Wise

Wise

Wise embeds international money transfer widgets and multi-currency payment flows on partner websites. Scripts load during send-money transactions and may collect payment intent data, exchange rate selections, and user session information.

Overview

Wise (formerly TransferWise) is a regulated international money transfer and multi-currency account platform, authorized as an Electronic Money Institution by the UK Financial Conduct Authority (FCA) and regulated across multiple jurisdictions including the EU (under PSD2 via FCA passporting arrangements), the US (state-by-state money transmitter licenses), and others. On partner websites, financial aggregators, and marketplace platforms, Wise embeds payment widgets that enable users to initiate cross-border transfers, calculate exchange rates, and complete send-money flows without leaving the host site.

What This Script Does

Wise embeds load JavaScript from wise.com and associated CDN domains (cdn.transferwise.com, assets.wise.com) to render interactive payment widgets. The primary embed types are the currency converter calculator widget, the send-money flow widget, and the Wise account sign-up widget.

Cookies Set by Wise Embeds:

  • twp_session — encrypted session cookie, session-scoped, set under wise.com; maintains the user's transaction state (selected currencies, amounts, recipient details) during the payment flow
  • wise_device_id — persistent device identifier, typically 365 days; used for fraud detection and device fingerprinting to flag anomalous payment activity; set under wise.com first-party context
  • WAUTHID — Wise authentication token cookie, persists for the authenticated session; detects whether the user is currently signed in to a Wise account and enables single-click transfer initiation for authenticated users
  • csrf_token — CSRF protection token, session-scoped; included in all POST requests to Wise's API
  • wise_marketing — marketing attribution cookie, 30 days; set only if the user arrived via a tracked affiliate link; captures referrer and affiliate parameters

Network Requests:

  • REST API calls to wise.com/api/v1/rates for real-time exchange rate and fee data
  • Transfer initiation requests to wise.com/api/v1/transfers (POST) after user completes the send-money flow
  • Fraud detection signals sent to Wise's backend including device fingerprint data

Data Collected:

  • Payment intent data: source and target currencies, transfer amount, recipient country
  • Authenticated user identity (if signed in): Wise account ID, verified name, linked bank account metadata
  • Device fingerprint signals for fraud prevention: user-agent, screen resolution, timezone, installed fonts, WebGL renderer (used server-side; not stored in cookies)

Wise operates as a regulated financial institution under the supervision of the UK FCA (reference 900507), FinCEN (US), and multiple EU national competent authorities. Data processing is governed by financial services regulations in addition to GDPR. Wise is GDPR-compliant with a full DPA available. Wise Inc. (US entity) participates in the EU-US Data Privacy Framework.

Consent & Compliance

Wise widgets are categorized as functional technology. Under GDPR and the ePrivacy Directive, cookies that maintain session state during a user-initiated financial transaction are strictly necessary for the requested service and are exempt from consent requirements under Recital 25 of the ePrivacy Directive. The fraud detection device identifier serves a security and anti-fraud purpose, which is also recognized as strictly necessary for financial service providers under regulatory guidance. The marketing attribution cookie (wise_marketing) is an exception — this requires consent if present. Under CCPA/CPRA, transaction data collected through the widget is processed for the purpose of providing a requested financial service and does not constitute a sale or sharing of personal information.

Should You Block This Without Consent?

No. Wise widgets are functional payment tools serving user-initiated financial transactions. Their core cookies maintain transaction state, authentication, and fraud detection — all strictly necessary for the requested financial service. Blocking would prevent users from completing money transfers.

Is Wise GDPR compliant?

Wise typically loads functional trackers, which are not strictly necessary for your site to work. Under the GDPR and the ePrivacy Directive, non-essential cookies and trackers must stay blocked until a visitor gives clear opt-in consent. So Wise can be fully GDPR compliant, but only if your site holds its scripts until consent is granted and lets visitors decline just as easily. Compliance depends on how your site loads Wise, not on Wise itself.

Visit website

Consent Categories

Also Known As

WiseWise widgetTransferWiseWise payment embedWise cookiesWise money transfer

Industries

Finance

Tracked Domains (2)

wise.comFunctional

wise.com is a functional domain operated by Wise, used to run site features like chat, video, embeds, and preferences.

transferwise.comFunctional

transferwise.com is a functional domain operated by Wise, used to run site features like chat, video, embeds, and preferences.

Frequently Asked Questions

Related Vendors

Affirm
Affirm
Affirm embeds buy-now-pay-later payment options on product and checkout pages. Scripts display monthly installment widgets, initiate financing applications, and integrate with merchant checkout flows to offer consumer lending at point of sale.
Cashfree
Cashfree
Cashfree Payments is an Indian payment gateway for processing online payments and disbursing payouts. Scripts render secure payment forms and handle transaction authentication flows. Cookies maintain checkout session state and support fraud detection during payment processing.
Canvas LMS
Canvas LMS
Canvas LMS embeds course content players, assignment interfaces, and learning modules on institutional websites. Scripts track learner progress, engagement events, and assignment completions to support LMS functionality and reporting.
Zoho SalesIQ
Zoho SalesIQ
Zoho SalesIQ is a live chat and visitor intelligence platform. Scripts embed chat widgets on websites, track visitor navigation paths, and score leads based on behavioral signals such as pages visited and time on site. Cookies identify returning visitors and link chat sessions to visitor profiles.
Udemy
Udemy
Udemy embeds course preview widgets and enrollment flows on partner and affiliate websites. Scripts track engagement with course content and may set cookies to attribute referrals and enrollments back to the originating partner site.
Yelp for Business
Yelp for Business
Yelp for Business provides review and rating widgets for embedding on business websites. Scripts render star ratings, review counts, and review excerpts sourced from Yelp's platform. Scripts may set cookies to track widget impressions and user interactions with the embedded content.

Manage consent for Wise

ConsentStack automatically detects and manages Wise trackers so your site stays compliant with global privacy regulations.