Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
How Freshop handles cookies and personal data, and what European websites must do to use it in a GDPR and ePrivacy compliant way.
Freshop is a hosted ecommerce platform. It is a grocery ecommerce platform, now part of NCR Voyix, that lets independent grocers offer online ordering and pickup. When it runs on a website it operates as a third party processor whose scripts, cookies and network requests are loaded into the browsers of your European visitors.
In a typical deployment Freshop processes shopping basket contents, order and customer data, device identifiers and analytics on how visitors browse the store. Most of this information qualifies as personal data under the GDPR because it can be linked to an identifiable person, directly or through online identifiers stored on the device.
Any storage of or access to information on a visitor device is governed by Article 5(3) of the ePrivacy Directive, transposed into national law across the EU. The GDPR then governs the subsequent processing, so Freshop must have a valid legal basis, a clear retention period and transparent information for the data subject.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Because Freshop sets cookies or identifiers that are not strictly necessary to deliver a service the visitor explicitly requested, prior, freely given, specific and informed consent is required before it loads. Scripts must stay blocked until the visitor accepts, and refusal must be as easy as acceptance.
Freshop is operated by NCR Voyix in the United States, so personal data is processed on servers in a third country without an adequacy decision. Transfers of personal data outside the European Economic Area need an appropriate safeguard such as an adequacy decision or Standard Contractual Clauses, together with a transfer impact assessment where required.
List Freshop in your records of processing and your cookie policy, load it only through a consent management platform, document the consent you collect and review the vendor data processing agreement at least once a year. Test the site with consent refused to make sure no identifier is set before a choice is made.
Websites using Freshop must obtain user consent under GDPR regulations.
DPIA considerations
Assess the volume and sensitivity of data processed through Freshop, whether visitors are profiled or tracked across sites, and any transfer outside the EEA. A formal DPIA is advisable where Freshop enables large scale monitoring or combines data from several sources.
Sample consent text
We use Freshop to power parts of this site. It may store cookies and identifiers on your device and process related data. With your consent we activate Freshop. You can withdraw your consent at any time from the cookie settings.
Third-party domains contacted
freshop.comfreshop.ncrcloud.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| freshop_session | necessary | Session | Maintains the shopper session |
| cart_id | necessary | 30 days | Stores the online grocery cart |
| _ga | analytics | 2 years | Google Analytics visitor measurement |
| _fbp | marketing | 3 months | Meta advertising and remarketing |
Freshop uses cookies for user preferences — inform visitors with a consent banner.
Freshop typically stores session identifiers and, depending on configuration, analytics or marketing cookies. The exact names and lifetimes appear in the cookie table on this page, and you should scan your own site because deployments differ.
Yes. Freshop sets cookies or identifiers that are not strictly necessary, so under Article 5(3) ePrivacy you must obtain prior consent before it loads.
The non essential cookies rely on consent under Article 6(1)(a) GDPR combined with Article 5(3) ePrivacy. Strictly necessary processing can rely on contract under Article 6(1)(b) or legitimate interest under Article 6(1)(f).
Freshop is operated by NCR Voyix in the United States, so personal data is processed on servers in a third country without an adequacy decision. Any such transfer needs Standard Contractual Clauses or an adequacy decision and a transfer impact assessment.
A DPIA is required when processing is likely to result in a high risk, for example large scale tracking or profiling. Where Freshop monitors behaviour at scale or combines data sources, run a DPIA before going live.
Load Freshop only after consent through a consent management platform, keep it blocked by default, document each consent, list it in your records and cookie policy, and sign a data processing agreement with the vendor.
Yes. Depending on your goal you can choose privacy first or cookieless tools, or self hosted options that keep data in the EEA. Whichever you pick, the same consent and transparency duties apply.
Add Freshop to the cookie policy with its purpose, the cookies it sets, their duration and the recipient, note any third country transfer and the safeguard used, and refresh the entry whenever you change configuration or after a new cookie scan.