A Data Protection Officer (DPO) is an independent role responsible for overseeing GDPR compliance, advising on data protection impact assessments, and acting as a contact point for supervisory authorities and data subjects. This guide is written for DPOs, privacy leads, and anyone accountable for vendor review or privacy policy language when evaluating Qusto for a merchant's store.
How to use this guide
Qusto sits in the analytics layer of a merchant's stack. That role has specific privacy implications: what identifiers are collected, where data is processed, and whether a cookie banner is still required for analytics once Qusto is deployed cookielessly. This guide is written for that review — factual and tier-aware, without marketing language.
For day-to-day dashboard use, see the operator guide. For installation mechanics on Shopify, see the Shopify guide.
Architectural commitments
These properties are structural — not configuration toggles merchants enable after legal review:
- Cookieless-by-design — no persistent cross-site identifiers for analytics measurement; coarse geo derived at ingest (country, region, city) without storing raw IP addresses for that purpose
- Open-core verifiability — Community Edition source is inspectable; managed hosting is optional
- EU data residency — analytics processing hosted in Europe
Qusto is intended to remove the analytics consent requirement when deployed in its cookieless mode. It does not remove consent obligations for advertising pixels, marketing cookies, or any third-party tags the merchant continues to run. Policy language should be scoped accordingly — "no cookie banner needed" is only accurate when the full stack has been reviewed.
Capability boundaries by tier
When approving external copy or sales materials, these boundaries matter:
| Topic | What to verify |
|---|---|
| Cart abandonment | Analytics visibility only — not recovery, win-back automation, or outbound email |
| Channel → revenue attribution | Available on Growth tier and above |
| Location intelligence | Visitor geography on all tiers; revenue and cart-abandonment by region on Growth+ |
Regulatory context
Cookie-consent violations — analytics or marketing tags firing before a visitor responds to a banner — remain among the most common, most avoidable categories in EU enforcement. Qusto's cookieless architecture is designed so the analytics layer itself does not depend on that consent interaction, provided the merchant's remaining stack does not reintroduce the requirement.
Shopify GDPR webhooks
For App Store distribution, Shopify requires mandatory compliance webhooks. Qusto implements handlers for:
customers/data_request— processed: export bundle + Data Monitor audit rowcustomers/redact— processed: token-scoped erasure + audit rowshop/redact— processed: full site commerce data redaction
Vendor-review checklist
Before sign-off, we suggest confirming:
- Which subscription tier the merchant will use — feature claims should match tier (Core vs Growth+)
- Whether any non-Qusto tags still require a separate consent management platform
- That the Data Processing Agreement and subprocessor list are acceptable for your organisation
- That location-related claims distinguish visitor geography from revenue-by-region (Growth+ only)