Features Pricing GDPR cookie banner Google Consent Mode v2 WordPress plugin Cookiebot alternative For Agencies GDPR ePrivacy About Contact
RO | EN
Start Free →
Statistics

sbjs_udata Cookie (WooCommerce) – What It Is & Does

sbjs_udata is a session cookie set by the Sourcebuster.js library, used by WooCommerce, to record information about a visitor's browser and device for traffic-source tracking. It supports attributing sales to the correct marketing channel and falls under the statistics/analytics category.

Name
sbjs_udata
Provider
WooCommerce
Category
Statistics
Type
HTTP cookie
Lifetime
Session
Consent
Yes, before it is set (GDPR / ePrivacy)

What is the sbjs_udata cookie?

sbjs_udata is a cookie generated by Sourcebuster.js, an open-source JavaScript library commonly bundled with online stores running WooCommerce (the e-commerce plugin for WordPress). Its role is to identify a visitor's traffic source so that completed orders can be correctly attributed to the marketing channel that drove them (Google, Facebook, email, direct traffic, etc.).

The cookie appears as soon as a visitor lands on a WooCommerce site that has traffic-source tracking enabled, either through marketing/affiliate extensions or custom store integrations. It is a session cookie, so it is automatically deleted when the browser is closed.

What data it stores

sbjs_udata stores technical information about the visitor's device and browser – typically the browser user agent, screen resolution, and browser language. This data does not directly identify the person, but it contributes to a technical profile of the browsing session.

The exact value format may vary depending on the version of Sourcebuster.js used by the theme or installed extensions. The data is generally kept locally in the browser and read by the site's scripts to complete attribution information sent to the store's internal analytics (not to an external third-party server, since Sourcebuster.js is a self-hosted library).

What it is used for

The main purpose of sbjs_udata is to support accurate attribution of sales and conversions within a WooCommerce store. Together with other cookies in the "sbjs_" family (e.g. sbjs_current, sbjs_first, sbjs_session), it helps reconstruct the path a visitor took, from their first visit to a completed order.

For the site owner, this data provides insight into the effectiveness of the marketing channels used (paid campaigns, social media, newsletters) and helps optimize the promotion budget, without necessarily involving data transfer to an external third party.

Does it require consent?

Because sbjs_udata is used for analytics and traffic attribution, and is not strictly necessary for the site's core functionality (displaying products, the shopping cart, checkout), CookieFix classifies it under the statistics/analytics category.

Under GDPR and the ePrivacy Directive (transposed in Romania through Law 506/2004), cookies in this category require the visitor's prior, explicit consent before being set. Site owners must disclose it in their cookie policy and make sure the Sourcebuster.js/WooCommerce script that generates it only runs after consent has been obtained.

How to block or delete sbjs_udata

  • Visitors can manually delete or block sbjs_udata from their browser settings (Chrome, Firefox, Edge, Safari), under the cookie management section for a specific site.
  • Being a session cookie, it disappears automatically when the browser is closed, but it can be recreated on the next visit if the script runs again.
  • For site owners, the most effective approach is blocking the script site-wide before consent, using a CMP such as CookieFix, which can automatically stop statistics-category tracking scripts from running until the visitor gives consent.

Frequently asked questions

It records technical information about the visitor's browser and device, used by Sourcebuster.js to attribute WooCommerce sales to the correct traffic source.

No, it does not store sensitive data like passwords or payment details; it only contains technical data about the browsing session.

It is a session cookie, so it is automatically deleted when the visitor closes their browser.

Yes, since it is used for analytics and traffic attribution, it requires the visitor's prior consent under GDPR and ePrivacy rules.

Updated 7 September 2026 · Information comes from the provider’s public documentation and CookieFix scans; it is not legal advice.