johnstonespaint.com
Last scanned October 8, 2026
A cookie scan of johnstonespaint.com conducted on October 8, 2026 found 22 cookies and 17 third-party tracking requests. The assessment covered 10 pages across 10 unique page templates. The site relies on Cookiebot as its consent management platform with Google Consent Mode v2; IAB TCF v2.3 was not observed. 17 third-party requests were detected from 11 vendors.
Consent behaviour grade
3 / 100
This site set multiple tracking cookies before the visitor consented. Under ePrivacy Article 5(3), these require prior consent.
Automated point-in-time check of the scanned pages; not legal advice. How our check works.
Consent enforcement level
-
1
Nothing non-essential runs before consent is given. This is the strict reading of ePrivacy Article 5(3) and the strongest position.
-
2
Google tags load with storage defaulted to denied and send only cookieless pings before consent. Permitted in Google's model, but not the strict reading of Article 5(3).
-
3
Partially enforced This site
Google Consent Mode v2 restrains Google tags, but other trackers or cookies were observed before consent.
-
4
Trackers or cookies execute before the visitor consents, with no consent signals restraining them.
Consent banner as encountered
The first layer offers a Reject option alongside Accept.
Load timeline before consent
Milliseconds from navigation start until each request fired or each cookie was set.
and 12 more
Observed before consent
Cookies set before consent (22)
-
_fbpmarketing · Facebook -
_hjSession_3636749analytics · Hotjar -
_hjSessionUser_3636749analytics · Hotjar -
mage-cache-sessidfunctional · Magento -
mage-cache-storagefunctional · Magento -
mage-cache-storage-section-invalidationfunctional · Magento -
mage-messagesfunctional · Magento -
private_content_versionfunctional · Magento -
product_data_storagefunctional · Magento -
recently_compared_productfunctional · Magento -
recently_compared_product_previousfunctional · Magento -
recently_viewed_productfunctional · E-commerce -
recently_viewed_product_previousfunctional · E-commerce -
section_data_idsfunctional · Magento -
X-Magento-Varyfunctional · Magento -
hnbotstopper-auth-146e942cunknown -
hnbotstopper-cookie-verification-146e942cunknown -
magepal-enhanced-ecommerceunknown -
magepal-google-analytics4unknown -
form_keynecessary · Magento - and 2 more
Tracking requests before consent (11)
- ContentSquare static.hotjar.com set by www.johnstonespaint.com/choosing-the-right-paint · at 85 ms
- ContentSquare content.hotjar.io set by script.hotjar.com/modules.ac003456795fba9e297a.js · at 304 ms
- ContentSquare vc.hotjar.io set by script.hotjar.com/modules.ac003456795fba9e297a.js · at 872 ms
- Google LLC www.googletagmanager.com set by www.johnstonespaint.com/datalayer.js · at 320 ms
- MyFonts hello.myfonts.net set a cookie at 75 ms
- tracker.3dissue.com tracker.3dissue.com set a cookie set by code.3dissue.com/jquery-3.6.0.min.js · at 2865 ms
- Zendesk johnstonespaint.zendesk.com set a cookie set by static.zdassets.com/web-widget-main-fdbc813.js · at 207 ms
- Zendesk Inc. static.zdassets.com at 64 ms
- Intuit chimpstatic.com at 48 ms
- Meta Platforms, Inc. connect.facebook.net at 397 ms
- Meta Platforms, Inc. www.facebook.com at 463 ms
How we tested
Browser: Chrome/150.0.7871.124 · Scan origin: EU · Viewport: 1440×900 · Checked: 8 Oct 2026 22:57
Cookies
22
Third-party
0
Trackers
17
Vendors
11
Consent banner
Cookiebot
Scans
1
What this setup is missing
- Script blocking is manual. Each script must be tagged by hand, and untagged scripts run before consent.
- The published cookie declaration does not include all cookies observed on the site.
Compliance by audience
European Union
✗ Not metGDPR + ePrivacy · Prior consent (opt-in)
United Kingdom
✗ Not metUK GDPR + PECR · Consent-based
United States
✓ Meets this modelCCPA/CPRA + state laws · Notice & opt-out
Canada
! Needs attentionPIPEDA + Québec Law 25 · Consent-based
Brazil
! Needs attentionLGPD · Consent-based
Scanned from the EU; sites may serve different banners or tracking to other regions. Verdicts reflect observed behaviour measured against each audience's rules.
Connection security
HTTPS supported
✓Redirects HTTP to HTTPS
✓HSTS
✗Content Security Policy
✗
Third-Party Trackers
17 requests detected from 11 vendors: ContentSquare, Google LLC, MyFonts, tracker.3dissue.com, Zendesk...
Third-Party Trackers
17 requests detected from 11 vendors: ContentSquare, Google LLC, MyFonts, tracker.3dissue.com, Zendesk...
Analytics
7
Marketing
3
Necessary
5
Functional
1
Other
1
| Vendor | Category | Type | Domain |
|---|---|---|---|
| ContentSquare before consent ContentSquare tracker domain (source: Disconnect.me, category: Analytics) | Analytics | script | static.hotjar.com |
| ContentSquare before consent ContentSquare tracker domain (source: Disconnect.me, category: Analytics) | Analytics | script | content.hotjar.io |
| ContentSquare before consent ContentSquare tracker domain (source: Disconnect.me, category: Analytics) | Analytics | script | vc.hotjar.io |
| Google LLC before consent Google Tag Manager | Analytics | script | www.googletagmanager.com |
| MyFonts before consent MyFonts tracker domain (source: Disconnect.me, category: Analytics) | Analytics | script | hello.myfonts.net |
| tracker.3dissue.com before consent | Analytics | xhr | tracker.3dissue.com |
| Zendesk before consent Zendesk tracker domain (source: Disconnect.me, category: Content) | Analytics | script | johnstonespaint.zendesk.com |
| Zendesk Inc. before consent Zendesk assets | Functional | script | static.zdassets.com |
| Intuit before consent Intuit tracker domain (source: Disconnect.me, category: Advertising) | Marketing | script | chimpstatic.com |
| Meta Platforms, Inc. before consent Facebook SDK / Pixel | Marketing | script | connect.facebook.net |
| Meta Platforms, Inc. before consent Facebook tracking pixel | Marketing | pixel | www.facebook.com |
| Amazon Amazon tracker domain (source: Disconnect.me, category: Content) | Necessary | script | s3.amazonaws.com |
| Cybot A/S (Cookiebot) Cookiebot consent management | Necessary | script | consent.cookiebot.com |
| Google LLC Google Fonts stylesheet | Necessary | script | fonts.googleapis.com |
| Google LLC Google Fonts files | Necessary | script | fonts.gstatic.com |
| Zendesk Zendesk tracker domain (source: Disconnect.me, category: Content) | Necessary | script | ekr.zdassets.com |
| UserCentrics UserCentrics tracker domain (source: Disconnect.me, category: ConsentManagers) | Unknown | script | consentcdn.cookiebot.com |
Scan history
One completed scan: cookies and trackers from the scan on October 8, 2026.
Recent scans
| October 8, 2026 | 22 17 |
More Cookie Compliance Reviews
RelationshipU | Enroll
join-ru.com
Nisa Retail | Privacy Policy | Read Nisa's priv...
join-nisa.com
MEMM: Make Everything Money
join-memm.com
Squarespace - Please Stand By
join-ggsir.com
Education - joimax®
joimax.com
Joifilabs - Software Industrial para el Sector ...
joifilabs.com
Le bureau de l'association - Joie et santé Agn...
joietsante.com
Robot Challenge Screen
joifulnotary.com
Is johnstonespaint.com your website?
Claim it to monitor your cookies and trackers, set up a consent banner with automatic script blocking, and keep your cookie policy up to date.