whats-best.ai

E-Commerce Platforms & Shop Systems

Shopware

EU-Made Report an error

Panel rating · 6 judges · How to read the stars

Category median

Sovereignty: not determined

0–5 in half steps. 5 means the rubric's top anchor is met on the evidence.

by shopware AG · www.shopware.com

Compare with JTL-Shop → Compare with Gambio → Report an error on this page Is this your product? →

Read this page as one judge. Each weighs the same scores by what they care about.

The Data Protection Officer

Weighted verdict

The shop holds customers, addresses and buying histories, and the checkout is full of third parties. Wants the subprocessor list, consent handling that survives a complaint, deletion that executes against order history, and an answer on where the CDN and analytics sit.

Same scores as the panel view — this lens weights them the way this judge cares.

Scored by The Data Protection Officer

Catalogue & checkout

How this is scored

Products, variants, pricing rules and the path to payment — the part that either converts or does not.

0 — Flat product list with one price and no variants; checkout is a form and one payment method.

3 — Variants and categories with a standard checkout and two or three payment methods, but no bundles, no tiered pricing and no guest checkout worth the name.

5 — Full variant matrix, product bundles, tiered and customer-group pricing, guest checkout, and the payment methods a German shop needs including invoice and direct debit.

8 — Configurable products, per-channel pricing, promotions and vouchers with rules, a checkout that can be customised without a rebuild, and payment via the major providers plus buy-now-pay-later where offered.

10 — Merchandising and checkout are the product: rule-driven pricing and promotions, A/B-testable checkout, multi-currency and multi-language as standard, and conversion features (abandoned cart, one-page checkout) shipped rather than bolted on.

Report an error

The Data Protection Officer

Variants are properly modelled — parent-child inheritance, a configurator assembled for each variant product, hierarchical categories — and payments sit on a documented handler architecture with synchronous and asynchronous flows, PayPal the one provider named. We found no public information on bundles, tiered pricing, guest checkout, or German-standard payment methods such as invoice and direct debit; customer-specific prices appear only in the Beyond tier. The checkout is clearly extendable, but the conversion machinery itself is not evidenced. 1 2 5 6

Report an error

Extensibility & developer surface

How this is scored

Themes, apps, APIs and headless — whether the shop can be shaped to the business, and at what cost in lock-in.

0 — Fixed templates, no app ecosystem, no API.

3 — Theme editing within limits and a small app store; a read-mostly API and no local development story.

5 — Custom themes with a template language, an app or plugin ecosystem, a documented REST API, and webhooks for the core order events.

8 — Full storefront API for headless builds, an extension framework with its own lifecycle, staging environments, version control for themes, and documented rate limits.

10 — A platform a team can own: headless-first APIs, open-source or source-available core, plugin architecture with a real dependency model, local development and CI supported, and upgrade paths that do not orphan customisations.

Report an error

The Data Protection Officer

The developer surface is real: plugins are Symfony bundles and Composer packages with a dependency model, the Store API is a documented service-based route system with decorators, and the payment flow is explicitly designed for headless use. The Community Edition is open source and self-hosted, so a team can run the whole thing. We found no public information on staging environments, theme version control or documented rate limits, and the documentation states plugins are not compatible with the cloud stores, where apps are required instead. 1 6 9 10

Report an error

Order operations & back office

How this is scored

What happens after checkout: order management, stock, returns, shipping, and the link to ERP or accounting.

0 — An order list and an email; stock is a number nobody trusts, returns are manual.

3 — Order statuses and basic stock, one shipping integration, and returns handled by hand.

5 — Order workflow with partial shipments, multi-warehouse stock, named carrier integrations with label printing, and a returns process in the system.

8 — Multi-channel order intake, automated fulfilment routing, supplier and dropshipping flows, and maintained interfaces to named ERP and accounting systems.

10 — The shop is the front of an operation: real-time stock across channels and warehouses, returns and refunds fully worked including partials, ERP integration the vendor maintains, and operational reporting a merchant runs the business from.

Report an error

The Data Protection Officer

The order model is workflow-built: three state machines for order, transaction and delivery with configurable, otherwise blocked transitions, and partial states throughout — shipped partially, returned partially, refunded partially — so partial shipments, returns and refunds are worked into the core. Multi-inventory arrives only with the Beyond tier, and shipping appears as an integration category without named carriers, label printing, or any named ERP or accounting system. We found no public information on fulfilment routing, dropshipping or operational reporting. 1 2 11 12

Report an error

Data ownership & exit

How this is scored

Whether the catalogue, customers and order history remain the merchant's: export completeness, hosting choice, and what leaving actually costs.

0 — Export is a partial CSV; order history and customer records cannot leave intact, and hosting is the vendor's alone.

3 — CSV export of products and customers, order history partial, no self-hosting, no documented migration path.

5 — Complete export of catalogue, customers and orders via API or dump, documented deletion, and a stated data-return commitment.

8 — Full-fidelity export including media and order documents, self-hosting or a choice of hosting partner, and no metering that prices a migration out of reach.

10 — Ownership is structural rather than promised: open-source or source-available platform the merchant can run anywhere, database-level access, documented migration in both directions, and contractual data return.

Report an error

The Data Protection Officer

Ownership is partly structural: the Community Edition is open source and self-hosted, orders are denormalised and persisted independently of the catalogue, and numerous data-portability and management tools are claimed. The Migration Assistant is documented in depth — connections, profiles, gateways, dedicated media handling, checksum-based deltas — but the captured pages describe migrating into Shopware; we found no public information on a documented export or exit path out, on deletion executing against order history, or on a data-return commitment. 1 11 14

Report an error

European sovereignty

How this is scored

Where customer and order data live, who the contracting entity is, and which subprocessors sit in the checkout path. Independently sourced by the sovereignty pipeline.

0 — Non-EU vendor and contracting entity, hosting unstated or non-EU, subprocessors unnamed.

3 — EU hosting offered as an option while the contracting entity is non-EU, or the subprocessor list is absent.

5 — EU hosting as standard and an EU contracting entity, but parts of the chain — CDN, analytics, payment routing, support tooling — are non-EU without an explained safeguard.

8 — EU hosting on named infrastructure, EU contracting entity, complete subprocessor list published, any non-EU processing named with its legal basis.

10 — Sovereign end to end and evidenced: vendor, entity, hosting and every subprocessor European, certification published, and a self-hosted option that puts the shop entirely under the merchant's control.

Report an error

The Data Protection Officer

The contracting entity is solidly European — shopware AG, registered at the Amtsgericht Coesfeld, seat in Schöppingen, German VAT ID — and European data centres are claimed alongside self-hosting, PaaS and SaaS, with a data processing agreement on the EU Commission's standard contractual clauses plus ISO 27001 and SOC 2 Type II stated. We found no public information on a subprocessor list, on where the CDN, analytics or payment routing sit, or on confirmed data residence for the hosted offerings beyond a data-centre claim made in the context of the Copilot. A German entity with an unnamed processing chain — and a compliance statement that privacy standards in the USA and further markets are also met — leaves the checkout path unaccounted for. 1 3 4

Report an error

Pricing transparency

How this is scored

Whether a merchant can compute the real annual cost — licence, transaction fees, apps, hosting — from public pages alone. The category where the headline price is least often the invoice.

0 — No public prices at all; every tier is a sales conversation.

3 — A monthly headline exists, but transaction fees, mandatory apps or hosting costs are unstated — the invoice is unknowable from the page.

5 — Tier prices public with billing period stated and transaction fees given, but at least one commonly needed piece (a required app, hosting, payment gateway rate) is unpriced.

8 — Every tier priced publicly including transaction or revenue-share rates, order or GMV limits, and the cost of the extensions most shops need; VAT treatment and minimum term stated.

10 — Complete price computability: annual cost derivable for a given order volume and GMV including licence, transaction fees, hosting and typical extensions — and for open-source platforms, an honest statement that the licence is free and where the money actually goes.

Report an error

The Data Protection Officer

Tier prices are public with VAT treatment stated — Community Edition at € 0, Rise "Ab € 600 /Monat exkl. MwSt.", Evolve "Ab € 2.400 /Monat exkl. MwSt." — and the Intelligence+ add-on is priced per tier, with Nexus in a free introductory phase carrying a non-binding review limit of 10,000 requests per customer and calendar month. From-pricing and an individually quoted Beyond tier mean the annual invoice is not computable from the page, and we found no public information on transaction or revenue-share fees, order or revenue limits, minimum terms, or the cost of the extensions most shops need beyond that one add-on. 1 2

Report an error

European sovereignty — proven facts

0 of 4 dimensions proven

Built only from facts shown on the vendor's own pages. A dimension we could not prove is left open, not scored as zero.

Ownership Not determined — uncited Report an error
Data residency Not determined ⚠ unverified — uncited Report an error
Subprocessors Not determined — uncited Report an error

Where this could be wrong

What we left out

A claim that does not survive our checks costs us the claim, not the page. This is what was taken off this one.

Sources (14)

The pages every claim on this page was read from — each one checked, dated, and kept verifiable.

  1. 1 Vendor homepage www.shopware.com Checked 5 Oct 2026 Details →
  2. 2 Pricing www.shopware.com Checked 5 Oct 2026 +2 earlier captures: 15 Sep 2026, 31 Aug 2026 Details →
  3. 3 Imprint www.shopware.com Checked 5 Oct 2026 Details →
  4. 4 Privacy policy www.shopware.com Checked 5 Oct 2026 +2 earlier captures: 15 Sep 2026, 11 Sep 2026 Details →
  5. 5 Catalogue & checkout — found from sitemap developer.shopware.com Checked 5 Oct 2026 Details →
  6. 6 Catalogue & checkout — found from sitemap developer.shopware.com Checked 5 Oct 2026 Details →
  7. 7 Tax & German legal correctness — found from sitemap developer.shopware.com Checked 5 Oct 2026 Details →
  8. 8 Tax & German legal correctness — found from sitemap developer.shopware.com Checked 5 Oct 2026 Details →
  9. 9 Extensibility & developer surface — found from sitemap developer.shopware.com Checked 5 Oct 2026 Details →
  10. 10 Extensibility & developer surface — found from sitemap developer.shopware.com Checked 5 Oct 2026 Details →
  11. 11 Order operations & back office — found from sitemap developer.shopware.com Checked 5 Oct 2026 Details →
  12. 12 Order operations & back office — found from sitemap developer.shopware.com Checked 5 Oct 2026 Details →
  13. 13 Data ownership & exit — found from sitemap developer.shopware.com Checked 5 Oct 2026 Details →
  14. 14 Data ownership & exit — found from sitemap developer.shopware.com Checked 5 Oct 2026 Details →