Commerce.com and GDPR
CertReports found no public GDPR evidence for Commerce.com as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.
Evidence
- Kind
- listing
- Issued or listed
- 11 Oct 2016
- Expires or valid through
- 26 Jan 2027
- Scope
- Commerce collects and processes data to provide, maintain, protect, develop, and improve the products we offer to our customers, detect and prevent potential fraud and security risks, and support Commerce internal business operations (i.e., billing). To the extent that any such data is capable of being used to identify (alone or in conjunction with other data, an individual), it is treated as personal data. Commerce may receive and process personal data as a data processor. As a data processor, we act on the instructions of our customers. As a data processor, Commerce will only disclose personal information as instructed by our customer or as required by applicable law. Merchants and Prospective Merchants: Types of data: ● Account Information means data about how and when a Commerce.com account is accessed and the features used ○ Information which identifies you in relation to your account with us for example: store number or ID. ○ Plan information ○ Time and date stamp for access. ○ Information about how you use your account ○ information about your store, its products, and its architecture. ● Browser Information means data provided by a browser such as ○ IP address ○ the website visited ○ network connection data ○ device information ○ Cookie data ● Contact Information means basic personal and business information such as ○ first and last name, ○ company name ○ email address ○ postal address ○ phone number ○ social media account information. ● Payment Information means data about payment methods such as: ○ credit card ○ ACH ○ other payment information. ● Support Information is data used to support the data subject and includes: ○ information about your hardware and software used, ○ authentication data, ○ chat session contents, ○ error reports, ○ performance data, ○ other communication or technical information ○ Information about remote access to facilitate troubleshooting when authorized. ● Device Information means information about your device collected from the devices when accessing our website, using the Mobile App, or any of our services, such as ○ device ID number, ○ device model, ○ device manufacturer, ○ operating system ○ geographical region of the device ● Security Information means information used for authentication and account access ○ user ID ○ password ○ password hints ○ other security information used for authentication and account access. ● Transaction Information means the data related to transactions that occur on our platform, such as ○ Product ○ Orders, ○ shipping information, ○ Contact Information ○ Payment Information. ● Usage Information means information collected when you interact with the Commerce.com website, Mobile App or any of our services, such as ○ functionalities accessed, ○ pages visited ○ other interaction data. Who is the data Shared with: ● Partners where the Merchant/Prospect authorizes the sharing of their data. Partners are separate legal entities that participate in Commerce’s Agency Partner Program, Technology Partner Program or other third-party technology integration with the Commerce.com platform, such as a theme designer, reseller, or referrer of the services. ● Third-Party Service Providers/ Contractors- Providers of a Service which is Controlled by Commerce for the enablement of our business and the services we provide. ● Third-Party Product Providers which are the providers of Third-Party Products that the data subject engages with or enables that we do not Control and which are not a part of our product (for example: ReCAPTCHA or Youtube videos), this is further described in 8.7. ● Commerce Affiliates: means entities operated and controlled by Commerce and includes any subsidiaries and affiliates. These entities include companies with the names and marks of Commerce, BigCommerce, Feedonomics, and Makeswift, such as Commerce.com US, Inc., a Texas corporation in the United States; Commerce Software UK Ltd., a United Kingdom limited company, Commerce Software Ireland Ltd., an Irish limited company, Commerce.com Pty. Ltd., an Australia proprietary limited company, Feedonomics Holdings LLC, a Delaware corporation in the United States, and Makeswift, Inc., a Delaware Corporation in the United States. Partners and Prospective Partners: Types of Data: ● Account Information means data about how and when a Commerce.com account is accessed and the features used ○ Store number ○ Plan level ○ Information about how you use your account ○ information about your store, its products, and its architecture. ● Browser Information means data provided by a browser such as ○ IP address ○ the website visited ○ network connection data ○ device information ○ Cookie data ● Contact Information means basic personal and business information such as ○ first and last name, ○ company name ○ email address ○ postal address ○ phone number ○ social media account information. ● Payment Information means data about payment methods such as: ○ credit card ○ ACH ○ other payment information. ● Support Information is data used to support the data subject and includes: ○ information about your hardware and software used, ○ authentication data, ○ chat session contents, ○ error reports, ○ performance data, ○ other communication or technical information ○ Information about remote access to facilitate troubleshooting when authorized. ● Security Information means information used for authentication and account access ○ user ID ○ password ○ password hints ○ other security information used for authentication and account access. ● Usage Information means information collected when you interact with the Commerce.com website, Mobile App or any of our services, such as ○ functionalities accessed, ○ pages visited ○ other interaction data. Who is the data shared with: ● Merchants- Those who are our customer/ consumers of our platform. that they can engage the Partner when interested in the partners product or service offering. ● Third-Party Service Providers/ Contractors- Providers of a Service which is Controlled by Commerce for the enablement of our business and the services we provide. ● Third-Party Product Providers which are the providers of Third-Party Products that the data subject engages with or enables that we do not Control and which are not a part of our product (for example: ReCAPTCHA or Youtube videos), this is further described in 8.7. ● Commerce Affiliates-means entities operated and controlled by Commerce and includes any subsidiaries and affiliates. These entities include companies with the names and marks of Commerce, BigCommerce, Feedonomics, and Makeswift, such as Commerce.com US, Inc., a Texas corporation in the United States; Commerce Software UK Ltd., a United Kingdom limited company, Commerce Software Ireland Ltd., an Irish limited company, Commerce.com Pty. Ltd., an Australia proprietary limited company, Feedonomics Holdings LLC, a Delaware corporation in the United States, and Makeswift, Inc., a Delaware Corporation in the United States. Visitors: Types of Data: ● Browser Information means data provided by a browser such as ○ IP address ○ the website visited ○ network connection data ○ device information ○ Cookie data ● Contact Information means basic personal and business information such as ○ first and last name, ○ company name ○ email address ○ postal address ○ phone number ○ social media account information. ● Support Information is data used to support the data subject and includes: ○ information about your hardware and software used, ○ authentication data, ○ chat session contents, ○ error reports, ○ performance data, ○ other communication or technical information ○ Information about remote access to facilitate troubleshooting when authorized. ● Usage Information means information collected when you interact with the Commerce.com website, Mobile App or any of our services, such as ○ functionalities accessed, ○ pages visited ○ other interaction data. Who is the data shared with: ● Third-Party Service Providers/ Contractors- Providers of a Service which is Controlled by Commerce for the enablement of our business and the services we provide. ● Third-Party Product Providers which are the providers of Third-Party Products that the data subject engages with or enables that we do not Control and which are not a part of our product (for example: ReCAPTCHA or Youtube videos). This is further described in 8.7. ● Commerce Affiliates -means entities operated and controlled by Commerce and includes any subsidiaries and affiliates. These entities include companies with the names and marks of Commerce, BigCommerce, Feedonomics, and Makeswift, such as Commerce.com US, Inc., a Texas corporation in the United States; Commerce Software UK Ltd., a United Kingdom limited company, Commerce Software Ireland Ltd., an Irish limited company, Commerce.com Pty. Ltd., an Australia proprietary limited company, Feedonomics Holdings LLC, a Delaware corporation in the United States, and Makeswift, Inc., a Delaware Corporation in the United States. We also generally share for the following reason ● Compliance obligations ● Protection of Merchants, Prospects, Partners, Shoppers, Visitors, or others ● To operate and maintain security or to stop or prevent an attack on our computer systems and networks. ● Payment Processing ● Change of Control (i.e., Merger or Acquisition)
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | Commerce.com: Active: EU-US Certification, SW-US Certification, UK Extension Certification | Live pagesha256 016a811220 |
What GDPR means, and what it does not
"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.
Read the GDPR guide and browse all vendors with evidenceQuestions buyers ask
Is Commerce.com GDPR compliant?
There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.
How does CertReports verify this?
Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.
Alternatives with GDPR evidence
Similar vendors (shared product tags or the E-commerce category) whose GDPR row is verified or vendor-stated, ranked by similarity.
No E-commerce vendor has GDPR evidence in the index yet.