Back to Tools
Alokai logo

Alokai

Partially Compliant

Polish frontend and integration layer for headless commerce, formerly Vue Storefront, with a US group company for international clients.

🇵🇱PolandPaid
Alokai website screenshot

GDPR Compliance Data

Not independently verified
GDPR Status
Partially Compliant
HQ CountryPoland
OwnershipEuropean-owned
Foreign Disclosure ExposureNot yet verified
Data Hosting Location
UnknownNot published. The privacy policy names no cloud provider or region for the Alokai platform, referring only to "email and server hosting providers" among the recipients of data. Source: alokai.com/privacy-policy (read 2026-08-24).
EU Servers Available
Data Processing AgreementNot verified
Sub-processor ListNot verified
Schrems II Risk
Unknown
SCCs in Place
Last Verified24 August 2026

How we reached this

Controller named as Alokai Sp. z o.o., registered office in Warsaw (00-032), KRS 0000870326, NIP 5272942049, share capital PLN 4,011,480. EU-owned. The same policy refers to a group entity "located in the USA (a company within the Alokai group, responsible for servicing international clients)", so which entity a customer contracts with is not automatic and a European buyer should confirm it is the Polish one. Transfers outside the EEA are committed to occur "only when it is necessary and with an adequate level of protection ensured", naming Commission adequacy decisions and standard contractual clauses, hence sccInPlace true. No hosting region, cloud provider or DPA is published, so dataHostingLocation, exposure and Schrems II risk are UNKNOWN. Given that Alokai's middleware proxies storefront and checkout traffic, the hosting region is the first question to resolve in procurement. Formerly Vue Storefront.

About Alokai

The Layer in Front of the Backend

Alokai does not sell commerce. It sells the storefront and the plumbing: a Next.js or Nuxt frontend, a middleware layer that normalises calls to whichever commerce, CMS, search and payment backends you have chosen, and hosting and observability around it.

That makes it complementary to most of this category rather than competitive with it. Teams pairing commercetools or Saleor with a custom frontend often end up rebuilding this integration layer themselves, and Alokai's argument is that they should not have to.

Polish Controller, US Group Entity

The privacy policy names the controller as Alokai Sp. z o.o., registered office in Warsaw (00-032), KRS 0000870326, NIP 5272942049, share capital PLN 4,011,480. A properly identified Polish company.

The same policy also refers to a group entity "located in the USA (a company within the Alokai group, responsible for servicing international clients)". So the group has an American arm, and which entity a given customer contracts with will depend on where they are. A European customer should confirm they are contracting with the Polish entity rather than the US one, because that single fact changes the analysis completely.

On transfers, the policy commits to sending personal data outside the EEA "only when it is necessary and with an adequate level of protection ensured", naming adequacy decisions and standard contractual clauses as the mechanisms.

The Gap

No hosting region is published for Alokai's own cloud, and no DPA was found at a public URL. For a layer that proxies every storefront request, including checkout traffic, that is the first thing to nail down in procurement.

More in ecommerce platforms.

Key Features

Next.js and Nuxt storefront frameworks
Middleware normalising commerce, CMS, search and payment backends
Prebuilt integrations for major headless platforms
Managed hosting and observability for the frontend layer
Storefront UI component library

Pros & Cons

Polish controller identified with KRS and NIP numbers
Removes bespoke integration work between frontend and headless backends
Commits to adequacy decisions or SCCs for any transfer outside the EEA
A US group entity services international clients, so check which entity you contract with
No hosting region or cloud provider published
No DPA at a public URL, despite proxying checkout traffic

Alokai GDPR & data protection: common questions

Is Alokai GDPR compliant?

Partly. Alokai meets some of the requirements, with caveats worth reading before you commit. Alokai is a European company headquartered in Poland.

Where does Alokai store data?

Alokai states: "Not published. The privacy policy names no cloud provider or region for the Alokai platform, referring only to "email and server hosting providers" among the recipients of data. Source: alokai.com/privacy-policy (read 2026-08-24).". Data is hosted in a location we have not been able to verify.

Does Alokai offer a Data Processing Agreement (DPA)?

We could not locate a published DPA for Alokai. That does not mean one is unavailable. Many vendors provide it on request or inside the account area rather than publishing it. Ask before you sign.

What a DPA has to cover →

Is Alokai a European company?

Yes. Alokai is headquartered in Poland and, as far as we can establish, European-owned.

Spotted something wrong?

Martech moves fast. Vendors change hosting regions, get acquired, publish a new DPA or rewrite their pricing, and they rarely announce it. We check what we publish and date every compliance review, but some of what you see here will be out of date before we catch it.

If you work at Alokai and something on this page is wrong, tell us and we will fix it. Readers, same invitation. Pointing us at the page that proves it gets it changed fastest.