Wise

Wise

Wise embeds international money transfer widgets and multi-currency payment flows on partner websites. Scripts load during send-money transactions and may collect payment intent data, exchange rate selections, and user session information.

Overview

Wise (formerly TransferWise) is a regulated international money transfer and multi-currency account platform, authorized as an Electronic Money Institution by the UK Financial Conduct Authority (FCA) and regulated across multiple jurisdictions including the EU (under PSD2 via FCA passporting arrangements), the US (state-by-state money transmitter licenses), and others. On partner websites, financial aggregators, and marketplace platforms, Wise embeds payment widgets that enable users to initiate cross-border transfers, calculate exchange rates, and complete send-money flows without leaving the host site.

What This Script Does

Wise embeds load JavaScript from wise.com and associated CDN domains (cdn.transferwise.com, assets.wise.com) to render interactive payment widgets. The primary embed types are the currency converter calculator widget, the send-money flow widget, and the Wise account sign-up widget.

Cookies Set by Wise Embeds:

  • twp_session — encrypted session cookie, session-scoped, set under wise.com; maintains the user's transaction state (selected currencies, amounts, recipient details) during the payment flow
  • wise_device_id — persistent device identifier, typically 365 days; used for fraud detection and device fingerprinting to flag anomalous payment activity; set under wise.com first-party context
  • WAUTHID — Wise authentication token cookie, persists for the authenticated session; detects whether the user is currently signed in to a Wise account and enables single-click transfer initiation for authenticated users
  • csrf_token — CSRF protection token, session-scoped; included in all POST requests to Wise's API
  • wise_marketing — marketing attribution cookie, 30 days; set only if the user arrived via a tracked affiliate link; captures referrer and affiliate parameters

Network Requests:

  • REST API calls to wise.com/api/v1/rates for real-time exchange rate and fee data
  • Transfer initiation requests to wise.com/api/v1/transfers (POST) after user completes the send-money flow
  • Fraud detection signals sent to Wise's backend including device fingerprint data

Data Collected:

  • Payment intent data: source and target currencies, transfer amount, recipient country
  • Authenticated user identity (if signed in): Wise account ID, verified name, linked bank account metadata
  • Device fingerprint signals for fraud prevention: user-agent, screen resolution, timezone, installed fonts, WebGL renderer (used server-side; not stored in cookies)

Wise operates as a regulated financial institution under the supervision of the UK FCA (reference 900507), FinCEN (US), and multiple EU national competent authorities. Data processing is governed by financial services regulations in addition to GDPR. Wise is GDPR-compliant with a full DPA available. Wise Inc. (US entity) participates in the EU-US Data Privacy Framework.

Consent & Compliance

Wise widgets are categorized as functional technology. Under GDPR and the ePrivacy Directive, cookies that maintain session state during a user-initiated financial transaction are strictly necessary for the requested service and are exempt from consent requirements under Recital 25 of the ePrivacy Directive. The fraud detection device identifier serves a security and anti-fraud purpose, which is also recognized as strictly necessary for financial service providers under regulatory guidance. The marketing attribution cookie (wise_marketing) is an exception — this requires consent if present. Under CCPA/CPRA, transaction data collected through the widget is processed for the purpose of providing a requested financial service and does not constitute a sale or sharing of personal information.

Should You Block This Without Consent?

No. Wise widgets are functional payment tools serving user-initiated financial transactions. Their core cookies maintain transaction state, authentication, and fraud detection — all strictly necessary for the requested financial service. Blocking would prevent users from completing money transfers.

Visit website

Consent Categories

Functional

Also Known As

WiseWise widgetTransferWiseWise payment embedWise cookiesWise money transfer

Industries

Finance

Tracked Domains (2)

wise.comFunctional
transferwise.comFunctional

Frequently Asked Questions

Does embedding a Wise payment widget require user consent?

No consent is required for Wise's core payment widget. Session state, authentication, and fraud detection cookies are strictly necessary for a user-initiated money transfer and are exempt under ePrivacy Directive Recital 25. The marketing attribution cookie requires consent if present.

What cookies does Wise set on my site?

Wise sets twp_session (session, cart state), wise_device_id (365 days, fraud detection), WAUTHID (auth token), and csrf_token. Only wise_marketing — a 30-day affiliate attribution cookie set when users arrive via tracked links — is non-essential and requires consent.

How does ConsentStack handle Wise?

ConsentStack classifies Wise as functional and loads the payment widget without consent by default. If wise_marketing is detected in your implementation, ConsentStack isolates that cookie and gates it behind marketing consent while keeping the core payment flow unblocked.

Related Vendors

Google Maps
Google Maps
Google Maps is the dominant web mapping service used for embedded maps and location features on websites. Scripts load interactive map tiles, geocoding, and Places API functionality through the Maps JavaScript API. May set cookies to remember map preferences and manage API quota.
Google Search
Google Search
Google Search appears on websites through the Programmable Search Engine, enabling custom site-specific search functionality. Scripts load the search widget from Google's servers to render search bars and display results within the host website. Sends search queries to Google's index and may set cookies for search personalization and query history.
Google
Google
Google is the dominant provider of web analytics, advertising, and infrastructure tools. Scripts like Google Analytics, Tag Manager, Ads, and reCAPTCHA collect behavioral data, manage tag firing, serve targeted ads, and detect bots. Sets persistent cookies to track users and correlate activity across sites.
Microsoft Teams
Microsoft Teams
Microsoft Teams is a workplace communication and collaboration platform that can be embedded on websites for chat, meetings, and document sharing. Embedded widgets load from Microsoft's servers to enable real-time messaging, video calls, and file collaboration. Sets authentication and session cookies to verify participant identity and maintain connection state.
Apple Maps JS
Apple Maps JS
Apple Maps JS is Apple's JavaScript mapping framework for embedding interactive maps on websites. Scripts load map tiles, location pins, and routing data from Apple's MapKit servers to render navigable maps within web pages. Requires a MapKit JS token for authentication but does not set tracking cookies or collect behavioral analytics data.
Apple Business Chat
Apple Business Chat
Apple Business Chat enables direct customer messaging between websites and Apple's Messages app. Scripts load chat buttons and conversation interfaces that connect visitors to business support agents through iMessage. Sets minimal session cookies to maintain conversation context but does not track browsing behavior or collect analytics data.

Manage consent for Wise

ConsentStack automatically detects and manages Wise trackers so your site stays compliant with global privacy regulations.