Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Volusion is a US based hosted ecommerce platform from Austin, Texas. Storefronts set strictly necessary cart and session cookies. All shop data is stored in the United States, so European merchants must disclose the EU US transfer and gate any optional analytics or advertising cookie behind consent.
Volusion is a hosted ecommerce platform founded in 1999 by Volusion LLC, headquartered in Austin, Texas. It targets small and mid sized merchants who want an all in one shop solution with templates, catalog, checkout and reporting. Storefronts run on a customer subdomain (mystore.volusion.com) or a custom domain. The admin backoffice manages products, orders and marketing campaigns.
Volusion sets ASP.NET_SessionId, VolusionShopperCart and OrderNumber cookies that are strictly necessary for the cart and checkout. The admin uses its own authentication cookies on the merchant backoffice. Volusion Insights, if enabled by the merchant, can add analytics cookies. Third party integrations (Google Analytics, Meta Pixel, Klaviyo, Mailchimp) installed by the merchant introduce their own cookies and require consent.
Strictly necessary cart and session cookies fall under the Article 5(3) ePrivacy carveout. Article 6(1)(b) GDPR (performance of a contract) covers the order processing flow. Any optional analytics or advertising tag requires prior opt in consent under Article 5(3) ePrivacy. The merchant is the controller, Volusion LLC is the processor under Article 28 GDPR with a DPA available on request.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
All Volusion shop data is hosted on AWS in the United States. There is no European data center option. The Standard Contractual Clauses and the EU US Data Privacy Framework cover the transfer. European merchants must include this in the privacy notice. The Akamai CDN delivers assets globally from edges, which is acceptable since cached HTML and images do not carry personal data. Email and customer service tooling are also US based.
Add a consent banner script in the Volusion theme that blocks third party trackers until opt in. Include the US transfer disclosure in your privacy notice. Request and sign the Volusion DPA. Document the processor in your record of processing activities with the AWS US region, the order retention period and the list of installed integrations. Set up a procedure to honor DSAR requests from shoppers via the Volusion admin or email.
Websites using Volusion must obtain user consent under GDPR regulations.
DPIA considerations
A DPIA is recommended for European Volusion shops because the platform stores all order and customer data in the United States. Document the legal basis for the transfer, the retention period, the consent management strategy for analytics and advertising tags, and the procedure for data subject access and erasure requests.
Sample consent text
This shop runs on Volusion. Volusion sets a session and cart cookie that are strictly necessary for the checkout to work. Your shop data is stored on Volusion servers in the United States. Optional analytics and advertising cookies are activated only after you accept them in the consent banner.
Third-party domains contacted
volusion.commivamerchant.netstatic.volusion.comcdn.volusion.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| ASP.NET_SessionId | first-party | Session | ASP.NET session identifier used by the Volusion storefront to maintain shopper context across pages. Strictly necessary. |
| VolusionShopperCart | first-party | Up to 30 days | Cart identifier used to persist the basket between visits. Strictly necessary for ecommerce. |
| OrderNumber | first-party | Session | Stores the in progress order identifier during the checkout. Strictly necessary. |
| VOLUSION-ADMIN | first-party (admin only) | Session | Authentication cookie for the Volusion merchant backoffice. Strictly necessary, never set on the public storefront. |
Volusion uses cookies for user preferences — inform visitors with a consent banner.
Yes. Volusion sets ASP.NET_SessionId, VolusionShopperCart and OrderNumber cookies that are strictly necessary for the cart and checkout. Optional analytics and advertising cookies only appear if the merchant installs the corresponding integration (Google Analytics, Meta Pixel, Klaviyo).
No consent is required for the strictly necessary cart and session cookies. Prior opt in consent is required for any analytics or advertising tag activated by the merchant.
Article 6(1)(b) GDPR (performance of a contract) for order processing, Article 6(1)(f) (legitimate interest) for strictly necessary cookies, Article 6(1)(a) (consent) for any optional tracking tag. The merchant is the controller, Volusion LLC is the processor.
Yes. Volusion hosts all shop data on AWS in the United States and has no EU data center option. The transfer is covered by Standard Contractual Clauses and the EU US Data Privacy Framework. European merchants must disclose this in the privacy notice.
A DPIA is recommended for European Volusion shops because all customer data is transferred to the United States. Document the transfer legal basis, the retention period and the consent management strategy.
Add a consent banner script to the Volusion theme that gates analytics and advertising tags, include the US transfer in the privacy notice, sign the Volusion DPA, document the processor in your RoPA, and set up a DSAR procedure for shoppers.
Other hosted ecommerce platforms include Shopify, BigCommerce, Wix Stores, Squarespace Commerce, Lightspeed eCom, Ecwid and self hosted options like WooCommerce, PrestaShop (France) and Shopware (Germany).
List the strictly necessary Volusion cookies (ASP.NET_SessionId, VolusionShopperCart, OrderNumber) in your cookie disclosure with purpose and duration. Add an entry for each third party integration with retention and EU US transfer information.