Find Out What You Collect Deeper

Digital Compliance

Every Tracker We Have Found

A Running Index of Cookies, Services and What Each One Is

By Tyler Hackbart 3 weeks ago 5 min read

You opened your browser tools, found a cookie called something like _gcl_au or __hstc, and searched for it. That is usually how people end up here.

This is the working list of everything our scanner currently recognizes: 32 services across 11 categories. Fourteen of them need notice and a working opt out, three depend on how the tool is set up or need a manual look, and the rest are the site doing its job. It grows whenever an audit turns up something the list did not already know.

Cookie names are shown as prefixes, never as values. A cookie like _ga_ carries your property id after the underscore, and _gcl_au carries a click identifier. Those identify a specific account or a specific person, so they are not printed here and they are not printed in client reports either.

The index

Tracking services recognized by the scanner, ordered by how sensitive the category is
ServiceCategoryCookie prefixesNeeds notice and an opt out
Google Ads / DoubleClick Advertising _gcl_, _gac_ Yes, and this is the strictest
LinkedIn Insight Advertising li_, bcookie, lidc Yes, and this is the strictest
Meta (Facebook) Pixel Advertising _fbp, _fbc, fr Yes, and this is the strictest
Microsoft / Bing Ads Advertising _uet, MUID Yes, and this is the strictest
TikTok Pixel Advertising _ttp Yes, and this is the strictest
Hotjar Profiling / session recording _hj Yes, express if it records input
Microsoft Clarity Profiling / session recording _clck, _clsk Yes, express if it records input
Google Analytics 4 Analytics _ga_, _gid, _gat Yes, notice and an opt out
HubSpot Analytics __hstc, hubspotutk, __hssc, __hssrc, __hmpl, hublytics_events Yes, notice and an opt out
Matomo Analytics _pk_ Yes, notice and an opt out
Squarespace Analytics Analytics ss_cvr, ss_cvisit, ss_cpvisit, ss_cid, ss_cvt Yes, notice and an opt out
Wix Analytics Analytics detected by request host only Yes, notice and an opt out
WooCommerce Order Attribution (Sourcebuster) Analytics sbjs_ Yes, notice and an opt out
Sender.net Email marketing _seg, _ce., cebs, _CEFT, pscd Yes
Google Tag Manager Tag manager detected by request host only No, on its own
HubSpot Chat Chat / support messagesUtk, hs-messages- Depends on the tool
Intercom Chat / support intercom- Depends on the tool
Complianz Consent tool cmplz_ No
CookieYes Consent tool cookieyes No
Cookiebot Consent tool CookieConsent No
HubSpot Consent Preferences Consent tool __hs_opt_out, __hs_do_not_track, __hs_initial_opt_in, __hs_cookie_cat_pref, __hs_gpc_banner_dismiss, __hs_notify_banner_dismiss No
OneTrust Consent tool OptanonConsent, OptanonAlertBoxClosed No
Osano Consent tool osano No
Termly Consent tool TERMLY No
Usercentrics Consent tool uc_ No
iubenda Consent tool _iub No
CleanTalk Spam Protect Security apbct_, ct_ No
Cloudflare Security __cf_bm, __cfruid, __cfuvid No
HubSpot Membership Strictly necessary __hsmem, hs-membership- No
Squarespace Platform detected by request host only No
Wix Platform detected by request host only No
HubSpot A/B Testing Unclassified hs_ab_test Unknown until reviewed

Canada has no cookie banner law. For ordinary, non sensitive tracking Personal Information Protection and Electronic Documents Act, Canada's federal privacy law allows implied consent, which in practice means notice at or before collection, presented somewhere findable rather than buried in the policy, and an opt out that works and persists. Express opt in is the standard where the information is sensitive, where the purpose is one a reasonable person would not expect, where the site is aimed at children, and for session recording that captures what a person types. Quebec's Law 25 goes further again and expects technology that profiles, locates or identifies a person to be off by default.

How to read it

Detected by request host only. Four rows carry that phrase instead of a cookie prefix. Those services set no cookie of their own, so the scanner spots them by the requests they make. A tag manager is the usual example. It still loads other things, and each of those is assessed on its own.

Consent tools appear in the list too. A cookie banner sets its own cookie to remember your answer, which is why Cookiebot, OneTrust and the rest show up here. That cookie is not a finding. It is the record of the choice.

Platform cookies are not trackers. Squarespace and Wix both set cookies simply to deliver the site, and neither of those is a finding. Both platforms also switch on their own analytics, which is why Squarespace Analytics and Wix Analytics each get a row of their own and a different answer in the last column.

The last column is not a banner column. Canada has no cookie banner law. Ordinary analytics can sit on the lighter path: tell people plainly what you collect, somewhere they can find it, and give them an opt out that actually takes effect. The strict path, where nothing fires until a visitor agrees, is what the advertising and profiling tools call for, along with session recording that captures typing and anything sensitive. If you have customers in Quebec, Law 25 pushes the profiling tools to off by default regardless of where you land federally.

One vendor can be several entries

HubSpot is the clearest example. It sets seventeen cookie prefixes across five completely different purposes, so it appears here as five separate rows. The analytics cookies tie an anonymous visit to a known contact record. The chat cookies recognize someone who has messaged you. The membership cookies keep a logged in user logged in. One records which version of a page a visitor was shown. And one records the visitor's own decision about being tracked at all. Treating those as one thing would be wrong in several directions at once.

The row worth pausing on is HubSpot Consent Preferences. Cookies like __hs_do_not_track and __hs_opt_out are the record of a visitor choosing not to be tracked. Reporting those as tracking would mean flagging a site for respecting somebody's decision, which is the worst mistake this kind of scan can make.

Not on the list?

Then either it is not a tracker, or the scanner has not met it yet. Unrecognized third parties are never reported as a finding without a manual review, because an unknown is a question rather than a failure. If you have found something here that is not listed, send it over and it will end up on this page.

We are not lawyers and this is not legal advice. The last column is our reading of the Privacy Commissioner's guidance applied to what each tool actually does. For your own obligations, talk to a lawyer.

If you want to know which of these are on your own site, and whether any of them fire before a visitor agrees to anything, that is exactly what the audit tests. Reach out below.

Want to know where your own site stands? See what the audit covers, or reach out and we'll get the ball rolling.

Reach out

JUMP BACK

All Content
#