FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. E-commerce
  4. Spryker

Spryker

PreferencesWebsite

Related services

24nettbutikk

24nettbutikk is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. 24nettbutikk supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, 24nettbutikk ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Preferences

2ClickShop

2ClickShop is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 2ClickShop integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 2ClickShop helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences

4-Tell

4-Tell is a marketing platform that equips businesses with tools to amplify their digital presence and drive customer acquisition. It supports audience segmentation, campaign automation, and cross-channel engagement. 4-Tell provides real-time analytics and reporting dashboards for performance measurement and strategy optimization. By combining data intelligence with marketing execution, 4-Tell helps deliver the right message to the right audience at the right time.

Preferences

42stores

42stores is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 42stores integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 42stores helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences

4Partners

4Partners is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 4Partners integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 4Partners helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences
4

4Partners CMS

4Partners CMS is a powerful content management system (CMS) designed to help businesses and developers build, manage, and publish digital content with ease. It offers a flexible architecture that supports custom content types, templates, and workflows, making it ideal for websites of any scale. With 4Partners CMS, teams can streamline content creation, improve collaboration, and deliver engaging web experiences. Its extensible plugin ecosystem and API-first approach ensure seamless integration with.

Preferences
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does Spryker do?

Spryker is a German headless commerce platform for B2B, B2C and marketplace scenarios, delivered as Cloud Commerce OS on AWS or as on premise PaaS+ stack with a composable architecture and EU based data centres.

What Spryker actually does

Spryker is a German headless and composable commerce platform operated by Spryker Systems GmbH (Berlin). It targets B2B, B2C and enterprise marketplaces such as ALDI Sourcing, Toyota, Hilti, ZF Friedrichshafen and many DACH retailers. The platform is delivered either as Spryker Cloud Commerce OS (PaaS on AWS) or as a self managed installation. Spryker provides a glue layer (Spryker Glue REST and GraphQL APIs) that lets the publisher build any frontend (Next.js, Nuxt, mobile app, voice) on top of the commerce capabilities.

Cookies and storage set by Spryker

The default Yves storefront writes first party cookies on the publisher domain: PHPSESSID (session, browser session), spryker_csrf (CSRF protection, 1 hour), spryker_cart (anonymous cart id, 30 days) and spryker_customer (logged in customer flag, browser session). All of these cookies fall under the strictly necessary category and are exempt from prior consent under ePrivacy art. 5(3) and the EDPB guidelines 2/2023. When the publisher activates marketing integrations (Google Tag Manager, Klaviyo, Adobe Experience Platform), additional cookies are loaded by those vendors and require consent.

Lawful basis and consent

The commerce flow itself relies on performance of contract (GDPR art. 6(1)(b)) for the order, legal obligation (art. 6(1)(c)) for invoicing and customs documents, and legitimate interest (art. 6(1)(f)) for fraud prevention and stock management. Cart abandonment emails and personalised recommendations are non essential and require consent or, for existing customers and similar products, the soft opt in of ePrivacy art. 13(2). PSD2 strong customer authentication applies to payments above 30 EUR.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

International data transfers

Spryker Cloud Commerce OS for EU customers runs on AWS Frankfurt and Dublin. Customer commerce data stays in the EEA. The Spryker DPA is fully German law compliant and lists the sub processors (AWS, Datadog, Sentry, Spryker SaaS support entities). Customers self hosting Spryker keep full control over the data location. The Spryker Composable AI features rely on Microsoft Azure OpenAI Service in the European region; the publisher must accept the additional AI addendum.

Practical compliance checklist

Sign the Spryker DPA and select the EU Cloud Commerce region. Disable the analytics features that need consent (Customer Insights, Recommender) until the CMP allows them. Document Spryker Systems GmbH in your records of processing (GDPR art. 30) and the privacy notice. Implement the right to erasure and the right of access via the Spryker Customer API. For B2C retailers, configure the 14 day right of withdrawal as required by the EU consumer rights directive. Run a DPIA if the Composable AI features take decisions affecting customer offers or pricing.

Alternatives

Direct competitors include commercetools (Germany), SAP Commerce Cloud (Germany and US), Salesforce Commerce Cloud (US), Adobe Commerce ex Magento (US, EU hosted optional), Shopify Plus (Canada, EU hosted in Ireland) and BigCommerce (US). For B2B specific scenarios, Sana Commerce (Netherlands) and OroCommerce (US and France) are also relevant.

GDPR consent category

Preferences

Websites using Spryker must obtain user consent under GDPR regulations.

Legal basisFor checkout and order processing: performance of the contract (GDPR art. 6(1)(b)) and legal obligation for invoicing. For the Spryker session cookies and the basket persistence cookies: strictly necessary, exempt from consent under ePrivacy art. 5(3). For embedded third party services (recommendations, search, marketing) triggered from a Spryker storefront: consent under GDPR art. 6(1)(a).
Risk levellow
Applicable regulationsGDPR, ePrivacy Directive 2002/58/EC, EU consumer rights directive 2011/83/EU, PSD2 SCA, German BGB §312j, French Code de la consommation, LOPDGDD, TTDSG, AI Act (for Spryker Composable AI features)

DPIA considerations

A DPIA is recommended for large scale B2C deployments because Spryker processes customer accounts, orders and behavioural data. Document storefront tags separately.

Sample consent text

This site is built with Spryker, a German headless commerce platform operated by Spryker Systems GmbH in Berlin. The Spryker storefront writes strictly necessary cookies (session id, cart id, CSRF token) that do not require consent. We process your name, billing and shipping address, order history and payment metadata to fulfil your order under GDPR art. 6(1)(b) and the legal obligation to keep accounting records. Spryker Cloud Commerce OS hosts your data on AWS Frankfurt and Dublin; no transfer outside the European Economic Area takes place unless we explicitly enable a non EU integration.

Technical details

Tracking methodheadless_commerce_platform_self_hosted_or_paas
Server locationSpryker offers Spryker Cloud Commerce OS (PaaS) hosted on AWS, with EU customers running in Frankfurt (eu-central-1) and Dublin (eu-west-1). Self managed installations run on the customer chosen infrastructure.
Cookieless tracking availableYes

Third-party domains contacted

spryker.comspryker.comcloud.spryker.comspryker.cloudstatic.spryker.comglue.mysprykershop.comyves.mysprykershop.com

Cookies placed

NameTypeDurationPurpose
PHPSESSIDhttp_cookieSessionStrictly necessary session cookie set by the Yves storefront to identify the visitor across requests and maintain the cart and login state.
yves_sessionFirst party (Spryker)SessionMaintains the customer session on the Yves storefront.
spryker_customerhttp_cookie90 daysPersistent first party cookie that stores a customer reference for returning authenticated buyers so the storefront can restore preferences and personalised pricing.
PHPSESSIDFirst party (Spryker)SessionDefault PHP session cookie used by the Spryker storefront.
spryker_csrfFirst party (Spryker)SessionCSRF protection token used during form submissions.
csrf_token_*http_cookieSessionStrictly necessary CSRF token rotated per form submission to prevent cross site request forgery against checkout and account endpoints.
cart_referencehttp_cookie30 daysFunctional cookie that stores the cart reference so the basket can be restored when the buyer returns within the validity window.

Spryker uses cookies for user preferences — inform visitors with a consent banner.

Get started freeScan your site

Frequently asked questions

Which cookies does Spryker set by default?

Out of the box, the Yves storefront sets PHPSESSID for the session, a customer reference cookie for authenticated users, a CSRF token (csrf_token_*) and a basket reference cookie. These are strictly necessary. Any other cookie comes from optional Spryker modules (tracking, recommendations) or third party integrations that the merchant has activated.

What cookies does Spryker set?

Spryker storefronts set technical cookies (yves_session, PHPSESSID, spryker_csrf) that are strictly necessary for the cart and session. Third party analytics or marketing cookies are added by you, not by Spryker itself.

Do users have to consent to Spryker itself?

No. The default Spryker cookies are strictly necessary under Article 5(3) ePrivacy because they maintain the cart, the login state and CSRF protection. Consent becomes mandatory when the merchant enables the Spryker Tracking module, recommendation engines or third party integrations that store information for analytics or marketing purposes.

Do I need consent for Spryker?

No consent is required for strictly necessary storefront cookies. Consent is required for any analytics, advertising or personalisation tag you add on top of Spryker (Google Analytics, Meta Pixel, etc.).

What is the legal basis for processing customer data in Spryker?

Account creation, order processing, payment and fulfilment rely on Article 6(1)(b) GDPR (performance of contract). Statutory invoice and tax retention relies on Article 6(1)(c) (legal obligation). Fraud prevention can be based on Article 6(1)(f) (legitimate interest). Personalisation and marketing tracking require consent (Article 6(1)(a)).

What is the legal basis for Spryker?

Contract performance (Art. 6(1)(b) GDPR) for the storefront and account features. Legitimate interest (Art. 6(1)(f)) for fraud prevention. Consent (Art. 6(1)(a)) for optional storefront tags.

Does Spryker transfer data to the United States?

Spryker Cloud Commerce OS does not. All environments run in AWS Frankfurt, Dublin or Stockholm and support staff outside the EU access data only through audited bastion sessions. However, merchants commonly integrate US based services (Salesforce, Algolia, Twilio); those transfers are out of Spryker scope and need to be assessed separately.

Does Spryker transfer data to the US?

Spryker Cloud customers in Europe default to AWS Frankfurt. No transfer outside the EU for the platform itself. AWS as the hosting layer is covered by EU SCCs and the EU US Data Privacy Framework as a sub processor.

Is a DPIA needed for Spryker?

A DPIA is recommended when the deployment combines marketplace functionality (joint controllership with sellers under Article 26), large scale profiling (recommendation engines, customer segmentation), B2B account hierarchies that mix personal and corporate data, or special category processing (health, finance). For a vanilla B2C storefront without behavioural tracking, a DPIA is generally not required.

Do I need a DPIA for Spryker?

A DPIA is recommended for large scale B2C deployments processing many customer records, or for B2B sales with personal contacts. Document Spryker as a processor and the storefront tags separately.

How do I implement Spryker compliantly?

Sign the Spryker DPA, document the AWS region in your record of processing, gate every optional tracking module behind your CMP, integrate Google Consent Mode v2 or the equivalent in the Yves storefront and Glue API responses, and expose the GDPR self service endpoints (access, rectification, erasure, portability) via the Customer Account API. Update the privacy notice when activating each new module or integration.

How do I implement Spryker compliantly?

Sign the Spryker DPA, host in EU regions, document retention, expose Subject Access and Deletion endpoints via the customer account, integrate a CMP for storefront analytics/marketing tags, and audit your storefront tags regularly.

What are the alternatives to Spryker?

Composable commerce alternatives in Europe: commercetools (Germany), Salesforce Commerce Cloud (US), SAP Commerce Cloud (Germany/Bulgaria), VTEX (Brazil/US), BigCommerce (US), Shopify Plus (Canada). For open source: Sylius (France), Saleor (Poland), OroCommerce.

What are the alternatives to Spryker?

Direct alternatives in the composable commerce space include commercetools (Germany), Vendure (UK, open source), BigCommerce, Salesforce Commerce Cloud, SAP Commerce Cloud (Hybris), Shopware (Germany) and Adobe Commerce (Magento). commercetools and Shopware are the closest European competitors with EU hosting; Salesforce, SAP and Adobe Commerce typically run on US infrastructure unless EU region is explicitly configured.

How do I keep my cookie policy up to date with Spryker?

Re scan the storefront with your CMP after every release because new merchandising modules (Algolia search, Cloudinary images, customer reviews) can introduce additional cookies. Update the cookie register with each new module or integration, including the duration and recipient, and synchronise the privacy notice when Spryker adds a new sub processor or AWS region.

How do I update my cookie policy for Spryker?

List the strictly necessary storefront cookies. Add separate entries for every analytics, marketing or personalisation tag you deploy on top of Spryker. Mention the EU hosting region and the Spryker DPA.