Overview
Podia is an all-in-one platform for selling digital products, online courses, memberships, and webinar access. Creators host their entire storefront on Podia's own infrastructure (mypodiasite.com subdomains or custom domains), but Podia also provides embeddable widgets that allow course enrollment and checkout to be initiated from a third-party website. This embedded checkout flow is where Podia scripts appear in the third-party context.
What This Script Does
When a creator embeds a Podia buy button or enrollment widget on an external site, Podia's JavaScript loads from Podia's CDN and renders an inline button or modal checkout interface.
Cookies and session management: Podia sets session cookies to maintain authentication state for logged-in students who may already have a Podia account. These cookies enable the embedded widget to recognize returning purchasers and pre-fill checkout information. A separate cookie tracks whether a visitor has previously viewed or interacted with the embedded widget.
Data collected: On widget load, Podia may collect page URL and referrer to attribute purchases to the correct creator storefront. If a visitor begins checkout, billing and contact information is transmitted directly to Podia's servers.
Network requests: Widget assets and checkout logic are served from podia.com. Payment processing is handled server-side by Podia's Stripe integration; the Stripe.js library may also load to handle card input tokenization.
Consent & Compliance
GDPR and ePrivacy Directive: The session authentication cookie set by Podia is functional — it is required for the checkout and enrollment flow to operate correctly for returning users. The referral attribution cookie that records the originating page is less clearly necessary and may require consent. Operators should audit which specific cookies Podia sets and categorize them accordingly.
CCPA/CPRA: Transaction data submitted through Podia's embedded checkout is processed by Podia as a service provider. This does not constitute a sale of personal information under CPRA, provided Podia's Data Processing Agreement limits use to fulfilling the transaction.
Consent category: functional. Podia's primary purpose is enabling a transactional function — course enrollment and product purchase — rather than behavioral tracking.
Should You Block This Without Consent?
No.
Podia's embedded widgets are functional components enabling purchase and enrollment flows. Blocking them would prevent visitors from buying courses or digital products. The functional consent category covers this use case. Ensure the specific cookies set are accurately described in your site's cookie policy.
Is Podia GDPR compliant?
Podia typically loads functional trackers, which are not strictly necessary for your site to work. Under the GDPR and the ePrivacy Directive, non-essential cookies and trackers must stay blocked until a visitor gives clear opt-in consent. So Podia can be fully GDPR compliant, but only if your site holds its scripts until consent is granted and lets visitors decline just as easily. Compliance depends on how your site loads Podia, not on Podia itself.
Consent Categories
Also Known As
Industries
Tracked Domains (1)
podia.comFunctionalpodia.com is a functional domain operated by Podia, used to run site features like chat, video, embeds, and preferences.
Frequently Asked Questions
Related Vendors
Manage consent for Podia
ConsentStack automatically detects and manages Podia trackers so your site stays compliant with global privacy regulations.