Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Sonline appears to be an e-commerce or webshop platform that lets businesses run an online store, manage products and process customer orders.
Sonline appears to be an e-commerce or webshop platform that businesses use to run an online store, manage a product catalogue and process customer orders. Detailed public information about the provider is limited, so the description below sets out the typical behaviour of e-commerce platforms in this category and should be confirmed against the vendor documentation before you rely on specific facts.
An e-commerce platform like Sonline lets a merchant publish products, take orders, accept payment and manage delivery. To do this it needs to keep a shopping session and basket, identify the customer at checkout and store the order, which means it handles personal data throughout the buying journey and usually connects to payment and shipping partners.
A webshop typically collects the customer name, billing and shipping address, email, phone number, order history and a payment reference, plus technical data such as the IP address and device. It sets first party cookies to keep the basket and session and may load third party analytics, personalisation or marketing tags. Because public detail on Sonline is limited, confirm the exact cookies and fields in your own store rather than assuming specific names.
Cookies that are strictly necessary to keep the basket and let the customer check out can rely on the strictly necessary exemption of the ePrivacy Directive, with contract performance or controller legitimate interest as the GDPR basis. Analytics, personalisation and marketing cookies are not strictly necessary and need prior consent. Customer and order data is personal data and must be processed under a clear lawful basis with a transparent privacy notice and an appropriate retention period.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
The hosting location and subprocessors for Sonline are not publicly confirmed, so a transfer outside the EEA cannot be ruled out. E-commerce platforms often integrate payment, analytics, shipping and marketing providers that may be in the United States or another third country. Where that happens you need a valid transfer mechanism such as the EU US Data Privacy Framework or Standard Contractual Clauses, and you should confirm the real data flows in the data processing agreement.
Sign a data processing agreement, list Sonline and its payment and marketing subprocessors in your records of processing and cookie policy, and configure the store so analytics and marketing cookies only load after consent. Collect only the order data you need, set retention periods that respect tax and consumer law, secure payment data and confirm the hosting location and transfer safeguards with the provider.
Websites using Sonline must obtain user consent under GDPR regulations.
DPIA considerations
As an e-commerce platform Sonline is likely to process customer and order data such as names, billing and shipping addresses, email addresses, phone numbers, order history and payment references, together with technical data like the IP address and device. Public detail on the provider is limited, so confirm the hosting location, the payment, analytics and marketing subprocessors and the retention periods directly with the vendor. A standard webshop usually does not require a full data protection impact assessment, but document a risk assessment and pay attention to large customer databases, any profiling for personalised offers and the payment data flows.
Sample consent text
This shop uses Sonline. Necessary cookies keep your basket and session working so you can browse and check out. Analytics, personalisation and marketing cookies are only set if you accept them. You can change your choice at any time.
Cookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| Sonline shop session cookie | first party | session | Keeps the shopping session active and links the visitor browser to the basket while they browse and check out. Generally treated as strictly necessary. Exact name not publicly confirmed, so verify in your store. |
| Sonline basket or preference cookie | first party | session or persistent | Remembers the basket contents and shop preferences such as language or currency. Usually strictly necessary for the shop to function. Verify the exact name in your deployment. |
| Analytics or marketing cookie | first party or third party | persistent | May be set by analytics, personalisation or marketing integrations added to the shop. Not strictly necessary and requires prior consent. Presence and names depend on the integrations enabled. |
Sonline uses cookies for user preferences — inform visitors with a consent banner.
An e-commerce platform like Sonline typically sets first party cookies to keep the shopping session and remember the basket and preferences such as language or currency, which are usually strictly necessary. It may also load analytics, personalisation or marketing cookies, which are not necessary. Public detail is limited, so confirm the exact cookies in your own store.
The strictly necessary shop and basket cookies can run without consent because they are needed to deliver the service the customer is using, but you must still inform people. Any analytics, personalisation or marketing cookie needs prior consent through your cookie banner before it loads. Order data is processed to fulfil the purchase the customer requests.
Processing orders and keeping the basket usually rests on performance of a contract under Article 6(1)(b) of the GDPR, with controller legitimate interest for related operational needs and legal obligation for tax and accounting records. The necessary cookies fall under the strictly necessary exemption of the ePrivacy Directive, while analytics and marketing cookies require consent under Article 6(1)(a).
This is not publicly confirmed. The hosting location and subprocessors for Sonline are not clearly documented, so a transfer outside the EEA cannot be ruled out. E-commerce platforms often use payment, analytics, shipping and marketing providers in the United States or elsewhere, so check the data processing agreement and rely on the EU US Data Privacy Framework or Standard Contractual Clauses where a subprocessor is in a third country.
A standard webshop usually does not require a full data protection impact assessment, but a documented risk assessment is sensible. Consider the size of the customer database, whether you profile customers for personalised offers or recommendations, and how payment data flows, since these factors can raise the risk and may trigger an assessment.
Sign a data processing agreement, list Sonline and its payment and marketing subprocessors in your records of processing and cookie policy, and set the shop so analytics and marketing cookies only load after consent. Collect only the order data you need, apply retention periods that respect tax and consumer law, secure payment data and confirm the hosting location and transfer safeguards with the provider.
Other e-commerce and webshop platforms include Shopify, WooCommerce, PrestaShop, Magento, BigCommerce and Wix. Several can be hosted in the EU, and open source options give you more control over data location. They raise similar privacy considerations around customer data, cookies and subprocessors, so compare hosting region, data processing terms and transfer safeguards before choosing.
List the strictly necessary shop and basket cookies separately from any optional analytics, personalisation or marketing cookies in your cookie and privacy policy, and explain that customer and order data is processed to fulfil purchases. Name Sonline and its payment subprocessors as recipients, state retention periods and the hosting location once confirmed, and keep the policy and your consent settings consistent.