Overview
Lightspeed Commerce is a cloud-based unified commerce platform serving retail, restaurant, and golf businesses with integrated point-of-sale, inventory management, payments, and e-commerce storefronts. Headquartered in Montreal and publicly traded (NYSE: LSPD), Lightspeed powers tens of thousands of merchants globally across independent retail, apparel, electronics, sporting goods, and food service verticals.
Lightspeed's e-commerce product (previously Lightspeed eCom, now integrated as part of Lightspeed Retail and Lightspeed Restaurant) generates the primary browser-side footprint on merchant storefronts. When a retailer runs their online store on the Lightspeed platform, Lightspeed's JavaScript is embedded as a first-party component of the storefront, handling commerce functionality, session management, and built-in analytics.
What This Script Does
Script loading: On Lightspeed-hosted storefronts, commerce scripts load from the merchant's subdomain (e.g., [merchant].ecwid.com for merchants using Lightspeed's Ecwid-based e-commerce layer, or from [merchant].lightspeedhq.com). Third-party retailers embedding a Lightspeed e-commerce widget may load scripts from app.ecwid.com/script.js?[store-id].
Essential commerce functions:
- Cart management: First-party session cookie (
ECWID_SESSIONorec_SID) — session duration — maintains cart contents, quantity selections, and visitor session identity throughout the shopping flow. This is strictly necessary for checkout. - Checkout processing: Authentication tokens and transaction state cookies are set during the checkout flow to maintain PCI-compliant state between checkout steps and payment processing. Session duration.
- Authentication: For returning customers with saved accounts, session cookies maintain the logged-in state (
ec_AUTH, session duration).
Analytics and reporting:
ec_GUEST— First-party persistent cookie, up to 2 years, stores an anonymized returning visitor identifier used to recognize repeat customers in the merchant's built-in analytics dashboard (conversion rate, repeat purchase rate)- Page view events, product view events, category navigation, and cart interaction events are tracked and sent to Lightspeed's analytics APIs to populate the merchant's built-in reporting
- Purchase conversion events (order value, product SKUs, payment method) are logged for revenue reporting
Ecwid widget (embedded storefronts): Merchants embedding a Lightspeed/Ecwid widget on a non-Lightspeed website load app.ecwid.com/script.js, which renders an iframe-based storefront widget. The widget sets cookies on the ecwid.com domain for cart and session management. The persistent visitor cookie for analytics is also set in this context.
Payment processing: Lightspeed Payments (powered by Stripe in many regions) handles card tokenization. Payment processing cookies are strictly necessary for checkout.
Consent & Compliance
Lightspeed is categorized as analytics and essential.
- Essential (no consent required): Cart state cookies (
ECWID_SESSION,ec_SID), checkout authentication tokens, and payment processing session cookies are strictly necessary for the e-commerce service the visitor has requested. These qualify for the ePrivacy strictly necessary exemption. - Analytics (consent required): The
ec_GUESTpersistent visitor cookie and the behavioral event tracking (page views, product interactions, conversion data) that populate the merchant's analytics dashboard are not strictly necessary for checkout and require consent under GDPR/ePrivacy. Some DPA guidance treats merchant-only analytics on their own storefront as falling under a narrow analytics exemption, but this varies by jurisdiction. - CCPA/CPRA: Transaction data is processed as a service provider function. The analytics data usage should be disclosed in the merchant's privacy policy.
- Lightspeed as data processor: For analytics data, Lightspeed acts as a data processor on behalf of the merchant. A DPA is available and should be executed for GDPR-regulated merchants.
Should You Block This Without Consent?
Conditional. The essential cart, checkout, and authentication cookies must not be blocked — doing so would break the e-commerce experience. The analytics tracking components (persistent visitor identifier, behavioral event reporting) should be suppressed or anonymized without consent. If you are a merchant operating on Lightspeed, review your platform settings for options to disable persistent visitor identification in analytics, or configure your CMP to allow essential Lightspeed cookies while blocking the analytics cookie on first visit.
Is LightSpeed GDPR compliant?
LightSpeed typically loads analytics trackers, which are not strictly necessary for your site to work. Under the GDPR and the ePrivacy Directive, non-essential cookies and trackers must stay blocked until a visitor gives clear opt-in consent. So LightSpeed can be fully GDPR compliant, but only if your site holds its scripts until consent is granted and lets visitors decline just as easily. Compliance depends on how your site loads LightSpeed, not on LightSpeed itself.
Consent Categories
Also Known As
Industries
Tracked Domains (1)
lightspeedhq.comAnalyticslightspeedhq.com is an analytics domain operated by LightSpeed, used to measure visits, sessions, and on-site behavior.
Frequently Asked Questions
Related Vendors
Manage consent for LightSpeed
ConsentStack automatically detects and manages LightSpeed trackers so your site stays compliant with global privacy regulations.