Skip to main content
grao.cat

grao.cat

https://grao.cat

Last scanned September 24, 2026

A cookie scan of grao.cat completed on September 24, 2026 found 10 cookies and 9 third-party tracking requests. The assessment covered 10 pages across 10 unique page templates. The site employs CookieYes as its consent management platform. Neither IAB TCF v2.3 nor Google Consent Mode v2 was observed on our check. 9 third-party requests were detected from 4 vendors.

Cookies

10

Third-party

0

Trackers

9

Vendors

4

Consent banner

CookieYes

Scans

1

What this setup is missing

  • No Reject option on the first layer; declining requires extra steps.

Compliance by audience

European Union

✗ Not met

GDPR + ePrivacy · Prior consent (opt-in)

United Kingdom

✗ Not met

UK GDPR + PECR · Consent-based

United States

✓ Meets this model

CCPA/CPRA + state laws · Notice & opt-out

Canada

! Needs attention

PIPEDA + Québec Law 25 · Consent-based

Brazil

! Needs attention

LGPD · Consent-based

Scanned from the EU; sites may serve different banners or tracking to other regions. Verdicts reflect observed behaviour measured against each audience's rules.

Connection security

HTTPS supported

Redirects HTTP to HTTPS

HSTS

Content Security Policy

Cookies

10 cookies detected: 2 necessary, 7 analytics, 0 marketing

Total

10

Necessary

2

Functional

1

Analytics

7

Marketing

0

Unknown

0

Filter by category
Name Domain Category Provider Expiry Secure HttpOnly Party
sbjs_current before consent .grao.cat Analytics WooCommerce Session 1st
sbjs_current_add before consent .grao.cat Analytics WooCommerce Session 1st
sbjs_first before consent .grao.cat Analytics WooCommerce Session 1st
sbjs_first_add before consent .grao.cat Analytics WooCommerce Session 1st
sbjs_migrations before consent .grao.cat Analytics WooCommerce Session 1st
sbjs_session before consent .grao.cat Analytics WooCommerce Expired 1st
sbjs_udata before consent .grao.cat Analytics WooCommerce Session 1st
cookieyes-consent www.grao.cat Functional CookieYes 365 d 1st
__stripe_mid .www.grao.cat Necessary Stripe 365 d 1st
__stripe_sid .www.grao.cat Necessary Stripe Expired 1st

Browser storage set by the site

Name Domain Party
wpEmojiSettingsSupports set by www.grao.cat/:33:113 https://www.grao.cat 1st before consent
wc set by www.grao.cat/cart-fragments.min.js https://www.grao.cat 1st before consent
wc set by www.grao.cat/cart-fragments.min.js https://www.grao.cat 1st before consent
wc_fragments_6550a7cc19b493cd3f93d29abd2e2bca set by www.grao.cat/cart-fragments.min.js https://www.grao.cat 1st before consent
wc_cart_hash_6550a7cc19b493cd3f93d29abd2e2bca set by www.grao.cat/cart-fragments.min.js https://www.grao.cat 1st before consent
wc_cart_hash_6550a7cc19b493cd3f93d29abd2e2bca set by www.grao.cat/cart-fragments.min.js https://www.grao.cat 1st before consent

Third-Party Trackers

9 requests detected from 4 vendors: Stripe, Stripe Inc., Google LLC, Automattic

Analytics

2

Marketing

0

Necessary

5

Functional

1

Other

1

Vendor Category Type Domain
Stripe before consent Stripe tracker domain (source: Disconnect.me, category: Content) Analytics script r.stripe.com
Stripe Inc. before consent Stripe fraud detection Analytics script m.stripe.com
Google LLC before consent Google Maps API Functional script maps.googleapis.com
Automattic Automattic tracker domain (source: Disconnect.me, category: Content) Necessary script secure.gravatar.com
Google LLC Google tracker domain (source: Disconnect.me, category: Content) Necessary script maps.gstatic.com
Google LLC Google Fonts stylesheet Necessary script fonts.googleapis.com
Google LLC Google Fonts files Necessary script fonts.gstatic.com
Stripe Inc. Stripe payment processing Necessary script js.stripe.com
Stripe before consent Stripe tracker domain (source: Disconnect.me, category: FingerprintingInvasive) Unknown script m.stripe.network

Scan history

One completed scan: cookies and trackers from the scan on September 24, 2026.

Recent scans

September 24, 2026 10 9

Is grao.cat your website?

Claim it to monitor your cookies and trackers, set up a consent banner with automatic script blocking, and keep your cookie policy up to date.