
VTEX and GDPR
CertReports found no public GDPR evidence for VTEX as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.
Evidence
- Kind
- listing
- Issued or listed
- 12 Jul 2024
- Expires or valid through
- 6 Jul 2027
- Scope
- VTEX processes the personal data of Shoppers who access the e-commerce environments (the “VTEX Platform”) controlled by VTEX Clients ("Merchants"), available on the Merchants' websites or applications. VTEX is a processor of personal data and only collects and processes the personal data provided by Shoppers, within the VTEX Platform and according to the purposes defined by the Merchants to carry out all the steps necessary to complete the Shopper's purchases. VTEX processes the following personal data for the related purposes noted below: 1) Registration data provided by Shoppers such as: - Name; - E-mail; - Telephone number; - Applicable ID number, depending on the country of the Shopper. The above is processed for the purposes of Shopper registration in the relevant store, enabling navigation in the logged-in environment, making purchases and issuing invoices via the Merchant, and for the Merchant to contact the Shopper about their orders and, if necessary, for support purposes. 2) Access data to the VTEX Platform, such as: - IP address; - Browsing information collected through cookies; - Session passwords (encrypted); - Generated tokens. The above is processed for the purposes of improving the performance of the Store and the VTEX Platform, based on statistical analysis of browsing data, recording access logs on the Store and the VTEX Platform, as required by law, to guarantee information security and prevent fraud during the use of the Store and the VTEX Platform, and personalizing advertising to be offered by the Store. 3) Purchasing data, such as: - Cart information; - Order information and history; - Gift card history; - Unused trolley; - Delivery address. The above is processed for the purposes of enabling navigation in the logged-in environment as well enabling purchases in the Store in a personalized way, and enabling the Merchant to deliver the products correctly. 4) Contact data, such as: - Conversation history. The above is processed for the purposes of guarenteeing the consultation of conversations, requests for information and the resolution of doubts between Shopper and Merchant and possible use in dispute resolution. 5) Other personal data, if required by Merchant. VTEX discloses personal data to the following third parties: - Subprocessors (Service Providers) - Regulatory and legal authorities - Merchant's other third party service providers (on the Merchant's instructions) that Merchants use to integrate the Store with third-party environments, such as payment methods, CRM tools, logistics operators, etc.
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | VTEX: Active: EU-US Certification, SW-US Certification, UK Extension Certification | Live pagesha256 d7e9391935 |
What GDPR means, and what it does not
"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.
Read the GDPR guide and browse all vendors with evidenceQuestions buyers ask
Is VTEX GDPR compliant?
There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.
How does CertReports verify this?
Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.
Alternatives with GDPR evidence
Similar vendors (shared product tags or the E-commerce category) whose GDPR row is verified or vendor-stated, ranked by similarity.
No E-commerce vendor has GDPR evidence in the index yet.