Skip to main content

GDPR and Online Stores on Cartum

How to Prepare the Online Store for GDPR Requirements

GDPR — General Data Protection Regulation — a European Union law regarding data privacy and security. It came into effect on May 25, 2018, and sets rules for the collection, use, and storage of personal data by companies.

Who GDPR Requirements Apply To

These requirements also apply to online stores. Your site may be subject to data protection laws enacted both in your country and in the country of residence of your visitors/customers. If your business targets EU customers, your site must comply with GDPR requirements regardless of whether you or your business are located in the EU.

At Cartum, the security of personal data is important to us, and we take their protection seriously, ensuring the privacy and security of our customers and their visitors' data.

However, important steps must be taken on your part. Compliance with GDPR is the responsibility of every site owner. Here we have gathered some recommendations for preparing your site for GDPR requirements.

Note: any information in this and other articles in our Help Center is not legal advice or a comprehensive guide to action, and should not be considered legally reliable.

GDPR may require you to take certain actions depending on the regions you operate in and how you plan to use site visitors' data. If you are unsure of the measures to take, we recommend seeking legal advice from a relevant specialist.

How Cartum Processes Your Data

The processing and storage of provided personal data are carried out in data centers where the equipment that ensures the functioning of the Cartum platform services is located. The provided personal data is processed and may be stored in the Personal Data Database or in a separate table of the platform's Database.

Personal data is stored and processed at the address: OVH, Roubaix, France, 2 Rue Kellermann, 59100.

For more details on how the platform processes data from your site visitors, read our privacy policy.​

Your Site's Privacy Policy

Legislation requires online store owners to inform their visitors and customers in a transparent and understandable manner about what data they collect, for what purpose, and how they process it.

Privacy Policy — an official document that explains how a site or company collects, uses, protects, and stores users' personal data. Therefore, among other things, you need to create such a document so that visitors know how your site processes their data, including information about cookies and other tracking technologies.​

Create a privacy policy on the site and place it so that it is accessible to all visitors. We do not provide advice on the content of the privacy policy, but we have standard tools to easily place it.

How to Place a Privacy Policy on the Site

There is a separate information page for placing your privacy policy on the site. By default, the display of this page is disabled.

To place the privacy policy:

  1. Go to Site → Pages → User Agreement page.

  2. Go to edit the page.

  3. In the Text field, place the appropriate content in all the languages you use on the site.

  4. Check other settings and make the page available to visitors by checking the Display checkbox.

  5. Save the changes.

Note that having a published privacy policy on the site may be a mandatory requirement for connecting some third-party services, such as payment systems.

After publication, the policy will be available via a direct link, as well as in the info menu in the header and footer of the site.

Add Information About Store Terms and Policies on the Checkout Page

Draw the user's attention to the site's terms and policies during checkout. To do this, enable the consent checkbox that customers must check.

In the Cartum admin panel:

  1. Go to Settings → General Settings → Checkout.

  2. Select the state for the User Agreement field — Checkbox and text.

  3. Save the changes.

On the checkout page, users will see a checkbox agreeing to the site's terms of use; it must be checked to place an order.

In the text next to the checkbox "By confirming the order, I accept the terms of the user agreement," there will also be an active link to the store's terms and policies. You can change the consent text using Interface Translation.

Cookies

Cookies that are placed by default on your store's site are necessary. They ensure the performance of various functions of the online store. You can learn about the cookies we use in Cartum's Privacy Policy, which is part of our offer agreement.

Informer About Store Agreement and Policies

In the general site settings, you can enable an informer about the use of necessary cookies.

In the store admin panel:

  1. Go to Settings → General Settings → Cookies Window.

  2. Enable the display of the informer on the site in the required language versions.

  3. Save the changes.

During the first visit, visitors will see an informer with a warning text and an active link to the store's terms and policies and can confirm that they are informed about these terms.​

However, you can choose to connect various scripts, third-party systems, and integrations. Such systems may place other types of cookies on the site, for which explicit consent may be required under GDPR.

In this case, add a full-fledged consent banner to the site. With such a banner, your visitors can give informed consent to the placement of non-essential cookies on their devices.

Consent Banner for Using Cookies

The choice of a consent banner solution depends on the traffic, geography of your store's operations, the need for banner localization, etc. Experts recommend using one of the specialized Consent Management Platforms officially recommended by Google.

Most of these services have free plans that are quite sufficient for a small online store.

The most convenient solutions we can recommend are:

These solutions are actively used by popular sites; their banners are recognizable and inspire additional trust in visitors. Additionally, each of these solutions offers simple and clear explanations for setting up the appearance, options, and behavior of the banner.​
Some other useful options of such services include site scanning, automatic classification of cookies, and content generation for your privacy policies.

How to Install a Consent Banner on the Site

Most of the proposed consent banner services can be installed either through Google Tag Manager or by placing a simple script on the site pages.

Copy the script code in the service's cabinet and familiarize yourself with the instructions for placing it.

After that, in the Cartum admin panel:

  1. Go to Settings → General Settings → Scripts.

  2. Add the copied script code to the appropriate field.

  3. Save the changes.

You can also see instructions for these services in the Connecting Third-Party Systems section in our Help Center.

→ How to connect a consent banner from CookieScript

​

Consent to Receive Your Marketing Mailings

For email marketing mailings, you need to obtain the consent of the store's users.

If you use special services for mailings, such as eSputnik, Mailchimp, or similar, place the service's subscription form on the site using the processes created by it to obtain informed consent.

You can ask buyers for consent to receive mailings during checkout. Buyers can check a box agreeing to receive not only transactional but also marketing messages from you.

In the Cartum admin panel:

  1. Go to Settings → General Settings → Checkout.

  2. Enable the Consent to receive mailings checkbox and add a hint text for it.

  3. Save the changes.​

After setting up, buyers will see a checkbox on the checkout page and in the quick order form.

Additional Services and Systems

According to GDPR, you are responsible for any third-party services and applications you connect to your site. As a platform, we allow the connection of various services through Marketing Systems or the GTM container. These may include analytics services, various Google tools, Meta, other advertising services, etc.

Ensure that the services you connect comply with GDPR requirements. If you are unsure, contact the application developers directly to clarify this issue.

When you install a consent banner from CMP on the site, this service automatically scans the site and informs visitors about the use of non-essential cookies on it.

Did this answer your question?