SAP

SAP

SAP's enterprise software ecosystem includes SAP Customer Data Cloud (formerly Gigya), SAP Emarsys (marketing automation), and SAP Commerce Cloud. On-site scripts handle identity management, consent collection, and behavioral event tracking for enterprise marketing workflows.

Overview

SAP's web-facing product portfolio includes SAP Customer Data Cloud (formerly Gigya) for identity and consent management, SAP Emarsys for omnichannel marketing automation, and SAP Commerce Cloud for enterprise e-commerce. These products collectively handle user authentication, consent orchestration, behavioral tracking, and personalized marketing for large enterprise brands.

What This Script Does

SAP's client-side presence depends on which products are deployed. Each product has a distinct script footprint and data collection profile.

SAP Customer Data Cloud (formerly Gigya)

  • gigya.js — Loaded from cdns.gigya.com. Handles social login (Google, Facebook, Apple, LinkedIn), user registration flows, and screen-sets (embeddable UI components for login/registration).
  • Sets gig_bootstrap_* cookies — Short-lived cookies used during the authentication flow to maintain state.
  • Sets gig_canary cookie — Tracks A/B testing assignments for Gigya UI experiments.
  • API calls to accounts.{datacenter}.gigya.com for account operations, social token exchange, and consent recording.
  • Stores user profiles, consent preferences, and identity graph data in Gigya's cloud.

SAP Emarsys

  • scarab.js or the Emarsys Web Extend script — Loaded from recommender.scarabresearch.com or Emarsys CDN endpoints.
  • Tracks product page views, category browsing, cart additions, and purchases.
  • Sets scarab.visitor cookie — Persistent visitor identifier used to build behavioral profiles for email campaign personalization and on-site recommendations. Persists for 1 year.
  • Sets scarab.session cookie — Session-level behavioral tracking. Expires on session end.
  • Sends behavioral events to Emarsys' recommendation engine to generate personalized product recommendations and trigger automated email flows.

SAP Commerce Cloud

  • Hybris-based frontend JavaScript handles product catalog rendering, cart management, and checkout flows.
  • Session cookies for cart state and checkout continuity — typically JSESSIONID or SAP-specific session tokens.

Domains Contacted

  • cdns.gigya.com, accounts.us1.gigya.com, accounts.eu1.gigya.com — Customer Data Cloud CDN and API
  • recommender.scarabresearch.com, cdn.scarabresearch.com — Emarsys Web Extend tracking
  • SAP Commerce endpoints vary by customer deployment (typically customer-specific subdomains)

Consent & Compliance

Consent category: Marketing / Functional (varies by product)

  • GDPR/ePrivacy: Emarsys behavioral tracking (scarab.visitor) requires explicit consent — it profiles users across sessions for marketing personalization. Gigya's core authentication is functional, but progressive profiling and analytics features require separate consent. Under ePrivacy, all non-essential cookies (Emarsys tracking, Gigya analytics) require prior opt-in consent.
  • CCPA/CPRA: Emarsys behavioral profiles constitute personal information used for targeted marketing, which is subject to opt-out rights. Gigya identity data is personal information subject to access and deletion requests.
  • IAB TCF: Emarsys is a registered IAB TCF vendor (Vendor ID varies). Relevant TCF purposes include Purpose 1 (store/access device information), Purpose 3 (create personalised ad profile), and Purpose 4 (select personalised ads).
  • EU-US transfers: SAP is a German company (EU-headquartered). Gigya data centers are available in the EU (eu1, eu2, eu5 data centers). Emarsys (headquartered in Austria) processes EU data within the EU. US deployments rely on SCCs.

Should You Block This Without Consent?

Conditional. SAP Customer Data Cloud's core authentication and consent collection scripts are functional and can load without marketing consent. SAP Emarsys' behavioral tracking scripts (scarab.js) should be blocked until marketing consent is obtained. Evaluate each SAP product independently — the presence of one SAP product does not imply all SAP products are deployed.

Is SAP GDPR compliant?

SAP typically loads marketing and functional trackers, which are not strictly necessary for your site to work. Under the GDPR and the ePrivacy Directive, non-essential cookies and trackers must stay blocked until a visitor gives clear opt-in consent. So SAP can be fully GDPR compliant, but only if your site holds its scripts until consent is granted and lets visitors decline just as easily. Compliance depends on how your site loads SAP, not on SAP itself.

Visit website

Products (3)

Consent Categories

Also Known As

SAP Customer Data CloudSAP EmarsysSAP Commerce CloudGigya SAPSAP CDCenterprise marketing automation

Industries

Computers Electronics and TechnologyProgramming and Developer Software

Tracked Domains (2)

SAP's trackers are rarely seen, seen on under 1% of the sites ConsentStack has scanned. Scan your own site to see which of these are firing before consent.

scarabresearch.comMarketing

scarabresearch.com is a marketing domain operated by SAP, used to serve ads, build audiences, and measure ad conversions. Seen on under 1% of scanned sites.

sap.comMarketing

sap.com is a marketing domain operated by SAP, used to serve ads, build audiences, and measure ad conversions.

Frequently Asked Questions

Related Vendors

Manage consent for SAP

ConsentStack automatically detects and manages SAP trackers so your site stays compliant with global privacy regulations.