检查清单

BigCommerce pre-consent checklist

开始免费审计

Check BigCommerce Script Manager, apps, pixels, and cache before Accept. Compare Fresh and Reject on the public shop URL. A test checklist.

In brief

On a BigCommerce storefront, a pre-consent check loads the public shop in a browser, skips Accept, and records whether marketing pixels and non-essential cookies stay off until a choice. Script Manager, theme scripts, marketplace apps, and a page cache can fire early. Compare Fresh with Reject All, then use Accept All as a positive control. ConsentProbe can run those scenarios. A free US-baseline scan is not an EU or California legal conclusion. This checklist is testing guidance, not legal advice.

Not legal advice

This checklist helps BigCommerce operators observe cookies, pixels, and scripts that fire before Accept. It is not legal advice, not a GDPR, ePrivacy, or CPRA certificate, and not an official BigCommerce document. ConsentProbe reports are technical observations of what fired. They do not say what counsel would allow.

Last updated September 24, 2026. Admin and Script Manager labels change, so this page describes capabilities, not click-paths. The pre-consent checklist owns the platform-agnostic pass. The before-Accept audit owns the longer method. Shopify and WooCommerce have sibling checklists. This page stays on BigCommerce.

Short answer

Load the public shop in a clean browser, do not click Accept, and check that marketing pixels and non-essential cookies stay off until a choice. Pay attention to Script Manager snippets, theme header and footer scripts, and marketplace apps for pixels, analytics, chat, and reviews. A CDN or page-cache layer can serve a stale banner state, or HTML that already contains tags.

List first-party and third-party cookies, capture the key requests, then compare after Reject All. A CMP app in the control panel is a claim. The storefront visit is the record. ConsentProbe can run labeled Fresh and Reject scenarios on the public URL and tie findings to a request, a cookie, or a screenshot.

Use the platform-agnostic checklist for the method that is not tied to one cart. Shopify merchants use the Shopify checklist. WooCommerce shops use the WooCommerce checklist. A free US-baseline scan is not an EU or California legal conclusion. ConsentProbe does not install a CMP. This checklist is testing guidance, not legal advice.

Why BigCommerce gets its own list

BigCommerce storefronts combine Script Manager, theme code, and marketplace apps. Those pieces can inject tags on first paint even when a CMP app is installed. Shopify's app embeds and WooCommerce's plugin stack are different early-fire paths. Do not paste either sibling checklist onto this one.

Use the public homepage and one public product URL. A Stencil preview is a useful debug view. Cite the customer URL for the pass you will keep. Note whether a page cache, a CDN, or an optimization layer is on. That note explains a stale result. It is not a ranking of cache vendors.

Prep the browser

One clean profile is enough for the first pass. Do not click Accept on that pass. If results flicker between loads, purge the cache you control and run the same public URL again before you call it a tag bug.

  1. Open a clean browser profile.
  2. Load the public homepage, then one public product URL.
  3. Note whether a page cache, CDN, or optimization layer is active.
  4. Leave the banner unclicked on this first pass.

Checklist

Read each row as an observation. A missing Reject control is a record of the UI you saw, not a legal ruling about the banner design. Analytics and ads IDs, including a _ga-style cookie, belong on the pre-Accept list when they appear before a choice. Permission for any of them stays with counsel. Party labels, when you need them, live on the first-party versus third-party guide. This page only asks you to list both domains.

BigCommerce storefront checks before Accept, after Reject, and after Accept.
CheckPass signalFail signal
Fresh load, no clickNo ads or marketing pixels on the public URLMeta, Google Ads, or TikTok-style hosts before Accept
Cookies before AcceptNo clear marketing or analytics IDs beyond what you are treating as essential for this testEarly analytics IDs, ads IDs, or similar values
Script Manager, apps, and themeOptional scripts wait until a choiceChat, reviews, upsell, or similar tools inject trackers early
Cache or CDNFresh and Reject states match the live banner behaviorStale HTML fires tags or shows the wrong banner state
Reject All, then navigateMarketing stays off on the next pageThe same fan-out as Accept
Accept AllThe vendors you expect show up as a positive controlYou cannot tell on from off, so the earlier rows are hard to read

Script Manager, apps, and cache

Suspect list, not a brand ranking: Script Manager snippets, theme header or footer injects, pixel apps, analytics apps, chat widgets, review widgets, upsell modules, and abandoned-cart tools. If one of them sets an ID or sends a hit before a choice, write the snippet or app name when you know it, plus the host or cookie name. A label inside Script Manager that calls a script essential is still a claim. Confirm it on the public URL.

Cache failures look like a tag that disappears after a hard reload, or a banner that still offers Accept after you already clicked Reject. Re-test after a purge when the two loads disagree. This page does not walk a control-panel menu. Those labels move.

What to send engineering

Send state-labeled screenshots, the cookie list, and the key request rows. Add the Script Manager snippet name or app name when you have it. The evidence pack guide holds the fuller field list. Keep this handoff to the Fresh row, the Reject row, and the Accept control.

Run Fresh and Reject on the shop URL

Walking Script Manager, apps, and cached pages by hand takes a long time. ConsentProbe runs labeled Fresh and Reject scenarios on the public URL. Each finding stays tied to a request, a cookie, or a screenshot.

Use the free US-baseline visit when you want the report format. Use paid EU or California scenarios when those regions are the claims. The free versus paid guide draws that line. ConsentProbe does not replace a CMP app, does not install a CMP, and does not issue a certificate.

FAQ

Is a CMP app enough on BigCommerce?

Only if the storefront runtime matches. Check Fresh and Reject in the browser. The control panel is not that check.

Can Script Manager break a pre-consent test?

Yes, when a snippet injects marketing hosts before a choice. List the snippet name and the host.

Can caching break a consent test?

Yes. Stale HTML or a CDN copy can fire tags or show the wrong banner state. Purge and re-test when two loads disagree.

Is this the same as the Shopify or WooCommerce checklist?

No. Those are sibling pages. The platform-agnostic pass is the pre-consent checklist. This page stays on BigCommerce.

Does a free US scan prove GDPR for EU shoppers?

No. A free US-baseline scan is not an EU legal conclusion. See the free versus paid guide.

Is this legal advice?

No. This is a technical checklist. ConsentProbe does not replace counsel, and it does not install a CMP.

Limits of this page

This page is a BigCommerce pre-consent checklist for Script Manager, apps, pixels, and cache. It is not legal advice, not a Shopify or WooCommerce guide, and not a certificate. ConsentProbe reports stay tied to requests, cookies, and screenshots. A free US-baseline scan is not an EU or California legal conclusion.

Related guides

Open the pre-consent checklist for the platform-agnostic pass and the before-Accept audit for the longer method. The Shopify and WooCommerce checklists are sibling pages. Keep their steps on those pages.

Sources

These links cover the platform and regulatory context used in this guide. Applicability still depends on the organization and jurisdiction.

保存一次美国基线技术记录

完成自行检查后,可以跑一次免费美国基线审计:在加州以外做一次浏览器访问,把 Cookie、请求和截图存成证据。这次访问不会跑欧盟拒绝/接受,也不会跑加州 GPC。欧盟、加州和 Global 2 可在登录后的账单页购买。

BigCommerce 同意前检查清单 | ConsentProbe