Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Hummerce is a mature B2B and B2C ecommerce platform from the Polish agency Best.net that sets functional cart and session cookies and lets merchants add analytics and marketing tags.
Hummerce is a mature ecommerce platform developed by the Polish agency Best.net in Poznan and refined over more than twenty years. It powers both B2B and B2C online stores, supports networks of shops under a single brand and integrates with external systems through a two way API. Like any online storefront, a Hummerce shop relies on functional cookies to keep a shopping basket and a session working, and merchants commonly extend it with analytics and marketing tags.
Hummerce is a commercial ecommerce platform aimed at established businesses that want to run or scale their online sales. It offers rich product presentation, advanced search, configurable category pages and dedicated B2B features such as individual price lists, complex offers and order workflows. Because it is a complete storefront solution rather than a single tracking script, its privacy impact comes mostly from the cookies it sets to operate the store and from any third party tools a merchant chooses to add.
To work correctly, a Hummerce store sets functional cookies that identify the visitor session and remember the contents of the shopping cart between page views. These cookies are strictly necessary to deliver the service the customer has requested. Beyond that baseline, individual merchants frequently add optional analytics cookies to measure traffic and marketing or advertising pixels to support remarketing campaigns. The personal data handled therefore ranges from a simple session identifier up to behavioural and device data when extra tools are enabled.
Under the GDPR and the ePrivacy Directive, the strictly necessary cart and session cookies can rely on contract or legitimate interest and do not require prior consent, although they must still be disclosed. Any analytics or marketing cookies that are not essential to the store fall under the consent rule of the ePrivacy Directive and must be switched off until the visitor agrees. The merchant operating the Hummerce store is the data controller and is responsible for the lawful basis, transparency and the cookie banner.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
A compliant Hummerce store should load only the functional cookies by default and present a consent banner before placing any analytics or marketing cookies. Consent must be freely given, specific, informed and as easy to refuse as to accept, and the visitor must be able to withdraw it at any time. Keeping a clear record of the choices made allows the merchant to demonstrate accountability if a supervisory authority asks.
The Hummerce platform itself can be hosted within Poland and the wider European Economic Area through Best.net, which keeps core store data inside the EU. Transfers to third countries usually arise from the extra services a merchant connects, such as analytics suites, advertising networks or payment processors based in the United States. Where such transfers occur, the operator must rely on a valid transfer mechanism, for example the EU US Data Privacy Framework or standard contractual clauses, and inform visitors accordingly.
Start by auditing every cookie and tag active on your Hummerce store and classifying each as strictly necessary or optional. Deploy a consent management banner that blocks optional analytics and marketing cookies until the shopper agrees, and mirror those categories in a clear cookie policy and privacy notice. Document the providers you use, the data they receive and any transfers outside the European Economic Area, and review the setup whenever you add a new integration.
Websites using Hummerce must obtain user consent under GDPR regulations.
DPIA considerations
A standalone Hummerce storefront that relies only on functional cart and session cookies usually presents a low data protection risk and rarely requires a full DPIA. The risk profile rises to medium once a merchant adds third party analytics, advertising pixels or extensive customer profiling, which can warrant a DPIA. Operators should document the cookies in use, the providers involved and any transfers outside the European Economic Area.
Sample consent text
We use functional cookies to run your shopping cart and, with your consent, analytics and marketing cookies to measure traffic and personalise offers.
Third-party domains contacted
hummerce.combest.net.plgoogle-analytics.comgoogletagmanager.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| cart | Functional | Session to 14 days | Stores the contents of the shopping cart so that selected products persist as the visitor browses the store. |
| session | Functional | Session | Maintains the visitor session and login state so that the store works correctly across page views. |
| csrf_token | Functional | Session | Protects forms and checkout against cross site request forgery to keep transactions secure. |
| cookie_consent | Functional | 12 months | Remembers the cookie preferences chosen by the visitor in the consent banner. |
Hummerce uses cookies for user preferences — inform visitors with a consent banner.
A Hummerce store sets functional cookies that maintain the visitor session and remember the shopping cart contents between pages. These are strictly necessary to run the shop. Individual merchants often add optional analytics cookies and marketing or advertising pixels on top of this baseline.
No prior consent is needed for the strictly necessary cart and session cookies, although they must still be disclosed in your cookie policy. Consent is required before any optional analytics or marketing cookies are placed, and these must stay switched off until the visitor agrees.
The functional cart and session cookies and the related order processing rely on contract or legitimate interest under Art. 6(1)(b) and 6(1)(f) GDPR. Any analytics and marketing cookies that are not essential require consent under Art. 6(1)(a) GDPR together with the ePrivacy Directive.
The Hummerce platform itself can be hosted in Poland and the wider European Economic Area through Best.net. Transfers to the United States usually arise only from third party tools a merchant adds, such as analytics, advertising or payment providers, and then require a valid transfer mechanism like the EU US Data Privacy Framework or standard contractual clauses.
A store that uses only functional cart and session cookies usually presents a low risk and rarely needs a full DPIA. A DPIA becomes advisable once you add extensive analytics, advertising pixels or large scale customer profiling, which raise the data protection risk to medium.
Load only functional cookies by default and place optional analytics and marketing cookies behind a consent banner that blocks them until the shopper agrees. Maintain a clear cookie policy and privacy notice, record consent choices and document every provider and data transfer involved.
Yes, other ecommerce platforms such as WooCommerce, Shopware, PrestaShop, Magento and Shopify cover similar B2B and B2C needs. The cookie and consent considerations are broadly the same for any storefront, since functional cookies are necessary and added analytics or marketing tags require consent.
Audit the cookies and tags active on your Hummerce store, classify each as strictly necessary or optional, and list them with their purpose and duration in your cookie policy. Update the policy whenever you add or remove an integration and keep it aligned with the categories shown in your consent banner.