Overview
SAP's web-facing product portfolio includes SAP Customer Data Cloud (formerly Gigya) for identity and consent management, SAP Emarsys for omnichannel marketing automation, and SAP Commerce Cloud for enterprise e-commerce. These products collectively handle user authentication, consent orchestration, behavioral tracking, and personalized marketing for large enterprise brands.
What This Script Does
SAP's client-side presence depends on which products are deployed. Each product has a distinct script footprint and data collection profile.
SAP Customer Data Cloud (formerly Gigya)
gigya.js— Loaded fromcdns.gigya.com. Handles social login (Google, Facebook, Apple, LinkedIn), user registration flows, and screen-sets (embeddable UI components for login/registration).- Sets
gig_bootstrap_*cookies — Short-lived cookies used during the authentication flow to maintain state. - Sets
gig_canarycookie — Tracks A/B testing assignments for Gigya UI experiments. - API calls to
accounts.{datacenter}.gigya.comfor account operations, social token exchange, and consent recording. - Stores user profiles, consent preferences, and identity graph data in Gigya's cloud.
SAP Emarsys
scarab.jsor the Emarsys Web Extend script — Loaded fromrecommender.scarabresearch.comor Emarsys CDN endpoints.- Tracks product page views, category browsing, cart additions, and purchases.
- Sets
scarab.visitorcookie — Persistent visitor identifier used to build behavioral profiles for email campaign personalization and on-site recommendations. Persists for 1 year. - Sets
scarab.sessioncookie — Session-level behavioral tracking. Expires on session end. - Sends behavioral events to Emarsys' recommendation engine to generate personalized product recommendations and trigger automated email flows.
SAP Commerce Cloud
- Hybris-based frontend JavaScript handles product catalog rendering, cart management, and checkout flows.
- Session cookies for cart state and checkout continuity — typically
JSESSIONIDor SAP-specific session tokens.
Domains Contacted
cdns.gigya.com,accounts.us1.gigya.com,accounts.eu1.gigya.com— Customer Data Cloud CDN and APIrecommender.scarabresearch.com,cdn.scarabresearch.com— Emarsys Web Extend tracking- SAP Commerce endpoints vary by customer deployment (typically customer-specific subdomains)
Consent & Compliance
Consent category: Marketing / Functional (varies by product)
- GDPR/ePrivacy: Emarsys behavioral tracking (
scarab.visitor) requires explicit consent — it profiles users across sessions for marketing personalization. Gigya's core authentication is functional, but progressive profiling and analytics features require separate consent. Under ePrivacy, all non-essential cookies (Emarsys tracking, Gigya analytics) require prior opt-in consent. - CCPA/CPRA: Emarsys behavioral profiles constitute personal information used for targeted marketing, which is subject to opt-out rights. Gigya identity data is personal information subject to access and deletion requests.
- IAB TCF: Emarsys is a registered IAB TCF vendor (Vendor ID varies). Relevant TCF purposes include Purpose 1 (store/access device information), Purpose 3 (create personalised ad profile), and Purpose 4 (select personalised ads).
- EU-US transfers: SAP is a German company (EU-headquartered). Gigya data centers are available in the EU (eu1, eu2, eu5 data centers). Emarsys (headquartered in Austria) processes EU data within the EU. US deployments rely on SCCs.
Should You Block This Without Consent?
Conditional. SAP Customer Data Cloud's core authentication and consent collection scripts are functional and can load without marketing consent. SAP Emarsys' behavioral tracking scripts (scarab.js) should be blocked until marketing consent is obtained. Evaluate each SAP product independently — the presence of one SAP product does not imply all SAP products are deployed.
Is SAP GDPR compliant?
SAP typically loads marketing and functional trackers, which are not strictly necessary for your site to work. Under the GDPR and the ePrivacy Directive, non-essential cookies and trackers must stay blocked until a visitor gives clear opt-in consent. So SAP can be fully GDPR compliant, but only if your site holds its scripts until consent is granted and lets visitors decline just as easily. Compliance depends on how your site loads SAP, not on SAP itself.
Products (3)
Consent Categories
Also Known As
Industries
Tracked Domains (2)
SAP's trackers are rarely seen, seen on under 1% of the sites ConsentStack has scanned. Scan your own site to see which of these are firing before consent.
scarabresearch.comMarketingscarabresearch.com is a marketing domain operated by SAP, used to serve ads, build audiences, and measure ad conversions. Seen on under 1% of scanned sites.
sap.comMarketingsap.com is a marketing domain operated by SAP, used to serve ads, build audiences, and measure ad conversions.
Frequently Asked Questions
Related Vendors


Manage consent for SAP
ConsentStack automatically detects and manages SAP trackers so your site stays compliant with global privacy regulations.