FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. E-commerce
  4. WooCommerce

WooCommerce

Preferences

Related services

24nettbutikk

24nettbutikk is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. 24nettbutikk supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, 24nettbutikk ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Preferences

2ClickShop

2ClickShop is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 2ClickShop integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 2ClickShop helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences

4-Tell

4-Tell is a marketing platform that equips businesses with tools to amplify their digital presence and drive customer acquisition. It supports audience segmentation, campaign automation, and cross-channel engagement. 4-Tell provides real-time analytics and reporting dashboards for performance measurement and strategy optimization. By combining data intelligence with marketing execution, 4-Tell helps deliver the right message to the right audience at the right time.

Preferences

42stores

42stores is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 42stores integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 42stores helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences

4Partners

4Partners is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 4Partners integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 4Partners helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences
4

4Partners CMS

4Partners CMS is a powerful content management system (CMS) designed to help businesses and developers build, manage, and publish digital content with ease. It offers a flexible architecture that supports custom content types, templates, and workflows, making it ideal for websites of any scale. With 4Partners CMS, teams can streamline content creation, improve collaboration, and deliver engaging web experiences. Its extensible plugin ecosystem and API-first approach ensure seamless integration with.

Preferences
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does WooCommerce do?

WooCommerce is the most widely deployed e-commerce platform in Europe, an open-source plugin for WordPress published by Automattic. It is fully self-hosted, so all customer and order data stays on the merchant infrastructure. WooCommerce sets only strictly necessary first-party cookies for cart and checkout flow; analytics, marketing and most third-party integrations are opt-in via additional plugins.

What is WooCommerce?

WooCommerce is an open source e-commerce plugin for WordPress launched in 2011 and now developed by Automattic. It powers an estimated 30 percent of online stores worldwide and is the dominant platform for European SMEs that already run WordPress. Because WooCommerce is a self hosted plugin rather than a SaaS, the merchant remains in full control of where the data lives and which third party integrations are loaded.

Cookies and data collected

By default WooCommerce sets a small set of strictly necessary first party cookies: woocommerce_cart_hash, woocommerce_items_in_cart, wp_woocommerce_session_*. These cookies persist the cart, the customer session and the checkout flow. Customer accounts, orders and addresses are stored in the WordPress database. The optional WooCommerce Analytics module reads order data already in the database without sending it externally. Marketing emails, abandoned cart recovery and external analytics require dedicated plugins that the merchant chooses.

GDPR and ePrivacy implications

The strictly necessary cookies are exempt from consent under Art. 5(3) ePrivacy. Customer accounts and orders rely on contract performance (Art. 6(1)(b) GDPR). Marketing communications, abandoned cart automation, profiling and any third party tracker added through plugins (Google Analytics, Meta Pixel, TikTok Pixel, etc.) require freely given consent (Art. 6(1)(a)).

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Data transfers and hosting

WooCommerce does not transfer data anywhere by itself. The actual transfer surface depends on the hosting provider, the CDN, the email service, the payment processor and any analytics or marketing plugin. To stay inside the EEA, choose an EU host (e.g. Hetzner, OVHcloud, Infomaniak, Scaleway), favour EU based plugins and document the residency of every external integration.

Practical compliance steps

Install a consent platform (Complianz, CookieYes, OneTrust) that blocks marketing and analytics scripts before opt-in. Use the WooCommerce privacy settings to configure data retention and the predefined privacy notice template. Sign DPAs with your host, payment processor and any plugin vendor that processes personal data. Audit installed plugins regularly. Provide a documented process for data subject requests using the built-in WordPress export and erase tools.

GDPR consent category

Preferences

Websites using WooCommerce must obtain user consent under GDPR regulations.

Legal basisStrictly necessary cookies (cart, session, checkout flow) rely on Art. 5(3) ePrivacy Directive exemption. Customer account data and order processing rely on contract performance (Art. 6(1)(b) GDPR). Marketing emails, abandoned cart recovery and analytics extensions require consent (Art. 6(1)(a)).
Risk levellow
Applicable regulationsGDPR, ePrivacy Directive 2002/58/EC, national consumer protection laws (e.g. French Code de la consommation, German UWG/BGB)

DPIA considerations

A DPIA is generally not required for standard WooCommerce stores. It becomes relevant when the store processes special category data, very large customer volumes, or extensive behavioural profiling through analytics and marketing plugins.

Sample consent text

This online store runs on WooCommerce. Cart and checkout cookies are strictly necessary. Analytics, advertising and marketing scripts are loaded only after you give consent in our cookie banner.

Technical details

Tracking methodself hosted WordPress plugin written in PHP; first party session and cart cookies for the storefront and checkout, optional WooCommerce Analytics module
Server locationdepends on the WordPress hosting provider chosen by the merchant

Third-party domains contacted

woocommerce.comwoo.comapi.woocommerce.com

Cookies placed

NameTypeDurationPurpose
woocommerce_cart_hashfirst_partySessionStrictly necessary cookie that stores a hash of the cart contents so the storefront can quickly detect when the cart changes.
woocommerce_items_in_cartfirst_partySessionStrictly necessary cookie that stores the number of items in the cart, used to update the mini cart and checkout summary.
wp_woocommerce_session_*first_party48 hoursStrictly necessary cookie that stores a unique customer session identifier so cart and checkout data persist between page loads.
woocommerce_recently_viewedfirst_partySessionOptional cookie that stores recently viewed products to power related-product widgets in some themes.

WooCommerce uses cookies for user preferences — inform visitors with a consent banner.

Get started freeScan your site

Frequently asked questions

What cookies does WooCommerce set?

By default WooCommerce sets only strictly necessary first party cookies: woocommerce_cart_hash and woocommerce_items_in_cart (session, store the cart state) and wp_woocommerce_session_* (48 hours, persist the customer session). woocommerce_recently_viewed is sometimes set by themes. Customer accounts and orders are stored in the WordPress database, not in cookies. Any analytics, marketing or social cookies come from extra plugins, not from WooCommerce itself.

Do I need consent to use WooCommerce on my website?

No banner is required for the WooCommerce cart and checkout cookies because they are strictly necessary under Art. 5(3) ePrivacy. You do need consent for any third party tracker added by a plugin (Google Analytics, Meta Pixel, TikTok Pixel, abandoned cart automation, customer reviews widgets, social plugins, etc.). Configure your CMP to block those scripts before opt-in.

What is the legal basis for processing personal data through WooCommerce?

Order processing, account creation and shipment fulfilment rely on contract performance (Art. 6(1)(b) GDPR). Tax and accounting retention rely on legal obligation (Art. 6(1)(c)). Marketing emails, newsletter subscriptions, abandoned cart recovery and any analytics or advertising integration require consent (Art. 6(1)(a)). Strictly necessary cookies rely on Art. 5(3) ePrivacy.

Does WooCommerce transfer data to third countries?

WooCommerce itself does not transfer data anywhere. Whether your store transfers customer data outside the EEA depends on the hosting provider, the CDN, the email service, the payment processor and any third party plugin you install. Document the location of every external service in your records of processing.

Do I need a DPIA for WooCommerce?

A standalone WooCommerce store with standard products typically does not require a DPIA. A DPIA is recommended when you process special category data (health, biometric, political opinions), very large customer volumes or extensive behavioural profiling through marketing and analytics plugins.

How do I implement WooCommerce compliantly?

Pick an EU host. Install a CMP that blocks marketing and analytics scripts before opt-in. Use the WooCommerce privacy settings to configure data retention and the predefined privacy notice template. Sign DPAs with your host, payment processor and every plugin vendor. Audit installed plugins quarterly. Use the built-in WordPress export and erase tools to handle data subject requests.

Are there privacy-friendly alternatives to WooCommerce?

EU-based open source alternatives include PrestaShop (France), Sylius (France) and Shopware (Germany). Hosted EU SaaS options include Lightspeed eCom (Belgium) and Wix Stores (Israel based but with EU hosting). The privacy result depends mostly on the hosting and integrations selected.

How should I update my cookie policy for WooCommerce?

List the strictly necessary WooCommerce cookies (woocommerce_cart_hash, woocommerce_items_in_cart, wp_woocommerce_session_*, woocommerce_recently_viewed) with name, purpose, duration and category. Add every cookie introduced by your theme, payment, shipping, analytics and marketing plugins. Document the consent mechanism and the third party processors involved.