Europe Alternatives
Shopware logo

Shopware

Schöppingen-headquartered German e-commerce platform with an MIT-licensed open-source core and SaaS, PaaS or self-hosted deployment.

🇩🇪 Germany

Profile last updated: · View sources

About Shopware

Shopware AG is a Schöppingen, North Rhine-Westphalia headquartered e-commerce platform founded in 2000 by brothers Stefan and Sebastian Hamann, who remain co-CEOs and the controlling shareholders. The legal entity is registered at Amtsgericht Coesfeld HRB 11471, VAT DE261679493; the management board is German and around 400 employees work from the Schöppingen HQ plus a US sales office in New York.

The Shopware 6 platform core is published under the MIT license at github.com/shopware/shopware and ships in three deployment models: a free Community Edition self-hosted on any infrastructure, a managed SaaS hosted on AWS Frankfurt eu-central-1, and a PaaS option on Upsun / Platform.sh over OVHcloud, Microsoft Azure France, Google Cloud France or AWS Europe. Named customers include Toyota Germany, AIDA Cruises, Philips, Stabilo, Thyssenkrupp, Veolia and the Rijksmuseum.

Features

  • Shopware 6 core under MIT license at github.com/shopware/shopware; current stable 6.7.10.0 (May 2026)
  • Three deployment models: managed SaaS on AWS Frankfurt, PaaS on Upsun / Platform.sh, or self-hosted on customer infrastructure
  • Self-hosted PaaS routes via OVHcloud / Microsoft Azure FR / Google Cloud FR / AWS Europe, or sovereign hosts (Hetzner / IONOS / Scaleway)
  • SaaS storage pinned to AWS eu-central-1 (Frankfurt) per DPA Annex IV; Datadog observability uses Datadog Germany region
  • Public DPA at shopware.com/en/privacy/dpa/ on EU Commission Implementing Decision 2021/915 SCCs; 3-month subprocessor change notice
  • ISO/IEC 27001:2022 certified ISMS via the Trust Center; certificate / validity available on request from Shopware
  • Operational controls per DPA Annex III: encryption in transit + at rest, four-eyes access, external DPO, GDPR Article 30 RoP
  • Strategic Upsun / Platform.sh partnership (Nov 2025) -- Franco-German sovereign-e-commerce alliance with 45+ joint customers
  • Customers include Toyota, AIDA Cruises, Philips, Thyssenkrupp, Veolia, Rijksmuseum, Schwalbe; Gartner Visionary 2025 (6th year)
  • Public vulnerability disclosure policy covering Shopware 6 / 5 / Cloud and Composable Frontends; coordinated 2-4 week fix window

Sovereignty Scorecard

Procurement-grade signals on data sovereignty, ownership, and EU residency.

The SHIELD framework

We score every European vendor against six sovereignty dimensions captured in the SHIELD acronym. Each card below maps to one letter — read them as a checklist when comparing providers.

S
Subprocessors

The third parties that touch customer data — payment processors, KYC vendors, support chatbots, analytics.

H
Headquarters & ownership

Where the legal entity sits, who controls it, and which subsidiaries operate under the same group.

I
Infrastructure & residency

Where customer data is physically stored, who runs the hosting stack, which CDN sits in front.

E
Exposure

Whether the vendor or its subprocessors fall under the US CLOUD Act or other extraterritorial reach.

L
Legal documents

Public terms, privacy policy, DPA, subprocessor list, impressum, and security or trust pages.

D
Diligence

Independent audits and certifications (ISO 27001, BSI C5, TISAX, SOC 2) plus open-source transparency.

Ownership

Privately held

European majority control

Parent: Shopware Holding GmbH (Germany)

Shopware AG (Amtsgericht Coesfeld HRB 11471) is 100 percent owned by Shopware Holding GmbH (Amtsgericht Coesfeld HRB 20410, same Schöppingen address). The holding company has three active shareholders: founders Stefan and Sebastian Hamann (through associated family vehicles, holding the significant majority and continuing on the Vorstand of the operating company) and PayPal Holdings, Inc. (Nasdaq: PYPL, around 41 percent since 2025-10-21). Shopware was bootstrapped from 2000 to 2022; the first and only external round closed 2022-02-08 with USD 100 million growth equity from Carlyle Europe Technology Partners IV and PayPal. On 2025-10-21 PayPal took over the entire Carlyle stake, taking PayPal from around 11 percent to around 41 percent and exiting Carlyle fully; financial terms were not disclosed. The Hamann brothers retain the majority and operational control of the company.

Headquarters

🇩🇪 Schöppingen, Germany

Shopware AG

Subsidiaries
  • Shopware US Inc. 🇺🇸 United StatesUS-incorporated subsidiary identified in the Shopware Holding GmbH registry filings as a held participation; opened in New York City in 2022 with Jason Nyhus appointed President and General Manager of Shopware US. Handles US sales and marketing; does not host the Shopware Cloud SaaS infrastructure, which remains on AWS Frankfurt eu-central-1 under Shopware AG.
Data residency
DE
EU
GB
US
CA
AU

Region selectable

SaaS storage is pinned to AWS eu-central-1 (Frankfurt) per the DPA Annex IV; Datadog Inc. as the observability subprocessor processes data in the Datadog Germany region. Shopware on Upsun PaaS is customer-selectable -- AWS Europe exposes EU / UK / US / CA / AU; Google Cloud France exposes EU / UK / US; Microsoft Azure France, OVHcloud and Platform.sh SAS as Upsun are EU-only. Self-hosted customers select their own residency. The DPA explicitly relies on EU Commission Implementing Decision 2021/915 standard contractual clauses for the Article 28 GDPR relationship.

Hosting infrastructure

Website: Fastly CDN in front of the marketing site (CNAME x.sni.global.fastly.net; HTTP response headers via: 1.1 varnish, x-served-by cache-muc13965-MUC observed from Fastly Munich PoP). Authoritative DNS for shopware.com and shopware.de is AWS Route 53.

Application: Shopware Cloud SaaS production runs on AWS EMEA SARL in eu-central-1 Frankfurt per DPA Annex IV. account.shopware.com resolves to Amazon EC2 instances in eu-central-1 (Frankfurt). api.shopware.com resolves to DigitalOcean Netherlands (AS14061, EU-DIGITALOCEAN-NL1).

Email: Microsoft 365 / Exchange Online tenant shopwareag.onmicrosoft.com for both shopware.com and shopware.de (separate MX terminators shopware-com.mail.protection.outlook.com and shopware-de.mail.protection.outlook.com). DKIM via selector1-shopware-com._domainkey.shopwareag.onmicrosoft.com; SPF v=spf1 include:spf.protection.outlook.com -all; DMARC p=quarantine pct=100 with strict alignment. Amazon SES handles outbound transactional email per the amazonses: TXT record.

CDN: Fastly for www.shopware.com and www.shopware.de (x-cache-layer: Fastly-Default response header).

Subprocessors
NameCountryPurpose
AWS EMEA SARL🇱🇺 LuxembourgShopware Cloud SaaS IaaS provider; storage location EU, region eu-central-1 in Frankfurt, Germany per DPA Annex IV. Also a customer-selectable IaaS option on the Shopware PaaS over Upsun with storage in EU, UK, US, CA or AU. US parent exposure via Amazon.com, Inc.
Datadog, Inc.🇺🇸 United StatesMonitoring and observability for Shopware Cloud SaaS per DPA Annex IV; data processed in the Datadog Germany region. New York-domiciled entity with direct CLOUD Act reach.
Microsoft Azure France🇫🇷 FranceShopware PaaS IaaS option through Upsun / Platform.sh; storage EU only per DPA Annex IV. French operating entity with US parent corporate exposure via Microsoft Corporation.
Google Cloud France SARL🇫🇷 FranceShopware PaaS IaaS option through Upsun / Platform.sh; storage EU, UK or US (customer-selectable) per DPA Annex IV. French operating entity with US parent corporate exposure via Google LLC.
OVH GROUPE SAS🇫🇷 FranceShopware PaaS IaaS option through Upsun / Platform.sh; storage EU only per DPA Annex IV. Pure-French operating entity with no US parent exposure.
Platform.sh SAS (doing business as Upsun)🇫🇷 FranceShopware PaaS provider; storage EU only per DPA Annex IV. Paris-headquartered with no US parent exposure. Partnership announced 2025-11-17 as a Franco-German alliance for European digital sovereignty in e-commerce.
Microsoft Corporation (Microsoft 365 / Exchange Online)🇺🇸 United StatesCorporate email termination for shopware.com and shopware.de via Exchange Online tenant shopwareag.onmicrosoft.com (observed in MX, DKIM and SPF DNS records). Internal use; not in the Shopware Cloud customer data path.
Usercentrics GmbH🇩🇪 GermanyConsent management platform for the shopware.com and shopware.de marketing sites; named in the website privacy policy as the operator selected for privacy-friendly criteria.
HubSpot, Inc.🇺🇸 United StatesMarketing CRM, lead-capture forms and tracking on shopware.com per the website privacy policy; both the US Cambridge MA entity and the HubSpot European Office in Dublin are named.
Amplitude, Inc.🇺🇸 United StatesProduct and website usage analytics for shopware.com per the website privacy policy (San Francisco, CA).
Functional Software, Inc. (Sentry)🇺🇸 United StatesApplication error and crash analysis for Shopware applications per the website privacy policy (San Francisco, CA).
Oktopost Technologies Inc. IsraelSocial media analytics for shopware.com per the website privacy policy; consent-based US data transfer.
Dreamdata🇩🇰 DenmarkB2B attribution and customer-journey analytics layered on the LinkedIn Insight Tag per the shopware.com website privacy policy.
PayPal (Europe) S.à r.l. et Cie, S.C.A.🇱🇺 LuxembourgPayment processing for shopware.com purchases per the website privacy policy; no intended third-country transfer declared. PayPal Holdings, Inc. is also the approximately 41 percent shareholder of Shopware Holding GmbH since 2025-10-21.
Unzer GmbH🇩🇪 GermanyPayment processor for shopware.com purchases per the website privacy policy (Vangerowstraße 18, 69115 Heidelberg).
Fastly, Inc.🇺🇸 United StatesCDN for www.shopware.com and www.shopware.de (CNAME x.sni.global.fastly.net; x-cache-layer Fastly-Default response header; Munich PoP observed).

Subprocessor list

Certifications
iso-27001
Certified

ISO/IEC 27001:2022 information security management system per the Shopware Trust Center. Certificate number, certifying body and validity dates are not published publicly and must be requested directly from Shopware.

soc-2-type-2
Self-assessed

Trust Center states verbatim: 'Our hosted environments also align with SOC 2 Type II principles' (German: 'Unsere Hosting-Umgebungen entsprechen den Grundsätzen von SOC 2 Type II'). No third-party SOC 2 Type II attestation report is published; the language is alignment with principles, not a certified Type II audit.

US CLOUD Act exposure
Partial, via US subsidiaries
Open source
Has open components
View source

Pricing

Community Edition

Free

no fee; self-hosted
  • MIT-licensed Shopware 6 core, self-hosted on the customer's PC, Mac, Linux server, hosting environment or virtual machine
  • Full open-source feature set including modular architecture, Symfony 7 backend, Vue.js 3 administration and Twig storefront
  • Community support via the Shopware forum, Discord and Stack Overflow; no SLA
  • Fair Usage Policy applies to high-volume Community Edition merchants: those scaling materially through their Shopware store are expected to move to a paid plan to keep access to the Shopware Account and Shopware Store services
Rise

from EUR 600/month

monthly, excluding VAT; deployable as SaaS, PaaS or self-hosted
  • Eight-hour reaction time, Monday to Friday
  • Includes Shopware Intelligence (AI), 3D capabilities and unlimited sales channels
  • Prices scale with gross merchandise value and individual factors per the public pricing page
Evolve

from EUR 2,400/month

monthly, excluding VAT; deployable as SaaS, PaaS or self-hosted
  • Four-hour reaction time with phone support
  • Adds B2B Components, Advanced Search and Dynamic Access on top of Rise
Beyond

Custom

contract; deployable as SaaS, PaaS or self-hosted
  • 24/7 support, one-hour reaction time, personal account manager and dedicated onboarding
  • Adds Digital Sales Rooms, Multi-Inventory and Subscriptions

Official downloads

Questions & Answers

6 questions

Where is Shopware headquartered, and which entity contracts with EU customers?

Shopware AG is the operating entity, registered at Amtsgericht Coesfeld under HRB 11471 with German VAT ID DE261679493 and registered office Ebbinghoff 10, 48624 Schöppingen, North Rhine-Westphalia, Germany. The two-member management board is founders Stefan Hamann and Sebastian Hamann; the supervisory board is chaired by Christoph Hertz. The parent of Shopware AG is the German holding company Shopware Holding GmbH (Amtsgericht Coesfeld HRB 20410, same Schöppingen address), in which the Hamann brothers hold the majority and PayPal Holdings, Inc. holds around 41 percent. EU and German customers contract with Shopware AG; the legal department contact for the data processing agreement is legal@shopware.com. A separate US entity, Shopware US Inc., handles sales and marketing in the United States but does not host the SaaS infrastructure.

Where is my data stored when I use Shopware Cloud or Shopware PaaS?

Shopware Cloud SaaS storage location is committed verbatim in DPA Annex IV: EU, region eu-central-1 in Frankfurt, Germany, on AWS EMEA SARL infrastructure. The observability subprocessor Datadog Inc. processes data in the Datadog Germany region. Shopware on Upsun PaaS lets the customer choose between AWS Europe (EU, UK, US, CA, AU), Microsoft Azure France (EU only), Google Cloud France (EU, UK, US), OVHcloud (EU only) and Platform.sh / Upsun itself (EU only). Customers who self-host the MIT-licensed Community or paid edition run Shopware entirely on their own infrastructure and choose their own residency. Annex II of the DPA declares that the processor does not collect or process Article 9 GDPR special-category data.

Is Shopware subject to US legal process under the CLOUD Act?

Shopware AG itself is a German private company controlled by its German management board, and the customer-data plane for Shopware Cloud SaaS sits in AWS Frankfurt. The CLOUD Act exposure runs through two indirect channels. First, the SaaS subprocessor chain: AWS EMEA SARL is a Luxembourg entity but ultimately a subsidiary of Amazon.com, Inc., and Datadog Inc. is a New York entity processing data in the EU region; both are reachable under 18 U.S.C. § 2713 for data within their possession, custody or control. Second, since 2025-10-21 PayPal Holdings, Inc. (Nasdaq: PYPL, US-listed) holds a strategic minority of around 41 percent of Shopware Holding GmbH after taking over the Carlyle Group stake; the Hamann brothers retain the majority and operational control, but PayPal is a US-listed shareholder with board representation. Customers who self-host on European sovereign hosts (such as Hetzner, IONOS, OVHcloud or Scaleway) or who pick the OVHcloud or Upsun PaaS regions avoid every US-domiciled processor in the production data path.

Is Shopware actually open source, or is it open core?

Shopware 6 publishes its full e-commerce core under the MIT license at github.com/shopware/shopware (Copyright 2019 shopware AG); the composer.json identifies the package as shopware/platform with type library and license MIT. The core is not crippled, dual-licensed or feature-gated relative to the paid editions: Community Edition users get the same MIT-licensed core that the Rise, Evolve and Beyond subscription editions extend with managed services, premium plugins (B2B Components, Advanced Search, Dynamic Access, Digital Sales Rooms, Multi-Inventory, Subscriptions) and managed cloud hosting. The Shopware Account portal and the Shopware Store extension marketplace are operated by Shopware as commercial services and gate above EUR 1 million annual GMV per the Fair Usage Policy, but the software itself is free to run. Around 3,100 community extensions are published in the Shopware Store, and Shopware was ranked No. 1 in open-source e-commerce software in the Emerce 100 2026.

Where can I find the Shopware subprocessor list?

Shopware publishes its subprocessor list directly in Annex IV of the Data Processing Agreement at shopware.com/en/privacy/dpa/ rather than on a separate page. The SaaS subprocessors are AWS EMEA SARL (IaaS, Frankfurt eu-central-1) and Datadog Inc. (monitoring, Germany region). The PaaS subprocessors are AWS EMEA SARL, Microsoft Azure France, Google Cloud France, OVHcloud and Platform.sh SAS doing business as Upsun. The shopware.com website itself uses a separate set of marketing and analytics processors disclosed in the website privacy notice at shopware.com/de/datenschutz/website/, including Usercentrics (consent management), HubSpot, Amplitude, Sentry, Dreamdata, Google products, Meta, LinkedIn, Microsoft Advertising, PayPal Luxembourg and Unzer; these never see Shopware Cloud customer data. Shopware commits to at least three months notice of any new subprocessor per Clause 7.7(a) of the DPA.

What deployment models does Shopware offer, and which one fits sovereignty-conscious buyers?

Every paid Shopware tier (Rise, Evolve, Beyond) is available as SaaS on AWS Frankfurt, as PaaS on Upsun over a customer-selectable European cloud region, or as a self-hosted installation on customer-controlled infrastructure. The free Community Edition is self-hosted only. The strongest sovereignty path is self-hosting the MIT-licensed core on a European host such as Hetzner, IONOS, OVHcloud or Scaleway, which removes Shopware AG from the data processing chain entirely. The next-strongest is Shopware on Upsun PaaS over the OVHcloud region, which keeps every subprocessor in the production data path in the European Union and avoids US-parent IaaS providers. Shopware Cloud SaaS on AWS Frankfurt offers EU residency but retains the AWS plus Datadog subprocessor chain with US-parent corporate exposure.

Alternatives

Other European companies in the same category as Shopware.

Quick facts

Languages supported
Deutsch
English
Categories
Alternative to

Sources & verification

Every fact on this page is backed by a primary or independent source. Most recent verification: May 15, 2026.

Found an error? Report it

Citations

Profile content

Tagline
Description
Languages
Pricing
Features
Q&A
Integrations
Downloads

Sovereignty (SHIELD)

SSubprocessors
  • primary · dpawww.shopware.com/en/privacy/dpaAnnex IV: SaaS subprocessors AWS EMEA SARL + Datadog Inc.; PaaS subprocessors AWS Europe, Microsoft Azure France, Google Cloud France, OVHcloud, Platform.sh SAS as Upsun
  • primary · privacy-policywww.shopware.com/de/datenschutz/websiteWebsite-marketing subprocessor stack named in the website privacy notice: Usercentrics, HubSpot, Amplitude, Sentry, Dreamdata, Oktopost, PayPal Luxembourg, Unzer. (Advertising-tracker partners like Google Ads, Meta, LinkedIn, Microsoft Advertising and Pinterest are also named in the same notice but are independent controllers per playbook line 199-201, not GDPR processors of Shopware's customer data, and are intentionally out of sovereignty.subprocessors[].)
  • primary · dns-recordsshopware.comMicrosoft 365 corporate email tenant shopwareag.onmicrosoft.com observed via MX, DKIM and SPF; Amazon SES outbound email; Fastly CDN front
HHeadquarters
HOwnership
HSubsidiaries
IData residency
  • primary · dpawww.shopware.com/en/privacy/dpaAnnex IV verbatim: 'Storage Location: EU, Region eu-central-1 in Frankfurt, Germany'; PaaS regions per provider; SCC Implementing Decision 2021/915
IHosting infrastructure
  • primary · dpawww.shopware.com/en/privacy/dpaAWS EMEA SARL eu-central-1 Frankfurt as Shopware Cloud SaaS IaaS
  • primary · dns-recordswww.shopware.comdig CNAME www.shopware.com → x.sni.global.fastly.net; dig A account.shopware.com → AWS EC2 eu-central-1; dig A api.shopware.com → DigitalOcean NL
  • primary · http-headerswww.shopware.com/de/impressumx-cache-layer: Fastly-Default; x-served-by: cache-muc13965-MUC; via: 1.1 varnish
  • primary · dns-recordsshopware.comMX shopware.com → shopware-com.mail.protection.outlook.com (Microsoft 365); DKIM selector1 CNAME → shopwareag.onmicrosoft.com; SPF Microsoft only; DMARC p=quarantine adkim=s aspf=s; amazonses: TXT for outbound SES
EUS CLOUD Act exposure
LLegal documents
DCertifications
DOpen source