Features Pricing GDPR cookie banner Google Consent Mode v2 WordPress plugin Cookiebot alternative For Agencies GDPR ePrivacy About Contact
RO | EN
Start Free →
Necessary

crumb Cookie (Squarespace) – What It Is and What It Does

The crumb cookie is set by the Squarespace website-building platform on sites hosted on its infrastructure, and it is used for form and session security. It is a strictly necessary, session-only cookie that does not require visitor consent under ePrivacy rules.

Name
crumb
Provider
Squarespace
Category
Necessary
Type
HTTP cookie
Lifetime
Session
Consent
No, but it must be listed in the cookie policy

What is the crumb cookie?

The crumb cookie is set by Squarespace, the website and online store builder, on domains running on its infrastructure. It typically appears when a visitor interacts with a form (for example a contact form, checkout form, or the Squarespace admin login) or when pages containing protected dynamic elements load.

The name „crumb” reflects a common technical pattern of attaching a unique verification token — a small „trail” tied to a session — a technique widely used by platforms to prevent Cross-Site Request Forgery (CSRF) attacks.

What data it stores

The cookie stores a randomly generated identifier/token linked to the visitor's or logged-in user's current session. Squarespace does not publish the exact value format, and it varies between sessions; as far as is publicly known, it does not contain directly identifying personal data such as a name or email address.

It is an HTTP cookie with a session lifespan (it is deleted automatically when the browser is closed). Its value is sent to Squarespace's servers along with requests made on the site's domain, to validate form submissions.

What it is used for

The main purpose of the crumb cookie is technical security: it helps Squarespace verify that a form submission genuinely originates from the page shown to the visitor, rather than from a malicious external source. Without this mechanism, a site would be more vulnerable to request forgery (CSRF) attacks.

For the site owner, this cookie does not provide marketing or analytics functionality — it is part of the technical infrastructure that keeps forms, and sometimes login to the Squarespace editor, working correctly.

Does it require consent?

In CookieFix's classification, crumb falls under the strictly necessary category. Under Article 5(3) of the ePrivacy Directive (transposed in Romania via Law 506/2004) and ANSPDCP's interpretation, cookies strictly necessary for a service explicitly requested by the user (here, submitting a secured form) are exempt from the prior-consent requirement.

  • No visitor consent via the banner is required.
  • It must still be disclosed, along with its purpose and duration, in the site's cookie policy for GDPR transparency.
  • Site owners should classify it correctly as „necessary” in their CMP so it is not blocked by default alongside marketing or statistics cookies.

How to block or delete crumb

A visitor can delete or block this cookie from their browser settings (for example Chrome, Firefox, Safari, Edge – per-site cookie management). Since it is strictly necessary, blocking it may prevent forms on Squarespace-powered sites from submitting correctly, causing validation errors.

Because it is a necessary technical cookie, it should not, and generally cannot, be blocked by a CMP without breaking site functionality. A platform like CookieFix automatically scans a site's cookies and classifies crumb as necessary, so the consent banner does not block it, while statistics or marketing cookies remain blocked until the visitor consents.

Frequently asked questions

It is a session cookie used by Squarespace to protect site forms against request forgery (CSRF) by verifying that a submission genuinely comes from the displayed page.

No. It is classified as strictly necessary, so it is exempt from prior consent under ePrivacy rules, but it must still be disclosed in the site's cookie policy.

It is a session cookie; it is automatically deleted when the browser is closed and has no fixed expiration date.

Forms on Squarespace-powered sites (contact, checkout, login) may fail to submit correctly or may trigger security errors.

Updated 8 September 2026 · Information comes from the provider’s public documentation and CookieFix scans; it is not legal advice.