Skip to main content
come.to

come.to

https://come.to

Last scanned July 7, 2026

A cookie scan of come.to completed on July 7, 2026 found 12 cookies and 9 third-party tracking requests. The assessment covered 4 pages across 4 unique page templates. No consent management platform was detected. Our check observed 9 third-party requests from 3 vendors; non-essential tracking of this kind requires prior consent under the ePrivacy Directive.

Cookies

12

Third-party

0

Trackers

9

Vendors

3

Consent banner

None detected

Scans

1

What this setup is missing

  • No consent management platform was detected.
  • Google tags were observed, but Google Consent Mode v2 was not detected.

Compliance by audience

European Union

✗ Not met

GDPR + ePrivacy · Prior consent (opt-in)

United Kingdom

✗ Not met

UK GDPR + PECR · Consent-based

United States

! Needs attention

CCPA/CPRA + state laws · Notice & opt-out

Canada

! Needs attention

PIPEDA + Québec Law 25 · Consent-based

Brazil

! Needs attention

LGPD · Consent-based

Scanned from the EU; sites may serve different banners or tracking to other regions. Verdicts reflect observed behaviour measured against each audience's rules.

Cookies

12 cookies detected: 2 necessary, 6 analytics, 2 marketing

Total

12

Necessary

2

Functional

0

Analytics

6

Marketing

2

Unknown

2

Filter by category
Name Domain Category Provider Expiry Secure HttpOnly Party
_ga before consent .welcome.to Analytics Google Analytics 1 yr 1st
_ga before consent .come.to Analytics Google Analytics 1 yr 1st
_ga_F3DM4RV3QQ before consent .welcome.to Analytics Google Analytics 1 yr 1st
_ga_F3DM4RV3QQ before consent .come.to Analytics Google Analytics 1 yr 1st
_gcl_au before consent .welcome.to Analytics Google Analytics 71 d 1st
_gcl_au before consent .come.to Analytics Google Analytics 71 d 1st
_fbp before consent .welcome.to Marketing Facebook 71 d 1st
_fbp before consent .come.to Marketing Facebook 71 d 1st
XSRF-TOKEN welcome.to Necessary CSRF Protection Expired 1st
XSRF-TOKEN come.to Necessary CSRF Protection Expired 1st
welcometo-session before consent welcome.to Unknown - Expired 1st
welcometo-session before consent come.to Unknown - Expired 1st

Third-Party Trackers

9 requests detected from 3 vendors: Google LLC, Meta Platforms, Inc., Cloudflare Inc.

Analytics

1

Marketing

2

Necessary

4

Functional

0

Other

2

Vendor Category Type Domain
Google LLC before consent Google Tag Manager Analytics script www.googletagmanager.com
Meta Platforms, Inc. before consent Facebook SDK / Pixel Marketing script connect.facebook.net
Meta Platforms, Inc. before consent Facebook tracking pixel Marketing pixel www.facebook.com
Cloudflare Inc. Cloudflare Turnstile / bot protection Necessary script challenges.cloudflare.com
Google LLC Google Fonts stylesheet Necessary script fonts.googleapis.com
Google LLC Google tracker domain (source: Disconnect.me, category: Content) Necessary script lh3.googleusercontent.com
Google LLC Google Fonts files Necessary script fonts.gstatic.com
Google LLC before consent Google tracker domain (source: Disconnect.me, category: FingerprintingGeneral) Unknown script ad.doubleclick.net
Google LLC before consent Google tracker domain (source: Disconnect.me, category: FingerprintingGeneral) Unknown script region1.google-analytics.com

Scan history

One completed scan: cookies and trackers from the scan on July 7, 2026.

Recent scans

July 7, 2026 12 9

Is come.to your website?

Claim it to monitor your cookies and trackers, set up a consent banner with automatic script blocking, and keep your cookie policy up to date.