FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. E-commerce
  4. Saleor

Saleor

PreferencesWebsite

Related services

24nettbutikk

24nettbutikk is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. 24nettbutikk supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, 24nettbutikk ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Preferences

2ClickShop

2ClickShop is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 2ClickShop integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 2ClickShop helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences

4-Tell

4-Tell is a marketing platform that equips businesses with tools to amplify their digital presence and drive customer acquisition. It supports audience segmentation, campaign automation, and cross-channel engagement. 4-Tell provides real-time analytics and reporting dashboards for performance measurement and strategy optimization. By combining data intelligence with marketing execution, 4-Tell helps deliver the right message to the right audience at the right time.

Preferences

42stores

42stores is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 42stores integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 42stores helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences

4Partners

4Partners is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 4Partners integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 4Partners helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences
4

4Partners CMS

4Partners CMS is a powerful content management system (CMS) designed to help businesses and developers build, manage, and publish digital content with ease. It offers a flexible architecture that supports custom content types, templates, and workflows, making it ideal for websites of any scale. With 4Partners CMS, teams can streamline content creation, improve collaboration, and deliver engaging web experiences. Its extensible plugin ecosystem and API-first approach ensure seamless integration with.

Preferences
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does Saleor do?

Saleor is an open source headless e commerce platform developed in Poland by Saleor Commerce. It exposes a GraphQL API used by custom storefronts and apps. Saleor itself is privacy friendly: it stores order and customer data on the operator infrastructure and does not include third party trackers by default. The compliance footprint depends on the chosen hosting region (Saleor Cloud EU or US) and on the tracking pixels that operators add to their custom storefront.

What is Saleor

Saleor is an open source headless e commerce platform developed by Saleor Commerce sp. z o.o., based in Wroclaw, Poland. It is written in Python (Django, GraphQL) and is used by retailers and DTC brands across Europe and the Americas. Saleor exposes a GraphQL API that can be consumed by any storefront framework: Next.js, Astro, mobile apps, point of sale terminals or marketplaces. It is available both as Saleor Core (self hosted, MIT licensed) and as Saleor Cloud, a managed offering with EU and US regions.

What data does Saleor process

Saleor processes the data a typical e commerce backend needs: customer accounts (email, name, address, phone), order history, baskets, payment statuses, refunds, vouchers and loyalty rewards. It logs IP addresses and user agents for fraud prevention and stores admin user accounts for staff. The platform does not ship with marketing analytics, advertising pixels or third party trackers; any such tracking is added by the storefront developer.

GDPR and ePrivacy implications

Saleor falls under standard GDPR rules for e commerce: lawfulness of processing, data minimisation, security, retention and data subject rights. Strictly necessary cookies for cart, login and checkout are exempt from consent under Art. 5(3) of the ePrivacy Directive. Any optional cookies added by the storefront (analytics, retargeting, A/B testing) require prior consent and must be blocked until the visitor accepts.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Consent requirements

The Saleor core platform does not require visitor consent for its own operation. Consent obligations stem from the front end stack: analytics tags, marketing pixels, third party search and personalisation widgets. Implementing a Consent Management Platform that blocks these scripts by default is the cleanest way to keep the storefront compliant with GDPR and ePrivacy across all EU member states.

Data transfers outside the EU

When Saleor is self hosted in the EU or deployed in a Saleor Cloud EU region, no transfer outside the EU is required. Saleor Cloud US regions involve a transfer to the United States, which currently relies on the EU US Data Privacy Framework or Standard Contractual Clauses. The deployment region must be documented in the Article 30 register and disclosed in the privacy notice.

Practical compliance steps

Choose an EU region for Saleor Cloud or self host inside the EU, sign the Saleor DPA, harden Saleor admin access with MFA and IP restrictions, enable detailed audit logs, and configure retention rules for inactive customers. On the storefront side, integrate a CMP that blocks every non essential tag, document each Saleor App that adds external processors, and review payment processors and shipping carriers in your privacy notice.

GDPR consent category

Preferences

Websites using Saleor must obtain user consent under GDPR regulations.

Legal basisPerformance of a contract (Art. 6(1)(b) GDPR) for order processing, account management and shipping. Legitimate interest (Art. 6(1)(f)) for fraud prevention and security. Consent (Art. 6(1)(a)) applies only to optional tracking, analytics or marketing layered on top of the storefront.
Risk levellow
Applicable regulationsGDPR, ePrivacy Directive, TDDDG, LSSI CE, Polish Personal Data Protection Act, ENISA security guidelines for e commerce

DPIA considerations

A DPIA is not generally required for Saleor itself when used for standard order processing. A DPIA becomes appropriate when the storefront layered on Saleor implements large scale behavioural tracking, scoring or profiling, or when sensitive product categories are sold.

Sample consent text

This online store is powered by Saleor, an open source e commerce engine. Strictly necessary cookies are used to manage your cart, your account and your checkout. Optional cookies for analytics, advertising or personalization are only set after you give your consent.

Technical details

Tracking methodHeadless e commerce backend exposing a GraphQL API. The platform itself does not set tracking cookies on shopper browsers by default; tracking is implemented in the front end storefront that integrates with the API. Session cookies are used for the admin dashboard and for cart persistence when a server side checkout is built.
Server locationSelf hosted on the operator infrastructure when using Saleor Core (open source). Saleor Cloud is operated by Saleor Commerce sp. z o.o. in Wroclaw, Poland, with regional deployments in the EU and in the US on cloud providers including AWS and Google Cloud.
Cookieless tracking availableYes

Third-party domains contacted

saleor.iocloud.saleor.ioapi.saleor.ioeu.saleor.cloudus.saleor.cloud

Cookies placed

NameTypeDurationPurpose
refreshTokenhttp_only_cookie30 days (configurable, JWT refresh token lifetime)Strictly necessary. Stores the JWT refresh token issued by Saleor so the user stays authenticated and can request new access tokens without re entering credentials.
csrfTokenfirst_party_cookieSession (paired with refreshToken)Strictly necessary. CSRF protection token required by Saleor when refreshing tokens via cookie based flows. Prevents cross site request forgery on the tokenRefresh mutation.
accessTokenmemory_or_first_party_cookie5 to 15 minutes (JWT access token lifetime)Strictly necessary. Short lived JWT access token sent in the Authorization header to call the Saleor GraphQL API. Often kept in memory, optionally in a first party cookie.
checkoutTokenfirst_party_cookie_or_localStorageUp to 30 days or until checkout completesStrictly necessary. Stores the identifier of the current checkout / cart so the basket persists across page reloads and devices for logged in users.
localefirst_party_cookie1 yearFunctional. Remembers the language and currency selected by the visitor on the Saleor storefront. Considered strictly necessary when explicitly chosen by the user.
saleor_app_sessionfirst_party_cookieSessionStrictly necessary. Used by the Saleor Dashboard and installed Saleor Apps for authenticated admin sessions.

Saleor uses cookies for user preferences — inform visitors with a consent banner.

Get started freeScan your site

Frequently asked questions

Which cookies does Saleor set by default?

Saleor Core only sets strictly necessary cookies for the admin dashboard (authentication session, CSRF token) and, when using the server side cart, a cart identifier. The platform does not include analytics or advertising cookies; any such cookies are added by the storefront layer that consumes the GraphQL API.

Is consent required to operate Saleor on a European storefront?

No consent is required for the strictly necessary cookies used by Saleor itself: cart persistence, authentication and security tokens fall under the exemption in Art. 5(3) of the ePrivacy Directive. Consent is required for any additional analytics, marketing or personalization scripts added to the storefront.

What is the legal basis for storing customer data in Saleor?

Performance of a contract (Art. 6(1)(b) GDPR) for order processing and account management, legitimate interest (Art. 6(1)(f)) for security, fraud prevention and audit, and consent (Art. 6(1)(a)) for any marketing communication or behavioural profiling layered on top of the core platform.

Does Saleor transfer data outside the European Union?

Self hosted Saleor stays in the region you deploy it to. Saleor Cloud EU regions keep data in the EU. Saleor Cloud US regions transfer data to the United States under the EU US Data Privacy Framework or Standard Contractual Clauses. Choose your region according to the data residency requirements of your business.

Is a DPIA required when launching a Saleor based shop?

A DPIA is not generally required for a standard online shop built on Saleor. It becomes necessary when the storefront introduces large scale behavioural tracking, scoring, sensitive product categories (health, political opinions) or automated decision making that significantly affects customers.

How do I implement Saleor in a GDPR compliant way?

Deploy Saleor in the EU, configure retention rules for inactive customers, restrict admin access with MFA and IP allow lists, sign a Data Processing Agreement with Saleor for Cloud deployments, document Saleor in your Article 30 register, and use a Consent Management Platform on the storefront for any optional tag.

Are there alternative open source e commerce platforms based in Europe?

Yes. Sylius (France) and CoreShop (Austria) are mature open source platforms with strong European communities. Shopware (Germany) and PrestaShop (France) are popular open source choices. Spryker (Germany) targets B2B enterprises. All of them allow EU only hosting and reduce the burden of international data transfers.

How do I update my cookie policy when launching a Saleor storefront?

List each strictly necessary cookie used by Saleor (session, CSRF, cart) along with each optional cookie added by your front end (analytics, advertising, personalization). Indicate retention, processor and purpose. Re trigger the consent banner whenever a new third party integration is added through a Saleor App.