Support

What Counts as Tracking

CookieInspector separates third-party requests from third-party tracking. Accessibility widgets, payment processors, CAPTCHAs, fonts and your own consent platform are listed in the report but do not lower the score. This page explains how that line is drawn and what to do if a service landed on the wrong side of it.

Contact support

A third-party request is not the same as third-party tracking

Almost every modern website talks to other companies' servers while it loads: a payment form, a CAPTCHA, a font, a script library, an accessibility widget. Each of those is a third-party request. None of them is, by itself, tracking.

Tracking is when a third party observes the visitor for its own purposes: analytics, advertising, session recording, fingerprinting. That is what privacy law asks you to hold back until the visitor consents, and that is what CookieInspector scores.

So the scanner does not count requests. It classifies each third-party host it sees and only counts the ones that track. Everything else still appears in the report, so you can see the whole picture, but it does not move the score.

What never counts against your score

These are recognized as necessary or functional and are listed, not scored:

  • Your consent platform itself. Cookiebot, OneTrust, Usercentrics, Iubenda, CookieYes, Didomi and the other major CMPs have to load before consent to ask for it. Their infrastructure and their own consent-state cookies are never tracking.
  • Security and session plumbing. CSRF tokens, session cookies, Cloudflare and Akamai bot-management cookies, load-balancer affinity cookies.
  • Accessibility widgets. UserWay, accessiBe, AudioEye, EqualWeb and Recite Me exist so the page is usable by more people. Their requests fire before consent because the widget has to be there from the first paint. They are labelled as accessibility services and do not count as tracking.
  • Payment and donation processors. Stripe, PayPal, Braintree, Adyen, Square and the donation platforms a checkout or donate page depends on.
  • CAPTCHA and anti-abuse challenges. reCAPTCHA, hCaptcha.
  • Asset delivery. Google Fonts, Bunny Fonts, jsDelivr, cdnjs, unpkg, and the asset CDNs of site builders and page optimizers that serve the site's own files.

What still counts

The list above is deliberately short. Being conservative is the point of a compliance tool:

  • Analytics, advertising and session recording always count, whoever serves them. Google Analytics, Meta Pixel, LinkedIn Insight, Hotjar, Clarity and the rest.
  • Unknown third parties count. If the scanner cannot tell what a host does, it stays in the tracking column rather than being waved through. Telling you a site is clean when it is not is the expensive mistake.
  • General-purpose CDNs such as CloudFront, Fastly or Azure CDN are not exempt, because anyone can serve anything from them, real trackers included.
  • Vendors that mix roles. HubSpot's banner is recognized as a consent platform, but HubSpot's analytics and advertising pixels are still measured. Platforms that sell accessibility and site analytics under the same domain are treated the same way: the accessibility part does not whitelist the analytics part.

How this shows up in the report

A functional third party appears in the trackers and domains tables with its role spelled out, for example Accessibility widget (UserWay), and in the consent timeline marked as functional. If the only third-party requests before consent are functional ones, the report says so in a low-severity note rather than raising Third-party tracking before consent or Consent banner not blocking tracking.

If a real tracker fires on the same page, it is flagged exactly as before. Recognizing the accessibility widget never hides the analytics tag next to it.

Think a service is misclassified?

Every report has a Request a review box at the bottom. Tell us which host you believe is functional and what it does on the page. Real people read those, and when a vendor qualifies it is added to the registry for every customer, not just yours.

The bar is simple: the vendor's product has to be the service itself, with no analytics or advertising business attached to the same domain.

Prefer to write? Contact support.

Ready to prove your compliance?

Start with a scan so you can show regulators and stakeholders the evidence you followed cookie compliance checker best practices.

Contact support