Back to Tools
Saleor logo

Saleor

GDPR Compliant

Polish open source headless commerce API with a managed cloud, a published DPA and EEA data storage stated in its terms.

🇵🇱Poland🇪🇺EU Hosted🇪🇺 EuropeanFreemium
Saleor website screenshot

GDPR Compliance Data

Not independently verified
GDPR Status
GDPR Compliant
HQ CountryPoland
OwnershipEuropean-owned
Foreign Disclosure ExposureNot yet verified
Data Hosting Location
European Union"Saleor Commerce declares that data, including personal data, provided by the Customer will be stored in the European Economic Area (EEA) or outside EEA" with GDPR-compliant security measures for such a transfer. Source: saleor.io/legal/terms (read 2026-08-24). No specific cloud provider or region is named.
EU Servers Available
Data Processing AgreementView DPA
Sub-processor ListNot verified
Schrems II Risk
Medium Risk
SCCs in Place
Last Verified24 August 2026

How we reached this

Saleor Commerce sp. z o.o., Tęczowa 7, 53-601 Wrocław, Poland, named in the terms of use, which also give a Wrocław address for notices. EU-owned. Terms declare EEA storage as the norm with transfers outside the EEA contemplated under GDPR-compliant safeguards, so dataHostingLocation is EU with that caveat recorded. A DPA is published at saleor.io/legal/dpa/. extraterritorialExposure is UNKNOWN because no cloud provider is named anywhere public: if Saleor Cloud runs on a US hyperscaler, CLOUD Act reach would apply to the host, and that question should be put to the vendor. The open source core is self-hostable, which removes the vendor from the path entirely.

About Saleor

Commerce as an API

Saleor has no storefront. It is a GraphQL API for products, carts, checkout, payments, orders and fulfilment, and the shop front is whatever you build against it, typically Next.js. That makes it a fit for teams who already have a frontend practice and want commerce as a service in their own stack, and a poor fit for anyone expecting to install a shop.

Apps extend it out of process rather than as plugins in the core, which keeps upgrades from becoming archaeology.

Polish Company, EEA Storage

The terms of use name Saleor Commerce sp. z o.o. at Tęczowa 7, 53-601 Wrocław, Poland. On data, they state that Saleor Commerce "declares that data, including personal data, provided by the Customer will be stored in the European Economic Area (EEA) or outside EEA" with security measures compliant with GDPR for any such transfer.

That is a real commitment with a real caveat attached, and the caveat is worth reading rather than skipping. EEA storage is the stated norm; storage outside it is contemplated and covered rather than excluded.

A data processing agreement is published at a stable URL, which puts Saleor ahead of most of this category.

Self-Host to Remove the Question

The open source core is BSD-licensed and self-hostable. Running it on European infrastructure removes the vendor from the data path entirely, and unlike some open core products the self-hosted version is the same commerce engine rather than a cut-down one.

Compare with the other headless option here, commercetools, which is more enterprise and less transparent about ownership.

More in ecommerce platforms.

Key Features

GraphQL-first headless commerce API
Open source core, self-hostable
Apps extension model running out of process
Multi-channel, multi-currency and multi-warehouse
Saleor Cloud managed hosting
Published DPA

Pros & Cons

Polish company with a published DPA at a stable URL
Terms state EEA storage as the norm
Self-hosting uses the same engine as the managed product
No cloud provider or region named for Saleor Cloud
Terms contemplate storage outside the EEA rather than excluding it
No storefront, so a frontend team is a prerequisite

Saleor GDPR & data protection: common questions

Is Saleor GDPR compliant?

Yes. On the evidence we checked, Saleor meets the requirements European businesses usually need. Saleor is a European company headquartered in Poland, data is hosted within the European Union, and a Data Processing Agreement is published.

Where does Saleor store data?

Saleor states: ""Saleor Commerce declares that data, including personal data, provided by the Customer will be stored in the European Economic Area (EEA) or outside EEA" with GDPR-compliant security measures for such a transfer. Source: saleor.io/legal/terms (read 2026-08-24). No specific cloud provider or region is named.". Data is hosted within the European Union.

Does Saleor offer a Data Processing Agreement (DPA)?

Yes. Saleor publishes a DPA at https://saleor.io/legal/dpa/. A DPA is required under Article 28 GDPR whenever a provider processes personal data on your behalf.

What a DPA has to cover

Is Saleor a European company?

Yes. Saleor is headquartered in Poland and, as far as we can establish, European-owned.

Spotted something wrong?

Martech moves fast. Vendors change hosting regions, get acquired, publish a new DPA or rewrite their pricing, and they rarely announce it. We check what we publish and date every compliance review, but some of what you see here will be out of date before we catch it.

If you work at Saleor and something on this page is wrong, tell us and we will fix it. Readers, same invitation. Pointing us at the page that proves it gets it changed fastest.