Overview
Ecwid (now part of Lightspeed) is an embeddable e-commerce widget that adds a complete online store to any existing website. Unlike full-platform solutions that require dedicated hosting, Ecwid injects a shopping cart, product catalog, and checkout flow into pages built on WordPress, Wix, Squarespace, or any custom HTML site. This makes it a popular choice for small businesses that want to add e-commerce to an established web presence without rebuilding their site.
What This Script Does
Ecwid's scripts load from app.ecwid.com and associated CDN domains. The SDK injects a full storefront widget into a designated container on the host page, rendering product grids, category navigation, product detail views, a shopping cart sidebar, and a multi-step checkout flow. Cookies set by Ecwid include session identifiers for maintaining cart state across page navigations (ecwid_session), shopping cart contents hashes, customer authentication tokens for returning buyers, and currency/locale preferences. These cookies typically persist for the browsing session, with cart persistence cookies lasting up to 30 days to support abandoned cart recovery.
Script Behavior
The Ecwid widget operates as a single-page application within the host page, managing its own routing and state. Product browsing, cart updates, and checkout steps all occur within the widget without full page reloads. The scripts communicate with Ecwid's API servers to fetch product data, validate inventory, calculate shipping rates, and process payments. No analytics or marketing tracking is included in Ecwid's core scripts — any such tracking requires separate integrations configured through Ecwid's app market.
Consent & Compliance
Ecwid scripts are classified as functional. The entire purpose of the integration is to provide e-commerce functionality — product browsing, cart management, and checkout processing — that the site owner has explicitly added and the visitor actively engages with. Under GDPR and the ePrivacy Directive, the cookies set by Ecwid for session management, cart persistence, and checkout processing qualify as strictly necessary for the service requested by the user. No consent is required for these functional cookies. Under CCPA/CPRA, the transaction data collected through Ecwid falls under the transactional exemption for data necessary to complete a purchase. However, if additional analytics or marketing apps are installed through Ecwid's app market, those would carry their own consent requirements.
Should You Block This Without Consent?
No. Ecwid's core scripts provide essential e-commerce functionality. Blocking them would prevent visitors from browsing products, managing their cart, or completing purchases. The cookies set by Ecwid are strictly necessary for the shopping experience and do not require consent. If third-party analytics or marketing integrations are added through Ecwid's ecosystem, those should be evaluated and managed separately.
Is Ecwid GDPR compliant?
Ecwid typically loads functional trackers, which are not strictly necessary for your site to work. Under the GDPR and the ePrivacy Directive, non-essential cookies and trackers must stay blocked until a visitor gives clear opt-in consent. So Ecwid can be fully GDPR compliant, but only if your site holds its scripts until consent is granted and lets visitors decline just as easily. Compliance depends on how your site loads Ecwid, not on Ecwid itself.
Consent Categories
Also Known As
Industries
Tracked Domains (1)
ecwid.comFunctionalecwid.com is a functional domain operated by Ecwid, used to run site features like chat, video, embeds, and preferences.
Cookies Ecwid Sets (1)
ecwid_visitor_idEcwid storefront visitor identifier for cart persistence and analytics.
Frequently Asked Questions
Related Vendors
Manage consent for Ecwid
ConsentStack automatically detects and manages Ecwid trackers so your site stays compliant with global privacy regulations.