Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
InSales is a hosted e-commerce SaaS platform popular in Russia and the CIS that lets businesses build online stores and sync sales across marketplaces. When used for a storefront it sets first party session and cart cookies and offers built in analytics. Because it is hosted in the Russian Federation, data location and third country transfer questions are central for European operators.
InSales is a hosted software as a service e-commerce platform widely used in Russia and the CIS region. It lets merchants build and run online stores, manage inventory and customer relationships and synchronise sales across large marketplaces. As a SaaS product the store front end, the customer data and the order processing run on infrastructure operated by the vendor.
In a standard deployment the storefront sets first party cookies to hold the session, remember the cart and keep account holders signed in. The platform processes customer contact details, delivery and billing addresses and order history, and its built in analytics may set additional measurement cookies. Marketing integrations can introduce further non essential cookies.
If a European business uses InSales to serve EEA visitors, the GDPR applies and the merchant is the controller. Strictly necessary cookies do not need consent under Article 5(3) of the ePrivacy Directive, but analytics and marketing cookies do. The most significant issue is data location, since the platform is hosted in the Russian Federation rather than the EEA.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Operating the store and fulfilling orders rests on the performance of a contract and needs no consent. Prior, informed and freely given consent must be collected before any analytics or marketing cookies load, and visitors must be able to withdraw it as easily as they gave it. A consent banner should block non essential tracking until the user agrees.
Because hosting is in the Russian Federation, a country without a European Commission adequacy decision, using InSales for EEA customers means transferring personal data to a third country. This requires Standard Contractual Clauses, a documented transfer impact assessment and supplementary measures, with particular attention to the risk of government access and the practical enforceability of data subject rights.
Confirm where data is stored, sign a data processing agreement and Standard Contractual Clauses, complete a transfer impact assessment, classify and gate cookies through a consent platform and document everything in your records of processing. Given the elevated transfer risk, weigh whether an EEA hosted alternative is more appropriate for European customers.
Websites using InSales must obtain user consent under GDPR regulations.
DPIA considerations
A DPIA is strongly recommended because hosting in the Russian Federation is a transfer to a third country with no adequacy decision and a heightened risk profile. Assess the data categories processed, the transfer mechanism and its effectiveness, the risk of government access and whether an EEA hosted alternative would better protect data subjects.
Sample consent text
We use essential cookies to run our online store and process your orders. With your consent we also use analytics and marketing cookies. Please note that our store platform is hosted outside the European Economic Area. You can accept, reject or manage cookies at any time.
Third-party domains contacted
insales.rustatic.insales.ruCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| insales_session | Strictly necessary | Session | Maintains the storefront session and keeps the visitor signed in to their account |
| cart_id | Strictly necessary | Up to 30 days | Holds the contents of the shopping cart across page views |
| csrf_token | Strictly necessary | Session | Protects checkout and account forms against cross site request forgery |
| insales_visit | Analytics | Up to 1 year | Built in store analytics measuring visits and conversions, set only after consent |
InSales uses cookies for user preferences — inform visitors with a consent banner.
In a standard storefront it sets first party strictly necessary cookies for the session, the cart and form security. Its built in analytics and any marketing integrations may add non essential cookies, which should load only after the visitor consents.
Strictly necessary cookies for running the store need no consent. Consent is required before loading the built in analytics or any marketing cookies, and the privacy notice should also flag the non EEA hosting.
Operating the store and fulfilling orders relies on performance of a contract, security relies on legitimate interest, and analytics and marketing rely on consent under the GDPR and ePrivacy Directive.
Yes. InSales is hosted in the Russian Federation, which has no EU adequacy decision, so serving EEA customers means a third country transfer requiring Standard Contractual Clauses and a transfer impact assessment.
A DPIA is strongly recommended because the hosting is in a third country without adequacy and carries a heightened risk of government access and limited enforceability of rights.
Confirm the data location, sign a data processing agreement and Standard Contractual Clauses, complete a transfer impact assessment, gate non essential cookies behind a consent banner and update your records of processing and privacy notice.
EEA hosted e-commerce platforms and self hosted store software keep data within Europe and avoid the third country transfer issues that arise with Russian hosting.
List each InSales cookie with its purpose and duration, separate necessary from optional cookies, clearly state that the store is hosted outside the EEA and keep the notice consistent with your consent banner.