FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. E-commerce
  4. commercetools

commercetools

PreferencesWebsite

Related services

24nettbutikk

24nettbutikk is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. 24nettbutikk supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, 24nettbutikk ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Preferences

2ClickShop

2ClickShop is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 2ClickShop integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 2ClickShop helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences

4-Tell

4-Tell is a marketing platform that equips businesses with tools to amplify their digital presence and drive customer acquisition. It supports audience segmentation, campaign automation, and cross-channel engagement. 4-Tell provides real-time analytics and reporting dashboards for performance measurement and strategy optimization. By combining data intelligence with marketing execution, 4-Tell helps deliver the right message to the right audience at the right time.

Preferences

42stores

42stores is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 42stores integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 42stores helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences

4Partners

4Partners is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 4Partners integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 4Partners helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences
4

4Partners CMS

4Partners CMS is a powerful content management system (CMS) designed to help businesses and developers build, manage, and publish digital content with ease. It offers a flexible architecture that supports custom content types, templates, and workflows, making it ideal for websites of any scale. With 4Partners CMS, teams can streamline content creation, improve collaboration, and deliver engaging web experiences. Its extensible plugin ecosystem and API-first approach ensure seamless integration with.

Preferences
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does commercetools do?

commercetools is a German headless and composable commerce platform built on Google Cloud Platform, with EU regions and a strong fit for European retailers, B2B players and marketplaces.

What commercetools is

commercetools is a German headless and composable commerce platform operated by commercetools GmbH in Munich. It exposes a REST and GraphQL API for product, cart, order and customer management, and runs on Google Cloud Platform with regions in Frankfurt and Belgium. It is widely used by European retailers, B2B brands and marketplaces.

Data and cookies set

As a headless backend, commercetools does not set browser cookies by itself. The storefront built on top (Next.js, Nuxt, Hybris frontend) sets session and cart cookies. Marketing, recommendation and personalisation features add consent based cookies, depending on the integration.

GDPR and ePrivacy implications

Order, customer and cart data are processed under Article 6(1)(b) GDPR. Personalisation, behavioural recommendations and marketing analytics require consent under Article 6(1)(a) GDPR and Article 5(3) ePrivacy.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Consent requirements

You do not need consent for the headless commerce APIs that support order processing, but every script attached to the storefront for analytics, advertising or personalisation must be loaded only after a valid consent recorded through a CMP.

Data transfers outside the EEA

commercetools provides EU regions on GCP. The vendor signs a GDPR aligned data processing agreement with SCCs for any global support function. Watch sub processors and Google Cloud disclosures, and run a transfer impact assessment if global support is engaged for production.

Practical compliance steps

Pin projects to an EU region, restrict API tokens with scoped roles, separate order data from marketing analytics, integrate a CMP on the storefront, document GCP sub processors and run a DPIA for personalisation modules.

GDPR consent category

Preferences

Websites using commercetools must obtain user consent under GDPR regulations.

Legal basisPerformance of a contract (Article 6(1)(b) GDPR) for order processing, consent (Article 6(1)(a) GDPR and Article 5(3) ePrivacy) for marketing and personalisation features added on top
Risk levellow
Applicable regulationsGDPR, ePrivacy Directive 2002/58/EC, German TDDDG, French CNIL guidelines, Spanish LSSI, PCI DSS

DPIA considerations

A DPIA is generally limited for commercetools itself because hosting stays in the EU. It can be triggered by personalisation, recommendation or marketing modules and by integrations with third party CRMs, especially when they involve US processors.

Sample consent text

Our commerce backend is powered by commercetools, operated by commercetools GmbH (Germany), and hosted on Google Cloud Platform in the European Union. Marketing and personalisation features are activated only with your prior consent.

Technical details

Tracking methodapi_integration
Server locationEuropean Union (Google Cloud Platform, Frankfurt or Belgium)
Cookieless tracking availableYes

Third-party domains contacted

api.europe-west1.gcp.commercetools.comauth.europe-west1.gcp.commercetools.commc.europe-west1.gcp.commercetools.com

Cookies placed

NameTypeDurationPurpose
ctsessfirst_partySessionMaintains the API session between the storefront and the commercetools backend (strictly necessary).
ct-anonymous-cartfirst_party30 daysStores the anonymous cart identifier for guest checkout (strictly necessary).

commercetools uses cookies for user preferences — inform visitors with a consent banner.

Get started freeScan your site

Frequently asked questions

Which cookies does commercetools set?

commercetools is headless and does not set browser cookies itself. The storefront on top sets session and cart cookies which are strictly necessary, while integrations such as analytics or recommendations may add consent based cookies.

Do I need consent?

Not for order processing, which relies on Article 6(1)(b) GDPR. Yes for marketing, recommendation and analytics features that store or read information on the device.

What is the legal basis?

Contract performance for order data. Consent for marketing cookies, behavioural recommendations and analytics.

Are any data transferred to the United States?

In EU configuration no. The platform runs on GCP Frankfurt or Belgium. Global support engagements should be analysed for any US access.

Is a DPIA needed?

Generally limited for the core platform. Run a DPIA for personalisation, recommendation, marketing automation and any integration with US sub processors.

How do I implement compliance correctly?

Pin projects to an EU region, scope API tokens, integrate a CMP on the storefront, gate analytics and personalisation behind consent, and document sub processors.

What are the alternatives?

Spryker, SAP Commerce Cloud, Salesforce Commerce Cloud, Adobe Commerce (Magento), Shopify Plus and BigCommerce. EU based options reduce transfer complexity.

How do I update the cookie policy?

Inventory cookies from the storefront and every integration, separate strictly necessary from consent based, version the policy in your CMS and update it on every release.