FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. E-commerce
  4. SellBe

SellBe

PreferencesWebsite

Related services

24nettbutikk

24nettbutikk is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. 24nettbutikk supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, 24nettbutikk ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Preferences

2ClickShop

2ClickShop is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 2ClickShop integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 2ClickShop helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences

4-Tell

4-Tell is a marketing platform that equips businesses with tools to amplify their digital presence and drive customer acquisition. It supports audience segmentation, campaign automation, and cross-channel engagement. 4-Tell provides real-time analytics and reporting dashboards for performance measurement and strategy optimization. By combining data intelligence with marketing execution, 4-Tell helps deliver the right message to the right audience at the right time.

Preferences

42stores

42stores is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 42stores integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 42stores helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences

4Partners

4Partners is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 4Partners integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 4Partners helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences
4

4Partners CMS

4Partners CMS is a powerful content management system (CMS) designed to help businesses and developers build, manage, and publish digital content with ease. It offers a flexible architecture that supports custom content types, templates, and workflows, making it ideal for websites of any scale. With 4Partners CMS, teams can streamline content creation, improve collaboration, and deliver engaging web experiences. Its extensible plugin ecosystem and API-first approach ensure seamless integration with.

Preferences
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does Sellbe do?

Sellbe is a Polish e-commerce SaaS platform operated by Comarch that lets small and mid-sized businesses launch online stores quickly. The service is hosted on infrastructure located in Poland, which keeps merchant and customer data inside the European Economic Area. Sellbe sets first-party cookies for shopping cart and session management, plus optional analytics and marketing cookies that fall under Article 5(3) of the ePrivacy Directive and require informed consent.

What Sellbe is and who operates it

Sellbe is a hosted e-commerce platform aimed at small and mid-sized merchants. It is published by Comarch S.A., a Polish technology group headquartered in Krakow, and accessible through the sellbe.com domain. Merchants pick a template, configure products, taxes and shipping rules, and the resulting storefront runs as a SaaS service. The platform integrates with Comarch ERP back-office products as well as third-party payment, shipping and accounting providers, but the operating tenant is hosted in Poland.

Data and cookies set by the storefront

A standard Sellbe storefront stores first-party session cookies that link the visitor to their shopping basket, authentication cookies for logged in customers and a CSRF protection token. On the operations side it processes order data, addresses, payment references, contact details for newsletter subscribers and access logs. Optional analytics or marketing add-ons, such as Google Analytics, Meta Pixel or affiliate trackers, may set their own cookies if the merchant activates them.

GDPR and ePrivacy framework

The merchant is the controller of the personal data collected through the store. Comarch acts as a processor under Article 28 GDPR and provides a data processing agreement. Functional and shopping cart cookies fall outside the consent obligation of Article 5(3) ePrivacy because they are strictly necessary to provide the service explicitly requested by the user. Analytics and marketing cookies require prior, informed and freely given consent, expressed through a compliant consent banner.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Hosting and data transfers

Sellbe runs on Comarch infrastructure located in Poland and, as such, keeps customer data within the European Economic Area by default. Transfers outside the EEA only occur when the merchant deliberately activates an integration that involves a third country processor, such as a non European payment gateway, a US analytics suite or a marketing tool. Each such integration must be assessed separately by the merchant and documented in the record of processing activities.

Consent and DPIA approach

A standard SMB storefront does not in itself trigger the obligation of a formal DPIA. However, a record of processing activities under Article 30, an information notice under Articles 13 and 14, a configured consent banner and a data processing agreement with Comarch are mandatory. If the merchant enables behavioural advertising, customer scoring or large scale newsletter campaigns, a focused DPIA is recommended to address profiling, retention and security risks.

Practical steps and alternatives

Merchants should publish a clear privacy notice, install a granular consent banner that separates strictly necessary, analytics and marketing cookies, sign the Comarch DPA, document subprocessors and configure retention periods inside the back office. If a fully self-hosted setup is preferred, alternatives include Shoper, PrestaShop, WooCommerce or Sylius, each of which can run on EU infrastructure with similar feature coverage.

GDPR consent category

Preferences

Websites using Sellbe must obtain user consent under GDPR regulations.

Legal basisContract performance (Article 6(1)(b) GDPR) for order processing and shopping cart cookies. Legitimate interest (Article 6(1)(f)) for security and basic logging. Consent (Article 6(1)(a) plus Article 5(3) ePrivacy) for analytics and marketing cookies.
Risk levellow
Applicable regulationsGDPR, Polish Act on the Provision of Electronic Services, Polish Telecommunications Law (ePrivacy implementation), Consumer Rights Directive (Directive 2011/83/EU)

DPIA considerations

A full DPIA is not automatically required for a typical Sellbe store, but the merchant should document the categories of data processed (identification, contact, order, payment), the retention periods, the role of Comarch as processor and the chain of subprocessors (payment gateway, shipping carrier, marketing module). If the catalogue includes special category data, profiling features or large scale processing, a formal DPIA under Article 35 GDPR becomes necessary.

Sample consent text

This online store runs on the Sellbe platform. Essential cookies are needed to keep your basket and to complete your order. With your consent we also use analytics cookies to measure aggregated traffic and marketing cookies to display tailored offers. You can accept, refuse or fine-tune your choice at any time from the cookie preferences link in the footer.

Technical details

Tracking methodFirst-party cookies for shopping cart, session management and authentication, plus basic web analytics cookies. Server-side processing of order, payment and customer data. No persistent device fingerprinting under default configuration.
Server locationEuropean Union, Poland. Sellbe is operated by Comarch S.A. and hosted on infrastructure located in Polish data centres, which keeps personal data inside the European Economic Area by default.

Third-party domains contacted

sellbe.comstatic.sellbe.comapi.sellbe.comcomarch.com

Cookies placed

NameTypeDurationPurpose
sellbe_sessionfirst_partySessionIdentifies the visitor session and links it to the shopping basket. Strictly necessary for the storefront to function.
sellbe_cartfirst_party30 daysPersists the contents of the shopping basket between visits so the buyer can resume the order. Strictly necessary functional cookie.
sellbe_authfirst_party14 daysKeeps the logged in customer authenticated across pages. Set only after sign in, strictly necessary for the account area.
sellbe_csrffirst_partySessionCSRF token preventing cross-site request forgery on forms and checkout. Strictly necessary security cookie.
sellbe_consentfirst_party12 monthsStores the visitor cookie preferences (accepted, rejected, granular categories) to enforce the consent on subsequent visits.
sellbe_localefirst_party12 monthsRemembers the language and currency selected by the visitor. Functional cookie that improves the browsing experience.
sellbe_analyticsfirst_party13 monthsAggregated traffic measurement (page views, conversion funnel). Set only after the visitor accepts analytics cookies.

Sellbe uses cookies for user preferences — inform visitors with a consent banner.

Get started freeScan your site

Frequently asked questions

Which cookies does a Sellbe store set?

A default Sellbe storefront sets first-party cookies for the session, the shopping basket, authentication of logged in customers, CSRF protection, language preference and consent state. Analytics or marketing cookies are added only when the merchant activates the corresponding modules and the visitor agrees through the consent banner.

Do I need consent to use Sellbe on my website?

You do not need consent for strictly necessary cookies (session, cart, authentication, CSRF, consent record): they fall under the exemption of Article 5(3) of the ePrivacy Directive. You do need prior, granular consent for any analytics, advertising or personalisation cookies you decide to enable.

What is the legal basis for processing customer data on Sellbe?

Order processing, payment and account management rely on contract performance (Article 6(1)(b) GDPR). Tax records and consumer law obligations rely on legal obligation (Article 6(1)(c)). Security logs and fraud prevention rely on legitimate interest (Article 6(1)(f)). Newsletter and behavioural advertising rely on consent (Article 6(1)(a) plus Article 5(3) ePrivacy).

Does Sellbe transfer data outside the European Union?

Sellbe itself does not. Comarch hosts the platform on Polish infrastructure, keeping customer data within the EEA. Third-country transfers only happen when the merchant activates an external integration (US analytics, non European payment gateway, etc.). In that case the merchant must rely on an adequacy decision, SCCs or another Chapter V mechanism.

Is a DPIA needed for a Sellbe store?

Not automatically. A standard SMB storefront involves moderate volumes of routine data (identification, order, payment) and presents a low risk. A focused DPIA becomes useful when the merchant enables profiling, large scale newsletter campaigns, scoring or any processing of special categories. A record of processing activities and an information notice remain required in any case.

How do I implement Sellbe in a GDPR-compliant way?

Sign the Comarch data processing agreement, complete the privacy and cookie policy with concrete categories and retention periods, install a consent banner that allows the visitor to accept, refuse or fine tune categories, restrict access to the back-office by role and configure automatic deletion of inactive accounts. Audit any third-party module added later.

What are the alternatives to Sellbe for EU merchants?

Comparable EU friendly options include Shoper (Poland), PrestaShop (France) and Sylius (Poland) for hosted or self-hosted SMB stores, plus WooCommerce on WordPress for the long tail. For larger catalogues, BigCommerce EU, Centra (Sweden) or commercetools (Germany) can be deployed on European infrastructure with mature DPAs.

How should I update my cookie policy when running Sellbe?

List in the cookie policy each cookie set by Sellbe (name, purpose, retention) and add a row whenever you activate an analytics or marketing module. Mention Comarch as processor, the hosting location in Poland and the contact for data subject rights. Review the policy at every major release of the platform or when you add a new integration.