Paidy

Paidy

Paidy scripts embed buy-now-pay-later payment option interfaces on Japanese e-commerce checkout pages. Visitors selecting Paidy as a payment method share purchase amounts, contact details, and billing information with Paidy's payment processing infrastructure to complete installment-based transactions.

Overview

Paidy is Japan's leading buy-now-pay-later (BNPL) payment service, acquired by PayPal in 2021 for approximately $2.7 billion USD. The platform allows Japanese consumers to make online and in-store purchases and pay later — via monthly convenience store payments, bank transfers, or installment plans — without requiring a credit card or pre-registration. Paidy's "3-click checkout" uses just a phone number and email address to complete a purchase, with Paidy handling its own risk assessment in real time.

When Paidy's scripts appear on e-commerce websites, they are embedding a payment option within the checkout flow specifically designed for the Japanese consumer market. The integration is functionally comparable to how Klarna, Afterpay, or PayPal appear as payment methods on Western e-commerce sites.

What This Script Does

Paidy's scripts (widget.paidy.com/paidy.js) embed BNPL payment functionality directly into Japanese e-commerce checkout flows:

Payment option rendering: The script displays Paidy as a selectable payment method during checkout, showing the merchant's accepted Paidy plan types (pay-in-3, pay-in-12, monthly payment) along with estimated monthly installment amounts. This widget loads from Paidy's CDN at widget.paidy.com.

Identity verification and risk assessment: When a customer selects Paidy, the checkout collects the customer's Japanese phone number and email address. Paidy performs a real-time proprietary risk assessment using these identifiers combined with its own behavioral and payment history data to approve or decline the transaction. This assessment happens server-side at Paidy's infrastructure.

Transaction authorization: The script handles the payment authorization handshake between the merchant's checkout, the customer's browser, and Paidy's payment infrastructure. Upon approval, Paidy issues an authorization token that the merchant uses to capture the payment.

Session state management: Cookies are set to maintain checkout session continuity through the multi-step authorization and confirmation flow. These are strictly functional session cookies scoped to the payment interaction.

Merchant SDK events: The Paidy.js library fires JavaScript events (e.g., on_success, on_close, on_error) that the merchant's checkout code listens to in order to advance the order flow upon payment completion.

Consent & Compliance

Paidy's payment scripts operate within a clear legal and compliance framework:

  • APPI (Japan): Japan's Act on the Protection of Personal Information governs Paidy's data handling. As a payment service provider, Paidy has a clear contractual and regulatory basis for collecting and processing the personal information necessary for payment processing and credit assessment. Paidy maintains a published privacy policy in Japanese covering these processing activities.
  • GDPR: While Paidy primarily serves Japan, GDPR applies if EU residents access Japanese e-commerce sites. Payment processing has a clear lawful basis under Article 6(1)(b) — performance of a contract — for the personal data collected during checkout.
  • ePrivacy Directive: Session cookies set during a payment flow are strictly necessary for the payment service the customer has explicitly selected. These are exempt from prior consent requirements under Article 5(3) of the ePrivacy Directive.
  • PCI-DSS: Paidy's payment infrastructure is PCI-DSS compliant. Card data (for Paidy's card-linked features) is handled through tokenization within Paidy's certified environment.

Should You Block This Without Consent?

Paidy's scripts serve a purely functional payment purpose — processing transactions that customers explicitly initiate by selecting Paidy as their payment method at checkout. The data collection is limited to what is strictly necessary for payment processing and real-time credit assessment. Blocking Paidy without consent would prevent customers from completing purchases using this payment method.

No.

Is Paidy GDPR compliant?

Paidy typically loads functional trackers, which are not strictly necessary for your site to work. Under the GDPR and the ePrivacy Directive, non-essential cookies and trackers must stay blocked until a visitor gives clear opt-in consent. So Paidy can be fully GDPR compliant, but only if your site holds its scripts until consent is granted and lets visitors decline just as easily. Compliance depends on how your site loads Paidy, not on Paidy itself.

Visit website

Consent Categories

Also Known As

paidy consentpaidy cookiespaidy bnpl privacybuy now pay later consentpaidy scriptspaidy japan payments

Industries

Finance

Tracked Domains (1)

paidy.comFunctional

paidy.com is a functional domain operated by Paidy, used to run site features like chat, video, embeds, and preferences.

Frequently Asked Questions

Related Vendors

Braintree
Braintree
Online payment processing platform used by marketplaces and platforms to handle complex payment flows. The Braintree SDK (owned by PayPal) tokenizes card and PayPal credentials and handles 3D Secure authentication. Injects an iframe-based payment form to keep card data off the merchant's servers.
Maxio
Maxio
Maxio scripts load hosted billing portal and checkout flow interfaces on websites for SaaS subscription management. Data collected during checkout includes payment details, subscription plan selections, and billing contact information transmitted to Maxio's subscription billing and revenue management platform.
DatoCMS
DatoCMS
DatoCMS delivers structured content to websites via API as a headless CMS. Preview and live editing scripts may load for authenticated content editors in preview environments, enabling real-time content updates. Public visitor tracking is not part of DatoCMS's standard browser-side behavior on production pages.
HireVue
HireVue
HireVue scripts embed video interview recording interfaces on employer career portals, enabling candidates to record video responses to structured assessment questions. Data collected includes video recordings, audio, and response metadata transmitted to HireVue's hiring assessment platform for evaluation and scoring.
Cal.com
Cal.com
Cal.com embeds scheduling and appointment booking interfaces on websites, enabling visitors to book meetings directly. Scripts load calendar availability, handle time zone detection, and transmit booking confirmations. Data shared includes selected times, attendee contact details, and meeting preferences.
Oyster HR
Oyster HR
Oyster HR is a global employment platform for managing international remote hires. The platform operates primarily as a SaaS application for HR teams. Browser-side scripts on public websites are limited to career site embeds that may appear on partner company job posting and recruitment pages.

Manage consent for Paidy

ConsentStack automatically detects and manages Paidy trackers so your site stays compliant with global privacy regulations.