Bolt

Bolt

Bolt is a one-click checkout platform for e-commerce merchants. It embeds checkout acceleration scripts that recognize returning shoppers across the Bolt network and pre-fill payment and shipping information. Persistent identity cookies are set to enable cross-site shopper recognition.

Overview

Bolt is a one-click checkout platform that accelerates the e-commerce purchase flow by maintaining a network of recognized shoppers whose payment and shipping details are stored securely across all Bolt-enabled merchants. When a returning Bolt shopper visits any merchant in the network, Bolt detects them via a persistent identity cookie, pre-fills their checkout details, and enables purchase completion with minimal friction. The platform serves direct-to-consumer brands, particularly in apparel, footwear, and consumer goods, that prioritize conversion rate optimization on their checkout pages.

Beyond checkout acceleration, Bolt also operates as a payment processor for some merchants and provides an account creation flow (Bolt Accounts) that allows first-time shoppers to save their details to the Bolt network during their initial purchase.

What This Script Does

Script loading: Bolt loads JavaScript from connect.bolt.com/track.js (for shopper recognition and analytics) and connect.bolt.com/embed.js (for the checkout widget). These scripts initialize when the page loads, not only when the visitor reaches checkout, because shopper recognition requires early detection.

Cross-merchant shopper recognition:

  • _bolt_cid — Third-party persistent cookie set on the bolt.com domain, up to 1 year, stores an anonymized Bolt shopper identifier. This cookie is read on any Bolt-enabled merchant site to determine if the visitor is a recognized Bolt account holder. This is a cross-site identity mechanism by design — it is how Bolt recognizes shoppers across different merchants.
  • _bolt_session — Session cookie on the bolt.com domain, maintains the active checkout session during a transaction
  • First-party cookies may also be set on the merchant's domain to persist checkout state and cart recovery signals

Checkout module behavior:

  • When a returning shopper is detected via _bolt_cid, the checkout widget pre-populates the visitor's saved email, shipping address, and payment method (card last four digits and type)
  • The visitor authenticates via a one-time passcode (OTP) sent to their phone or email to confirm their identity before the stored payment details are used
  • New shoppers are offered the option to save their details to Bolt during checkout, creating a Bolt account

Fraud detection:

  • Browser fingerprinting signals (user agent, screen dimensions, timezone, language, installed fonts via canvas fingerprinting) are collected during checkout initialization for risk scoring
  • Device intelligence is transmitted to Bolt's fraud scoring API at api.bolt.com

Cart recovery and analytics:

  • Bolt may capture the visitor's email address from cart or checkout form fields before form submission (known as "email capture") to support abandoned cart recovery flows
  • Conversion events and checkout funnel metrics are reported to the merchant via Bolt's analytics dashboard

Consent & Compliance

Bolt is categorized as essential and functional.

  • Essential (payment processing): The cookies required to complete the checkout transaction that the visitor has initiated are strictly necessary and qualify for the ePrivacy exemption.
  • Functional (shopper recognition): The _bolt_cid cross-merchant shopper identity cookie presents a nuanced consent question under GDPR/ePrivacy. While its purpose is to deliver a functional benefit (pre-filled checkout), it operates as a persistent cross-site identifier linking the visitor's identity across multiple unrelated merchants. EU DPA guidance on third-party persistent identifiers is relevant here — some regulators may classify this as requiring consent despite its functional framing.
  • Email capture before submission: Capturing email addresses from checkout form fields before the visitor completes the form (for abandoned cart recovery) is a controversial practice under GDPR that may require consent or a robust legitimate interest assessment.
  • CCPA/CPRA: The cross-merchant shopper identity network involves personal data (email, address, payment method) processed across multiple business entities. Merchants must disclose Bolt's role in their privacy policy. The cross-merchant data flow should be evaluated for "sharing" obligations under CPRA.
  • EU-US Data Privacy Framework: Bolt (a US company) should be assessed for DPF participation or SCCs for EU personal data transfers.

Should You Block This Without Consent?

No. The core checkout functionality that Bolt provides is essential for completing transactions the visitor has initiated. Blocking Bolt would break the accelerated checkout experience entirely. However, EU-focused merchants should review the cross-merchant _bolt_cid cookie carefully and consult their DPA or legal counsel on whether explicit consent is required for this persistent cross-site identifier, given the strict interpretation of ePrivacy Article 5(3) by some European regulators.

Is Bolt GDPR compliant?

Bolt typically loads functional trackers, which are not strictly necessary for your site to work. Under the GDPR and the ePrivacy Directive, non-essential cookies and trackers must stay blocked until a visitor gives clear opt-in consent. So Bolt can be fully GDPR compliant, but only if your site holds its scripts until consent is granted and lets visitors decline just as easily. Compliance depends on how your site loads Bolt, not on Bolt itself.

Visit website

Consent Categories

Also Known As

bolt checkout trackingbolt cookiesbolt one click privacybolt checkout consentbolt shopper recognitionbolt gdpr

Industries

Programming and Developer SoftwareComputers Electronics and Technology

Tracked Domains (1)

bolt.comEssential

bolt.com is an essential domain operated by Bolt, used to keep the site working, including security, load balancing, and sessions.

Frequently Asked Questions

Related Vendors

Bizzabo
Bizzabo
Bizzabo is an event management and marketing platform for in-person, virtual, and hybrid events. It embeds event registration widgets, agenda displays, and ticketing flows on event websites. Scripts collect attendee information and track page interactions for event analytics.
Mailgun
Mailgun
Mailgun is a transactional email API service used by developers to send, receive, and track email. It operates as a backend service; email tracking pixels appear in sent messages but Mailgun does not load scripts on third-party websites.
Avalara
Avalara
Avalara is an automated tax compliance platform for businesses. It embeds tax calculation scripts in e-commerce checkout flows to compute applicable sales tax in real time based on product type and buyer location. No behavioral tracking cookies are set.
Paysafe
Paysafe
Paysafe is a global payment solutions provider that includes Neteller and Skrill digital wallets. It embeds payment widgets on checkout and deposit pages. Scripts process payment data and set session cookies for transaction authentication and fraud prevention.
Flutterwave
Flutterwave
Flutterwave is an African payment technology platform that embeds checkout flows and payment widgets on merchant websites. Scripts load hosted payment forms supporting card, mobile money, and bank transfer methods for transactions across African and global markets.
Worldpay
Worldpay
Worldpay (FIS) is a global payment processing company. Scripts embed hosted payment pages, card tokenization forms, and 3D Secure authentication flows on merchant checkout pages. Collects payment card data within secure iframes; sets session and fraud detection cookies to manage transaction state.

Manage consent for Bolt

ConsentStack automatically detects and manages Bolt trackers so your site stays compliant with global privacy regulations.