
Medusa
Partially CompliantDanish-built open source commerce engine in Node.js, incorporated in the United States as MedusaJS, Inc.
Subject to the US CLOUD Act: a US parent company can be compelled to disclose data it holds, including data stored in the EU.
Freemium
GDPR Compliance Data
Not independently verified| GDPR Status | Partially Compliant |
| HQ Country | United States |
| Ownership | Non-European |
| Foreign Disclosure Exposure | US CLOUD Act / FISA 702 |
| Data Hosting Location | UnknownNot published for Medusa Cloud. The open source engine is self-hosted, so its location is the buyer's choice. The privacy policy covers only website and marketing data and states explicitly that it "does not apply to any of the personal information that our customers may process using Medusajs products and services". Source: medusajs.com/privacy-policy (read 2026-08-24). |
| EU Servers Available | |
| Data Processing Agreement | Not verified |
| Sub-processor List | Not verified |
| Schrems II Risk | Medium Risk |
| SCCs in Place | |
| Last Verified | 24 August 2026 |
How we reached this
Commonly listed as a Danish or European tool. The founding team is Danish and the project is associated with Copenhagen, but the privacy policy states "Who We Are: MedusaJS, Inc.", a US corporate form, and names no European entity, so ownershipOrigin is NON_EU. The distinction that matters: the engine is MIT licensed and self-hosted, so a European merchant running it on European infrastructure gives MedusaJS, Inc. no access to order data at all and has no transfer to document. Exposure US_CLOUD_ACT and Schrems II MEDIUM apply to Medusa Cloud, the managed offering from a US company, whose region is not published. euServerAvailable is true on the strength of self-hosting. No DPA was located and the privacy policy explicitly excludes customer data processed through the products, which is governed by separate contracts a Cloud buyer must obtain.
About Medusa
Commerce Modules in TypeScript
Medusa is a Node.js commerce engine composed of modules: products, carts, orders, payments, fulfilment, each replaceable. Teams already building in TypeScript can extend it in the language they use rather than dropping into PHP, which is most of its appeal against Sylius and Shopware.
The admin is a React application, the API is REST and the storefront is yours to build. Like Saleor, this is infrastructure for a development team, not software for a marketing team.
Danish in Origin, American in Law
Medusa is routinely listed as a European tool. The founding team is Danish and the project is strongly associated with Copenhagen.
The company is not European. The privacy policy states "Who We Are: MedusaJS, Inc.", a US corporate form, and it uses Google Analytics for its own site. There is no European legal entity named in its published documents.
Why That Matters Less Here Than Elsewhere
For a self-hosted Medusa deployment, it matters very little. The engine is MIT licensed, runs on your own infrastructure, and MedusaJS, Inc. never sees an order. A European merchant self-hosting on a European provider has no transfer to document and no vendor exposure at all, which is the case for every open source project on this list regardless of who owns the trademark.
It matters if you use Medusa Cloud, the managed offering. Then you are a customer of a US company, and the CLOUD Act and FISA 702 apply to whatever it holds. The privacy policy is explicit that it does not cover customer data processed through the products, which is governed by separate contracts, so a Medusa Cloud buyer needs to read those contracts rather than the policy.
More in ecommerce platforms.
Key Features
Pros & Cons
Categories
Medusa GDPR & data protection: common questions
Is Medusa GDPR compliant?
Partly. Medusa meets some of the requirements, with caveats worth reading before you commit. Medusa is based in United States, outside the EU/EEA.
Where does Medusa store data?
Medusa states: "Not published for Medusa Cloud. The open source engine is self-hosted, so its location is the buyer's choice. The privacy policy covers only website and marketing data and states explicitly that it "does not apply to any of the personal information that our customers may process using Medusajs products and services". Source: medusajs.com/privacy-policy (read 2026-08-24).". Data is hosted in a location we have not been able to verify. An EU region is available.
Does Medusa offer a Data Processing Agreement (DPA)?
We could not locate a published DPA for Medusa. That does not mean one is unavailable. Many vendors provide it on request or inside the account area rather than publishing it. Ask before you sign.
What a DPA has to cover βIs Medusa a European company?
No. Medusa is based in United States, outside the EU/EEA. It may still be a sound choice (EU hosting and a signed DPA matter more than a flag) but the ownership is not European.
Is Medusa subject to the US CLOUD Act?
Yes. US authorities can compel disclosure of data held by a US company or its subsidiaries, regardless of the country the servers sit in. EU hosting alone does not remove this, the question is who controls the data, not where the disk is.
Schrems II compliance checklist βRelated Tools

Shopware
German commerce platform available self-hosted or as managed cloud, with an open source community edition.

PrestaShop
French open source ecommerce platform, self-hosted, whose own hosted services run on Google Cloud in the United States.

Saleor
Polish open source headless commerce API with a managed cloud, a published DPA and EEA data storage stated in its terms.
Spotted something wrong?
Martech moves fast. Vendors change hosting regions, get acquired, publish a new DPA or rewrite their pricing, and they rarely announce it. We check what we publish and date every compliance review, but some of what you see here will be out of date before we catch it.
If you work at Medusa and something on this page is wrong, tell us and we will fix it. Readers, same invitation. Pointing us at the page that proves it gets it changed fastest.