Skip to main content
grao.com

grao.com

https://grao.com

Last scanned September 24, 2026

A cookie scan of grao.com completed on September 24, 2026 found 16 cookies and 7 third-party tracking requests. The assessment covered 10 pages across 10 unique page templates. The site uses CookieYes as its consent management platform. Neither IAB TCF v2.3 nor Google Consent Mode v2 was observed on our check. 7 third-party requests were detected from 3 vendors.

Cookies

16

Third-party

5

Trackers

7

Vendors

3

Consent banner

CookieYes

Scans

1

What this setup is missing

  • Google tags were observed, but Google Consent Mode v2 was not detected.

Compliance by audience

European Union

✗ Not met

GDPR + ePrivacy · Prior consent (opt-in)

United Kingdom

✗ Not met

UK GDPR + PECR · Consent-based

United States

✓ Meets this model

CCPA/CPRA + state laws · Notice & opt-out

Canada

! Needs attention

PIPEDA + Québec Law 25 · Consent-based

Brazil

! Needs attention

LGPD · Consent-based

Scanned from the EU; sites may serve different banners or tracking to other regions. Verdicts reflect observed behaviour measured against each audience's rules.

Connection security

HTTPS supported

Redirects HTTP to HTTPS

HSTS

Content Security Policy

Cookies

16 cookies detected: 4 necessary, 9 analytics, 0 marketing, 5 third-party

Total

16

Necessary

4

Functional

1

Analytics

9

Marketing

0

Unknown

2

5 third-party cookies detected

Third-party cookies require explicit user consent under GDPR/ePrivacy.

Filter by category
Name Domain Category Provider Expiry Secure HttpOnly Party
sbjs_current before consent .grao.com Analytics WooCommerce Session 1st
sbjs_current_add before consent .grao.com Analytics WooCommerce Session 1st
sbjs_first before consent .grao.com Analytics WooCommerce Session 1st
sbjs_first_add before consent .grao.com Analytics WooCommerce Session 1st
sbjs_migrations before consent .grao.com Analytics WooCommerce Session 1st
sbjs_session before consent .grao.com Analytics WooCommerce Expired 1st
sbjs_udata before consent .grao.com Analytics WooCommerce Session 1st
_ga before consent .grao.world Analytics Google Analytics 1.1 yr lifetime over 13 months 3rd
_ga_8G8D59Q5PL before consent .grao.world Analytics Google Analytics 1.1 yr lifetime over 13 months 3rd
cookieyes-consent www.grao.com Functional CookieYes 365 d 1st
cf_clearance .grao.world Necessary Cloudflare 365 d 3rd
wp_woocommerce_session_2bfd2620b10322f4f012a233982563fb .www.grao.com Necessary WooCommerce 2 d 1st
__stripe_mid .www.grao.com Necessary Stripe 365 d 1st
__stripe_sid .www.grao.com Necessary Stripe Expired 1st
_faristol_session before consent grao.world Unknown - 30 d 3rd
_faristol_vid before consent grao.world Unknown - 365 d 3rd

Browser storage set by the site

Name Domain Party
wpEmojiSettingsSupports set by www.grao.com/:33:113 https://www.grao.com 1st before consent
wc set by www.grao.com/cart-fragments.min.js https://www.grao.com 1st before consent
wc set by www.grao.com/cart-fragments.min.js https://www.grao.com 1st before consent
wc_fragments_34d43789331c9021737c3010e2ff8bde set by www.grao.com/cart-fragments.min.js https://www.grao.com 1st before consent
wc_cart_hash_34d43789331c9021737c3010e2ff8bde set by www.grao.com/cart-fragments.min.js https://www.grao.com 1st before consent
wc_cart_hash_34d43789331c9021737c3010e2ff8bde set by www.grao.com/cart-fragments.min.js https://www.grao.com 1st before consent

Third-Party Trackers

7 requests detected from 3 vendors: Google LLC, Stripe Inc., Stripe

Analytics

2

Marketing

0

Necessary

3

Functional

0

Other

2

Vendor Category Type Domain
Google LLC before consent Google Tag Manager Analytics script www.googletagmanager.com
Stripe Inc. before consent Stripe fraud detection Analytics script m.stripe.com
Google LLC Google Fonts stylesheet Necessary script fonts.googleapis.com
Google LLC Google Fonts files Necessary script fonts.gstatic.com
Stripe Inc. Stripe payment processing Necessary script js.stripe.com
Google LLC before consent Google tracker domain (source: Disconnect.me, category: FingerprintingGeneral) Unknown script region1.google-analytics.com
Stripe before consent Stripe tracker domain (source: Disconnect.me, category: FingerprintingInvasive) Unknown script m.stripe.network

Scan history

One completed scan: cookies and trackers from the scan on September 24, 2026.

Recent scans

September 24, 2026 16 7

Is grao.com your website?

Claim it to monitor your cookies and trackers, set up a consent banner with automatic script blocking, and keep your cookie policy up to date.