Wix is unusual among website builders in how much tracking it bakes directly into the platform rather than leaving it entirely to third-party apps. A Wix site sets its own session and security cookies the moment it loads, and Wix's native Marketing Integrations panel lets you connect a Meta Pixel or Google Ads tag without ever visiting the App Market. That's convenient for site owners, but it also means a cookie policy copied from a generic template misses a layer that's genuinely specific to Wix, cookies the platform itself sets that have nothing to do with any app you've chosen to install.
Here's what a Wix site actually sets, where the rest comes from, and how Wix's own consent banner setting fits into the document you publish.
The cookies Wix sets without any app installed
Every site built on Wix runs a baseline layer of cookies the platform needs for the editor, checkout, and basic security to function, independent of anything in your App Market list:
svSessionidentifies a visitor's session on the site, the core cookie Wix uses to keep a visit coherent as someone moves between pages.hsworks alongsidesvSessionfor session security, helping Wix validate that requests during a visit are coming from the same browser that started it.bSessionis a shorter-lived browser session cookie that supports Wix's own site analytics, the visitor and pageview counts you see in your Wix dashboard.XSRF-TOKENis a cross-site request forgery protection cookie, standard on forms and checkout flows so a submitted form can be verified as coming from your actual site.smSessionappears only on sites with a Members Area, tracking a logged-in visitor's member session separately from the general site session.consent-policystores the choice a visitor makes in your cookie banner, so the banner doesn't reappear on every page load once someone has responded to it.
Most of these are strictly necessary, session and security cookies especially, but "necessary" is a disclosure category, not a reason to leave a cookie off the list. A policy that only names your marketing apps and skips the cookies Wix sets by default is describing an incomplete site.
Wix platform cookies vs App Market and Marketing Integration cookies
| Wix platform cookies | App Market / Marketing | |
|---|---|---|
| Set without any app installed | ||
| Typical purpose | Session, security, checkout | Advertising, reviews, chat |
| Usually strictly necessary | ||
| Configured through | Fixed Wix platform behavior | Marketing Integrations panel |
| Changes when you | Rarely, tied to the editor | Connect a pixel or install an app |
Marketing Integrations: pixels without an app
Wix breaks from most other builders in a specific way worth calling out. Connecting a Meta Pixel, Google Ads tag, Google Analytics property, or a handful of other major ad and analytics tools doesn't require an App Market install at all, it's a native panel under Settings > Marketing Integrations (also called Marketing Tools on some Wix dashboards) where you paste in an ID or authorize the connection directly. Each one you connect there sets its own cookies the same way it would on any other platform, a Meta Pixel drops Meta's tracking cookies, a Google Ads tag drops Google's conversion cookies, and so on, but because the connection happens through Wix's own panel rather than an installed app, it's easy to forget it needs disclosing the same as anything from the App Market.
Where App Market apps add more
Beyond the native Marketing Integrations panel, the App Market is the second and usually larger source of cookies on an active Wix site. Live chat widgets, review and testimonial apps, upsell and cross-sell tools, email capture popups, loyalty programs, and heatmap or session-recording tools (Hotjar and similar) are all installed as apps, and each one typically sets its own cookies or uses browser storage the moment it's added to your site, independent of whatever you've configured in Marketing Integrations.
Wix requires apps published to its App Market to declare what data they collect during the review process, but that declaration lives in the app's own listing, not in your site's published cookie policy, and it doesn't automatically get pulled into anything a visitor sees on your site. Treat your installed app list as the thing to review each time you write or update your policy, not something Wix does for you.
Configuring the built-in Cookie Consent Banner
Wix ships a native Cookie Consent Banner, found under Settings in your site's dashboard (search "Cookie Consent Banner" if it's not immediately visible, since Wix has shifted this setting's exact location between the classic Editor, Editor X, and Wix Studio over the past few product generations). The banner sorts cookies into categories, typically Essential, Functional, Analytics, and Advertising and Marketing, lets you choose a banner style and position, and controls whether visitors see an accept-all option, a decline option, or granular per-category toggles.
Getting this configured correctly matters directly for your written policy. The policy should describe the actual banner a visitor sees and the actual categories it offers, not a generic description of "a cookie banner" that doesn't match your site's real settings. If you've set the banner to show only in the EU and UK, for example (a common configuration for GDPR's opt-in requirement, since not every jurisdiction requires the same consent mechanism), your policy should say so rather than imply every visitor everywhere sees the same prompt.
Writing the policy by category, not as a flat list
A Wix cookie policy reads clearest organized by category rather than one long list of cookie names. A workable structure for most sites:
- Strictly necessary:
svSession,hs,XSRF-TOKEN, andconsent-policyitself, explained as cookies that can't be turned off without breaking core site function. - Analytics:
bSessionand Wix's own site analytics, plus Google Analytics or any similar tool connected through Marketing Integrations. - Marketing and advertising: the Meta Pixel, Google Ads tag, and any other pixel connected through Marketing Integrations, each named by vendor since these are what a consent banner actually needs to gate.
- Functional: chat widgets, review apps, and loyalty or personalization tools from the App Market that aren't strictly necessary but aren't advertising either, worth their own middle category rather than forced into necessary or marketing.
For each category, note roughly how long the cookies persist (session-length versus longer-lived) and how a visitor opts out, through the consent banner for categories it covers, and through browser settings as a fallback for anything outside it.
Keeping it current as your app stack changes
A Wix site's App Market list and Marketing Integrations connections change more often than the underlying platform cookies do. Adding a new pixel, swapping review apps, or connecting a fresh analytics tool all add entries a cookie policy needs to reflect. Treat your Marketing Integrations panel and installed apps list as the source of truth, and revisit the policy whenever either changes rather than waiting for an annual review to catch the drift between what's disclosed and what's actually running.
Get a Wix-accurate cookie policy without starting from scratch
Writing an accurate cookie policy for a Wix site means separating what Wix sets by default from what your Marketing Integrations and App Market apps add, then keeping both current as your stack changes. Our Cookie Policy Generator builds a policy organized by category and named vendor from your actual answers, so the document your consent banner links to matches what's really running on your site instead of a generic list.
If you're deciding whether your Wix site needs a cookie policy alongside a broader privacy policy, or just one of the two, see privacy policy vs cookie policy. And if you're weighing whether a banner is even required when a site sets minimal cookies of its own, do you need a cookie banner if you don't use cookies walks through that question directly.
The information in this article is for informational purposes only and should not be construed as legal advice on any matter, and does not create a lawyer-client relationship.