Consent & tracking report for artoftea.com
Based on an automated pre-consent tracking scan on July 4, 2026.
Critical risk. A video player shares this page with pre-consent pixels — the VPPA footprint plaintiffs target — on top of heavy pre-consent tracking.
On a cold page load — before any consent was given — this page sent data to 6 third-party trackers (32 requests). A consent banner (Cookie banner (generic)) was detected, but it did not block these trackers.
Sending data to advertising and analytics third parties before a visitor consents is what powers the wave of CIPA "wiretapping" demand letters in the U.S. and GDPR / ePrivacy enforcement in the EU — and every item below is fixable.
VPPA exposure (Video Privacy Protection Act). When a marketing pixel fires on a page with video, plaintiffs argue it shares "what video this person watched" with a third party (e.g. Meta) without consent. The VPPA carries statutory damages of ~$2,500 per violation, and this video+pixel combination is the single hottest privacy-litigation pattern right now.
How to fix it: Gate the pixel until consent, embed video via youtube-nocookie.com (or a privacy-mode equivalent), or remove marketing pixels from pages that host video. Any one of these breaks the footprint.
Your consent banner isn’t blocking. Cookie banner (generic) is present on the page, but the trackers below still fired before any choice was made — the single most common real-world failure. A banner that loads alongside the trackers it’s meant to gate provides no protection.
What we found, and how to fix it
Hotjar starts recording the visitor’s session — mouse, clicks, scrolling, form input — on load, before consent.
US: CIPA (recording) EU: GDPR/ePrivacy Sends identifiers: sv
Why it matters: Session-replay tools (Hotjar, FullStory, Microsoft Clarity) capture a recording of the visitor’s actual session. That is the strongest "recording / interception" exposure under CIPA, and replay is never essential, so running it before consent is a clear GDPR/ePrivacy violation.
How to fix it: Load the session-replay script only after the visitor accepts. These tools are never strictly necessary, so they must be gated behind consent — nothing about them should run on a cold page load.
TikTok Pixel sends visitor data to a third-party ad network the moment the page loads — before anyone agrees.
US: CIPA (pen-register) EU: GDPR/ePrivacy
Why it matters: Marketing pixels (Meta, TikTok, Google Ads) bind the visitor to an advertising identifier and report their activity back to the ad network. Firing one before consent is the exact pattern CIPA "pen-register" wiretapping suits target (statutory damages up to $5,000 per violation in California) and a direct GDPR/ePrivacy breach in the EU.
How to fix it: Don't load the pixel's script (e.g. connect.facebook.net) or call its init/track functions until the visitor consents. If you manage tags through Google Tag Manager, fix it at the source: enable Google Consent Mode v2 (ad_storage defaulting to "denied") and fire the tags on a consent-granted trigger.
Google Ads / DoubleClick sends visitor data to a third-party ad network the moment the page loads — before anyone agrees.
US: CIPA (pen-register) EU: GDPR/ePrivacy Sends identifiers: guid, cid
Why it matters: Marketing pixels (Meta, TikTok, Google Ads) bind the visitor to an advertising identifier and report their activity back to the ad network. Firing one before consent is the exact pattern CIPA "pen-register" wiretapping suits target (statutory damages up to $5,000 per violation in California) and a direct GDPR/ePrivacy breach in the EU.
How to fix it: Don't load the pixel's script (e.g. connect.facebook.net) or call its init/track functions until the visitor consents. If you manage tags through Google Tag Manager, fix it at the source: enable Google Consent Mode v2 (ad_storage defaulting to "denied") and fire the tags on a consent-granted trigger.
Meta Pixel sends visitor data to a third-party ad network the moment the page loads — before anyone agrees.
US: CIPA (pen-register) EU: GDPR/ePrivacy
Why it matters: Marketing pixels (Meta, TikTok, Google Ads) bind the visitor to an advertising identifier and report their activity back to the ad network. Firing one before consent is the exact pattern CIPA "pen-register" wiretapping suits target (statutory damages up to $5,000 per violation in California) and a direct GDPR/ePrivacy breach in the EU.
How to fix it: Don't load the pixel's script (e.g. connect.facebook.net) or call its init/track functions until the visitor consents. If you manage tags through Google Tag Manager, fix it at the source: enable Google Consent Mode v2 (ad_storage defaulting to "denied") and fire the tags on a consent-granted trigger.
Google Tag Manager sends visitor data to a third-party analytics service before consent.
US: CIPA EU: GDPR/ePrivacy Sends identifiers: id
Why it matters: Analytics like GA4 set identifiers and report the visit to Google before the visitor agrees — cited under CIPA in the US and treated as non-essential tracking that requires prior consent under GDPR/ePrivacy in the EU.
How to fix it: Gate analytics behind consent. For Google Analytics, use Consent Mode v2 with analytics_storage defaulting to "denied" and flipping to "granted" only after the visitor accepts — you keep the measurement without the pre-consent exposure.
Google Analytics 4 sends visitor data to a third-party analytics service before consent.
US: CIPA EU: GDPR/ePrivacy Sends identifiers: tid, cid
Why it matters: Analytics like GA4 set identifiers and report the visit to Google before the visitor agrees — cited under CIPA in the US and treated as non-essential tracking that requires prior consent under GDPR/ePrivacy in the EU.
How to fix it: Gate analytics behind consent. For Google Analytics, use Consent Mode v2 with analytics_storage defaulting to "denied" and flipping to "granted" only after the visitor accepts — you keep the measurement without the pre-consent exposure.
Fix these before a demand letter finds them — free
The free ForensicConsent browser extension finds every tracker that fires before consent on your own pages, flags the VPPA footprint, and gives you the fix recipe for each — at no cost. Run it, gate your trackers, and re-check this page anytime.
Own this site? Gate your trackers behind consent, then re-scan — this report updates automatically, and comes down entirely once you pass.
This is an automated scan of the page’s public behavior on a single cold load; it reports what the page transmitted before any consent, not a legal verdict. Exposure flags show the public legal basis these patterns are cited under — they are informational, not legal advice. See our methodology.
How this report was produced
Automated scan of artoftea.com as it publicly behaved on
, using the ForensicConsent detection
ruleset (2026.06.22). The captured pre-consent requests and these results are sealed
with a tamper-evident hash (2d64198af60973e0…).
We report only what the page publicly transmitted before consent at that time.
This seal is anchored to a trusted RFC-3161 timestamp via freetsa.org on . Independently verify this receipt →