Consent & tracking report for flowers.kroger.com
Based on an automated pre-consent tracking scan on July 13, 2026.
High risk. Multiple trackers (or a session-replay/chat tool) fired before consent — the pattern CIPA suits target.
On a cold page load — before any consent was given — this page sent data to 1 third-party tracker (7 requests). No consent banner was detected at all.
Sending data to advertising and analytics third parties before a visitor consents is what powers the wave of CIPA "wiretapping" demand letters in the U.S. and GDPR / ePrivacy enforcement in the EU — and every item below is fixable.
What we found, and how to fix it
FullStory starts recording the visitor’s session — mouse, clicks, scrolling, form input — on load, before consent.
US: CIPA (recording) EU: GDPR/ePrivacy Sends identifiers: orgid
Why it matters: Session-replay tools (Hotjar, FullStory, Microsoft Clarity) capture a recording of the visitor’s actual session. That is the strongest "recording / interception" exposure under CIPA, and replay is never essential, so running it before consent is a clear GDPR/ePrivacy violation.
How to fix it: Load the session-replay script only after the visitor accepts. These tools are never strictly necessary, so they must be gated behind consent — nothing about them should run on a cold page load.
Fix these before a demand letter finds them — free
The free ForensicConsent browser extension finds every tracker that fires before consent on your own pages, flags the VPPA footprint, and gives you the fix recipe for each — at no cost. Run it, gate your trackers, and re-check this page anytime.
Own this site? Gate your trackers behind consent, then re-scan — this report updates automatically, and comes down entirely once you pass.
This is an automated scan of the page’s public behavior on a single cold load; it reports what the page transmitted before any consent, not a legal verdict. Exposure flags show the public legal basis these patterns are cited under — they are informational, not legal advice. See our methodology.
How this report was produced
Automated scan of flowers.kroger.com as it publicly behaved on
, using the ForensicConsent detection
ruleset (2026.06.22). The captured pre-consent requests and these results are sealed
with a tamper-evident hash (16da206892164055…).
We report only what the page publicly transmitted before consent at that time.