Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Selldone is a no code business operating system and ecommerce platform for building and running online stores, using first party session, cart, and authentication cookies plus optional analytics.
Selldone is a no code business operating system and ecommerce platform that lets companies build and run online stores without writing code. Beyond a simple storefront, it offers tools to manage products, orders, customers, and broader business workflows from a single environment served through selldone.com and app.selldone.com. This breadth means a single Selldone deployment can cover both the public store and the operational back office.
Selldone uses first party cookies for session continuity, shopping cart persistence, and authentication so signed in users and shoppers keep their state across pages. These cookies are strictly necessary to operate the store and the management console. Optional analytics cookies may be enabled to measure usage, and those sit outside the necessary category and are governed by consent.
The strictly necessary session, cart, and authentication cookies are exempt from consent under the ePrivacy Directive because they are required to deliver the requested service. Any analytics or marketing cookies enabled on top of the platform need informed, prior consent from the visitor. Store operators should present a clear banner that lets visitors accept or decline these optional categories before such cookies are set.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Necessary cookies and core order and account processing rely on performance of the contract, while optional analytics rely on consent. Whether personal data is transferred outside the European Economic Area depends on the infrastructure and regions Selldone uses for a given store, so operators should confirm this for their setup. Where transfers occur, appropriate safeguards such as standard contractual clauses should be applied.
Because Selldone can power both a storefront and back office tools, document which modules you use and which cookies each sets. Classify cookies as necessary or optional, deploy a consent banner that blocks optional analytics until the visitor agrees, and publish a privacy notice covering store, account, and order processing. Confirm the hosting regions so any cross border transfers are described accurately and reviewed periodically.
Selldone is a versatile no code ecommerce and business platform whose necessary session, cart, and authentication cookies are consent exempt, while optional analytics require consent. Its risk profile sits in the low to medium range because the same platform can span simple stores and richer business operations. With a correct cookie banner, an accurate privacy notice, and confirmed hosting regions, merchants can operate Selldone within GDPR and ePrivacy expectations.
Websites using Selldone must obtain user consent under GDPR regulations.
DPIA considerations
Selldone operates as a broad no code platform that can power storefronts, accounts, and business workflows, so the need for a data protection impact assessment depends on how a merchant uses it. Standard online retail typically does not require a full DPIA, but large scale profiling, integrated marketing analytics, or processing of sensitive data raises the threshold. Operators should map which Selldone modules they enable, the categories of personal data each handles, and the hosting regions involved.
Sample consent text
Our store runs on Selldone and uses strictly necessary cookies for your session, cart, and sign in. With your consent, we also enable optional analytics cookies to measure how the store is used. You can change your choice for optional cookies at any time.
Third-party domains contacted
selldone.comcdn.selldone.comapi.selldone.comstatic.selldone.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| selldone_session | Functional | Session | Maintains the authenticated session and keeps the shopper signed in during their visit |
| cart_id | Functional | 30 days | Remembers the contents of the shopping cart between page views and visits |
| XSRF-TOKEN | Functional | Session | Security cookie that protects forms and checkout against cross site request forgery |
| selldone_locale | Functional | 1 year | Stores the language and regional preference selected by the visitor |
| _sd_analytics | Analytics | 13 months | Optional analytics cookie that measures storefront traffic and shopper behavior |
| _sd_marketing | Marketing | 13 months | Optional cookie used for retargeting and personalized marketing when enabled by the merchant |
Selldone uses cookies for user preferences — inform visitors with a consent banner.
Selldone sets first party functional cookies for the session, the shopping cart, security tokens and language preferences, which are necessary for the store to operate. If a merchant enables analytics or marketing features, Selldone or connected tools may add optional cookies for measurement and personalization. The exact set depends on the features and integrations the merchant activates.
Consent is required for analytics and marketing cookies but not for the strictly necessary cookies that run the store. Essential session and cart cookies can be set without consent, while any tracking or advertising feature must wait for an opt in. Merchants should run a consent banner that separates necessary and optional cookies.
Processing of order and account data is usually based on performance of a contract under Article 6(1)(b) of the GDPR, since it is needed to complete purchases. Optional analytics and marketing rely on consent under Article 6(1)(a) and the ePrivacy Directive. Merchants should document the basis for each category of processing.
Selldone is a cloud platform whose infrastructure may be located in the United States and other regions, so customer data can be transferred outside the European Economic Area. These transfers should be covered by Standard Contractual Clauses or an adequacy framework. Merchants should confirm the hosting regions and disclose transfers in their privacy notice.
A data protection impact assessment is advisable when the store handles large volumes of customer data or activates profiling, analytics and marketing features. Assess which integrations are enabled, where data is stored and whether it leaves the European Economic Area. For a simple store using only essential cookies the risk is lower.
Sign a data processing agreement with Selldone, publish a clear privacy and cookie policy and deploy a consent banner that blocks optional cookies until the visitor accepts. Map all integrations, document the lawful basis for each activity and set retention periods for orders and accounts. Review activated features whenever you add marketing or analytics tools.
Alternatives include Shopify, WooCommerce, BigCommerce and Wix, each of which has its own cookie and data handling profile. Self hosted options such as WooCommerce give more control over data location, while hosted platforms simplify operations but may involve third country transfers. Compare hosting regions and consent controls when choosing.
Scan your live storefront regularly to capture the cookies that essential and optional features actually set, because enabling a new integration can introduce new cookies. Update the names, durations and purposes in your cookie policy and adjust your consent categories accordingly. Re check after any major theme or feature change.