Consent & tracking report for cotoncolors.com
Based on an automated pre-consent tracking scan on July 11, 2026.
High risk. Multiple trackers (or a session-replay/chat tool) fired before consent — the pattern CIPA suits target.
On a cold page load — before any consent was given — this page sent data to 2 third-party trackers (7 requests). No consent banner was detected at all.
Sending data to advertising and analytics third parties before a visitor consents is what powers the wave of CIPA "wiretapping" demand letters in the U.S. and GDPR / ePrivacy enforcement in the EU — and every item below is fixable.
What we found, and how to fix it
Intercom loads a chat/support widget that can transmit what the visitor types before they agree.
US: CIPA (interception) EU: GDPR/ePrivacy
Why it matters: Chat and search widgets (Intercom, Drift, Crisp, Tawk.to) can capture and transmit typed input before the visitor consents — cited as interception under CIPA and a consent breach under GDPR/ePrivacy.
How to fix it: Load the chat widget only after consent, and make sure it never transmits typed input before the visitor agrees. Defer the widget script behind your consent gate.
Google Tag Manager sends visitor data to a third-party analytics service before consent.
US: CIPA EU: GDPR/ePrivacy Sends identifiers: id
Why it matters: Analytics like GA4 set identifiers and report the visit to Google before the visitor agrees — cited under CIPA in the US and treated as non-essential tracking that requires prior consent under GDPR/ePrivacy in the EU.
How to fix it: Gate analytics behind consent. For Google Analytics, use Consent Mode v2 with analytics_storage defaulting to "denied" and flipping to "granted" only after the visitor accepts — you keep the measurement without the pre-consent exposure.
Fix these before a demand letter finds them — free
The free ForensicConsent browser extension finds every tracker that fires before consent on your own pages, flags the VPPA footprint, and gives you the fix recipe for each — at no cost. Run it, gate your trackers, and re-check this page anytime.
Own this site? Gate your trackers behind consent, then re-scan — this report updates automatically, and comes down entirely once you pass.
This is an automated scan of the page’s public behavior on a single cold load; it reports what the page transmitted before any consent, not a legal verdict. Exposure flags show the public legal basis these patterns are cited under — they are informational, not legal advice. See our methodology.
How this report was produced
Automated scan of cotoncolors.com as it publicly behaved on
, using the ForensicConsent detection
ruleset (2026.06.22). The captured pre-consent requests and these results are sealed
with a tamper-evident hash (9f3a2741374fa517…).
We report only what the page publicly transmitted before consent at that time.