Legal Notices, Cookie Banners & Product Safety
You can manage the legal notice, terms and conditions, privacy policy, and return policy in the CMS Manager or have them provided by a legal text provider. This guide shows where the store displays which information, how cookie banners and proof of consent work, and where you can enter the manufacturer’s product safety information.
At a Glance
- Legal texts: Under CMS → CMS Manager on the “Legal Notice,” “Privacy Policy,” “Terms and Conditions,” “Right of Withdrawal,” and “Shipping and Payment” pages. These pages are permanently enabled. Therefore, their status cannot be changed.
- Legal text providers: You can connect Händlerbund, janolaw, and IT-Recht Kanzlei under Settings → Interfaces → Legal Portals. Händlerbund and janolaw retrieve the texts when someone logs into the backend, at most once a day. IT-Recht Kanzlei sends updates on its own initiative.
- Cookie Banner: Settings → Privacy → General → Cookie Consent Tool: Set the mode to “
modal.” Each configured service is assigned its own category; none is preselected. - Record-keeping: The store saves every selection made in the cookie banner and every consent given in forms under Tools → Privacy Management.
- Product Safety: You can maintain the manufacturer’s address and the responsible person in the EU under Products → Manufacturer. The product page displays this information in the “About the Manufacturer…” tab.
In this guide
There are separate guides for the cancellation button, the EU warranty label, consent for Google Analytics and Google Ads, and for other advertising platforms.
What’s Where in the Store
The required pages are set up in every store. The table shows where you enter each piece of information and where your customers see it.
| Information | Where to enter it | Where it appears |
|---|---|---|
| Legal Notice | CMS → CMS Manager, “Legal Notice” page | Separate page; in the cookie banner (expandable) |
| Privacy Policy | "Privacy Policy" page | Separate page; in the cookie banner; included as a PDF in the order confirmation by default |
| Terms and Conditions | "Terms and Conditions" page | Separate page; during the order process; as a PDF only if you enable it |
| Right of Withdrawal | "Right of Withdrawal" page | Separate page; during the ordering process; included as a PDF with the order confirmation |
| Sample Withdrawal Form | Module $cms_withdrawal | Included as a PDF with the order confirmation |
| Shipping and Payment Terms | “Delivery and Payment” page | Separate page |
| Battery Disposal Guidelines | Module $cms_battery_notice | Separate page |
| Authenticity of Customer Reviews | Page “Information on the Authenticity of Customer Reviews” | See the Reviews & Seals Guide |
| Text of the Cookie Banner | Module $cms_cookie_information | Cookie Banner |
| Company Name and Address | Settings → General → Basic Settings → Store Address and Contact Information | Emails, Sample Withdrawal Form, Sender for Shipping Interfaces |
| Manufacturer’s Product Safety Information | Products → Manufacturer | "About the Manufacturer..." tab on the product page |
You can configure what the store attaches as a PDF to the order confirmation under Settings → Interfaces → Email Marketing / CRM → Email Options; see the CMS Manager & Emails Guide.
Maintain Legal Texts in the CMS
A new store contains sample texts. Replace them with your own, reviewed texts in every language your store supports before going live.
To change a legal text
- Open CMS → CMS Manager.
- Click “Edit” next to the page, such as “Terms and Conditions” or “Privacy Policy.”
- Replace the text in each language tab.
- Save and review the page in the store.
Why the required pages cannot be disabled
The Legal Notice, Privacy Policy, Terms and Conditions, Right of Withdrawal, Shipping and Payment, and almost all other pages that come with the store are system pages. Their status toggle is locked, and the “Store Content Page” toggle is missing. The store references these pages in many places: in the cookie banner, in emails, and during the checkout process.
For these system pages, the “CMS Page Name” is predefined; the store displays it as the page title, for example, in the cookie banner. You can edit the text, the SEO name, and the meta tag title. You can enable or disable pages that you create yourself. If a required page in an older store is set to “inactive,” please contact us.
The privacy policy page is a system page: The status toggle is locked, the “Shop Content Page” toggle is missing, and you maintain the text on each language tab. Click to enlarge.
Multiple Languages
- Each page has a tab for each language. Edit the text for every language in which your store sells.
- If you’ve set up automatic translation with DeepL, it will also cover the pages in the CMS Manager. After saving, the shop will mark the page for a new translation. Review translated legal texts or obtain versions in other languages from your legal text provider. For details on how the translation works, see the Languages & Translation Guide.
- If your texts come from a legal text provider, they will only provide the languages you have subscribed to there; see Legal Text Providers.
PDF Attachments to the Order Confirmation
By default, the store attaches the right of withdrawal notice, sample withdrawal form, and privacy policy as PDFs to the order confirmation, but not the Terms and Conditions. You can add the Terms and Conditions by going to Settings → Interfaces → Email Marketing / CRM → Email Options → Order Confirmation Email Attachment (PDF Terms and Conditions).
If the PDF generated by the store does not look good due to complex formatting, upload your own PDF file and enter its name under Settings → General → Basic Settings: “Alternative Terms and Conditions PDF File,” “Alternative Cancellation Policy PDF File,” or “Alternative Privacy Policy PDF File.” The order summary will then also link to these files. Remember to replace them whenever you make any changes to the text.
Legal Texts from a Provider
The shop supports three legal text providers. They can be found under Settings → Interfaces → Legal Portals. The provider writes its texts directly into the pages of the CMS Manager.
| Händlerbund | janolaw | IT-Recht Kanzlei | |
|---|---|---|---|
| Setup | Enter the “Händlerbund API - AccessToken” | Enter “janolaw User ID” and “janolaw Shop ID” | Set the “IT-Recht Kanzlei Interface Status” to “ true,” enter the “IT-Recht Kanzlei API Token” in the law firm’s portal, and select the “XONIC” Shop System there |
| Texts | Terms and Conditions, Cancellation Policy, Legal Notice, Shipping and Payment, Privacy Policy, Battery Notice; select from “Händlerbund API - Documents” | Terms and Conditions, Right of Withdrawal, Legal Notice, Privacy Policy; one button per text | Terms and Conditions, Right of Withdrawal, Legal Notice, Privacy Policy |
| Languages | Every language of your store that you have registered with Händlerbund; German is always included | German, English, French; select under “janolaw Languages for Import” | the language in which the law firm sends a text, if your store carries it |
| When updated | when someone logs in to the backend and the last update was more than one day ago; the time is shown under “Händlerbund API - Last Update” | when someone logs in to the backend, at most once every 24 hours per text and language; immediately by clicking “Update Documents” | as soon as the law firm submits a text |
| Edit in the CMS | Locked: The selected pages cannot be saved in any language | Possible, but the next update will overwrite the selected languages; unselected languages remain | Possible, but the next upload will overwrite the text in that language |
| Disable | Clear the AccessToken or deselect individual documents | Turn off the text toggles or clear the User ID and Shop ID | “IT-Recht Kanzlei Interface Status” at false; the shop will then reject transfers |
At the top are the four fields of the Händlerbund interface; at the bottom are the six checkboxes that appear after clicking “Edit” under “Händlerbund API - Documents.” Click to enlarge.
What happens to the texts when you disable them
Nothing. The most recently transferred texts remain on the pages and continue to apply. From then on, you maintain them yourself in the CMS Manager, and changes to the legal situation will no longer be automatically applied. If you terminate the contract with the provider, you should therefore review your texts yourself or with your legal counsel.
Updates Depend on Login
Händlerbund and janolaw only check for updates when someone logs in to the backend. If no one logs in for days, the old version remains in place. For janolaw, you can retrieve new versions at any time by clicking “Update Documents” under Settings → Interfaces → Legal Portals → janolaw Terms of Service Hosting Service.
Changing Company Information and Ownership Transfers
Your company’s name and address appear in several places. If you change your company name or ownership, go through this list.
| What | Where |
|---|---|
| Company name, address, phone number, email | Settings → General → Basic Settings: “Store Name,” “Store Owner Name,” “Store Address and Contact Information.” The address is used as the sender in emails, the model cancellation form (via the placeholder {STORE_NAME_ADDRESS}), and some shipping interfaces. |
| Bank Account Information | Same group: “Store Bank Account Account Holder,” “Store Bank Account IBAN,” and the remaining “Store Bank Account …” fields |
| Documents | Settings → Design → Documents: “Edit Invoice Footer” tab (for each language), “Document Address (Horizontal),” and “Your Company’s Tax ID,” see guide Orders |
| Email sender address | Settings → Interfaces → Email Marketing / CRM → Email Options → Shop owner’s email address; contact form recipient under Settings → General → Basic Settings → Contact Page Data |
| Legal Notice and Legal Texts | CMS → CMS Manager. If the texts come from a provider, change the company information there; otherwise, the next update will overwrite your changes. |
| Email Templates | CMS → Emails & Marketing / Automations: Templates with placeholders such as {STORE_NAME} will automatically update themselves. Look for templates where the old name is written out as text. |
| Logo | Settings → General → Basic Settings → Store Logo |
Change accounts with payment providers, shipping carriers, and marketplaces directly with the respective provider. Please notify us of any change in account ownership so that the contract and billing address at XONIC are correct.
Notes in the Order Process
These settings control which legal texts, checkboxes, and notices your customers see before placing an order. Consult your legal counsel to determine whether you require a checkbox to be selected.
| Setting | Default | Effect |
|---|---|---|
| Settings → Checkout → General → Terms and Conditions in the Order Process: On/Off | true | Displays “Our Terms and Conditions apply” on the order summary, with a link to the Terms and Conditions |
| Settings → Checkout → General → Confirm Terms and Conditions During the Order Process | false | The customer must confirm the Terms and Conditions. This only applies if the Terms and Conditions are displayed. |
| Settings → Checkout → General → Enable/Disable Right of Withdrawal in the Order Process | true | Displays the cancellation period with a link to the cancellation policy and the sample cancellation form |
| Settings → Checkout → General → Exclusion from the right of withdrawal for digital goods and services | true | Check the box for services and downloads; see below |
| Settings → Privacy → General → Privacy Consents for Order Completion Page | false | advise Displays a notice that " opt-in " is checked |
The Order Button
The button on the order summary page is set by default to “Place Order with Obligation to Pay.” You can change the text under Tools → xoLanguage in the “default” section by entering your own value; see the Languages & Translation Guide. Please consult your legal counsel beforehand to determine whether a different wording is permissible.
Services and Digital Content
If an item is marked as a “service product” or is a download, the order summary displays a checkmark: The customer agrees that you may begin providing the service before the end of the cancellation period. You can also change the text of the checkmark and the confirmation in the order email in xoLanguage. Details and pitfalls are outlined in the Withdrawal Button Guide.
Privacy Notices in Forms
Under Settings → Privacy → General, you can specify for each form whether the store displays nothing (false), a notice (advise), or a checkbox (opt-in):
- “Privacy Consents for Customer Registration” (default:
opt-in) - “Privacy Consents for General Forms” for contact forms, inquiries, callbacks, and tickets (default:
opt-in), see the Forms & Spam Protection Guide - “Data Protection Consents for Shipping Providers” and “Data Protection Consent for Shipping: Mode” for sharing the email address with the package delivery service
- “Privacy Consents for Review Portals (eKomi, Trusted Shops, Google Customer Reviews),” see the Reviews & Seals Guide
Set Up a Cookie Banner
The cookie banner asks your visitors which services they consent to. As long as a visitor does not consent to a category, the store does not load the services in that category.
Under “Custom Cookie Settings,” a category appears for each configured service; none are preselected. Click to enlarge.
Settings
Under Settings → Privacy → General:
- “Cookie Consent Tool: Mode” set to “
modal” (default). With “false,” the store does not display a banner and treats all services as if visitors had consented. - “Cookie Consent Tool: Button Display”: “
equal” (default) makes the “Accept” and “Reject” buttons look the same; “performance” highlights “Accept All Cookies.” - “Privacy Consents for Tracking Scripts” on
false(default). In this case, no category is preselected.
What the visitor sees
- A window with your notification text and the buttons “Accept All Cookies” and “Only Technically Necessary Cookies.”
- Under “Individual Cookie Settings,” one category per configured service, saved by clicking “Save Settings.”
- Your privacy policy and legal notice can be expanded in the window.
The mode, button appearance, and default selection for the cookie banner, along with the consent options for the forms, can be found under Settings → Privacy → General. Click to enlarge.
Categories and Explanatory Texts
A category appears as soon as the service is set up—for example, when a tracking ID is entered or a chat service is enabled. You can manage the texts in the CMS Manager:
| Text | Module in the CMS Manager |
|---|---|
| Note text at the top of the banner | $cms_cookie_information |
| "Google Analytics" category | $tracking_google_analytics |
| "Google Ads" category | $tracking_google_ads |
| "Facebook" category | $tracking_facebook |
| Category for PayPal installment payment notices | $tracking_paypal_marketing_solutions |
| "xoStats" category | $tracking_xostats |
The “Google Store Widget” includes a fixed text. The other categories display only the name of the service; please describe these services in your privacy policy. If a block is missing, the category banner will not display any text. If you create a block manually, use exactly this name, set the status to “Active,” select “Shop Content Page,” and set “Link in XML sitemaps for search engines” to “No.”
When the banner appears
- on the first visit; after a selection is made, the browser remembers it for one year
- again when you set up a new service: The new service will not appear
- not on the “Legal Notice,” “Privacy Policy,” and “My Data” pages, so visitors can read them undisturbed
- Not visible to search engines
- If Settings → Checkout → Customer Details → “Require Login” Popup Modal is enabled in the frontend, the login window takes precedence for visitors who are not logged in. They will see the banner on the login page or after logging in.
Change selection later
Customers can change their selection in their customer account under “My Data.” The same page also displays the categories to guests. A link to this page in the footer is not part of the standard template.
Therefore, link to the page yourself—for example, in your privacy policy as “Change Cookie Settings.” To do this, copy the URL of the “My Data” page from your store.
Chat, Videos, Maps, and Widgets
Chat windows and embedded content from other providers also load only after the visitor gives consent.
Chat Services
You can enable Userlike, Smartsupp, and crispAI under Settings → Interfaces → Chat Tools. Each service is assigned its own category in the cookie banner, named after the provider.
The chat window won’t load until the visitor has consented to this category, starting with the next page view. If the window is missing, check in a private browser window: consent, then reload the page. If the category is also missing from the banner, the service isn’t fully set up—for example, because an access key is missing.
Videos and Maps
The store initially displays embedded videos from YouTube and Vimeo and maps from Google Maps as placeholders with “Load video” or “Load map” and a note that data will be sent to the provider in the process. Consent applies to the current visit. YouTube videos load via youtube-nocookie.com.from 4.9.144
This applies to the map in the footer and legal notice, the Content Editor blocks, and any videos or maps you’ve inserted into text. Product videos in the image gallery already had this prompt previously.
- Google Store Widget: The widget displaying your Google rating has its own category, “Google Store Widget,” and loads only after consent is given.from 4.9.144
- reCAPTCHA: The spam protection loads without a banner prompt, but only after the visitor clicks on, fills out, or submits a protected form.from 4.9.144
- Custom Template: If your store uses a custom template with its own footer or forms, the card may continue to load there without a prompt. Contact us, and we’ll make the necessary adjustments.
Proof of Consent
Under Tools → Privacy Management, you’ll find all consents recorded by the store, including type, date, IP address, and deletion date.
What Is Recorded
- Every selection made in the cookie banner and in “My Data” is recorded as “Customer Information and Privacy Settings Updated,” with the specific selection for each service
- Registration, newsletter subscription and unsubscription, contact and product inquiries, callbacks, review emails, and the sharing of the email address with the shipping provider
- The deletion of a customer account by the customer or by you
Searching and Storing
The live search finds entries by email address or phone number. Entries from guests do not include an email address. The button next to the type shows the saved selection for each service. The IP address displays a truncated version of the list.
Each entry is assigned a deletion date ten years after creation. The store automatically deletes expired entries when logging into the backend.from 4.10
Product Safety (GPSR)
You maintain the manufacturer’s contact information once per manufacturer. The shop displays it on every product page for that manufacturer and transmits it to marketplaces.
Enter Manufacturer Information
- Open Products → Manufacturers and edit the manufacturer.
- Fill in “Manufacturer’s Address”: Company name or first and last name, street, ZIP code, city, country, plus email address or website.
- If the manufacturer is located outside the EU, the form will display the “Address of the Responsible Person” fields. Enter the responsible person in the EU there.
- Assign the manufacturer to the items.
This is how it appears in the store
The product page displays the “About the Manufacturer…” tab with the heading “Contact Information per Art. 19 EU GPSR,” including the mailing address and email address; for manufacturers outside the EU, it also includes the responsible person.
The tab appears only if the name, street, ZIP code, city, and country are complete and Settings → Design → Product Detail View → Product Detail View: Automatic Manufacturer Description Yes/No is set to “ true ” (default). Select “Product Detail View: Automatically expand manufacturer description (yes/no)” to open it from the start.
If the manufacturer is located outside the EU, the form displays the fields for the responsible person in the EU. Click to enlarge.
The “About the Manufacturer…” tab displays the contact information from the manufacturer management system; for manufacturers outside the EU, it also displays the responsible person. Click to enlarge.
- Manufacturer no longer exists: Set “Manufacturer exists” to No and select the “Legal Successor.” The product page will then list the legal successor. The “What does this mean?” button on the screen explains the situation.
- Multiple manufacturers at once: Porter lists the manufacturer’s address along with the responsible person; see the Import & Export Guide.
- Marketplaces: eBay and Kaufland receive the information from the manufacturer management system. eBay requires the manufacturer’s country and a ZIP code with a maximum of nine characters; Kaufland requires the street name, house number, and email address or website. The export reports missing information using the manufacturer’s name.
- Warnings and safety instructions on the product: There is no separate field for this. Create a product tab within the product, save it using “Save as Template,” and assign the template to other products or entire categories via “Select Templates.” You can display a notice for all products by creating a separate CMS page and using the “Activate as a tab for the product page” toggle.
Accessibility
The standard templates are designed to meet the requirements of WCAG 2.1, Level AA. Whether your store meets the requirements of the Accessibility Enhancement Act also depends on your content and customizations.
What the Store Offers
- Sufficient contrast for text and user interface elements
- Keyboard navigation with a visible focus indicator
- Labeled form fields
What’s left for you to do
- Meaningful alternative text for images, for example in the “Image Title / Alt Text” field of the image blocks in the Content Editor
- Clear text and headings on your pages
- Checking your own templates and customizations
- An accessibility statement as a separate page in the CMS Manager; see the CMS Manager & Emails Guide
Shop for business customers only
If you sell only to businesses, adjust these settings. Consult your legal counsel to verify that your shop actually reaches only business customers: Whether a customer is considered a consumer depends on the customer, not on your settings.
| Setting | Effect |
|---|---|
| Settings → Checkout → Customer Details → Required Login Pop-up modal on the front end | Visitors who are not logged in see a login window that cannot be closed. It contains the privacy policy and legal notice. |
| Settings → Checkout → General → Cancellation Button: Target Audience | auto (Default) excludes detected commercial orders; b2b never offers the right of withdrawal—see the guide on the "Right of Withdrawal" button.from 4.9.85 |
| Settings → Checkout → General → EU Warranty Notice: Target Audience | b2c (Default) shows the notice to everyone; “ b2b ” shows it to no one; see the EU Warranty Label guide. |
| Registration with “Business” Account Type | “VAT ID Required Field On/Off” and verification of the VAT ID number with assignment to a merchant group; see the Sign-Up & Registration Guide. The requirement applies only to businesses, and a separate customer group for businesses is available starting with XONIC 4.10.from 4.10 |
| Net Prices by Customer Group | See the Prices & Customer Groups Guide |
Maintain the Terms and Conditions for business customers in the CMS Manager, just as you do for all legal texts. If you serve both customer groups, consult your legal counsel to determine how to separate the texts.
Deleting Customer Data, Information Requests, and Retention
The backend provides these tools for requests under the GDPR.
Delete Account
- By the customer: Settings → Checkout → Customer Details → Delete Customer Account. Using
delete(default), the customer requests deletion in “My Data”; the account is immediately locked and will be deleted after clicking the link in the confirmation email. “deactivate” only deactivates the account, while “false” hides the function. This requires “Allow customers to change their address” to be enabled in the same group. - By you: under Customers → Customers, select “Delete.” The store deletes the account, addresses, shopping carts, and wish lists; orders remain until the end of the retention period. The data protection management team records the process.
Information and Deadlines
- Information: There is no dedicated button for this. The data is available in the customer account, in the orders, and under Tools → Data Protection Management; if needed, you can export customer data using the Porter—see the Import & Export Guide.
- Orders: Settings → Data Protection → General → Retention Period for Orders (default 10 years). The shop automatically deletes older orders. Please consult your tax advisor to determine the correct retention period.
- Logs: “xoLog: Retention Period” in the same group (default: one month).
For information on how statistics handle visitor data, see the Statistics & Reports Guide; for details on which team members can view which customer data, see the Employees, Permissions & 2FA Guide.
Audit Reports, Scans, and Hosting
Automatic GDPR compliance reports and security scans for card payments often arrive unsolicited. Categorize each finding before taking action.
GDPR Audit Reports
These reports list what a website loads and stores when it’s accessed. Check each item in your own store, preferably in a private browser window before making a selection in the cookie banner:
- Every online store sets a session cookie for the shopping cart and login. The store also stores your cookie preferences in cookies.
- The default template does not load fonts from Google servers.
- With Google Consent Mode enabled by default, Google scripts load before the selection is made, with the status “rejected”—see the cookie banner.
- Videos, maps, and reCAPTCHA are loaded only after a click or interaction—see Chat, Videos, Maps.from 4.9.144
- The store does not check scripts that you have inserted yourself into text, blocks, or a custom template.
Card Payments, PCI-DSS, and ASV Scan
Your payment provider or bank determines whether you need an ASV scan or a self-assessment questionnaire (SAQ). With Stripe, your customers pay on Stripe’s payment page; with PayPal, they enter their card information into embedded PayPal fields. The older “Credit Card” module captures card data within the shop itself; do not use it—see the Payment Methods Guide.
If your provider requires a scan, hosting information, or a self-assessment questionnaire (SAQ), please contact us. For the hosting and operation of your store, you must enter into a data processing agreement with XONIC; if you do not have one, please request it from us.
Cancellation Button and Warranty Label
Two requirements have their own guides covering all settings.
Withdrawal button
The button that allows consumers to cancel a contract online, including exceptions for services, digital content, and personalized goods: Cancellation Button Guide.
EU Warranty Label
The harmonized notice regarding the statutory warranty and the EU-GARAN label, which displays the warranty period on the product: EU Warranty Label Guide.
Pre-Launch Checklist
- Legal Texts: Sample texts in the legal notice, privacy policy, terms and conditions, right of withdrawal, delivery and payment sections, and in the sample withdrawal form have been updated in every language.
- Provider: If the texts come from a provider, the last update is dated today and all languages are populated.
- Company data: Default settings, invoice footer, billing address, and tax ID are correct.
- Order Process: Terms and Conditions and Right of Withdrawal are displayed; services are marked as “service products.”
- Cookie Banner: Mode set to “
modal,” no default selection, explanatory texts available for all categories, tested in an incognito window. - Change selection: Link to “My Data” added to the Privacy Policy.
- Privacy Policy: Lists every service provided, including chat, maps, and videos.
- Product safety: Each manufacturer has a complete address; manufacturers outside the EU have a designated representative.
- PDF Attachments: Sent an order confirmation to myself and checked the attachments.
Frequently Asked Questions
Why can’t the Privacy Policy be enabled or disabled in the CMS?
Where do I edit the Terms and Conditions and Privacy Policy?
Where do I include liability provisions for services in the Terms and Conditions?
When does the legal text provider update the texts in the store?
How do I deactivate the Händlerbund interface?
How do I edit terms and conditions in other languages when a legal text interface is active?
Where do I update the legal notice and company name after a change in ownership?
Where is the notice regarding services defined in the checkout process?
How do I set up cookie banners and Google Consent Mode v2?
Why doesn’t the cookie banner appear as a pop-up window?
Why doesn’t the chat service appear, and what consent does it require?
Where do I enter the product safety information (GPSR)?
How do I display the note about the charger with the product?
Do I need to make any adjustments regarding the salutation during registration?
How do I set up a B2B-only store?
Does the store comply with the Accessibility Enhancement Act?
If an automatic GDPR audit report is generated, is action required?
Does XONIC perform the PCI-ASV scan?
How can visitors change their cookie preferences later?
Additional Guides
We'll help you set it up
The guides explain the technical aspects of the store; they are not a substitute for legal advice. We’re happy to help you with cookie banners, legal text interfaces, and manufacturer information.
Contact Support Now