FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. E-commerce
  4. BigCommerce B2B Edition

BigCommerce B2B Edition

PreferencesWebsite

Related services

24nettbutikk

24nettbutikk is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. 24nettbutikk supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, 24nettbutikk ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Preferences

2ClickShop

2ClickShop is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 2ClickShop integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 2ClickShop helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences

4-Tell

4-Tell is a marketing platform that equips businesses with tools to amplify their digital presence and drive customer acquisition. It supports audience segmentation, campaign automation, and cross-channel engagement. 4-Tell provides real-time analytics and reporting dashboards for performance measurement and strategy optimization. By combining data intelligence with marketing execution, 4-Tell helps deliver the right message to the right audience at the right time.

Preferences

42stores

42stores is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 42stores integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 42stores helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences

4Partners

4Partners is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 4Partners integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 4Partners helps organizations maintain robust websites that meet user expectations and technical requirements.

Preferences
4

4Partners CMS

4Partners CMS is a powerful content management system (CMS) designed to help businesses and developers build, manage, and publish digital content with ease. It offers a flexible architecture that supports custom content types, templates, and workflows, making it ideal for websites of any scale. With 4Partners CMS, teams can streamline content creation, improve collaboration, and deliver engaging web experiences. Its extensible plugin ecosystem and API-first approach ensure seamless integration with.

Preferences
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does BigCommerce B2B Edition do?

BigCommerce B2B Edition is the wholesale tier of the BigCommerce hosted commerce platform, with custom price lists, account hierarchies, quote management and a buyer portal. It runs on US infrastructure (Google Cloud) and sets first party cookies for cart, session and customer authentication, alongside optional analytics and marketing pixels that require consent under GDPR and ePrivacy.

What BigCommerce B2B Edition delivers

BigCommerce B2B Edition is the wholesale tier of the BigCommerce hosted commerce platform. It layers a B2B specific feature set, customer specific price lists, multi-level account hierarchies, quote management, sales rep dashboards and a self service buyer portal, on top of the standard BigCommerce storefront. The platform is delivered as software as a service: BigCommerce, Inc. operates the application, the database and the storefront CDN, while the merchant retains control over catalog, branding and the buyer experience. All storefront traffic, admin sessions and API calls terminate on BigCommerce infrastructure hosted on Google Cloud Platform in the United States.

Data and cookies set by the storefront

The storefront writes several first party cookies: SHOP_SESSION_TOKEN to maintain the shopping cart, fornax_anonymousId to identify the visitor across pages, CART_URL for cart recovery, XSRF-TOKEN for CSRF protection and an authentication cookie for logged in buyers. These cookies are strictly necessary for the contract performance covered by Article 6(1)(b) GDPR. In parallel the merchant may enable analytics (Google Analytics, BigCommerce Insights), marketing pixels (Meta, TikTok, LinkedIn) and personalisation engines, each of which sets its own cookies and requires prior consent under ePrivacy Article 5(3).

GDPR and ePrivacy implications

BigCommerce, Inc. acts as a data processor for the merchant under Article 28 GDPR. The Data Processing Addendum (DPA) bundled with the platform contract reflects the processor obligations and lists sub processors. Strictly necessary commerce cookies (session, cart, authentication) do not require consent because they are essential to deliver the service the buyer has explicitly requested. Analytics and marketing cookies always do. Merchants must therefore wire a CMP into the storefront and block non essential vendors until consent is captured. B2B portals that target named buyers may also rely on contract or legitimate interest for first party behavioural analytics, but a documented balancing test is then required.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

International data transfers and the DPF

Because BigCommerce processes buyer accounts, orders and storefront analytics in the United States, every European merchant must rely on a Chapter V transfer mechanism. BigCommerce maintains an EU US and UK extension Data Privacy Framework certification, considered adequate by the Commission and recognised by the UK ICO. The DPA also offers the 2021 EU Standard Contractual Clauses for merchants that prefer not to depend on the DPF. A Transfer Impact Assessment should review the impact of FISA Section 702 and Executive Order 12333 on buyer account data, particularly when the catalog contains sensitive procurement information.

Consent, DPIA and security controls

For B2B portals that store extensive buyer profiles or expose pricing intelligence, a DPIA is advisable. The assessment should cover the categories of buyers and procurement contacts, the retention of order history, the use of behavioural analytics inside the B2B portal and the impact of the US transfer. BigCommerce holds PCI DSS Level 1 certification and SOC 2 Type II reports that can be referenced in the DPIA. Single sign on, IP allowlists and two factor authentication on the admin should be enabled as technical safeguards.

Practical compliance steps and alternatives

Wire a CMP such as Didomi, Cookiebot or OneTrust into the storefront and use BigCommerce Script Manager to conditionally fire analytics and marketing scripts only after consent. Document the DPF certification number and the SCCs in the cookie policy. Refresh the cookie scan after every storefront theme update. EU based alternatives include Shopware (Germany), Spryker (Germany), commercetools (Germany) and Centra (Sweden) for merchants who must keep all processing inside the EU/EEA.

GDPR consent category

Preferences

Websites using BigCommerce B2B Edition must obtain user consent under GDPR regulations.

Legal basisContract performance (Art. 6(1)(b) GDPR) for cart, session, account and order cookies. Consent (Art. 6(1)(a) GDPR and ePrivacy Article 5(3)) for analytics, marketing and personalisation cookies set on the storefront.
Risk levelmedium
Applicable regulationsGDPR, ePrivacy Directive 2002/58/EC, PCI DSS 4.0, CCPA/CPRA, UK GDPR

DPIA considerations

A DPIA is recommended for B2B merchants that process large volumes of buyer account data, payment metadata or behavioural analytics through BigCommerce. Map the data flow from storefront to BigCommerce US infrastructure, assess the impact of FISA Section 702 on hosted customer records, and verify that the BigCommerce Data Processing Addendum covers all sub processors. The DPIA should distinguish between strictly necessary commerce cookies (contract basis) and consent based marketing tags injected via the storefront.

Sample consent text

This wholesale storefront runs on BigCommerce B2B Edition. Cookies used to keep you signed in, hold your cart and process orders are strictly necessary and do not require your consent. We also set optional analytics and marketing cookies to measure storefront performance and to deliver relevant offers. You can accept, refuse or change these choices at any time using our preference center.

Technical details

Tracking methodHosted SaaS commerce platform served from US data centers. Sets first party functional cookies for session, cart and authentication, plus optional analytics and marketing cookies for the storefront, B2B portal and checkout.
Server locationUnited States (Google Cloud Platform, primary regions us-central1 and us-east1), with CDN edges worldwide via Fastly
Data transferred outside the EUBigCommerce, Inc. is headquartered in Texas and processes storefront, account and order data on US infrastructure. EU to US transfers rely on the EU US Data Privacy Framework certification or the EU 2021 Standard Contractual Clauses set out in the BigCommerce Data Processing Addendum.

Third-party domains contacted

bigcommerce.commybigcommerce.comcdn11.bigcommerce.comb2b-edition.bigcommerce.comapi.bigcommerce.com

Cookies placed

NameTypeDurationPurpose
SHOP_SESSION_TOKENfunctionalSessionMaintains the buyer session and links the cart to the visitor across page loads. Strictly necessary for contract performance.
fornax_anonymousIdfunctional12 monthsAnonymous identifier that ties storefront pageviews to a single visitor so the cart and personalisation features work. Strictly necessary.
CART_URLfunctional30 daysStores the URL of an abandoned cart so the buyer can be redirected back to it. Strictly necessary for the cart recovery feature.
XSRF-TOKENstrictly-necessarySessionCSRF protection token used to validate requests sent to the BigCommerce storefront and admin.
_bc_customer_loginfunctional12 monthsAuthentication cookie for logged in B2B buyers, used by the buyer portal and quote management. Strictly necessary while logged in.
bc_visitorIdanalytics12 monthsOptional identifier used by BigCommerce Insights to measure storefront performance. Requires consent.

BigCommerce B2B Edition uses cookies for user preferences — inform visitors with a consent banner.

Get started freeScan your site

Frequently asked questions

What cookies does BigCommerce B2B Edition set?

The storefront writes session cookies (SHOP_SESSION_TOKEN, _bc_customer_login), an anonymous visitor identifier (fornax_anonymousId), a cart recovery cookie (CART_URL) and a CSRF token (XSRF-TOKEN). All of these are strictly necessary. If the merchant turns on BigCommerce Insights, a Google Analytics integration or a marketing pixel, additional consent based cookies are set.

Is consent required to operate a BigCommerce B2B storefront?

Consent is not required for the strictly necessary cookies that power the cart, the session and the buyer authentication, because they are essential to the commerce service the buyer has explicitly requested. Consent is required for every analytics, marketing or personalisation cookie added on top, including the BigCommerce Insights cookies if you activate them.

What legal basis applies to BigCommerce B2B processing?

Performance of a contract (Art. 6(1)(b) GDPR) covers cart, checkout, account and order processing. Legal obligation (Art. 6(1)(c)) covers invoicing and tax reporting. Consent (Art. 6(1)(a) GDPR and ePrivacy Article 5(3)) covers analytics, marketing and personalisation cookies. Legitimate interest (Art. 6(1)(f)) may justify fraud prevention and security telemetry with a documented balancing test.

Are there data transfers to the United States?

Yes. BigCommerce, Inc. is based in Texas and processes storefront, account and order data on Google Cloud infrastructure in the United States. The platform is certified under the EU US Data Privacy Framework (and its UK extension). The DPA also offers the 2021 EU Standard Contractual Clauses as an alternative. A Transfer Impact Assessment is recommended for any B2B catalog that holds sensitive procurement data.

When is a DPIA required for a BigCommerce B2B store?

A DPIA is recommended when the B2B portal stores detailed buyer profiles, payment metadata, or behavioural analytics, or when the storefront targets sectors with sensitive purchases (defence, healthcare, energy). The assessment must address the US transfer mechanism, the retention of order history, the categories of buyer contacts, and the sub processor list provided in the BigCommerce DPA.

How do I implement BigCommerce B2B compliantly?

Integrate a CMP via the BigCommerce Script Manager so analytics and marketing scripts only run after consent. Sign the BigCommerce DPA and verify the DPF certification number. Enable two factor authentication and IP allowlists on the admin. Disclose strictly necessary cookies in the cookie policy and provide a preference center. Document retention rules for order history and for any abandoned cart recovery feature.

Are there EU based alternatives to BigCommerce B2B Edition?

Yes. Shopware B2B Suite (Germany), Spryker (Germany), commercetools (Germany), Sana Commerce (Netherlands) and Centra (Sweden) all offer wholesale features comparable to BigCommerce B2B Edition with hosting inside the EU/EEE. They remove the US transfer question and often integrate more tightly with European ERP systems such as SAP or Microsoft Dynamics.

How should the cookie policy describe BigCommerce B2B Edition?

List BigCommerce, Inc. as the platform processor, mention that the storefront is hosted in the United States on Google Cloud, and reference the DPF certification and the SCCs in the DPA. Group strictly necessary cookies (session, cart, authentication, CSRF) separately from optional analytics and marketing cookies. Provide a link to the preference center and to the BigCommerce trust center where buyers can read the sub processor list.