Analytics for DPOs & privacy leads

If you are accountable for GDPR, vendor review, or privacy policy language, this page summarises how Qusto is designed — what it does architecturally, where its scope ends, and what to check before you approve it for a merchant's store.

← Documentation

A Data Protection Officer (DPO) is an independent role responsible for overseeing GDPR compliance, advising on data protection impact assessments, and acting as a contact point for supervisory authorities and data subjects. This guide is written for DPOs, privacy leads, and anyone accountable for vendor review or privacy policy language when evaluating Qusto for a merchant's store.

How to use this guide

Qusto sits in the analytics layer of a merchant's stack. That role has specific privacy implications: what identifiers are collected, where data is processed, and whether a cookie banner is still required for analytics once Qusto is deployed cookielessly. This guide is written for that review — factual and tier-aware, without marketing language.

For day-to-day dashboard use, see the operator guide. For installation mechanics on Shopify, see the Shopify guide.

Architectural commitments

These properties are structural — not configuration toggles merchants enable after legal review:

Qusto is intended to remove the analytics consent requirement when deployed in its cookieless mode. It does not remove consent obligations for advertising pixels, marketing cookies, or any third-party tags the merchant continues to run. Policy language should be scoped accordingly — "no cookie banner needed" is only accurate when the full stack has been reviewed.

Capability boundaries by tier

When approving external copy or sales materials, these boundaries matter:

TopicWhat to verify
Cart abandonmentAnalytics visibility only — not recovery, win-back automation, or outbound email
Channel → revenue attributionAvailable on Growth tier and above
Location intelligenceVisitor geography on all tiers; revenue and cart-abandonment by region on Growth+

Regulatory context

Cookie-consent violations — analytics or marketing tags firing before a visitor responds to a banner — remain among the most common, most avoidable categories in EU enforcement. Qusto's cookieless architecture is designed so the analytics layer itself does not depend on that consent interaction, provided the merchant's remaining stack does not reintroduce the requirement.

Shopify GDPR webhooks

For App Store distribution, Shopify requires mandatory compliance webhooks. Qusto implements handlers for:

Vendor-review checklist

Before sign-off, we suggest confirming:

Privacy policy → Data Processing Agreement → Operator guide →