Skip to main content
headstart.marketing

headstart.marketing

https://headstart.marketing

Last scanned September 27, 2026

A cookie scan of headstart.marketing completed on September 27, 2026 found 7 cookies and 22 third-party tracking requests. The assessment covered 9 pages across 9 unique page templates. The site relies on Cookiebot as its consent management platform with IAB TCF v2.3; Google Consent Mode v2 was not observed. 22 third-party requests were detected from 12 vendors.

Cookies

7

Third-party

0

Trackers

22

Vendors

12

Consent banner

Cookiebot

Scans

1

What this setup is missing

  • Script blocking is manual. Each script must be tagged by hand, and untagged scripts run before consent.
  • Google tags were observed, but Google Consent Mode v2 was not detected.
  • No Reject option on the first layer; declining requires extra steps.

Compliance by audience

European Union

✗ Not met

GDPR + ePrivacy · Prior consent (opt-in)

United Kingdom

✗ Not met

UK GDPR + PECR · Consent-based

United States

✓ Meets this model

CCPA/CPRA + state laws · Notice & opt-out

Canada

! Needs attention

PIPEDA + Québec Law 25 · Consent-based

Brazil

! Needs attention

LGPD · Consent-based

Scanned from the EU; sites may serve different banners or tracking to other regions. Verdicts reflect observed behaviour measured against each audience's rules.

Connection security

HTTPS supported

✓

Redirects HTTP to HTTPS

✓

HSTS

✓

Content Security Policy

✓

Cookies

7 cookies detected: 2 necessary, 4 analytics, 1 marketing

Total

7

Necessary

2

Functional

0

Analytics

4

Marketing

1

Unknown

0

Filter by category
Name Domain Category Provider Expiry Secure HttpOnly Party
_ga before consent .headstart.marketing Analytics Google Analytics 1.1 yr lifetime over 13 months – – 1st
_ga_YM8FM4CDVR before consent .headstart.marketing Analytics Google Analytics 1.1 yr lifetime over 13 months – – 1st
_hjSessionUser_3580907 before consent .headstart.marketing Analytics Hotjar 364 d ✓ – 1st
_hjSession_3580907 before consent .headstart.marketing Analytics Hotjar Expired ✓ – 1st
_fbp before consent .headstart.marketing Marketing Facebook 89 d – – 1st
_cfuvid .headstart.marketing Necessary Cloudflare Session ✓ ✓ 1st
_cfuvid .www.headstart.marketing Necessary Cloudflare Session ✓ ✓ 1st

Browser storage set by the site

Name Domain Party
_hjLocalStorageTest set by script.hotjar.com/modules.e762be2b6b709245aabb.js:2:217285 https://www.headstart.marketing 1st before consent
_hjSessionStorageTest set by script.hotjar.com/modules.e762be2b6b709245aabb.js:2:217510 https://www.headstart.marketing 1st before consent
hjViewportId set by script.hotjar.com/modules.e762be2b6b709245aabb.js:2:80374 https://www.headstart.marketing 1st before consent
hjActiveViewportIds set by script.hotjar.com/modules.e762be2b6b709245aabb.js:2:80510 https://www.headstart.marketing 1st before consent
lastExternalReferrer set by connect.facebook.net/fbevents.js:202:242 https://www.headstart.marketing 1st before consent
lastExternalReferrerTime set by connect.facebook.net/fbevents.js:202:242 https://www.headstart.marketing 1st before consent

Third-Party Trackers

22 requests detected from 12 vendors: ContentSquare, Google LLC, notifier-configs.airbrake.io, Stripe Inc., vzehfgmv.eug.stape.io...

Analytics

7

Marketing

2

Necessary

8

Functional

0

Other

5

Vendor Category Type Domain
ContentSquare before consent ContentSquare tracker domain (source: Disconnect.me, category: Analytics) Analytics script static.hotjar.com
ContentSquare before consent ContentSquare tracker domain (source: Disconnect.me, category: Analytics) Analytics script content.hotjar.io
ContentSquare before consent ContentSquare tracker domain (source: Disconnect.me, category: Analytics) Analytics script vc.hotjar.io
Google LLC before consent Google Tag Manager Analytics script www.googletagmanager.com
notifier-configs.airbrake.io before consent Analytics fetch notifier-configs.airbrake.io
Stripe Inc. before consent Stripe fraud detection Analytics script m.stripe.com
vzehfgmv.eug.stape.io before consent Analytics fetch vzehfgmv.eug.stape.io
Meta Platforms, Inc. before consent Facebook SDK / Pixel Marketing script connect.facebook.net
Meta Platforms, Inc. before consent Facebook tracking pixel Marketing pixel www.facebook.com
Amazon Amazon tracker domain (source: Disconnect.me, category: Content) Necessary script d3e54v103j8qbb.cloudfront.net
Cybot A/S (Cookiebot) Cookiebot consent management Necessary script consent.cookiebot.com
Google LLC Google tracker domain (source: Disconnect.me, category: Content) Necessary script ajax.googleapis.com
Google LLC Google Fonts stylesheet Necessary script fonts.googleapis.com
Google LLC Google Fonts files Necessary script fonts.gstatic.com
Google LLC Google tracker domain (source: Disconnect.me, category: Content) Necessary script www.gstatic.com
OneTrust LLC OneTrust consent management Necessary script cdn.cookielaw.org
Stripe Inc. Stripe payment processing Necessary script js.stripe.com
Google LLC before consent Google tracker domain (source: Disconnect.me, category: FingerprintingGeneral) Unknown script region1.google-analytics.com
Google LLC before consent Google tracker domain (source: Disconnect.me, category: Anti-fraud) Unknown script www.recaptcha.net
OneTrust OneTrust tracker domain (source: Disconnect.me, category: ConsentManagers) Unknown script geolocation.onetrust.com
Stripe before consent Stripe tracker domain (source: Disconnect.me, category: FingerprintingInvasive) Unknown script m.stripe.network
UserCentrics UserCentrics tracker domain (source: Disconnect.me, category: ConsentManagers) Unknown script consentcdn.cookiebot.com

Scan history

One completed scan: cookies and trackers from the scan on September 27, 2026.

Recent scans

September 27, 2026 7 22

Is headstart.marketing your website?

Claim it to monitor your cookies and trackers, set up a consent banner with automatic script blocking, and keep your cookie policy up to date.