English
consentglass · GDPR scanner for websites

kinsta.com

Checked on 9/3/2026 · https://kinsta.com/

F
0 / 100
No cookie banner detected · Privacy-policy link: yes · Legal-notice link: no

Critical items: 1 · also to review: 2.

How is the score calculated? (100 starting points)
Advertising/tracking service: Google Ads (DoubleClick)-22
Advertising/tracking service: Google AdSense (additional)-7
Advertising/tracking service: Google Ads Conversion (additional)-7
Analytics service: Google Analytics-15
Analytics service: Google Analytics 4 (additional)-5
Session recording: Hotjar-18
Tag manager: Google Tag Manager-12
Tag manager: Google Tag Manager (additional)-4
Tag-Manager lädt ungeprüft weitere Skripte nach-6
1 cookie(s) set on first load-8
1 detected services not found in the privacy policy-6
Result0 / 100

Multiple services of the same kind count on a sliding scale. The score is a guide, not a legal verdict.

What this scan doesn't see consentglass reads only the first, unmodified HTML — without executing JavaScript. A tag manager is embedded — which services it loads is decided only in the browser. So a good result here doesn't automatically mean “GDPR-compliant”. Monitoring runs the full test with JavaScript enabled.
Tiefen-Scan (mit JavaScript) Lädt die Seite wie ein echter Browser, führt JavaScript aus und protokolliert, welche Dritt-Dienste vor einer Einwilligung feuern und wie sich das Banner beim Ablehnen verhält. Dauert etwa eine Minute.

Cookies set on first load: __cf_bm

Findings

Critical

8 services requiring consent, no cookie banner detected

Analytics, advertising or social services load without any consent solution being detectable.

What you should do: Add a consent tool that loads these services only after active consent (not just displays a banner). Until then, remove the scripts or switch to consent-free alternatives.

§ 25 (1) TDDDG together with Art. 6 (1) GDPR — access to terminal equipment only with prior consent.

To review

1 cookie(s) set on first load

Set without a consent banner: __cf_bm. Only technically necessary cookies are permitted without consent.

What you should do: Check which of these cookies are really technically necessary (session, cart, language setting). Set everything else — especially analytics/marketing — only after consent.

§ 25 (2) TDDDG — exception only for strictly necessary cookies.

To review

1 detected services not found in the privacy policy

On the linked privacy page no mention of Hotjar was found. Automated text match — they may be referred to differently there.

What you should do: Check that every service in use is listed in the privacy policy with provider, purpose, legal basis, retention period and (for third countries) transfer basis.

Art. 13 (1) GDPR — duty to inform about recipients and purposes of processing.

Next steps

  1. 8 services requiring consent, no cookie banner detected. Add a consent tool that loads these services only after active consent (not just displays a banner). Until then, remove the scripts or switch to consent-free alternatives.
  2. 1 cookie(s) set on first load. Check which of these cookies are really technically necessary (session, cart, language setting). Set everything else — especially analytics/marketing — only after consent.
  3. 1 detected services not found in the privacy policy. Check that every service in use is listed in the privacy policy with provider, purpose, legal basis, retention period and (for third countries) transfer basis.

Third parties detected (8)

ServicePurposeVendorCountryLegal basis
Google Ads (DoubleClick)
doubleclick.net
Ad targeting and conversion tracking Google LLC US ⚠ Consent required
Google AdSense
googlesyndication.com
Ad targeting and conversion tracking Google LLC US ⚠ Consent required
Google Ads Conversion
googleadservices.com
Ad targeting and conversion tracking Google LLC US ⚠ Consent required
Google Analytics
google-analytics.com
Audience measurement and usage analysis Google LLC US ⚠ Consent required
Google Analytics 4
analytics.google.com
Audience measurement and usage analysis Google LLC US ⚠ Consent required
Hotjar
static.hotjar.com
Recording of mouse movements, clicks and input Hotjar Ltd. MT Consent required
Google Tag Manager
www.googletagmanager.com
loads further scripts — content depends on the configuration Google LLC US ⚠ Consent required once it loads non-essential items
Google Tag Manager
googletagmanager.com
loads further scripts — content depends on the configuration Google LLC US ⚠ Consent required once it loads non-essential items

⚠ Established outside the EU/EEA — the transfer needs an additional basis (e.g. the EU-US Data Privacy Framework or standard contractual clauses).

Monitor this URL automatically?

Weekly re-scan, email as soon as a new tracker appears — coming soon.

Method & limits

On 9/3/2026 we checked the HTML that kinsta.com delivers on first load without a login (normal desktop browser, EU location). Detected: services embedded in the source (scripts, stylesheets, iframes, pixels), a cookie banner based on known providers, cookies from the server response, and links to the privacy policy and legal notice.

Not checked: anything that loads only via JavaScript, content behind a login, subpages, behaviour after clicking “Accept”/“Reject”, server locations and data-processing agreements. The result is an automated snapshot and not a substitute for legal advice.

Scan another website