Digital Compliance
Every Tracker We Have Found
A Running Index of Cookies, Services and What Each One Is
You opened your browser tools, found a cookie called something like _gcl_au or __hstc, and searched for it. That is usually how people end up here.
This is the working list of everything our scanner currently recognizes: 32 services across 11 categories. Fourteen of them need notice and a working opt out, three depend on how the tool is set up or need a manual look, and the rest are the site doing its job. It grows whenever an audit turns up something the list did not already know.
Cookie names are shown as prefixes, never as values. A cookie like _ga_ carries your property id after the underscore, and _gcl_au carries a click identifier. Those identify a specific account or a specific person, so they are not printed here and they are not printed in client reports either.
The index
| Service | Category | Cookie prefixes | Needs notice and an opt out |
|---|---|---|---|
| Google Ads / DoubleClick | Advertising | _gcl_, _gac_ | Yes, and this is the strictest |
| LinkedIn Insight | Advertising | li_, bcookie, lidc | Yes, and this is the strictest |
| Meta (Facebook) Pixel | Advertising | _fbp, _fbc, fr | Yes, and this is the strictest |
| Microsoft / Bing Ads | Advertising | _uet, MUID | Yes, and this is the strictest |
| TikTok Pixel | Advertising | _ttp | Yes, and this is the strictest |
| Hotjar | Profiling / session recording | _hj | Yes, express if it records input |
| Microsoft Clarity | Profiling / session recording | _clck, _clsk | Yes, express if it records input |
| Google Analytics 4 | Analytics | _ga_, _gid, _gat | Yes, notice and an opt out |
| HubSpot | Analytics | __hstc, hubspotutk, __hssc, __hssrc, __hmpl, hublytics_events | Yes, notice and an opt out |
| Matomo | Analytics | _pk_ | Yes, notice and an opt out |
| Squarespace Analytics | Analytics | ss_cvr, ss_cvisit, ss_cpvisit, ss_cid, ss_cvt | Yes, notice and an opt out |
| Wix Analytics | Analytics | detected by request host only | Yes, notice and an opt out |
| WooCommerce Order Attribution (Sourcebuster) | Analytics | sbjs_ | Yes, notice and an opt out |
| Sender.net | Email marketing | _seg, _ce., cebs, _CEFT, pscd | Yes |
| Google Tag Manager | Tag manager | detected by request host only | No, on its own |
| HubSpot Chat | Chat / support | messagesUtk, hs-messages- | Depends on the tool |
| Intercom | Chat / support | intercom- | Depends on the tool |
| Complianz | Consent tool | cmplz_ | No |
| CookieYes | Consent tool | cookieyes | No |
| Cookiebot | Consent tool | CookieConsent | No |
| HubSpot Consent Preferences | Consent tool | __hs_opt_out, __hs_do_not_track, __hs_initial_opt_in, __hs_cookie_cat_pref, __hs_gpc_banner_dismiss, __hs_notify_banner_dismiss | No |
| OneTrust | Consent tool | OptanonConsent, OptanonAlertBoxClosed | No |
| Osano | Consent tool | osano | No |
| Termly | Consent tool | TERMLY | No |
| Usercentrics | Consent tool | uc_ | No |
| iubenda | Consent tool | _iub | No |
| CleanTalk Spam Protect | Security | apbct_, ct_ | No |
| Cloudflare | Security | __cf_bm, __cfruid, __cfuvid | No |
| HubSpot Membership | Strictly necessary | __hsmem, hs-membership- | No |
| Squarespace | Platform | detected by request host only | No |
| Wix | Platform | detected by request host only | No |
| HubSpot A/B Testing | Unclassified | hs_ab_test | Unknown until reviewed |
Canada has no cookie banner law. For ordinary, non sensitive tracking Personal Information Protection and Electronic Documents Act, Canada's federal privacy law allows implied consent, which in practice means notice at or before collection, presented somewhere findable rather than buried in the policy, and an opt out that works and persists. Express opt in is the standard where the information is sensitive, where the purpose is one a reasonable person would not expect, where the site is aimed at children, and for session recording that captures what a person types. Quebec's Law 25 goes further again and expects technology that profiles, locates or identifies a person to be off by default.
How to read it
Detected by request host only. Four rows carry that phrase instead of a cookie prefix. Those services set no cookie of their own, so the scanner spots them by the requests they make. A tag manager is the usual example. It still loads other things, and each of those is assessed on its own.
Consent tools appear in the list too. A cookie banner sets its own cookie to remember your answer, which is why Cookiebot, OneTrust and the rest show up here. That cookie is not a finding. It is the record of the choice.
Platform cookies are not trackers. Squarespace and Wix both set cookies simply to deliver the site, and neither of those is a finding. Both platforms also switch on their own analytics, which is why Squarespace Analytics and Wix Analytics each get a row of their own and a different answer in the last column.
The last column is not a banner column. Canada has no cookie banner law. Ordinary analytics can sit on the lighter path: tell people plainly what you collect, somewhere they can find it, and give them an opt out that actually takes effect. The strict path, where nothing fires until a visitor agrees, is what the advertising and profiling tools call for, along with session recording that captures typing and anything sensitive. If you have customers in Quebec, Law 25 pushes the profiling tools to off by default regardless of where you land federally.
One vendor can be several entries
HubSpot is the clearest example. It sets seventeen cookie prefixes across five completely different purposes, so it appears here as five separate rows. The analytics cookies tie an anonymous visit to a known contact record. The chat cookies recognize someone who has messaged you. The membership cookies keep a logged in user logged in. One records which version of a page a visitor was shown. And one records the visitor's own decision about being tracked at all. Treating those as one thing would be wrong in several directions at once.
The row worth pausing on is HubSpot Consent Preferences. Cookies like __hs_do_not_track and __hs_opt_out are the record of a visitor choosing not to be tracked. Reporting those as tracking would mean flagging a site for respecting somebody's decision, which is the worst mistake this kind of scan can make.
Not on the list?
Then either it is not a tracker, or the scanner has not met it yet. Unrecognized third parties are never reported as a finding without a manual review, because an unknown is a question rather than a failure. If you have found something here that is not listed, send it over and it will end up on this page.
We are not lawyers and this is not legal advice. The last column is our reading of the Privacy Commissioner's guidance applied to what each tool actually does. For your own obligations, talk to a lawyer.
If you want to know which of these are on your own site, and whether any of them fire before a visitor agrees to anything, that is exactly what the audit tests. Reach out below.
Want to know where your own site stands? See what the audit covers, or reach out and we'll get the ball rolling.
Reach outJUMP BACK
All ContentDiscover more content by us