Back to Tools
Medusa logo

Medusa

Partially Compliant

Danish-built open source commerce engine in Node.js, incorporated in the United States as MedusaJS, Inc.

πŸ‡ΊπŸ‡ΈUnited StatesπŸ‡ͺπŸ‡ΊEU HostedNon-EU Β· United States

Subject to the US CLOUD Act: a US parent company can be compelled to disclose data it holds, including data stored in the EU.

Freemium
Medusa website screenshot

GDPR Compliance Data

Not independently verified
GDPR Status
Partially Compliant
HQ CountryUnited States
OwnershipNon-European
Foreign Disclosure ExposureUS CLOUD Act / FISA 702
Data Hosting Location
UnknownNot published for Medusa Cloud. The open source engine is self-hosted, so its location is the buyer's choice. The privacy policy covers only website and marketing data and states explicitly that it "does not apply to any of the personal information that our customers may process using Medusajs products and services". Source: medusajs.com/privacy-policy (read 2026-08-24).
EU Servers Available
Data Processing AgreementNot verified
Sub-processor ListNot verified
Schrems II Risk
Medium Risk
SCCs in Place
Last Verified24 August 2026

How we reached this

Commonly listed as a Danish or European tool. The founding team is Danish and the project is associated with Copenhagen, but the privacy policy states "Who We Are: MedusaJS, Inc.", a US corporate form, and names no European entity, so ownershipOrigin is NON_EU. The distinction that matters: the engine is MIT licensed and self-hosted, so a European merchant running it on European infrastructure gives MedusaJS, Inc. no access to order data at all and has no transfer to document. Exposure US_CLOUD_ACT and Schrems II MEDIUM apply to Medusa Cloud, the managed offering from a US company, whose region is not published. euServerAvailable is true on the strength of self-hosting. No DPA was located and the privacy policy explicitly excludes customer data processed through the products, which is governed by separate contracts a Cloud buyer must obtain.

About Medusa

Commerce Modules in TypeScript

Medusa is a Node.js commerce engine composed of modules: products, carts, orders, payments, fulfilment, each replaceable. Teams already building in TypeScript can extend it in the language they use rather than dropping into PHP, which is most of its appeal against Sylius and Shopware.

The admin is a React application, the API is REST and the storefront is yours to build. Like Saleor, this is infrastructure for a development team, not software for a marketing team.

Danish in Origin, American in Law

Medusa is routinely listed as a European tool. The founding team is Danish and the project is strongly associated with Copenhagen.

The company is not European. The privacy policy states "Who We Are: MedusaJS, Inc.", a US corporate form, and it uses Google Analytics for its own site. There is no European legal entity named in its published documents.

Why That Matters Less Here Than Elsewhere

For a self-hosted Medusa deployment, it matters very little. The engine is MIT licensed, runs on your own infrastructure, and MedusaJS, Inc. never sees an order. A European merchant self-hosting on a European provider has no transfer to document and no vendor exposure at all, which is the case for every open source project on this list regardless of who owns the trademark.

It matters if you use Medusa Cloud, the managed offering. Then you are a customer of a US company, and the CLOUD Act and FISA 702 apply to whatever it holds. The privacy policy is explicit that it does not cover customer data processed through the products, which is governed by separate contracts, so a Medusa Cloud buyer needs to read those contracts rather than the policy.

More in ecommerce platforms.

Key Features

Modular open source commerce engine in TypeScript
MIT licensed and self-hostable
React admin application
Replaceable modules for payments, fulfilment and inventory
REST API with a headless storefront
Medusa Cloud managed hosting

Pros & Cons

Self-hosting keeps order data entirely away from the vendor
Extensible in TypeScript rather than PHP
MIT licence with no open core restriction on the engine
The company is MedusaJS, Inc., a US entity, despite the Danish origin story
No hosting region published for Medusa Cloud
Privacy policy covers only marketing data, not the product
Requires a development team

Medusa GDPR & data protection: common questions

Is Medusa GDPR compliant?

Partly. Medusa meets some of the requirements, with caveats worth reading before you commit. Medusa is based in United States, outside the EU/EEA.

Where does Medusa store data?

Medusa states: "Not published for Medusa Cloud. The open source engine is self-hosted, so its location is the buyer's choice. The privacy policy covers only website and marketing data and states explicitly that it "does not apply to any of the personal information that our customers may process using Medusajs products and services". Source: medusajs.com/privacy-policy (read 2026-08-24).". Data is hosted in a location we have not been able to verify. An EU region is available.

Does Medusa offer a Data Processing Agreement (DPA)?

We could not locate a published DPA for Medusa. That does not mean one is unavailable. Many vendors provide it on request or inside the account area rather than publishing it. Ask before you sign.

What a DPA has to cover β†’

Is Medusa a European company?

No. Medusa is based in United States, outside the EU/EEA. It may still be a sound choice (EU hosting and a signed DPA matter more than a flag) but the ownership is not European.

Is Medusa subject to the US CLOUD Act?

Yes. US authorities can compel disclosure of data held by a US company or its subsidiaries, regardless of the country the servers sit in. EU hosting alone does not remove this, the question is who controls the data, not where the disk is.

Schrems II compliance checklist β†’

Spotted something wrong?

Martech moves fast. Vendors change hosting regions, get acquired, publish a new DPA or rewrite their pricing, and they rarely announce it. We check what we publish and date every compliance review, but some of what you see here will be out of date before we catch it.

If you work at Medusa and something on this page is wrong, tell us and we will fix it. Readers, same invitation. Pointing us at the page that proves it gets it changed fastest.