Elavon, used to keep the site working, including security, load balancing, and sessions.

Frequently Asked Questions

Related Vendors

Braintree
Braintree
Online payment processing platform used by marketplaces and platforms to handle complex payment flows. The Braintree SDK (owned by PayPal) tokenizes card and PayPal credentials and handles 3D Secure authentication. Injects an iframe-based payment form to keep card data off the merchant's servers.
Nuvei
Nuvei
Nuvei is a global payment technology platform that embeds hosted payment forms and checkout flows on merchant websites. Scripts handle card and alternative payment processing, 3DS authentication, and transaction routing for online and in-app commerce.
CyberSource
CyberSource
CyberSource scripts embed hosted payment form components within PCI-compliant iframes on checkout pages. Device fingerprinting scripts run fraud screening by collecting browser characteristics and behavioral signals. Transaction data is processed through Visa's payment management infrastructure.
Jscrambler
Jscrambler
Jscrambler scripts protect JavaScript application code running in the browser through obfuscation, tampering detection, and runtime integrity monitoring. Scripts may also detect and block unauthorized third-party script injections and report client-side security events.
Auth0
Auth0
Auth0 is an identity-as-a-service platform providing authentication, authorization, and SSO for web and mobile applications. Scripts handle login flows, token management, and session persistence using Auth0's Universal Login. Integrates with social providers, enterprise IdPs, and MFA to secure application access.
Gumroad
Gumroad
Gumroad scripts embed product checkout overlays and purchase widgets on creator websites. Scripts handle payment processing, digital product delivery, and purchase confirmation; they set cookies to track checkout sessions and verify buyer eligibility for purchased content.

Manage consent for Elavon

ConsentStack automatically detects and manages Elavon trackers so your site stays compliant with global privacy regulations.