Back to Tools
theMarketer logo

theMarketer

GDPR Compliant

Romanian email, SMS and push marketing platform for e-commerce, and one of the few in this directory that publishes its full sub-processor list with countries.

πŸ‡·πŸ‡΄RomaniaπŸ‡ͺπŸ‡ΊEU HostedπŸ‡ͺπŸ‡Ί European

Subject to the US CLOUD Act: a US provider in this tool's processing chain can be compelled to disclose data it holds, including data stored in the EU. The vendor itself is European-owned.

Paid
theMarketer website screenshot

GDPR Compliance Data

Not independently verified
GDPR Status
GDPR Compliant
HQ CountryRomania
OwnershipEuropean-owned
Foreign Disclosure ExposureUS CLOUD Act / FISA 702
Data Hosting Location
European UnionThe published data processing addendum names each sub-processor with its country: "Hetzner (Germany) - for hosting services", "Amazon Web Services EMEA SARL and Sendgrid (USA) - email marketing services", "Google Firebase, Ireland - for push notification services", "Google Ads, Ireland" (themarketer.com/data-processing-addendum, read 2026-09-01). So the platform and contact database sit on Hetzner in Germany, while email delivery passes through AWS and SendGrid listed as USA.
EU Servers Available
Data Processing AgreementView DPA
Sub-processor ListView sub-processors
Schrems II Risk
Medium Risk
SCCs in Place
Last Verified1 September 2026

How we reached this

Romanian legal entity: S.C The Marketer International Srl, Strada Badea CΓ’rΘ›an 66, Sector 2, Bucharest, Trade Register J40/7641/21.04.2022, fiscal code RO46003544, from the privacy policy read 2026-09-01. Governing law is Romania. COMPLIANT because the data processing addendum is published at a public URL and, unusually, names every sub-processor with the country it operates in, which is the evidence standard this directory rates on and which most larger competitors do not meet. The policy also draws the controller/processor line explicitly: theMarketer is controller for its own site and account data, processor for beneficiary data pushed through the platform. Exposure is US_CLOUD_ACT and Schrems II risk MEDIUM, and the reason is worth reading rather than skipping: the platform and contact database are hosted on Hetzner in Germany, a German company on German infrastructure, but email delivery runs through Amazon Web Services and SendGrid, both listed as USA in the addendum. SendGrid is Twilio, a US company. So recipient addresses pass through a US provider even though the database does not. sccInPlace left false: the addendum names the US sub-processors but no transfer mechanism was stated for them, which is the one thing missing from an otherwise strong document. Noted separately: Google Analytics, Google Ads, Google Tag Manager and Dynamic Remarketing run on theMarketer's own website, which concerns their marketing rather than customer data.

About theMarketer

A Romanian E-commerce Platform That Shows Its Working

theMarketer covers the usual e-commerce marketing ground: campaigns across email, SMS and push, behavioural automation, segmentation, and integration into shop platforms. What lifts it above several better-known names in this directory is not a feature. It is that the company published a data processing addendum with the sub-processors actually named.

The Sub-processor List, Which Most Vendors Hide

From themarketer.com/data-processing-addendum:

Sub-processorPurposeCountry
HetznerHostingGermany
Amazon Web Services EMEA SARL, SendGridEmail marketing servicesUSA
Google FirebasePush notificationsIreland
Google AdsCustom audiencesIreland

Read what that actually tells you, because it is more than most vendors let you know.

The platform is hosted on Hetzner in Germany: a German company, German infrastructure, no American provider holding the database. That is a genuinely good position.

But the email delivery runs through AWS and SendGrid, and the addendum lists them as USA. SendGrid is Twilio, an American company. So the messages themselves, and therefore your recipients' addresses, pass through a US provider even though the contact database sits in Germany. That is the reason this listing carries US CLOUD Act exposure while a tool like Maileon does not.

None of that is a criticism of theMarketer. It is the normal architecture for a platform this size, and almost every competitor does something similar. The difference is that theMarketer wrote it down where you can read it before signing, and most of its competitors did not. That is worth a great deal when you are the one who has to answer a DPIA question.

The Company

S.C The Marketer International Srl, Strada Badea CΓ’rΘ›an 66, Sector 2, Bucharest, Trade Register J40/7641/21.04.2022, fiscal code RO46003544. The privacy policy is explicit about the split that trips people up: theMarketer is controller for its own website and account data, and processor for the beneficiary data its customers push through it, with the addendum governing the second relationship.

The platform is protected by password plus two-factor authentication, and the policy notes that support will only ever ask you to create an administrator account for a limited period, never for your password. Governing law is Romania.

The one gap: Google Analytics, Google Ads, Google Tag Manager and Dynamic Remarketing all run on theMarketer's own website. That is about their marketing, not your data, but it is worth noting on a page that otherwise reads as unusually careful.

Where It Fits

Against Ecomail and ExpertSender for e-commerce automation in Central and Eastern Europe. On published evidence rather than on features, theMarketer is ahead of both. See marketing automation.

Key Features

Email, SMS and push campaigns from one platform
Behavioural marketing automation for e-commerce
Segmentation and customer data management
Shop platform integrations
Published sub-processor list with countries
Two-factor authentication on accounts
Campaign reporting and analytics
Romanian-language support and governing law

Pros & Cons

Publishes a full sub-processor list with countries, which most larger competitors do not
Platform and contact database hosted on Hetzner in Germany, a German company
Draws the controller/processor line explicitly rather than blurring it
Email, SMS and push in one tool rather than three subscriptions
Support policy states it will never ask for your password
Email delivery runs through AWS and SendGrid, both listed as USA, so recipient data reaches a US provider
No transfer mechanism stated for those US sub-processors
Google Analytics, Ads, Tag Manager and Dynamic Remarketing all run on their own site
Smaller ecosystem and integration surface than the international platforms
Primarily aimed at the Romanian and regional e-commerce market

theMarketer GDPR & data protection: common questions

Is theMarketer GDPR compliant?

Yes. On the evidence we checked, theMarketer meets the requirements European businesses usually need. theMarketer is a European company headquartered in Romania, data is hosted within the European Union, and a Data Processing Agreement is published.

Where does theMarketer store data?

theMarketer states: "The published data processing addendum names each sub-processor with its country: "Hetzner (Germany) - for hosting services", "Amazon Web Services EMEA SARL and Sendgrid (USA) - email marketing services", "Google Firebase, Ireland - for push notification services", "Google Ads, Ireland" (themarketer.com/data-processing-addendum, read 2026-09-01). So the platform and contact database sit on Hetzner in Germany, while email delivery passes through AWS and SendGrid listed as USA.". Data is hosted within the European Union.

Does theMarketer offer a Data Processing Agreement (DPA)?

Yes. theMarketer publishes a DPA at https://themarketer.com/data-processing-addendum. A DPA is required under Article 28 GDPR whenever a provider processes personal data on your behalf.

What a DPA has to cover β†’

Is theMarketer a European company?

Yes. theMarketer is headquartered in Romania and, as far as we can establish, European-owned.

Is theMarketer subject to the US CLOUD Act?

Indirectly. theMarketer itself is European-owned and headquartered in Romania, so the company is not subject to US jurisdiction. The exposure runs through a US provider in its processing chain, a host, CDN or other sub-processor, which can be compelled to disclose data it holds even when that data sits on EU servers. That is a narrower exposure than a US-owned vendor, and the compliance notes above say which provider it is.

Schrems II compliance checklist β†’

Who are theMarketer's sub-processors?

theMarketer publishes its sub-processor list at https://themarketer.com/data-processing-addendum. Worth reading: a vendor hosting in the EU can still route data through non-EU sub-processors, which is where residency claims usually come apart.

Spotted something wrong?

Martech moves fast. Vendors change hosting regions, get acquired, publish a new DPA or rewrite their pricing, and they rarely announce it. We check what we publish and date every compliance review, but some of what you see here will be out of date before we catch it.

If you work at theMarketer and something on this page is wrong, tell us and we will fix it. Readers, same invitation. Pointing us at the page that proves it gets it changed fastest.