FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. E-commerce
  4. Big Cartel

Big Cartel

PreferencesWebsite

Related services

24nettbutikk

24nettbutikk is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. 24nettbutikk supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, 24nettbutikk ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Preferences

2ClickShop

2ClickShop is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 2ClickShop integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 2ClickShop helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences

4-Tell

4-Tell is a marketing platform that equips businesses with tools to amplify their digital presence and drive customer acquisition. It supports audience segmentation, campaign automation, and cross-channel engagement. 4-Tell provides real-time analytics and reporting dashboards for performance measurement and strategy optimization. By combining data intelligence with marketing execution, 4-Tell helps deliver the right message to the right audience at the right time.

Preferences

42stores

42stores is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 42stores integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 42stores helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences

4Partners

4Partners is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 4Partners integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 4Partners helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences
4

4Partners CMS

4Partners CMS is a powerful content management system (CMS) designed to help businesses and developers build, manage, and publish digital content with ease. It offers a flexible architecture that supports custom content types, templates, and workflows, making it ideal for websites of any scale. With 4Partners CMS, teams can streamline content creation, improve collaboration, and deliver engaging web experiences. Its extensible plugin ecosystem and API-first approach ensure seamless integration with.

Preferences
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does Big Cartel do?

Big Cartel is a US based hosted ecommerce platform popular with artists and makers. Storefronts set strictly necessary cart and session cookies. Because the platform is hosted in the United States, European merchants must disclose the EU US data transfer and obtain consent for any optional analytics or advertising cookie.

What Big Cartel is and how it serves a shop

Big Cartel is a hosted ecommerce platform founded in 2005 by Big Cartel LLC in Salt Lake City, Utah. It targets independent artists, designers and small makers who want a simple online shop with low monthly fees and a fast setup. The storefront runs on a customer subdomain (myshop.bigcartel.com) or a custom domain. The admin is at my.bigcartel.com. Themes can be customized with the Big Cartel theme language and additional analytics or marketing scripts can be embedded.

Cookies and identifiers set on visitors

Big Cartel sets a cart cookie that stores the basket identifier, a _bigcartel_session cookie that maintains the shopper context, a CSRF token to protect the checkout and a few feature flag cookies. These are strictly necessary for the cart and checkout. If the shop owner adds third party tags (Google Analytics, Meta Pixel, Pinterest Tag) through the theme code, those tags create their own cookies and must be governed by a consent banner.

GDPR and ePrivacy implications

Strictly necessary cart and session cookies fall under the Article 5(3) ePrivacy carveout. Article 6(1)(b) GDPR (performance of a contract) covers the order processing flow. Any analytics or advertising tag added to the theme requires prior opt in consent under Article 5(3) ePrivacy. The shop owner is the controller, Big Cartel LLC is the processor under Article 28 GDPR with a DPA in the merchant terms of service.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Data transfers and Schrems II

All Big Cartel shop data is hosted in the United States on AWS US East 1. European merchants must include this transfer in the privacy notice with the legal basis (Standard Contractual Clauses and the EU US Data Privacy Framework). The Fastly CDN serves static assets globally from edge nodes, which is acceptable since cached HTML and images do not carry personal data. Email notifications for orders go through US based mail providers.

Practical compliance steps

Add a consent banner script to the theme that blocks third party trackers until the visitor opts in. Include the US transfer disclosure in your privacy notice. Sign the Big Cartel DPA (included by reference in the Terms of Service). Document the processor in your record of processing activities with the AWS US East 1 region, the order retention period and the list of third party scripts. Configure a procedure for shopper data access and erasure requests via the Big Cartel admin or email.

GDPR consent category

Preferences

Websites using Big Cartel must obtain user consent under GDPR regulations.

Legal basisArticle 6(1)(b) GDPR (performance of a contract) for order processing. Article 6(1)(f) (legitimate interest) for the strictly necessary cart and session cookies. Article 6(1)(a) (consent) and Article 5(3) ePrivacy for any analytics or advertising cookie added through theme customization.
Risk levelmedium
Applicable regulationsGDPR, ePrivacy Directive, DSGVO, RGPD, LSSI, Schrems II, EU US Data Privacy Framework

DPIA considerations

A DPIA is recommended for European Big Cartel shops because the platform stores all order and customer data in the United States, triggering Schrems II considerations. Document the legal basis for the transfer (SCCs and the EU US Data Privacy Framework), the retention period for orders, the consent management strategy for added analytics or advertising tags, and the procedure for data subject access and erasure requests.

Sample consent text

This shop is powered by Big Cartel. Big Cartel sets a cart cookie and a session cookie that are strictly necessary for the checkout to work. Your shop data is stored on Big Cartel servers in the United States. Optional analytics or advertising cookies (Google Analytics, Meta Pixel) added by the shop owner are activated only after you accept them.

Technical details

Tracking methodHosted ecommerce platform for artists and small makers. Storefronts run on bigcartel.com subdomains or custom domains. Big Cartel sets first party cookies for the cart (cart, signed cart token), session (_bigcartel_session), CSRF protection and feature flags. The Big Cartel admin uses authentication cookies on my.bigcartel.com. Shop owners can install third party tags (Google Analytics, Meta Pixel) through theme customization.
Server locationBig Cartel LLC (Salt Lake City, Utah, United States). Hosting on Amazon Web Services with infrastructure primarily in US East 1 (Virginia). Asset delivery via Fastly with global PoPs.
Data transferred outside the EUBig Cartel is a US based company hosted on AWS US East 1. All shop data including order history, customer email addresses and analytics is stored in the United States. The Standard Contractual Clauses and the EU US Data Privacy Framework cover the transfer. European merchants must disclose this to their customers and obtain consent for any non strictly necessary cookie.

Third-party domains contacted

bigcartel.commy.bigcartel.combigcartel-assets.comcdn.bigcartel.netimages.bigcartel.com

Cookies placed

NameTypeDurationPurpose
cartfirst-party30 daysStores the basket identifier so the shopper can return to their cart on later visits. Strictly necessary for ecommerce.
_bigcartel_sessionfirst-partySessionMaintains the shopper session context across pages on the Big Cartel storefront. Strictly necessary.
_bigcartel_csrf_tokenfirst-partySessionCSRF protection token used on the checkout to prevent unauthorized state changes. Strictly necessary.
bigcartel_admin_sessionfirst-party (admin only)SessionAuthentication cookie for the my.bigcartel.com admin. Strictly necessary, not set on the shop storefront.

Big Cartel uses cookies for user preferences — inform visitors with a consent banner.

Get started freeScan your site

Frequently asked questions

Does Big Cartel set cookies on shop visitors?

Yes. Big Cartel sets cart, _bigcartel_session, a CSRF token and feature flag cookies that are strictly necessary for the cart and checkout. Optional analytics or advertising cookies appear only when the shop owner adds the corresponding script to the theme.

Do I need consent for Big Cartel under GDPR and ePrivacy?

No consent is required for the strictly necessary cart and session cookies. Prior opt in consent is required for any analytics or advertising cookie added to the theme, including Google Analytics, Meta Pixel and Pinterest Tag.

What is the legal basis for processing data with Big Cartel?

Article 6(1)(b) GDPR (performance of a contract) for order processing, Article 6(1)(f) (legitimate interest) for strictly necessary cookies, Article 6(1)(a) (consent) for optional tracking cookies. The merchant is the controller, Big Cartel LLC is the processor with a DPA in the merchant terms.

Does Big Cartel transfer data to the United States?

Yes. Big Cartel hosts all shop data on AWS US East 1 in Virginia. The transfer is covered by Standard Contractual Clauses and the EU US Data Privacy Framework. European merchants must disclose this transfer in the privacy notice.

Is a DPIA required for Big Cartel?

A DPIA is recommended for European Big Cartel shops because all customer data is transferred to the United States. Document the transfer legal basis, the retention period and the consent management strategy for any added analytics or advertising tag.

How do I implement Big Cartel compliantly?

Add a consent banner to the theme that blocks analytics and advertising scripts until opt in, include the US transfer in the privacy notice, document the processing in your RoPA, sign the Big Cartel DPA via the merchant terms, and set up a DSAR procedure to handle access and erasure requests for shoppers.

What are the alternatives to Big Cartel?

Other ecommerce platforms suitable for small makers include Shopify, Ecwid (by Lightspeed), Squarespace Commerce, Wix Stores, Etsy (marketplace), Tictail, Cratejoy, Sellfy and self hosted options like WooCommerce, PrestaShop (France) and Shopware (Germany).

How do I update the cookie policy for Big Cartel?

List the strictly necessary Big Cartel cookies (cart, _bigcartel_session, CSRF, feature flags) in your cookie disclosure with purpose and duration. Add an entry for each third party script added to the theme (Google Analytics, Meta Pixel) with retention and EU US transfer information.