Overview
BigCommerce is a SaaS e-commerce platform that hosts complete online storefronts, handling everything from product catalogs and shopping carts to checkout processing and order management. Unlike self-hosted solutions, BigCommerce controls the entire hosting stack, meaning its scripts are deeply integrated into every page of a BigCommerce-powered store. The platform also supports headless commerce deployments where BigCommerce serves as the backend while a custom frontend handles presentation.
What This Script Does
BigCommerce's storefront scripts manage product browsing, cart operations, checkout flows, and customer account functionality. Core cookies include session identifiers (SHOP_SESSION_TOKEN), cart state cookies, customer login tokens, and currency/locale preferences. These cookies are essential for store operations and typically expire at the end of the session or persist for up to 30 days for returning customer recognition.
Analytics and Tracking Layer
BigCommerce's built-in analytics module tracks page views, product impressions, add-to-cart events, and checkout funnel progression. The platform also supports native integrations with Google Analytics, Facebook Pixel, and other marketing tools through its control panel — these are injected as additional script tags on storefront pages. BigCommerce's own analytics cookies track conversion events and may set identifiers that persist for 30–90 days for attribution purposes. The platform's A/B testing capabilities also set cookies to maintain variant assignments across sessions.
Consent & Compliance
BigCommerce scripts span functional and analytics categories. The core storefront cookies — session management, cart persistence, and customer authentication — are essential for e-commerce operations and qualify as strictly necessary under the ePrivacy Directive. The analytics module and conversion tracking, however, collect behavioral data that goes beyond what is necessary for the requested service. Under GDPR, the analytics layer requires consent or a valid legitimate interest assessment. Under CCPA/CPRA, the behavioral analytics data must be disclosed in the privacy policy, and consumers must be offered opt-out rights if the data is sold or shared with third parties. BigCommerce's native marketing integrations (pixels, tags) each carry their own consent requirements.
Should You Block This Without Consent?
Conditional. BigCommerce's core storefront scripts are essential and must not be blocked — they power the shopping cart, checkout, and customer account functionality. The analytics tracking, conversion measurement, and marketing pixel integrations should be separated in the consent configuration and blocked until the visitor provides consent. Site operators using BigCommerce's headless API are already separating these concerns, as the API layer does not inject client-side tracking.
Is BigCommerce GDPR compliant?
BigCommerce typically loads functional and analytics trackers, which are not strictly necessary for your site to work. Under the GDPR and the ePrivacy Directive, non-essential cookies and trackers must stay blocked until a visitor gives clear opt-in consent. So BigCommerce can be fully GDPR compliant, but only if your site holds its scripts until consent is granted and lets visitors decline just as easily. Compliance depends on how your site loads BigCommerce, not on BigCommerce itself.
Consent Categories
Also Known As
Industries
Tracked Domains (1)
bigcommerce.comFunctionalbigcommerce.com is a functional domain operated by BigCommerce, used to run site features like chat, video, embeds, and preferences.
Frequently Asked Questions
Related Vendors
Manage consent for BigCommerce
ConsentStack automatically detects and manages BigCommerce trackers so your site stays compliant with global privacy regulations.