https://airtable.com
Scanned Apr 15, 2026 · 40.6s
Your website score is
Grade
BannerConsent Banner
Yes
Regulatory Compliance
Multi-regulation overview — click any regulation for details
Technical scan only. A passing score does not equal legal compliance. Consult qualified legal counsel for your jurisdiction.
Tag Leak detected 15 user data leaks before consent on airtable.com, including Advertising Tracker, Marketo, LinkedIn Insight Tag and 4 more.
Security Headers
4/6 presentStrict-Transport-Security
max-age=31536000; includeSubDomains
Content-Security-Policy
script-src https://www.airtable.com https://airtable-marketing.herokuapp.com https://airtable.com https://static.airtable.com/ 'unsafe-eval' 'unsafe-inline' 'report-sample' https: blob:; style-src 'unsafe-inline' https:; block-all-mixed-content; object-src //pages.airtable.com; base-uri 'none'; report-uri https://airtable.com/.csp/report
X-Frame-Options
Add X-Frame-Options header to prevent clickjacking attacks
X-Content-Type-Options
nosniff
Referrer-Policy
strict-origin-when-cross-origin
Permissions-Policy
Add a Permissions-Policy header to restrict browser features like camera, microphone, and geolocation
Google Consent Mode
V2Consent Parameters
Issues (1)
No default consent call detected — consent mode may not be initialised correctly
Post-Rejection Audit
Reject Button
Found
Post-Rejection Fires
8 vendors
Consent Mode
Advanced
GTM Load
1092ms pre-consent
Google Tag Manager(GTM-NCLXNTS)
Loaded 1092ms after page load — before the consent banner was detected (banner appeared at 8629ms). Per a 2022 German court ruling, GTM itself transmits the user's IP to Google pre-consent.
Consent Mode V2: Advanced
Advanced Consent Mode — consent update call fires on rejection and tracking stops correctly.
✓ gtag('consent', 'update') call detected on rejection
Vendors firing after rejection (8)
| Vendor | Category | Timing | URL |
|---|---|---|---|
| Google — Google Tag Manager | tag_management | 19670ms | www.googletagmanager.com |
| Adobe — Marketo | marketing | 19784ms | munchkin.marketo.net |
| OneTrust — CookiePro CMP | consent_management | 20291ms | cookie-cdn.cookiepro.com |
| Google — GA4 | analytics | 20292ms | www.googletagmanager.com |
| LinkedIn — LinkedIn Insight Tag | advertising | 20292ms | snap.licdn.com |
| Google — Google Ads | advertising | 20294ms | pagead2.googlesyndication.com |
| OneTrust — OneTrust CMP | consent_management | 20490ms | geolocation.onetrust.com |
| Google — GA4 | analytics | 20861ms | region1.google-analytics.com |
Consent Record Audit
PassConsent record stored after interaction
GDPR Art. 7(1)Found: OptanonConsent (OneTrust)
Record contains timestamp
Art. 7(1)Timestamp field detected
Record contains consent state
Art. 7(1)Accept/reject state detected
Record contains consent categories
Art. 7(1)Consent categories (analytics, marketing, etc.) not found in record
Consent withdrawal mechanism accessible
GDPR Art. 7(3)Cookie settings link / floating button found
Tracker categories detected
Critical18

GA4 (Google) loaded before consent: Sends pageview and event data to Google Analytics
advertising tracker at cdn.intellimize.co loaded before consent

Marketo (Adobe) loaded before consent: Marketo Munchkin tracking for marketing automation
LinkedIn Insight Tag (LinkedIn) loaded before consent: Tracks conversions and enables LinkedIn audience targeting

Google Ads (Google) loaded before consent: Google ad syndication and remarketing
Qualified (Advertising Tracker)4 findingsjs.qualified.com, app.qualified.com, assets.qualified.com, messenger-assets.qualified.com
js.qualified.com, app.qualified.com, assets.qualified.com, messenger-assets.qualified.com
Qualified (advertising) loaded before consent
Qualified (advertising) loaded before consent
Qualified (advertising) loaded before consent
Qualified (advertising) loaded before consent
LinkedIn2 findingsbcookie, lidc
bcookie, lidc
LinkedIn cookie "bcookie" set before consent — Used by LinkedIn to track the use of embedded services.
LinkedIn cookie "lidc" set before consent — Used by the social networking service, LinkedIn, for tracking the use of embedded services.

Google — Google Tag Manager fires after user rejected consent

Adobe — Marketo fires after user rejected consent

OneTrust — CookiePro CMP fires after user rejected consent

Google — GA4 fires after user rejected consent
LinkedIn — LinkedIn Insight Tag fires after user rejected consent

Google — Google Ads fires after user rejected consent

OneTrust — OneTrust CMP fires after user rejected consent
Warnings4
Google Tag Manager2 findingsID trackedwww.googletagmanager.com

www.googletagmanager.com

Google Tag Manager loads before consent — this is expected and required for GCM v2 to initialise consent defaults before any tags fire

GTM loaded before consent banner — IP address transmitted to Google pre-consent (container: GTM-NCLXNTS)
Unknown third-party request to px.ads.linkedin.com before consent
localStorage key "__q_local_form_debug" written before consent
Info9

CookiePro CMP (OneTrust) loaded before consent: CookiePro (OneTrust) consent management platform

OneTrust CMP (OneTrust) loaded before consent: OneTrust geo-lookup — determines which consent banner to show based on user location

Cloudflare Web Analytics (Cloudflare) loaded before consent: Cloudflare Web Analytics beacon — privacy-focused, no cookies
Sentry (Sentry) loaded before consent: Sentry error reporting endpoint
LinkedIn cookie "li_gc" set before consent — Used to store guest consent to the use of cookies for non-essential purposes

OneTrust cookie "OptanonConsent" set before consent
Cloudflare bot management — necessary for site operation
AWS Application Load Balancer — necessary for infrastructure
AWS Application Load Balancer — necessary for infrastructure
Compliant22
Google Analytics4 findingsID trackedregion1.analytics.google.com, _ga_MD9XNHKP59, _ga, _ga_VJY8J9RFZM

region1.analytics.google.com, _ga_MD9XNHKP59, _ga, _ga_VJY8J9RFZM

GA4 (Google) loaded correctly after consent

Google Analytics cookie "_ga_MD9XNHKP59" set correctly after consent

Google Analytics cookie "_ga" set correctly after consent

Google Analytics cookie "_ga_VJY8J9RFZM" set correctly after consent
Microsoft Clarity4 findingsID trackedwww.clarity.ms, scripts.clarity.ms, i.clarity.ms, _clck

www.clarity.ms, scripts.clarity.ms, i.clarity.ms, _clck

Microsoft Clarity (Microsoft) loaded correctly after consent

Microsoft Clarity (Microsoft) loaded correctly after consent

Microsoft Clarity (Microsoft) loaded correctly after consent

Microsoft Clarity cookie "_clck" set correctly after consent
Mouseflow (Mouseflow) loaded correctly after consent
Microsoft Ads3 findingsbat.bing.com, _uetsid, _uetvid

bat.bing.com, _uetsid, _uetvid

Microsoft Ads (Microsoft) loaded correctly after consent

Microsoft Ads cookie "_uetsid" set correctly after consent

Microsoft Ads cookie "_uetvid" set correctly after consent
Google Ads4 findingswww.google.com, googleads.g.doubleclick.net, _gcl_au, _gcl_ls

www.google.com, googleads.g.doubleclick.net, _gcl_au, _gcl_ls

Google Ads (Google) loaded correctly after consent

Google Ads (Google) loaded correctly after consent

Google Ads cookie "_gcl_au" set correctly after consent

Google Ads (Google) wrote "_gcl_ls" to localStorage correctly after consent

Meta Pixel (Meta) loaded correctly after consent
Reddit Pixel (Reddit) loaded correctly after consent

OneTrust cookie "OptanonAlertBoxClosed" set correctly after consent

Marketo cookie "_mkto_trk" set correctly after consent

DoubleClick/Google Marketing cookie "IDE" set correctly after consent

Bing / Microsoft cookie "MUID" set correctly after consent
Is this your site?
Run a full multi-page scan with monitoring and get detailed remediation steps
Scan airtable.com →This audit is based on publicly observable website behavior. To request removal from the index, email support@tagleak.com