FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. E-commerce
  4. BigCommerce

BigCommerce

Preferences

Related services

24nettbutikk

24nettbutikk is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. 24nettbutikk supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, 24nettbutikk ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Preferences

2ClickShop

2ClickShop is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 2ClickShop integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 2ClickShop helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences

4-Tell

4-Tell is a marketing platform that equips businesses with tools to amplify their digital presence and drive customer acquisition. It supports audience segmentation, campaign automation, and cross-channel engagement. 4-Tell provides real-time analytics and reporting dashboards for performance measurement and strategy optimization. By combining data intelligence with marketing execution, 4-Tell helps deliver the right message to the right audience at the right time.

Preferences

42stores

42stores is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 42stores integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 42stores helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences

4Partners

4Partners is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 4Partners integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 4Partners helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences
4

4Partners CMS

4Partners CMS is a powerful content management system (CMS) designed to help businesses and developers build, manage, and publish digital content with ease. It offers a flexible architecture that supports custom content types, templates, and workflows, making it ideal for websites of any scale. With 4Partners CMS, teams can streamline content creation, improve collaboration, and deliver engaging web experiences. Its extensible plugin ecosystem and API-first approach ensure seamless integration with.

Preferences
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does BigCommerce do?

BigCommerce is a hosted enterprise ecommerce platform competing with Shopify. Provides a storefront, checkout, native analytics, marketing tools and a Stencil theme engine. Strictly necessary cookies, plus consent for analytics and marketing apps and for the BigCommerce native analytics module.

What BigCommerce is

BigCommerce is a hosted ecommerce platform competing with Shopify and Adobe Commerce. It provides a storefront, a checkout, a Stencil theme engine, native analytics, abandoned cart recovery, email marketing, multi storefront, a headless API and a marketplace of apps. The platform serves the storefront pages, hosts product and order data, and exposes a Storefront API, a GraphQL Catalog API and a webhook system used by integrations.

Cookies set by BigCommerce

The strictly necessary cookies are BIGipServer* (load balancer affinity, session), _bigcommerce_session (session cookie that keeps the basket and the login), fornax_anonymousId (1 year, anonymous visitor identifier for the BigCommerce native analytics and abandoned cart recovery), XSRF-TOKEN (session, anti CSRF) and checkout_csrf_token (session, checkout CSRF). The native analytics module also sets _bcsi-c_external_account and conversion_visitor when active. Installed apps from the Marketplace add their own cookies (Facebook Pixel, Google Analytics, Klaviyo, etc.).

GDPR, ePrivacy and the checkout

For the checkout and the order, GDPR art. 6(1)(b) (contract) and art. 6(1)(c) (accounting obligation) apply, and the strictly necessary cookies are exempt from consent under ePrivacy art. 5(3). The BigCommerce native analytics and the fornax_anonymousId cookie used for behavioural tracking require consent under GDPR art. 6(1)(a). Any app from the App Marketplace that loads tracking pixels, recommendations engines or live chat needs to be wired to your CMP, because BigCommerce does not gate apps automatically.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Data residency and US access

EU storefronts are hosted on Google Cloud Platform regions eu-west-1 (Ireland) and europe-west4 (Eemshaven, Netherlands). The Stencil CDN runs on Fastly with European edges. The BigCommerce corporate analytics, support, fraud prevention and engineering tools are operated centrally from Austin, Texas. BigCommerce is certified under the EU US Data Privacy Framework. A Transfer Impact Assessment must accompany the deployment because US engineers retain contractual access to the EU databases.

Compliance checklist

Sign the BigCommerce Data Processing Addendum and pick the EU storage region, list strictly necessary cookies in the privacy notice without gating, gate the native analytics and every marketing app behind the relevant CMP categories, configure the BigCommerce GDPR consent capture for newsletter and account creation flows, train support on the BigCommerce DSAR process, document the apps as sub processors and minimise the order data retention.

GDPR consent category

Preferences

Websites using BigCommerce must obtain user consent under GDPR regulations.

Legal basisFor checkout and order processing: performance of a contract (GDPR art. 6(1)(b)) and legal obligation (art. 6(1)(c)) for accounting and tax records. For strictly necessary session cookies (BIGipServer, _bigcommerce_session, fornax_anonymousId): legitimate interest and the ePrivacy art. 5(3) exemption. For the BigCommerce native analytics, marketing automations and any installed app that profiles visitors: consent under GDPR art. 6(1)(a) and ePrivacy art. 5(3).
Risk levelmedium
Applicable regulationsGDPR, ePrivacy Directive, CNIL ecommerce guidance, EU US Data Privacy Framework, PSD2 for payment processing, NIS 2 for critical service providers, German TTDSG, AEPD ecommerce guidelines

DPIA considerations

A DPIA is recommended when the BigCommerce native analytics, the marketing automation modules or the Customer Login B2B Edition are enabled because they build behavioural profiles of customers. The DPIA should document the EU storage region, the access from US, Mexico and Philippines support teams, the retention of order history, the integration with third party apps from the BigCommerce App Marketplace and the legal basis for each marketing flow.

Sample consent text

Our store runs on BigCommerce. We use strictly necessary cookies to keep your basket and your session working (BIGipServer, _bigcommerce_session, fornax_anonymousId). With your consent we activate BigCommerce native analytics, marketing automations and third party apps that may set additional cookies. Your data is stored in the European Union (Dublin and Eemshaven) and may be accessed by BigCommerce support in the United States under the EU US Data Privacy Framework. You can accept, refuse or withdraw at any time.

Technical details

Tracking methodhosted_ecommerce_platform_with_first_party_cookies_and_native_analytics
Server locationBigCommerce is hosted on a multi cloud architecture (Google Cloud Platform primary, AWS secondary) with data centres in the United States (us-central1, us-east-1) and Europe (eu-west-1 Ireland, europe-west4 Netherlands). EU based merchants are served from the Dublin and Eemshaven regions by default but the corporate analytics, fraud prevention and support tools are operated centrally from the US headquarters in Austin, Texas.
Data transferred outside the EUBigCommerce Holdings Inc. is a US company headquartered in Austin, Texas. Even when the storefront and order data are stored on EU infrastructure, support and engineering teams in the US, Mexico, Ukraine and the Philippines retain contractual access. BigCommerce is certified under the EU US Data Privacy Framework and signs the 2021 Standard Contractual Clauses as fallback. The Stencil CDN runs on Fastly with EU points of presence.

Third-party domains contacted

mybigcommerce.combigcommerce.combigcommerce.commybigcommerce.comcdn11.bigcommerce.combcapp.devbigcommerceapp.comapi.bigcommerce.comcdn.bigcommerce.comcdn11.bigcommerce.com

Cookies placed

NameTypeDurationPurpose
SHOP_SESSION_TOKENfirst_party1 yearBigCommerce shopping session token that links the visitor browser to the active cart, customer wishlist and recently viewed products. Strictly necessary for the checkout flow.
SHOP_SESSION_TOKENStrictly necessarySessionIdentifies the shopper's session on the storefront. Required to maintain a logged in state and a working cart between pages.
CART_URLStrictly necessary7 daysStores a reference to the current shopping cart so that the shopper can resume the cart on a later visit or another device after recovery.
SHOP_TOKENfirst_party30 daysAuthenticated customer session token. Set after login to keep the customer signed in across the storefront and to enable saved payment methods and order history.
fornax_anonymousIdStrictly necessary12 monthsAssigns an anonymous identifier to the visitor for cart recovery and order continuity, even before login or registration.
fornax_anonymousIdfirst_party1 yearAnonymous identifier used by BigCommerce Analytics to attribute pageviews, cart actions and conversions to a single visitor session before login.
XSRF-TOKENStrictly necessarySessionProtects against Cross Site Request Forgery attacks on the BigCommerce storefront and checkout. Required for secure form submissions.
PHPSESSIDfirst_partySessionUnderlying PHP session cookie used by the BigCommerce backend during page rendering and form submissions. Strictly necessary.
CART_URLfirst_partySessionStores the current cart URL so the customer can resume the basket later in the same session. Strictly necessary for the shopping flow.
_abckStrictly necessary (security)12 monthsAkamai Bot Manager cookie used by BigCommerce to distinguish legitimate shoppers from automated bots during checkout and login.
bc_visitorIdAnalytics12 monthsBigCommerce Analytics cookie that assigns a pseudonymous visitor ID for storefront usage analysis and conversion reporting.
_ga / _ga_*third_party2 yearsGoogle Analytics cookies dropped when the merchant connects Google Analytics through Channel Manager. Require consent under ePrivacy.
_fbpthird_party90 daysMeta Pixel browser identifier dropped when the merchant connects the Facebook channel. Used for ad measurement and retargeting; requires consent.
_ttpthird_party13 monthsTikTok Pixel browser identifier dropped when the TikTok channel is connected. Used for conversion measurement and audience building; requires consent.

BigCommerce uses cookies for user preferences — inform visitors with a consent banner.

Get started freeScan your site

Frequently asked questions

Which cookies does BigCommerce set by default?

The default Stencil storefront sets SHOP_SESSION_TOKEN for the shopping session, SHOP_TOKEN for authenticated customers, fornax_anonymousId for cart attribution and PHPSESSID for the underlying PHP session. Optional analytics and marketing pixels (BigCommerce Analytics, Google Analytics, Meta Pixel, TikTok Pixel) are added when the merchant connects them through Channel Manager.

Does BigCommerce require user consent for cookies?

Cart, checkout and authentication cookies are strictly necessary and exempt under Article 5(3) ePrivacy. All BigCommerce Analytics, connected ad pixels and any third party script loaded through Scripts Manager require prior, freely given, specific, informed and unambiguous consent under GDPR and ePrivacy.

What legal basis applies to BigCommerce processing?

Cart and checkout cookies rely on Article 6(1)(b) GDPR (contract). Order management, fraud prevention and security rely on Article 6(1)(f) GDPR (legitimate interest). Analytics, marketing and personalisation cookies require Article 6(1)(a) GDPR consent. BigCommerce processes data as a processor under Article 28 GDPR.

Does BigCommerce transfer data to the United States?

Yes. BigCommerce Inc. is established in the US and processes data on Google Cloud Platform with US primary regions. The company self certifies under the EU US Data Privacy Framework, providing an adequacy basis. Standard Contractual Clauses are included in its DPA as an additional safeguard.

Is a DPIA needed for BigCommerce?

A small DTC store using only cart and checkout cookies usually does not need a DPIA. It becomes recommended for large stores, B2B portals processing big customer datasets, behavioural personalisation, multi channel retargeting or programmes combining loyalty, CRM and offline data.

How do I implement BigCommerce compliantly?

Sign the BigCommerce DPA, document the US transfer, list every cookie in your cookie policy, connect a consent management platform that intercepts tags injected through Scripts Manager and Channel Manager, enable IP anonymisation for connected analytics, and surface BigCommerce data subject request tools to your customers.

Are there EU based alternatives to BigCommerce?

EU based hosted ecommerce alternatives include Shopware (Germany), Lightspeed eCom (Netherlands and Canada), PrestaShop Cloud (France) and Centra (Sweden). Self hosted alternatives include WooCommerce, Magento Open Source, PrestaShop and Sylius. All require their own cookie audit.

How do I update my cookie policy for BigCommerce?

Run a fresh cookie scan after each Channel Manager or Scripts Manager change, list each storefront cookie with name, purpose, duration and provider, document analytics and marketing pixels, link to BigCommerce, Google, Meta and TikTok privacy notices, and update the EEA transfer information whenever the regional setup changes.

Which cookies does BigCommerce set on the storefront?

A default Stencil storefront sets strictly necessary cookies for the session and the cart (SHOP_SESSION_TOKEN, CART_URL, fornax_anonymousId, XSRF-TOKEN), security cookies for bot mitigation (_abck, bm_sz) and, if enabled, BigCommerce Analytics cookies plus any third party cookies from channels such as Google Analytics 4, Meta Pixel, TikTok Pixel or Klaviyo.

Is consent required to use BigCommerce in the EU?

Consent is not required for cart and checkout cookies that are strictly necessary to fulfil the order, which fall under the ePrivacy exemption. Consent is required for BigCommerce Analytics, marketing pixels and any optional A/B testing or personalization scripts before they are loaded, in line with Article 6(1)(a) GDPR and Article 5(3) of the ePrivacy Directive.

What is the legal basis for processing data through BigCommerce?

Order processing and account management rely on the performance of a contract under Article 6(1)(b) GDPR. Fraud prevention and platform security rely on legitimate interest under Article 6(1)(f) GDPR. Analytics, marketing pixels, personalization and re marketing rely on consent under Article 6(1)(a) GDPR collected through a consent management platform.

Are data transfers to the United States compliant under GDPR?

BigCommerce signs the EU Standard Contractual Clauses under Article 46(2)(c) GDPR with merchants via its Data Processing Addendum and confirms participation in the EU US Data Privacy Framework. Supplementary technical measures include TLS 1.3, encryption at rest, AWS regional isolation, PCI DSS Level 1 certification and SOC 2 Type II audits.

Do I need a DPIA for BigCommerce?

A DPIA is recommended when BigCommerce is used to systematically profile EU shoppers (advanced segmentation, behavioural triggers, abandoned cart automation), when the storefront serves regulated sectors (financial services, health, alcohol) or when sensitive data is collected at checkout. A DPIA is generally not necessary for a small storefront limited to standard order and contact data.

How should I implement BigCommerce in a GDPR compliant way?

Sign the BigCommerce Data Processing Addendum, list BigCommerce in your record of processing activities, configure a consent management platform integrated with the storefront, gate BigCommerce Analytics and channel pixels behind that consent, document retention rules for orders and customer accounts, and use the BigCommerce GDPR endpoints to handle access, rectification and deletion requests.

What are the alternatives to BigCommerce in Europe?

European merchants often consider Shopify (CA, US data residency), Shopware (Germany), Sylius and Sulu (open source, EU hosting), PrestaShop (France) and headless options like commercetools (Germany) or Saleor (Poland). The right choice depends on hosting requirements, B2B features, total cost of ownership and the depth of channels integrations needed.

How do I update the cookie policy when using BigCommerce?

List BigCommerce Holdings Inc. as the processor of the storefront, describe the categories of cookies set by Stencil (functional, security, analytics, marketing), mention the United States hosting and the SCC plus DPF safeguards, link to the BigCommerce Privacy Notice and explain how to withdraw consent through your consent management platform.