Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Kssib is an e commerce platform used to build and run online stores. The cookies it needs to keep a shopping cart and a session are strictly necessary, so they do not require consent, while the platform also processes customer and order data such as names, addresses, and purchase details. The main considerations are the lawful basis for orders, the security of customer data, and any analytics or payment integrations the merchant adds.
Kssib is an e commerce platform for building and running online stores. It handles the catalogue, the shopping cart, checkout, and order management, which means it processes customer and transaction data as a core part of its function rather than as optional tracking.
Kssib sets first party cookies to keep the shopping cart, the session, and security tokens, all of which are strictly necessary to complete a purchase. It also processes customer personal data such as names, contact details, delivery addresses, and order history, and it connects to payment providers to take payment.
Customer and order data are personal data under the GDPR, and the merchant is the controller. Processing an order relies on the contract with the customer, while marketing relies on consent. Payment data and any account features bring additional security and retention duties.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
The cart, session, and security cookies are strictly necessary and do not need consent. Consent is required for analytics, advertising, and marketing emails beyond the transaction, so gate any such tools and keep the order processing on a contract basis.
Where store data is processed depends on how Kssib is hosted and which payment and delivery integrations you use. Keeping hosting and integrations within the European Economic Area avoids transfers, while non EU services need Standard Contractual Clauses or another valid mechanism.
Set the lawful basis for orders and marketing, gate non essential cookies behind consent, sign a data processing agreement if Kssib is a hosted service, and secure payment and customer data. Set retention for orders, confirm where data is processed, and describe the store cookies in your cookie policy.
Websites using Kssib must obtain user consent under GDPR regulations.
DPIA considerations
As an e commerce platform, assess the customer and order data processed, payment handling, the lawful basis for orders and marketing, retention, and any integrations that send data outside the EEA. The cart and session cookies are strictly necessary.
Sample consent text
This store runs on Kssib. Cookies needed for your cart and checkout are strictly necessary, while any analytics or marketing cookies run only after you accept them.
Cookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| kssib_session | Functional | Session | Strictly necessary cookie that maintains the visitor session while browsing the store. |
| kssib_cart | Functional | 14 days | Strictly necessary cookie that remembers the contents of the shopping cart. |
| kssib_csrf | Functional | Session | Strictly necessary security cookie that protects checkout forms against cross site request forgery. |
Kssib uses cookies for user preferences — inform visitors with a consent banner.
Kssib sets first party cookies for the shopping cart, the session, and security. These are strictly necessary to browse and buy, so they do not require consent, unlike any analytics a store adds.
Not for the strictly necessary store cookies or for processing an order. You do need consent for analytics, advertising, and marketing emails that go beyond completing the purchase.
Processing an order relies on the contract with the customer under Article 6(1)(b) of the GDPR. Marketing relies on consent, and the merchant is the controller for customer data.
That depends on the hosting and the payment and delivery integrations you use. EU hosting and EU integrations keep data in the region, while non EU services introduce transfers requiring safeguards.
A DPIA may be worth it for large stores or where sensitive data is processed. Cover the customer and order data, payment handling, retention, and any transfers.
Set the lawful basis for orders and marketing, gate non essential cookies behind consent, secure customer and payment data, and sign a data processing agreement if hosted. Set retention and confirm the data location.
Alternatives include Shopify, WooCommerce, PrestaShop, and other store platforms. Compare where each hosts data and how it handles customer and payment information.
List the cart, session, and security cookies as strictly necessary. Add any analytics or marketing cookies you enable to the appropriate consent categories, and name the providers involved.