Stripe

Stripe

Payment processing infrastructure used by online businesses globally. The Stripe.js script loads securely to handle card tokenization, 3D Secure authentication, and payment element rendering. Stripe also runs fraud detection heuristics in the browser to assess transaction risk.

Overview

Stripe is the leading payment processing infrastructure provider for online businesses. Stripe.js handles secure card tokenization, renders payment input elements in isolated iframes, manages 3D Secure and Strong Customer Authentication flows, and runs fraud detection heuristics to assess transaction risk — all in the browser on the merchant's checkout page.

What This Script Does

Script Loading Stripe.js must be loaded from js.stripe.com/v3/ (Stripe's canonical URL) to qualify for PCI-DSS compliance. Loading Stripe from a local copy or any other domain breaks PCI compliance. The script file itself is stripe.js (or stripe.esm.js for ES module imports).

Stripe Elements (Hosted Input Fields) Stripe Elements renders secure card input fields as iframes hosted on Stripe's domain (js.stripe.com). This means raw card numbers, expiry dates, and CVV codes are entered directly into Stripe-controlled iframes and never touch the merchant's JavaScript execution environment or servers. The merchant's page communicates with the Stripe iframe via postMessage.

Elements rendered:

  • Card Number, Expiry, and CVV fields (separate or combined CardElement)
  • PaymentElement — a smart form that shows the appropriate payment methods for the customer's location (cards, SEPA Direct Debit, iDEAL, BLIK, etc.)
  • AddressElement — address collection with postal validation
  • PaymentRequestButton — Apple Pay and Google Pay button

Payment Processing Flow

  1. Customer enters card details in the hosted iframe
  2. Stripe.js calls stripe.createToken() or stripe.createPaymentMethod() — card data is sent directly to Stripe's servers at api.stripe.com
  3. Stripe returns a one-time use token or Payment Method ID
  4. The merchant's JavaScript submits this token/ID to the merchant's server
  5. The merchant's server charges the card via the Stripe API server-to-server

3D Secure and SCA For payments requiring 3D Secure authentication, Stripe.js opens an iframe or popup to the card's issuer bank authentication page. The SDK manages the redirect flow and confirmation via stripe.handleCardAction() or stripe.confirmPayment(). Domains involved include hooks.stripe.com and issuer bank authentication URLs.

Fraud Detection Stripe.js collects browser signals to power Stripe Radar fraud detection:

  • Browser fingerprint: User-Agent, screen dimensions, timezone, language, installed plugins
  • Behavioral signals: mouse movement entropy, keystroke timing on payment fields
  • Device signals: touch capability, hardware concurrency, memory class
  • Network signals: IP address and connection type (collected server-side) These signals are sent to q.stripe.com for risk scoring. Stripe Radar uses this data to assign a fraud risk score to each payment attempt.

Cookies set (on stripe.com domain):

  • __stripe_mid (first-party on stripe.com, 1 year) — machine identifier for fraud detection
  • __stripe_sid (first-party on stripe.com, 30 minutes) — session identifier for fraud detection

These cookies are set under stripe.com, not the merchant domain. On the merchant domain, Stripe.js does not set cookies — it uses the iframe isolation boundary.

Domains contacted: js.stripe.com, api.stripe.com, q.stripe.com, hooks.stripe.com, r.stripe.com (error reporting)

Consent & Compliance

GDPR/ePrivacy: Stripe.js is necessary for processing payments, covered by contractual necessity under GDPR Article 6(1)(b). Fraud detection processing is justified under legitimate interest (Article 6(1)(f)) — Stripe and the merchant both have a legitimate interest in preventing fraudulent transactions. Cookies set under stripe.com during a payment flow initiated by the user fall under the ePrivacy strictly necessary exemption for cookies needed to complete a user-requested transaction. Stripe acts as a data processor for the merchant and as an independent controller for fraud and risk data.

CCPA/CPRA: Payment data processing for transaction completion and fraud prevention is a necessary business operation exempt from opt-out requirements under CCPA.

EU-US Data Transfers: Stripe Inc. participates in the EU-US Data Privacy Framework (DPF) and offers Standard Contractual Clauses for EU payment data processing by Stripe's US entity.

PCI-DSS: Stripe.js's iframe architecture is designed to limit the merchant's PCI-DSS scope to SAQ A, the lowest level, as raw card data never enters the merchant's environment.

Consent category: Essential (payment processing) and Functional (saved payment methods, address collection).

Should You Block This Without Consent?

No. Stripe.js provides essential payment processing infrastructure. Blocking it prevents customers from completing purchases and renders the checkout page non-functional. The fraud detection data collection is a necessary security measure for payment processing under both GDPR legitimate interest and CCPA business necessity. Disclose Stripe as a payment processor in the site's privacy policy.

Is Stripe GDPR compliant?

Stripe typically loads functional trackers, which are not strictly necessary for your site to work. Under the GDPR and the ePrivacy Directive, non-essential cookies and trackers must stay blocked until a visitor gives clear opt-in consent. So Stripe can be fully GDPR compliant, but only if your site holds its scripts until consent is granted and lets visitors decline just as easily. Compliance depends on how your site loads Stripe, not on Stripe itself.

Visit website

Products (5)

Stripe Billing
Stripe Billing
Stripe Billing is Stripe's subscription and recurring revenue management module. Scripts embedded in checkout and account pages handle subscription lifecycle events, billing cycles, proration calculations, and payment retry logic. Stores session data and payment method tokens to support subscription management flows.
Stripe Connect
Stripe Connect
Stripe Connect is Stripe's platform payments product enabling marketplaces and SaaS platforms to process payments on behalf of third-party sellers. Scripts manage connected account onboarding flows, payment routing, and split payment configurations. OAuth tokens and account identifiers are stored to facilitate multi-party transactions.
Stripe Identity
Stripe Identity
Stripe Identity is a document-based identity verification service. Scripts load a verification flow that captures government-issued ID images and selfie photos via device camera, transmitting them to Stripe for automated document analysis and liveness detection. Collected biometric data and document details are processed to verify user identity.
Stripe Radar
Stripe Radar
Stripe Radar is Stripe's machine learning-based fraud detection system. Scripts collect browser signals including device fingerprints, behavioral patterns, and network metadata during payment flows to assess transaction risk. This data is used to score transactions and trigger 3D Secure challenges for suspicious activity.
Stripe Tax
Stripe Tax
Stripe Tax is an automated tax calculation and collection module integrated into Stripe checkout flows. Scripts calculate applicable sales tax, VAT, or GST in real time based on customer location and product type during payment. Tax calculations and jurisdiction data are transmitted to Stripe's servers for compliance reporting.

Consent Categories

Also Known As

Stripe.jsStripe paymentsStripe fraud detectionpayment processingStripe ElementsStripe checkoutcard tokenization

Industries

Computers Electronics and TechnologyProgramming and Developer Software

Tracked Domains (2)

Stripe's trackers are occasionally seen, seen on about 1% of the sites ConsentStack has scanned. Scan your own site to see which of these are firing before consent.

stripe.comFunctional

stripe.com is a functional domain operated by Stripe, used to run site features like chat, video, embeds, and preferences. Seen on about 1% of scanned sites.

stripe.networkFunctional

stripe.network is a functional domain operated by Stripe, used to run site features like chat, video, embeds, and preferences. Seen on under 1% of scanned sites.

Cookies Stripe Sets (3)

__stripe_mid

Stripe merchant ID cookie used by Radar fraud detection. One-year expiration; required for risk scoring on the customer apex.

__stripe_sid

Stripe session cookie used by Radar fraud detection during a checkout session. 30-minute expiration.

__stripe_orig_props

Stripe.js original-page-load properties for fraud detection. Captures the initial referrer and entry context so Stripe Radar can correlate the checkout to the legitimate user journey. Companion to __stripe_mid and __stripe_sid.

Frequently Asked Questions

Related Vendors

Valassis Digital
Valassis Digital
B2B marketing intelligence and audience activation platform. Valassis Digital scripts fire on advertiser sites to track conversions and enable audience extension campaigns that combine digital and offline data for consumer targeting.
Vimeo
Vimeo
Online video platform used to host and embed professional video content without advertising. The Vimeo player loads an interactive embed and sends play, pause, and completion events to Vimeo's analytics. Unlike YouTube, Vimeo's standard embed does not use cookies for behavioral advertising on third-party sites.
TrustArc
TrustArc
Privacy and consent management platform (CMP) that serves cookie consent banners and manages consent records. TrustArc scripts control script loading based on user consent decisions and maintain an audit log for regulatory compliance.
Usercentrics
Usercentrics
Privacy and consent management platform (CMP) used to serve cookie consent banners and record user consent decisions. Usercentrics scripts control which vendor scripts load based on user consent selections, enabling GDPR and ePrivacy compliance.
Akamai
Akamai
Enterprise CDN and security platform used by large companies to distribute assets globally and protect against DDoS and bot attacks. The mPulse script measures real-user performance (page load, resource timing) and sends metrics to Akamai's telemetry platform. Bot Manager may inject browser fingerprinting scripts to classify traffic.
Sourcepoint
Sourcepoint
Sourcepoint is a privacy and consent management platform for publishers and advertisers. Scripts deliver GDPR and CCPA-compliant consent notices, record consent decisions, and enforce script blocking based on user preferences.

Manage consent for Stripe

ConsentStack automatically detects and manages Stripe trackers so your site stays compliant with global privacy regulations.