Medusa
A single roll-up of ownership and CLOUD Act exposure.
-
EU-Sovereign EU/EEA/Switzerland-owned and -operated, with no identified CLOUD Act exposure.
-
EU-Based EU-operated, with at most minor or transient US exposure.
-
EU-Hosted EU hosting available, but a US parent or hyperscaler sub-processor creates material exposure.
-
US-Linked This listing Operated by a US-incorporated entity, directly subject to US jurisdiction.
MedusaJS, Inc. (Delaware, US); Danish operating subsidiary Medusa Commerce ApS, CVR 42394750, Store Kongensgade 55, 1264 Copenhagen K
Danish-built open-source commerce platform (MIT); Medusa Cloud is contracted with US parent MedusaJS, Inc., from $29/mo.
Medusa is operated by a US-incorporated entity and remains directly subject to the CLOUD Act. It is listed under E-commerce.
Assessment notes
Medusa is built in Copenhagen (Medusa Commerce ApS, CVR 42394750), but the Danish registry lists MedusaJS, Inc., a Delaware corporation, as the sole owner of that company, and the Medusa Cloud terms of service and DPA are both entered into with the US entity under California law. That makes the managed service directly reachable under US extraterritorial demands whatever region a project picks, so the EU eu-central-1 option does not repair the signal. The DPA is public and ungated, but no sub-processors list is published anywhere, and Medusa publishes no certification of its own, pointing instead to its unnamed infrastructure provider's. The MIT-licensed core is fully self-hostable and scored separately: that is the clean EU path.
Findings
- CLOUD Act
- CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct This listing The operator itself is US-incorporated.
-
- Ownership
- Ownership
Where ultimate control over the operating company sits.
-
EU-owned EU-incorporated and EU-controlled; no significant US ownership.
-
EU HQ, US-funded EU-headquartered but US venture- or PE-controlled.
-
EU subsidiary, US parent This listing European operating company owned by a US parent company.
-
US-owned The operating company itself is US-headquartered.
-
Other A non-EU jurisdiction. Swiss/EEA-owned vendors count as European here; the UK and others do not.
-
- Sub-processors
- — not disclosed
Verified signals
-
EU / adequacy hosting: Yes
-
EU / adequacy operator: Yes
-
No US CLOUD Act exposure: No
-
Public DPA: Yes
-
Sub-processors disclosed: No
-
Open-source clients: Yes
-
Third-party certification: No
Exposure depends on how you run this product.
Vendor-operated: the sub-processors below apply.
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct This listing The operator itself is US-incorporated.
Deploy on your own EU infrastructure and you control hosting and every sub-processor.
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None This listing EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Jump to
About Medusa
Medusa is an open-source commerce platform started in Copenhagen in 2021 by Sebastian Rindom, Nicklas Gellner and Oliver Juhl. The core is a Node.js / TypeScript framework of composable commerce modules (products, carts, orders, pricing, promotions, inventory, fulfilment) plus a React admin dashboard, published under the MIT licence on GitHub with roughly 35,700 stars. Merchants named publicly by the vendor include Heineken, Mitsubishi Motors Netherlands, Eight Sleep and Redington; the Mitsubishi Netherlands store is self-hosted and was delivered by an implementation partner.
There are two ways to run it, and the sovereignty verdict differs sharply between them.
Medusa Cloud is the managed offering, from $29 per month on the Develop plan, then $99 and $299, with no GMV fee. A project picks one region at creation and cannot change it later: US East (us-east-1), Europe Central (eu-central-1) or Asia Southeast (ap-southeast-1). An EU region is therefore available but is not the default, and Medusa does not publicly name the underlying cloud provider, though the region codes and the per-environment private S3 bucket match AWS naming. The decisive fact for procurement is corporate rather than geographic: the Cloud terms of service and the DPA are both concluded with MedusaJS, Inc., a Delaware corporation, under California law, and Danish registry data lists that same US corporation as the sole owner of the Danish operating company. CLOUD Act exposure for the managed service is therefore Direct. The DPA is public and readable without an account, but no sub-processors list is published and Medusa publishes no certification of its own, saying only that its infrastructure provider maintains GDPR-aligned controls and certifications that Medusa leverages.
Self-hosting is the other path and it is genuinely unconstrained: the MIT licence carries no GMV cap and no paid commercial tier, and Medusa states there is no lock-in and that data can be exported at any time. Run on Hetzner, OVHcloud or Scaleway, no US counterparty touches the data at all.
Best fit: developer teams and agencies building bespoke commerce on Node.js. EU buyers who need a clean sovereignty story should take the self-hosted path rather than Cloud.
Sub-processor map · not disclosed
Frameworks & certifications · none listed
Capability matrix
Table 1Capabilities of Medusa
Integration & access
Compliance & governance
Pricing & tiers
Public documents
Alternatives in this category
-
Germany · €600/moEU-HostedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material This listing US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Yes Sub-processors: Yes Open source: Yes -
-
France · €24/moEU-HostedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material This listing US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Yes Sub-processors: Yes Open source: Yes -
-
PolandEU-SovereignCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None This listing EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: No Sub-processors: No Open source: Yes -
| Product | Sovereignty | CLOUD Act | Signals | From |
|---|---|---|---|---|
|
|
EU-Hosted | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Yes
Sub-processors: Yes
Open source: Yes
|
€600/mo |
|
|
EU-Hosted | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Yes
Sub-processors: Yes
Open source: Yes
|
€24/mo |
|
|
EU-Sovereign | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: No
Sub-processors: No
Open source: Yes
|
— |