Medusa.js

Medusa.js

Medusa.js is an open-source headless e-commerce platform that provides API-driven backend services for custom storefronts. It serves product catalogs, cart, and order data through REST and GraphQL endpoints. Browser-side scripts are determined by the storefront implementation rather than Medusa itself.

Overview

Medusa.js is an open-source, MIT-licensed headless commerce platform that provides a modular backend for building custom e-commerce storefronts. Unlike SaaS e-commerce platforms, Medusa runs on the merchant's own infrastructure and does not introduce third-party tracking scripts. The framework provides REST and GraphQL APIs for cart, product, order, and customer management; browser-side behavior is entirely determined by the storefront the developer builds on top of it.

What This Script Does

Medusa.js itself does not ship browser-side tracking scripts. Client-side behavior depends entirely on the storefront implementation:

  • Storefront API calls: The browser-side storefront (typically built with Next.js, Nuxt, or a custom framework) makes API requests to the Medusa backend at the merchant's own domain or a dedicated API subdomain (e.g., api.store.com). These are first-party requests.
  • Cart and session state: Session tokens and cart state are typically managed via cookies or localStorage set by the storefront application, scoped to the merchant's domain. Medusa's backend issues JWT tokens or session identifiers for authenticated customer flows.
  • No third-party beacons: Medusa does not send data to Medusa Inc.'s servers from the browser. There is no telemetry, analytics, or tracking code bundled into Medusa's client-side packages.
  • Plugin ecosystem: Third-party analytics or payment plugins integrated with Medusa (e.g., Stripe.js, Segment, Klaviyo) are independent of Medusa itself and have their own consent requirements.

Consent & Compliance

GDPR and ePrivacy: Medusa.js is self-hosted open-source infrastructure. It does not impose any third-party data flows from the browser. Cart and authentication cookies are strictly necessary for the e-commerce functionality and are exempt from consent requirements under the ePrivacy Directive. The merchant is the sole data controller for all data processed through their Medusa implementation.

CCPA/CPRA: No personal information is transmitted to Medusa's servers from the browser. The merchant's own data practices govern all consumer data collected through the storefront.

This vendor is classified as essential and functional. It is backend infrastructure with no third-party tracking footprint.

Should You Block This Without Consent?

No.

Medusa.js is self-hosted open-source e-commerce infrastructure. There are no third-party tracking scripts to block. Consent management for a Medusa-based store should focus on the third-party tools the developer chooses to integrate (analytics platforms, ad pixels, payment processors) rather than Medusa itself.

Is Medusa.js GDPR compliant?

Medusa.js typically loads functional trackers, which are not strictly necessary for your site to work. Under the GDPR and the ePrivacy Directive, non-essential cookies and trackers must stay blocked until a visitor gives clear opt-in consent. So Medusa.js can be fully GDPR compliant, but only if your site holds its scripts until consent is granted and lets visitors decline just as easily. Compliance depends on how your site loads Medusa.js, not on Medusa.js itself.

Visit website

Consent Categories

Also Known As

medusa jsmedusajsheadless ecommercemedusa commerceopen source ecommerce consent

Industries

Programming and Developer SoftwareComputers Electronics and Technology

Tracked Domains (1)

medusajs.comEssential

medusajs.com is an essential domain operated by Medusa.js, used to keep the site working, including security, load balancing, and sessions.

Frequently Asked Questions

Related Vendors

accessiBe
accessiBe
accessiBe is an AI-powered web accessibility platform that remediates WCAG and ADA compliance gaps. Scripts inject a widget interface for users to adjust contrast, font size, and motion preferences. The AI engine scans and adjusts page elements for screen reader and keyboard navigation compatibility.
Mutiny
Mutiny
Mutiny is a website personalization platform. Its scripts identify visitor companies and audience segments using IP-based lookups and cookies, then dynamically modify page content, headlines, and calls to action in real time. They collect visitor behavior data and transmit segment information to Mutiny servers for targeting analytics.
Absorb LMS
Absorb LMS
Absorb LMS is a cloud-based learning management system. Its scripts serve course content, track learner progress, and manage authentication for training portals. They set session and authentication cookies, store completion state in browser storage, and transmit learner activity data to Absorb servers.
Joomla
Joomla
Loads core CMS functionality scripts on Joomla-powered websites, including extension integrations and component libraries. Third-party Joomla extensions may load additional scripts that collect usage analytics or personal data depending on the plugins installed and configured by site operators.
Lemon Squeezy
Lemon Squeezy
Lemon Squeezy is a payment and subscription platform for selling digital products and software. Its scripts embed checkout overlays and payment forms on websites, handle secure payment processing through iframe-based flows, and may set cookies to maintain cart state and attribute purchase sessions.
Imgix
Imgix
Imgix is an image content delivery network and real-time processing service. It serves optimized images from global edge servers using URL-based transformations for resizing, cropping, and format conversion. It does not set cookies or collect personal data, operating purely as an asset delivery layer.

Manage consent for Medusa.js

ConsentStack automatically detects and manages Medusa.js trackers so your site stays compliant with global privacy regulations.