Overview
Razorpay is India's leading payment gateway, processing transactions for over 8 million businesses. It supports a wide range of payment methods specific to the Indian market including UPI, netbanking across 50+ banks, credit and debit cards, and digital wallets like Paytm and PhonePe. On e-commerce and SaaS websites, Razorpay's checkout scripts handle the entire payment flow — from displaying the payment modal to tokenizing card data and processing the transaction. As a payment processor handling financial transactions, Razorpay's scripts are classified as essential.
What This Script Does
Razorpay's checkout is loaded via the checkout.razorpay.com script, which renders either a standard checkout modal or a custom payment form on the merchant's page.
Payment flow:
- Renders the Razorpay checkout modal with configured payment method options
- Handles PCI-DSS compliant card tokenization (card data never touches the merchant's servers)
- Processes UPI intent flows and QR code generation for UPI payments
- Manages netbanking redirects and wallet payment flows
- Handles 3D Secure authentication when required by the issuing bank
Cookies set:
rzp_checkout_session— session cookie maintaining checkout state during the payment flow- Fraud detection cookies that fingerprint the device and browser for risk scoring
- Session cookies scoped to
razorpay.comdomain for maintaining authentication state during bank redirects - No persistent marketing or analytics cookies are set
Data collected:
- Payment instrument details (tokenized, PCI-DSS compliant)
- Device fingerprint and browser attributes for fraud prevention
- IP address for geographic risk assessment
- Transaction metadata (amount, currency, order ID)
All data processing is governed by PCI-DSS Level 1 compliance requirements and RBI (Reserve Bank of India) payment processing regulations.
Consent & Compliance
Razorpay falls under the essential consent category. Under GDPR and the ePrivacy Directive, cookies that are strictly necessary for a service explicitly requested by the user — in this case, completing a payment — are exempt from consent requirements. The fraud detection cookies are also considered essential for the security of the transaction.
Under CCPA/CPRA, payment processing data is covered by the financial data exemption and is necessary to fulfill the consumer's transaction request. Razorpay should be disclosed as a payment processor in the privacy policy.
Razorpay operates under RBI regulations for payment data storage and processing, including the data localization mandate requiring payment data to be stored within India.
Should You Block This Without Consent?
No. Razorpay processes payments — a service explicitly requested by the user. Blocking the checkout script would prevent customers from completing purchases. The cookies set are essential for transaction security and fraud prevention. Payment processing scripts are universally recognized as strictly necessary under GDPR, ePrivacy, and CCPA frameworks.
Is Razorpay GDPR compliant?
Razorpay's trackers are classified as essential (strictly necessary), so they are generally exempt from prior consent under the GDPR. You should still list them in your cookie policy and privacy notice so visitors know they are there.
Consent Categories
Also Known As
Industries
Tracked Domains (1)
razorpay.comEssentialrazorpay.com is an essential domain operated by Razorpay, used to keep the site working, including security, load balancing, and sessions.
Frequently Asked Questions
Related Vendors
Manage consent for Razorpay
ConsentStack automatically detects and manages Razorpay trackers so your site stays compliant with global privacy regulations.