airback.store
Last scanned July 31, 2026
A cookie scan of airback.store completed on July 31, 2026 found 14 cookies and 25 third-party tracking requests. The assessment covered 10 pages across 10 unique page templates. The site relies on Cookiebot as its consent management platform with Google Consent Mode v2; IAB TCF v2.3 was not observed. 25 third-party requests were detected from 17 vendors.
Consent behaviour grade
24 / 100
This site set multiple tracking cookies before the visitor consented. Under ePrivacy Article 5(3), these require prior consent.
Automated point-in-time check of the scanned pages; not legal advice. How our check works.
Consent enforcement level
-
1
Nothing non-essential runs before consent is given. This is the strict reading of ePrivacy Article 5(3) and the strongest position.
-
2
Google tags load with storage defaulted to denied and send only cookieless pings before consent. Permitted in Google's model, but not the strict reading of Article 5(3).
-
3
Partially enforced This site
Google Consent Mode v2 restrains Google tags, but other trackers or cookies were observed before consent.
-
4
Trackers or cookies execute before the visitor consents, with no consent signals restraining them.
Consent banner as encountered
No Reject option on the first layer; declining requires extra steps.
Load timeline before consent
Milliseconds from navigation start until each request fired or each cookie was set.
and 13 more
Observed before consent
Cookies set before consent (14)
-
_sp_id.4b3danalytics · Snowplow -
_sp_ses.4b3danalytics · Snowplow -
_conv_sfunctional · Convert Insights -
_conv_vfunctional · Convert Insights -
_shopify_essentialfunctional · Shopify -
_shopify_essentialfunctional · Shopify -
cartfunctional · E-commerce -
cart_currencyfunctional · E-commerce -
localizationfunctional · Shopify -
__apex_test__unknown -
_conv_dunknown -
_conv_gunknown -
abconvert-sessionunknown -
yotpo_pixelunknown
Tracking requests before consent (14)
- api.config-security.com api.config-security.com set by airback.store/spring-collection · at 194 ms
- cdn1.profitmetrics.io cdn1.profitmetrics.io set by airback.store/how-to-use · at 1937 ms
- convertexperiments.com cdn-4.convertexperiments.com at 173 ms
- Google LLC www.googletagmanager.com set by airback.store/spring-collection · at 194 ms
- Microsoft www.clarity.ms set by airback.store/spring-collection · at 247 ms
- Sentry (Functional Software) js.sentry-cdn.com set by cdn.shopify.com/shipping-script.js · at 407 ms
- Sentry (Functional Software) browser.sentry-cdn.com set by js.sentry-cdn.com/da3671b69143e5322a4ef13d71ea93d5.min.js · at 664 ms
- Shopify otlp-http-production.shopifysvc.com set by airback.store/shop_events_listener-4e26a9ce.js · at 356 ms
- Shopify error-analytics-sessions-production.shopifysvc.com set by cdn.shopify.com/index.wWi2nVxw.js · at 1402 ms
- Shopify Inc. monorail-edge.shopifysvc.com set by airback.store/shop_events_listener-4e26a9ce.js · at 525 ms
- Adobe Fonts use.typekit.net at 172 ms
- Klaviyo Inc. static.klaviyo.com at 173 ms
- and 2 more
How we tested
Browser: Chrome/150.0.7871.124 · Scan origin: EU · Viewport: 1440×900 · Checked: 31 Jul 2026 08:27
Cookies
14
Third-party
0
Trackers
25
Vendors
17
Consent banner
Cookiebot
Scans
1
What this setup is missing
- Script blocking is manual. Each script must be tagged by hand, and untagged scripts run before consent.
- No Reject option on the first layer; declining requires extra steps.
Compliance by audience
European Union
✗ Not metGDPR + ePrivacy · Prior consent (opt-in)
United Kingdom
✗ Not metUK GDPR + PECR · Consent-based
United States
✓ Meets this modelCCPA/CPRA + state laws · Notice & opt-out
Canada
! Needs attentionPIPEDA + Québec Law 25 · Consent-based
Brazil
! Needs attentionLGPD · Consent-based
Scanned from the EU; sites may serve different banners or tracking to other regions. Verdicts reflect observed behaviour measured against each audience's rules.
Connection security
HTTPS supported
✓Redirects HTTP to HTTPS
✓HSTS
✓Content Security Policy
✓
Third-Party Trackers
25 requests detected from 17 vendors: api.config-security.com, cdn1.profitmetrics.io, convertexperiments.com, Google LLC, Microsoft...
Third-Party Trackers
25 requests detected from 17 vendors: api.config-security.com, cdn1.profitmetrics.io, convertexperiments.com, Google LLC, Microsoft...
Analytics
10
Marketing
2
Necessary
10
Functional
1
Other
2
| Vendor | Category | Type | Domain |
|---|---|---|---|
| api.config-security.com before consent | Analytics | xhr | api.config-security.com |
| cdn1.profitmetrics.io before consent | Analytics | script | cdn1.profitmetrics.io |
| convertexperiments.com before consent convertexperiments.com tracker domain (source: Disconnect.me, category: Analytics) | Analytics | script | cdn-4.convertexperiments.com |
| Google LLC before consent Google Tag Manager | Analytics | script | www.googletagmanager.com |
| Microsoft before consent Microsoft tracker domain (source: Disconnect.me, category: Analytics) | Analytics | script | www.clarity.ms |
| Sentry (Functional Software) before consent Sentry error tracking | Analytics | script | js.sentry-cdn.com |
| Sentry (Functional Software) before consent Sentry browser SDK | Analytics | script | browser.sentry-cdn.com |
| Shopify before consent Shopify tracker domain (source: Disconnect.me, category: Content) | Analytics | script | otlp-http-production.shopifysvc.com |
| Shopify before consent Shopify tracker domain (source: Disconnect.me, category: Content) | Analytics | script | error-analytics-sessions-production.shopifysvc.com |
| Shopify Inc. before consent Shopify analytics | Analytics | pixel | monorail-edge.shopifysvc.com |
| Adobe Fonts before consent Adobe Fonts (Typekit): web font delivery | Functional | script | use.typekit.net |
| Klaviyo Inc. before consent Klaviyo email marketing | Marketing | script | static.klaviyo.com |
| Yotpo before consent Yotpo tracker domain (source: Disconnect.me, category: EmailAggressive) | Marketing | script | cdn-widgetsrepository.yotpo.com |
| Amazon Amazon tracker domain (source: Disconnect.me, category: Content) | Necessary | script | d18eg7dreypte5.cloudfront.net |
| Cybot A/S (Cookiebot) Cookiebot consent management | Necessary | script | consent.cookiebot.com |
| Google LLC Google Fonts stylesheet | Necessary | script | fonts.googleapis.com |
| Google LLC Google Fonts files | Necessary | script | fonts.gstatic.com |
| Gorgias Gorgias tracker domain (source: Disconnect.me, category: Content) | Necessary | script | config.gorgias.chat |
| PayPal Holdings PayPal SDK | Necessary | script | www.paypal.com |
| PayPal Holdings PayPal static resources | Necessary | script | www.paypalobjects.com |
| Shopify Shopify tracker domain (source: Disconnect.me, category: Content) | Necessary | script | shop.app |
| Shopify Inc. Shopify platform | Necessary | script | cdn.shopify.com |
| Volentio JSD Volentio JSD tracker domain (source: Disconnect.me, category: Content) | Necessary | script | cdn.jsdelivr.net |
| Google LLC before consent Google tracker domain (source: Disconnect.me, category: FingerprintingGeneral) | Unknown | script | pagead2.googlesyndication.com |
| UserCentrics UserCentrics tracker domain (source: Disconnect.me, category: ConsentManagers) | Unknown | script | consentcdn.cookiebot.com |
Scan history
One completed scan: cookies and trackers from the scan on July 31, 2026.
Recent scans
| July 31, 2026 | 14 26 |
More Cookie Compliance Reviews
Loja Fechada
aircoolerbrasil.store
Loja Fechada
aircoolerbr.store
One moment, please...
air-essence.store
One moment, please...
aguadepez.store
Agonny Store
agonny.store
AG.Store | Ihr Amann Girrbach Onlineshop
ag.store
AfriVibe.Store – Drip with Meaning
afrivibe.store
Sorry, the website has been stopped
adm-games.store
Is airback.store your website?
Claim it to monitor your cookies and trackers, set up a consent banner with automatic script blocking, and keep your cookie policy up to date.