Skip to main content
hxa.io

hxa.io

https://hxa.io

Last scanned July 26, 2026

A cookie scan of hxa.io completed on July 26, 2026 found 3 cookies and 13 third-party tracking requests. The assessment covered 10 pages across 10 unique page templates. The site relies on Cookiebot as its consent management platform. Neither IAB TCF v2.3 nor Google Consent Mode v2 was observed on our check. 13 third-party requests were detected from 8 vendors.

Cookies

3

Third-party

0

Trackers

13

Vendors

8

Consent banner

Cookiebot

Scans

1

What this setup is missing

  • Script blocking is manual. Each script must be tagged by hand, and untagged scripts run before consent.
  • Google tags were observed, but Google Consent Mode v2 was not detected.

Compliance by audience

European Union

✓ Meets this model

GDPR + ePrivacy · Prior consent (opt-in)

United Kingdom

✓ Meets this model

UK GDPR + PECR · Consent-based

United States

✓ Meets this model

CCPA/CPRA + state laws · Notice & opt-out

Canada

✓ Meets this model

PIPEDA + Québec Law 25 · Consent-based

Brazil

✓ Meets this model

LGPD · Consent-based

Scanned from the EU; sites may serve different banners or tracking to other regions. Verdicts reflect observed behaviour measured against each audience's rules.

Connection security

HTTPS supported

Redirects HTTP to HTTPS

HSTS

Content Security Policy

Cookies

3 cookies detected: 1 necessary, 1 analytics, 0 marketing

Total

3

Necessary

1

Functional

0

Analytics

1

Marketing

0

Unknown

1

Filter by category
Name Domain Category Provider Expiry Secure HttpOnly Party
_gcl_au before consent .hxa.io Analytics Google Analytics 90 d 1st
PHPSESSID hxa.io Necessary PHP Session 1st
csrf_https-contao_csrf_token before consent hxa.io Unknown - Session 1st

Browser storage set by the site

Name Domain Party
modernizr set by hxa.io/jquery.min.js,rocksolid-slider.min.js,modernizr-2.6.2.min.js-9a55b799.js:20:7237 https://hxa.io 1st before consent
modernizr set by hxa.io/jquery.min.js,rocksolid-slider.min.js,modernizr-2.6.2.min.js-9a55b799.js:20:7354 https://hxa.io 1st before consent
_gcl_ls set by www.googletagmanager.com/js https://hxa.io 1st before consent
__sak set by maps.googleapis.com/js https://hxa.io 1st before consent
socialintents_vs_2c9fa5636fc83c31016fc8af2998009d set by www.socialintents.com/socialintents.1.3.js:71:36 https://hxa.io 1st before consent

Third-Party Trackers

13 requests detected from 8 vendors: cdn.leadinfo.eu, Google LLC, Microsoft, www.google.com, Cloudflare Inc....

Analytics

4

Marketing

0

Necessary

5

Functional

1

Other

3

Vendor Category Type Domain
cdn.leadinfo.eu before consent Analytics script cdn.leadinfo.eu
Google LLC before consent Google Tag Manager Analytics script www.googletagmanager.com
Microsoft before consent Microsoft tracker domain (source: Disconnect.me, category: Analytics) Analytics script www.clarity.ms
www.google.com before consent Analytics fetch www.google.com
Google LLC before consent Google Maps API Functional script maps.googleapis.com
Cloudflare Inc. Cloudflare CDNJS Necessary script cdnjs.cloudflare.com
Cybot A/S (Cookiebot) Cookiebot consent management Necessary script consent.cookiebot.com
Google LLC Google Fonts stylesheet Necessary script fonts.googleapis.com
Google LLC Google Fonts files Necessary script fonts.gstatic.com
Google LLC Google tracker domain (source: Disconnect.me, category: Content) Necessary script maps.gstatic.com
Google LLC before consent Google tracker domain (source: Disconnect.me, category: FingerprintingGeneral) Unknown script ad.doubleclick.net
LeadInfo before consent LeadInfo tracker domain (source: Disconnect.me, category: FingerprintingInvasive) Unknown script collector.leadinfo.net
UserCentrics UserCentrics tracker domain (source: Disconnect.me, category: ConsentManagers) Unknown script consentcdn.cookiebot.com

Scan history

One completed scan: cookies and trackers from the scan on July 26, 2026.

Recent scans

July 26, 2026 3 13

Is hxa.io your website?

Claim it to monitor your cookies and trackers, set up a consent banner with automatic script blocking, and keep your cookie policy up to date.