Skip to main content
hemson.no

hemson.no

https://hemson.no

Last scanned September 28, 2026

A cookie scan of hemson.no performed on September 28, 2026 found 11 cookies and 12 third-party tracking requests. The assessment covered 10 pages across 10 unique page templates. The site relies on Cookiebot as its consent management platform with Google Consent Mode v2; IAB TCF v2.3 was not observed. 12 third-party requests were detected from 7 vendors.

Cookies

11

Third-party

0

Trackers

12

Vendors

7

Consent banner

Cookiebot

Scans

1

What this setup is missing

  • No Reject option on the first layer; declining requires extra steps.

Compliance by audience

European Union

✗ Not met

GDPR + ePrivacy · Prior consent (opt-in)

United Kingdom

✗ Not met

UK GDPR + PECR · Consent-based

United States

✓ Meets this model

CCPA/CPRA + state laws · Notice & opt-out

Canada

! Needs attention

PIPEDA + Québec Law 25 · Consent-based

Brazil

! Needs attention

LGPD · Consent-based

Scanned from the EU; sites may serve different banners or tracking to other regions. Verdicts reflect observed behaviour measured against each audience's rules.

Connection security

HTTPS supported

✓

Redirects HTTP to HTTPS

✓

HSTS

✗

Content Security Policy

✗

Cookies

11 cookies detected: 3 necessary, 7 analytics, 0 marketing

Total

11

Necessary

3

Functional

0

Analytics

7

Marketing

0

Unknown

1

Filter by category
Name Domain Category Provider Expiry Secure HttpOnly Party
sbjs_current before consent .hemson.no Analytics WooCommerce Session – – 1st
sbjs_current_add before consent .hemson.no Analytics WooCommerce Session – – 1st
sbjs_first before consent .hemson.no Analytics WooCommerce Session – – 1st
sbjs_first_add before consent .hemson.no Analytics WooCommerce Session – – 1st
sbjs_migrations before consent .hemson.no Analytics WooCommerce Session – – 1st
sbjs_session before consent .hemson.no Analytics WooCommerce Expired – – 1st
sbjs_udata before consent .hemson.no Analytics WooCommerce Session – – 1st
__cf_bm .hemson.no Necessary Cloudflare Expired ✓ ✓ 1st
__stripe_mid .hemson.no Necessary Stripe 365 d ✓ – 1st
__stripe_sid .hemson.no Necessary Stripe Expired ✓ – 1st
nitroCachedPage before consent hemson.no Unknown - Session – – 1st

Browser storage set by the site

Name Domain Party
wpEmojiSettingsSupports set by hemson.no/wp-emoji-loader.min.js:3:327 https://hemson.no 1st before consent
elementor set by hemson.no/frontend.min.js https://hemson.no 1st before consent
elementor set by hemson.no/frontend.min.js https://hemson.no 1st before consent
wc set by hemson.no/cart-fragments.min.js https://hemson.no 1st before consent
wc set by hemson.no/cart-fragments.min.js https://hemson.no 1st before consent
wc_fragments_7f25b15778a9440352adf673eaaf5d03 set by hemson.no/cart-fragments.min.js https://hemson.no 1st before consent
wc_cart_hash_7f25b15778a9440352adf673eaaf5d03 set by hemson.no/cart-fragments.min.js https://hemson.no 1st before consent
wc_cart_hash_7f25b15778a9440352adf673eaaf5d03 set by hemson.no/cart-fragments.min.js https://hemson.no 1st before consent

Third-Party Trackers

12 requests detected from 7 vendors: Automattic, Google LLC, Stripe Inc., Crisp IM SARL, Cybot A/S (Cookiebot)...

Analytics

3

Marketing

0

Necessary

5

Functional

2

Other

2

Vendor Category Type Domain
Automattic before consent Automattic tracker domain (source: Disconnect.me, category: Content) Analytics script stats.wp.com
Google LLC before consent Google Tag Manager Analytics script www.googletagmanager.com
Stripe Inc. before consent Stripe fraud detection Analytics script m.stripe.com
Crisp IM SARL before consent Crisp live chat Functional script client.crisp.chat
Google LLC before consent Google reCAPTCHA bot protection Functional script www.google.com
Cybot A/S (Cookiebot) Cookiebot consent management Necessary script consent.cookiebot.com
Google LLC Google tracker domain (source: Disconnect.me, category: Content) Necessary script www.gstatic.com
Google LLC Google Fonts files Necessary script fonts.gstatic.com
Google LLC Google Fonts stylesheet Necessary script fonts.googleapis.com
Stripe Inc. Stripe payment processing Necessary script js.stripe.com
Stripe before consent Stripe tracker domain (source: Disconnect.me, category: FingerprintingInvasive) Unknown script m.stripe.network
UserCentrics UserCentrics tracker domain (source: Disconnect.me, category: ConsentManagers) Unknown script consentcdn.cookiebot.com

Scan history

One completed scan: cookies and trackers from the scan on September 28, 2026.

Recent scans

September 28, 2026 11 12

Is hemson.no your website?

Claim it to monitor your cookies and trackers, set up a consent banner with automatic script blocking, and keep your cookie policy up to date.