Skip to main content
dandy.co.uk

dandy.co.uk

https://dandy.co.uk

Last scanned August 31, 2026

A cookie scan of dandy.co.uk conducted on August 31, 2026 found 8 cookies and 12 third-party tracking requests. The assessment covered 8 pages across 8 unique page templates. The site uses OneTrust as its consent management platform with IAB TCF v2.3; Google Consent Mode v2 was not observed. 12 third-party requests were detected from 7 vendors.

Cookies

8

Third-party

8

Trackers

12

Vendors

7

Consent banner

OneTrust

Scans

1

What this setup is missing

  • Google tags were observed, but Google Consent Mode v2 was not detected.

Compliance by audience

European Union

✗ Not met

GDPR + ePrivacy · Prior consent (opt-in)

United Kingdom

✗ Not met

UK GDPR + PECR · Consent-based

United States

✓ Meets this model

CCPA/CPRA + state laws · Notice & opt-out

Canada

! Needs attention

PIPEDA + Québec Law 25 · Consent-based

Brazil

! Needs attention

LGPD · Consent-based

Scanned from the EU; sites may serve different banners or tracking to other regions. Verdicts reflect observed behaviour measured against each audience's rules.

Connection security

HTTPS supported

✓

Redirects HTTP to HTTPS

✓

HSTS

✓

Content Security Policy

✓

Cookies

8 cookies detected: 2 necessary, 4 analytics, 1 marketing, 8 third-party

Total

8

Necessary

2

Functional

0

Analytics

4

Marketing

1

Unknown

1

8 third-party cookies detected

Third-party cookies require explicit user consent under GDPR/ePrivacy.

Filter by category
Name Domain Category Provider Expiry Secure HttpOnly Party
hubspotutk before consent .dcthomsonshop.co.uk Analytics HubSpot 142 d – – 3rd
__hssc before consent .dcthomsonshop.co.uk Analytics HubSpot Expired – – 3rd
__hssrc before consent .dcthomsonshop.co.uk Analytics HubSpot Session – – 3rd
__hstc before consent .dcthomsonshop.co.uk Analytics HubSpot 142 d – – 3rd
messagesUtk before consent .dcthomsonshop.co.uk Marketing Hubspot 142 d ✓ – 3rd
OptanonConsent .dcthomsonshop.co.uk Necessary OneTrust 327 d – – 3rd
__cf_bm .dcthomsonshop.co.uk Necessary Cloudflare Expired ✓ ✓ 3rd
cohort before consent www.dcthomsonshop.co.uk Unknown - Expired ✓ ✓ 3rd

Third-Party Trackers

12 requests detected from 7 vendors: Cloud Software Group, Google LLC, HubSpot, HubSpot Inc., Cloudflare...

Analytics

4

Marketing

3

Necessary

4

Functional

0

Other

1

Vendor Category Type Domain
Cloud Software Group before consent Cloud Software Group tracker domain (source: Disconnect.me, category: Analytics) Analytics script www.cedexis.com
Google LLC before consent Google Tag Manager Analytics script www.googletagmanager.com
HubSpot before consent HubSpot tracker domain (source: Disconnect.me, category: Analytics) Analytics script js-eu1.hs-analytics.net
HubSpot before consent HubSpot tracker domain (source: Disconnect.me, category: Content) Analytics script perf-eu1.hsforms.com
HubSpot before consent HubSpot tracker domain (source: Disconnect.me, category: Advertising) Marketing script js-eu1.hs-scripts.com
HubSpot before consent HubSpot tracker domain (source: Disconnect.me, category: Advertising) Marketing script js-eu1.hs-banner.com
HubSpot Inc. before consent HubSpot marketing & CRM Marketing script js-eu1.hubspot.com
Cloudflare Cloudflare tracker domain (source: Disconnect.me, category: Content) Necessary script performance.radar.cloudflare.com
HubSpot HubSpot tracker domain (source: Disconnect.me, category: Content) Necessary script js-eu1.usemessages.com
HubSpot HubSpot tracker domain (source: Disconnect.me, category: Content) Necessary script static.hsappstatic.net
TrustPilot TrustPilot tracker domain (source: Disconnect.me, category: Content) Necessary script widget.trustpilot.com
OneTrust OneTrust tracker domain (source: Disconnect.me, category: ConsentManagers) Unknown script geolocation.onetrust.com

Scan history

One completed scan: cookies and trackers from the scan on August 31, 2026.

Recent scans

August 31, 2026 8 12

Is dandy.co.uk your website?

Claim it to monitor your cookies and trackers, set up a consent banner with automatic script blocking, and keep your cookie policy up to date.