Skip to content

Medusa

MedusaJS, Inc. (Delaware, US); Danish operating subsidiary Medusa Commerce ApS, CVR 42394750, Store Kongensgade 55, 1264 Copenhagen K

E-commerce · Denmark
Founded 2021 · medusajs.com

Danish-built open-source commerce platform (MIT); Medusa Cloud is contracted with US parent MedusaJS, Inc., from $29/mo.

Medusa is operated by a US-incorporated entity and remains directly subject to the CLOUD Act. It is listed under E-commerce.

Assessment notes

Medusa is built in Copenhagen (Medusa Commerce ApS, CVR 42394750), but the Danish registry lists MedusaJS, Inc., a Delaware corporation, as the sole owner of that company, and the Medusa Cloud terms of service and DPA are both entered into with the US entity under California law. That makes the managed service directly reachable under US extraterritorial demands whatever region a project picks, so the EU eu-central-1 option does not repair the signal. The DPA is public and ungated, but no sub-processors list is published anywhere, and Medusa publishes no certification of its own, pointing instead to its unnamed infrastructure provider's. The MIT-licensed core is fully self-hostable and scored separately: that is the clean EU path.

Findings

CLOUD Act
Ownership
Sub-processors
— not disclosed

Verified signals

Jurisdiction
  • EU / adequacy hosting: Yes
  • EU / adequacy operator: Yes
  • No US CLOUD Act exposure: No
Transparency
  • Public DPA: Yes
  • Sub-processors disclosed: No
  • Open-source clients: Yes
  • Third-party certification: No
CLOUD Act by deployment

Exposure depends on how you run this product.

Hosted SaaS (default)

Vendor-operated: the sub-processors below apply.

Self-hosted (open-source)

Deploy on your own EU infrastructure and you control hosting and every sub-processor.

Jump to

About Medusa

Medusa is an open-source commerce platform started in Copenhagen in 2021 by Sebastian Rindom, Nicklas Gellner and Oliver Juhl. The core is a Node.js / TypeScript framework of composable commerce modules (products, carts, orders, pricing, promotions, inventory, fulfilment) plus a React admin dashboard, published under the MIT licence on GitHub with roughly 35,700 stars. Merchants named publicly by the vendor include Heineken, Mitsubishi Motors Netherlands, Eight Sleep and Redington; the Mitsubishi Netherlands store is self-hosted and was delivered by an implementation partner.

There are two ways to run it, and the sovereignty verdict differs sharply between them.

Medusa Cloud is the managed offering, from $29 per month on the Develop plan, then $99 and $299, with no GMV fee. A project picks one region at creation and cannot change it later: US East (us-east-1), Europe Central (eu-central-1) or Asia Southeast (ap-southeast-1). An EU region is therefore available but is not the default, and Medusa does not publicly name the underlying cloud provider, though the region codes and the per-environment private S3 bucket match AWS naming. The decisive fact for procurement is corporate rather than geographic: the Cloud terms of service and the DPA are both concluded with MedusaJS, Inc., a Delaware corporation, under California law, and Danish registry data lists that same US corporation as the sole owner of the Danish operating company. CLOUD Act exposure for the managed service is therefore Direct. The DPA is public and readable without an account, but no sub-processors list is published and Medusa publishes no certification of its own, saying only that its infrastructure provider maintains GDPR-aligned controls and certifications that Medusa leverages.

Self-hosting is the other path and it is genuinely unconstrained: the MIT licence carries no GMV cap and no paid commercial tier, and Medusa states there is no lock-in and that data can be exported at any time. Run on Hetzner, OVHcloud or Scaleway, no US counterparty touches the data at all.

Best fit: developer teams and agencies building bespoke commerce on Node.js. EU buyers who need a clean sovereignty story should take the self-hosted path rather than Cloud.

Sub-processor map · not disclosed

Vendor does not publish a sub-processors list. Schrems II compliance and CLOUD Act exposure cannot be independently verified without it.

Frameworks & certifications · none listed

We checked the vendor's website and standard certification body registries. No active certifications found at the time of last audit (2026-08-10).

Capability matrix

Table 1Capabilities of Medusa

Self-hostable Yes
Multi-currency Yes
Multilingual Yes
Product variants Yes
Multi-vendor marketplace No
Abandoned cart recovery No

Integration & access

REST API Yes
SSO (SAML / OIDC) Yes

Compliance & governance

Audit log Yes
Self-host / on-prem option Yes

Pricing & tiers

from $29/mo
Freemium
View pricing page

Public documents

Vendor does not publish a sub-processors list. Schrems II compliance and CLOUD Act exposure cannot be independently verified without it.
  • Data Processing Addendum (DPA)
    medusajs.com/terms-of-service…
    Open
  • Sub-processors list
    — missing
    missing
  • Terms of Service
    medusajs.com/terms-of-service…
    Open

Alternatives in this category

  • Germany · €600/mo
    EU-Hosted
    Public DPA: Yes Sub-processors: Yes Open source: Yes
  • France · €24/mo
    EU-Hosted
    Public DPA: Yes Sub-processors: Yes Open source: Yes
  • Poland
    EU-Sovereign
    Public DPA: No Sub-processors: No Open source: Yes