Features Pricing GDPR cookie banner Google Consent Mode v2 WordPress plugin Cookiebot alternative For Agencies GDPR ePrivacy About Contact
RO | EN
Start Free →
Necessary

„m” Cookie (m.stripe.com) by Stripe – What It Does

The „m” cookie is set by Stripe on the m.stripe.com domain and is used to identify the visitor's device and help prevent fraud during payment processing. CookieFix classifies it as strictly necessary, since it directly supports the safe operation of Stripe payment forms.

Name
m
Provider
Stripe
Category
Necessary
Type
HTTP cookie
Lifetime
2 years
Domain / notes
m.stripe.com
Consent
No, but it must be listed in the cookie policy

What is the m cookie?

The „m” cookie is part of Stripe's anti-fraud infrastructure. Stripe is a payment processor used by many online stores and billing platforms. The cookie is set on the m.stripe.com domain, a subdomain dedicated to collecting signals about the visitor's device and browser.

It appears on a site when Stripe Checkout, Stripe Elements, or other Stripe payment components are loaded, even if the visitor doesn't complete a transaction. Essentially, any page that loads Stripe's scripts to display a payment form can trigger this cookie.

What data it stores

The cookie stores an identifier Stripe uses to recognize the device and payment session, contributing to fraud-risk assessment. The exact value format is not publicly documented by Stripe and may vary.

The collected data is sent to Stripe's servers, where it is analyzed alongside other technical signals (browser, behavior, transaction history) to detect suspicious activity. In this role, Stripe acts as a payment service provider/processor for the site that integrates it.

What it is used for

Its main purpose is payment security: the cookie helps Stripe identify potentially fraudulent transactions, reduce chargeback risk, and protect both merchants and buyers.

For the site using Stripe, this cookie is a technical requirement for reliably processing online payments — without it, Stripe's fraud-risk evaluation would be limited, which could affect transaction acceptance or safety.

Does it require consent?

CookieFix classifies „m” as strictly necessary, since it is essential for securely processing payments the visitor has initiated. Under the ePrivacy Directive (2002/58/EC), transposed in Romania via Law 506/2004, and ANSPDCP guidance, cookies strictly necessary to provide a service explicitly requested by the user (here, payment) do not require prior consent.

  • No prior consent is needed when it appears only within a payment flow.
  • The site owner must still disclose it in the cookie policy, including purpose, provider, and duration.
  • If Stripe's scripts load on every page rather than just at checkout, it's worth checking whether the use case still qualifies as strictly necessary.

How to block or delete m

A visitor can delete or block this cookie from their browser settings (Chrome, Firefox, Edge, Safari all offer per-site cookie management), but blocking it may prevent Stripe payments from completing on the affected sites.

For site owners who want centralized control over all cookies — including strictly necessary ones that only need to be disclosed — a platform like CookieFix can automatically scan the site, classify detected cookies, and block scripts from categories that require consent (statistics, marketing, preferences) until the visitor gives approval, while leaving strictly necessary cookies like „m” to function normally.

Frequently asked questions

No, Stripe uses it for fraud prevention during payment processing, not for advertising or commercial tracking.

No, it's classified as strictly necessary when it appears within a payment flow, so no prior consent is required, but it must be listed in the cookie policy.

The Stripe payment form may not work correctly, or the transaction could be declined for security reasons.

The typical reported duration is 2 years from being set, though Stripe may adjust this timeframe.

Updated 7 September 2026 · Information comes from the provider’s public documentation and CookieFix scans; it is not legal advice.