Amazon

amazon.com

Compare

https://amazon.com

Scanned Apr 15, 2026 · 24.1s

Your website score is

0/100
Critical

Grade

F0

Banner

No

Regulatory Compliance

Multi-regulation overview — click any regulation for details

Technical scan only. A passing score does not equal legal compliance. Consult qualified legal counsel for your jurisdiction.

Tag Leak detected 78 user data leaks before consent on amazon.com, including Amazon (Analytics Tracker), Amazon (Advertising Tracker), Microsoft (Advertising Tracker) and 50 more.

Security Headers

0/6 present

Strict-Transport-Security

Add HSTS header to enforce HTTPS connections and prevent downgrade attacks

Content-Security-Policy

Add a Content-Security-Policy header to prevent XSS and code injection attacks

X-Frame-Options

Add X-Frame-Options header to prevent clickjacking attacks

X-Content-Type-Options

Set X-Content-Type-Options to 'nosniff' to prevent MIME type sniffing

Referrer-Policy

Set a Referrer-Policy header to control how much referrer information is shared

Permissions-Policy

Add a Permissions-Policy header to restrict browser features like camera, microphone, and geolocation

Google Consent Mode

Not Detected

Google Consent Mode v2 was not found on this page. GCM v2 allows Google's tags to adjust their behavior based on user consent, and is required for compliant advertising measurement in the EU. Without it, your Google Ads and GA4 conversions may be impacted after consent is declined.

Post-Rejection Audit

Reject Button

Missing

Post-Rejection Fires

0 vendors

Consent Mode

Not Detected

GTM Load

Not detected

Consent Mode V2: Not Detected

Google Consent Mode was not detected on this site.

Consent Record Audit

Issues detected

Consent record stored after interaction

GDPR Art. 7(1)

No consent record written — cannot prove consent was given

No CMP consent cookie or localStorage entry was found after the consent interaction. GDPR requires controllers to demonstrate consent was given.

Consent withdrawal mechanism accessible

GDPR Art. 7(3)

No way for users to withdraw consent found on page

No cookie settings link, footer link, or floating consent button was detected. GDPR requires users to withdraw consent as easily as they gave it.

Why this matters

Under GDPR Article 7, controllers must be able to demonstrate that consent was given (Art. 7(1)) and ensure users can withdraw consent at any time, as easily as giving it (Art. 7(3)). Sites with no consent record or no withdrawal mechanism cannot legally rely on consent as a lawful basis.

Tracker categories detected

Advertising29 vendors
Analytics2 vendors
Marketing17 vendors
Security6
Critical72
Amazon (Analytics Tracker)
criticalNetworkAnalyticsAmazon (Analytics Tracker)

Amazon (analytics) loaded before consent

Host: images-na.ssl-images-amazon.comFired: 3167ms after load
Amazon (Advertising Tracker)
Amazon (Advertising Tracker)3 findings

s.amazon-adsystem.com, www.imdb.com, redirect.prod.experiment.routing.cloudfront.aws.a2z.com

Amazon (Advertising Tracker)
criticalNetworkAdvertisingAmazon (Advertising Tracker)

Amazon (advertising) loaded before consent

Host: s.amazon-adsystem.comFired: 4901ms after load
Amazon (Advertising Tracker)
criticalNetworkAdvertisingAmazon (Advertising Tracker)

Amazon (advertising) loaded before consent

Host: www.imdb.comFired: 5525ms after load
Amazon (Advertising Tracker)
criticalNetworkAdvertisingAmazon (Advertising Tracker)

Amazon (advertising) loaded before consent

Host: redirect.prod.experiment.routing.cloudfront.aws.a2z.comFired: 6655ms after load
Microsoft (Advertising Tracker)
criticalNetworkAdvertisingMicrosoft (Advertising Tracker)

Microsoft (advertising) loaded before consent

Host: ib.adnxs.comFired: 5524ms after load
Azerion (Advertising Tracker)
criticalNetworkAdvertisingAzerion (Advertising Tracker)

Azerion (advertising) loaded before consent

Host: match.360yield.comFired: 5524ms after load
Life360 (Advertising Tracker)
criticalNetworkAdvertisingLife360 (Advertising Tracker)

Life360 (advertising) loaded before consent

Host: jadserve.postrelease.comFired: 5524ms after load
TransUnion (Advertising Tracker)
criticalNetworkAdvertisingTransUnion (Advertising Tracker)

TransUnion (advertising) loaded before consent

Host: aa.agkn.comFired: 5524ms after load
Equativ (Advertising Tracker)
Equativ (Advertising Tracker)2 findings

rtb-csync.smartadserver.com, match.sharethrough.com

Equativ (Advertising Tracker)
criticalNetworkAdvertisingEquativ (Advertising Tracker)

Equativ (advertising) loaded before consent

Host: rtb-csync.smartadserver.comFired: 5524ms after load
Equativ (Advertising Tracker)
criticalNetworkAdvertisingEquativ (Advertising Tracker)

Equativ (advertising) loaded before consent

Host: match.sharethrough.comFired: 5525ms after load
IndexExchange (Advertising Tracker)
criticalNetworkAdvertisingIndexExchange (Advertising Tracker)

IndexExchange (advertising) loaded before consent

Host: dsum-sec.casalemedia.comFired: 5524ms after load
Criteo (Advertising Tracker)
criticalNetworkAdvertisingCriteo (Advertising Tracker)

Criteo (advertising) loaded before consent

Host: x.bidswitch.netFired: 5524ms after load
Advertising Tracker
Advertising Tracker3 findings

capi.connatix.com, lciapi.ninthdecimal.com, pi.ispot.tv

Advertising Tracker
criticalNetworkAdvertisingAdvertising Tracker

advertising tracker at capi.connatix.com loaded before consent

Host: capi.connatix.comFired: 5525ms after load
Advertising Tracker
criticalNetworkAdvertisingAdvertising Tracker

advertising tracker at lciapi.ninthdecimal.com loaded before consent

Host: lciapi.ninthdecimal.comFired: 5536ms after load
Advertising Tracker
criticalNetworkAdvertisingAdvertising Tracker

advertising tracker at pi.ispot.tv loaded before consent

Host: pi.ispot.tvFired: 5536ms after load
DailyMotion (Advertising Tracker)
criticalNetworkAdvertisingDailyMotion (Advertising Tracker)

DailyMotion (advertising) loaded before consent

Host: public-prod-dspcookiematching.dmxleo.comFired: 5525ms after load
Zeotap (Advertising Tracker)
Zeotap (Advertising Tracker)2 findings

spl.zeotap.com, mwzeom.zeotap.com

Zeotap (Advertising Tracker)
criticalNetworkAdvertisingZeotap (Advertising Tracker)

Zeotap (advertising) loaded before consent

Host: spl.zeotap.comFired: 5525ms after load
Zeotap (Advertising Tracker)
criticalNetworkAdvertisingZeotap (Advertising Tracker)

Zeotap (advertising) loaded before consent

Host: mwzeom.zeotap.comFired: 5608ms after load
Comcast (Advertising Tracker)
criticalNetworkAdvertisingComcast (Advertising Tracker)

Comcast (advertising) loaded before consent

Host: user-sync.fwmrm.netFired: 5525ms after load
FreakOut (Advertising Tracker)
criticalNetworkAdvertisingFreakOut (Advertising Tracker)

FreakOut (advertising) loaded before consent

Host: sync.rfp.fout.jpFired: 5525ms after load
Cint (Advertising Tracker)
criticalNetworkAdvertisingCint (Advertising Tracker)

Cint (advertising) loaded before consent

Host: usersync.samplicio.usFired: 5525ms after load
Samba.tv (Advertising Tracker)
criticalNetworkAdvertisingSamba.tv (Advertising Tracker)

Samba.tv (advertising) loaded before consent

Host: ads.samba.tvFired: 5525ms after load
Magnite (Advertising Tracker)
criticalNetworkAdvertisingMagnite (Advertising Tracker)

Magnite (advertising) loaded before consent

Host: pixel.rubiconproject.comFired: 5525ms after load
Ogury (Advertising Tracker)
criticalNetworkAdvertisingOgury (Advertising Tracker)

Ogury (advertising) loaded before consent

Host: ms-cookie-sync.presage.ioFired: 5525ms after load
Adobe (Tracker Tracker)
criticalNetworkAdobe (Tracker Tracker)

Adobe (tracker) loaded before consent

Host: dpm.demdex.netFired: 5525ms after load
WPP (Advertising Tracker)
criticalNetworkAdvertisingWPP (Advertising Tracker)

WPP (advertising) loaded before consent

Host: odr.mookie1.comFired: 5525ms after load
mediarithmics (Advertising Tracker)
criticalNetworkAdvertisingmediarithmics (Advertising Tracker)

mediarithmics (advertising) loaded before consent

Host: cookie-matching.mediarithmics.comFired: 5525ms after load
Google (Tracker Tracker)
criticalNetworkGoogle (Tracker Tracker)

Google (tracker) loaded before consent

Host: cm.g.doubleclick.netFired: 5525ms after load
comScore (Analytics Tracker)
criticalNetworkAnalyticscomScore (Analytics Tracker)

comScore (analytics) loaded before consent

Host: sb.scorecardresearch.comFired: 5525ms after load
LoopMe (Advertising Tracker)
criticalNetworkAdvertisingLoopMe (Advertising Tracker)

LoopMe (advertising) loaded before consent

Host: csync.loopme.meFired: 5525ms after load
OpenX (Tracker Tracker)
criticalNetworkOpenX (Tracker Tracker)

OpenX (tracker) loaded before consent

Host: us-u.openx.netFired: 5525ms after load
TripleLift (Advertising Tracker)
criticalNetworkAdvertisingTripleLift (Advertising Tracker)

TripleLift (advertising) loaded before consent

Host: eb2.3lift.comFired: 5525ms after load
SearchForce (Advertising Tracker)
criticalNetworkAdvertisingSearchForce (Advertising Tracker)

SearchForce (advertising) loaded before consent

Host: uipglob.semasio.netFired: 5530ms after load
Kargo (Advertising Tracker)
criticalNetworkAdvertisingKargo (Advertising Tracker)

Kargo (advertising) loaded before consent

Host: crb.kargo.comFired: 5530ms after load
GumGum (Advertising Tracker)
criticalNetworkAdvertisingGumGum (Advertising Tracker)

GumGum (advertising) loaded before consent

Host: usersync.gumgum.comFired: 5531ms after load
PubMatic (Advertising Tracker)
criticalNetworkAdvertisingPubMatic (Advertising Tracker)

PubMatic (advertising) loaded before consent

Host: image2.pubmatic.comFired: 5531ms after load
Nielsen (Advertising Tracker)
criticalNetworkAdvertisingNielsen (Advertising Tracker)

Nielsen (advertising) loaded before consent

Host: loadus.exelator.comFired: 5536ms after load
Ströer Core (Advertising Tracker)
criticalNetworkAdvertisingStröer Core (Advertising Tracker)

Ströer Core (advertising) loaded before consent

Host: ih.adscale.deFired: 5536ms after load
Yieldmo (Tracker Tracker)
criticalNetworkYieldmo (Tracker Tracker)

Yieldmo (tracker) loaded before consent

Host: sync-amazon.ads.yieldmo.comFired: 5536ms after load
EXTE (Advertising Tracker)
criticalNetworkAdvertisingEXTE (Advertising Tracker)

EXTE (advertising) loaded before consent

Host: us-east-sync.richaudience.comFired: 5536ms after load
Taboola (Advertising Tracker)
criticalNetworkAdvertisingTaboola (Advertising Tracker)

Taboola (advertising) loaded before consent

Host: sync.taboola.comFired: 5536ms after load
The Trade Desk (Tracker Tracker)
criticalNetworkThe Trade Desk (Tracker Tracker)

The Trade Desk (tracker) loaded before consent

Host: match.adsrvr.orgFired: 5765ms after load
Amazon
Amazon2 findings

ad-id, ad-privacy

Amazon
criticalCookieMarketingAmazon

Amazon cookie "ad-id" set before consent — Clickthroughs to Amazon websites: Noting how the user got to Amazon via this website

Cookie: ad-idDomain: .amazon-adsystem.comRetention: 190 days
Amazon
criticalCookieMarketingAmazon

Amazon cookie "ad-privacy" set before consent — Provided by amazon-adsystem.com for tracking user actions on other websites to provide targeted content to the users.

Cookie: ad-privacyDomain: .amazon-adsystem.comRetention: 5 years
criticalCookieMarketingPlatform161

Platform161 cookie "tuuid" set before consent — Unique value to identify individual users.

Cookie: tuuidDomain: .bidswitch.netRetention: 13 months
Adform
criticalCookieMarketingAdform

Adform cookie "c" set before consent — Used to determine if browser of user accepts cookies or not

Cookie: cDomain: .bidswitch.netRetention: 60 days till 3650 days
criticalCookieMarketingbidswitch.net

bidswitch.net cookie "tuuid_lu" set before consent — Contains a unique visitor ID, which allows Bidswitch.com to track the visitor across multiple websites. This allows Bidswitch to optimize advertisement relevance and ensure that the visitor does not see the same ads multiple times.

Cookie: tuuid_luDomain: .bidswitch.netRetention: 3 months
Casale Media3 findings

CMID, CMPS, CMPRO

criticalCookieMarketingCasale Media

Casale Media cookie "CMID" set before consent — Collects visitor data related to the user's visits to the website, such as the number of visits, average time spent on the website and what pages have been loaded, with the purpose of displaying targeted ads.

Cookie: CMIDDomain: .casalemedia.comRetention: 1 day
criticalCookieMarketingCasale Media

Casale Media cookie "CMPS" set before consent — Collects visitor data related to the user's visits to the website, such as the number of visits, average time spent on the website and what pages have been loaded, with the purpose of displaying targeted ads

Cookie: CMPSDomain: .casalemedia.comRetention: 1 day
criticalCookieMarketingCasale Media

Casale Media cookie "CMPRO" set before consent — Collects data on visitor behaviour from multiple websites, in order to present more relevant advertisement - This also allows the website to limit the number of times that the visitor is shown the same advertisement.

Cookie: CMPRODomain: .casalemedia.comRetention: 1 day
ComScore
criticalCookieMarketingComScore

ComScore cookie "pid" set before consent — Collects a code that identifies the specific website or advertiser participating in the ScorecardResearch data collection program.

Cookie: pidDomain: .smartadserver.comRetention: 1 year
Smartadserver
Smartadserver2 findings

TestIfCookieP, csync

Smartadserver
criticalCookieMarketingSmartadserver

Smartadserver cookie "TestIfCookieP" set before consent — Technical cookie used to test if persistent cookies are accepted

Cookie: TestIfCookiePDomain: .smartadserver.comRetention: 13 months
Smartadserver
criticalCookieMarketingSmartadserver

Smartadserver cookie "csync" set before consent — Optimises ad display based on the user's movement combined and various advertiser bids for displaying user ads.

Cookie: csyncDomain: .smartadserver.comRetention: 1 day
criticalCookieMarketingNativo

Nativo cookie "opt_out" set before consent — This cookie is used to remember not to serve that user targeted Ads if they opt out.

Cookie: opt_outDomain: .postrelease.comRetention: 1 year
criticalCookieMarketingZeotap

Zeotap cookie "zc" set before consent — Registers data on visitors from multiple visits and on multiple websites. This information is used to measure the efficiency of advertisement on websites.

Cookie: zcDomain: .zeotap.comRetention: 10 years
criticalCookieMarketingcsync.loopme.me

csync.loopme.me cookie "viewer_token" set before consent — This cookie is associated with csync.loopme.me. It is used to track visitors on multiple websites in order to present relevant advertising based on the visitor's preferences.

Cookie: viewer_tokenDomain: .csync.loopme.meRetention: 31 days
openx.net
openx.net2 findings

i, pd

openx.net
criticalCookieMarketingopenx.net

openx.net cookie "i" set before consent — Registers user data, such as IP address, geographical location, websites visited and on which advertisements the user has clicked, with the aim of optimizing the display of advertisements based on user relocation on websites that use the same advertising network.

Cookie: iDomain: .openx.netRetention: 1 year
openx.net
criticalCookieMarketingopenx.net

openx.net cookie "pd" set before consent — This cookie stores information about which other third parties the user cookie (‘i’ cookie) has been synced with to reduce the amount of user matching done on your device.

Cookie: pdDomain: .openx.netRetention: 15 days
DoubleClick/Google Marketing
DoubleClick/Google Marketing2 findings

IDE, id

DoubleClick/Google Marketing
criticalCookieMarketingDoubleClick/Google Marketing

DoubleClick/Google Marketing cookie "IDE" set before consent — This cookie is used for targeting, analyzing and optimisation of ad campaigns in DoubleClick/Google Marketing Suite

Cookie: IDEDomain: .doubleclick.netRetention: 2 years
DoubleClick/Google Marketing
criticalCookieMarketingDoubleClick/Google Marketing

DoubleClick/Google Marketing cookie "id" set before consent — This cookie is used for targeting, analyzing and optimisation of ad campaigns in DoubleClick/Google Marketing Suite

Cookie: idDomain: .mookie1.comRetention: 2 months
Neustar
criticalCookieMarketingNeustar

Neustar cookie "ab" set before consent — This cookie is used by the website’s operator in context with multi-variate testing. This is a tool used to combine or change content on the website. This allows the website to find the best variation/edition of the site.

Cookie: abDomain: .agkn.comRetention: 1 year
criticalCookieMarketingsemasio.net

semasio.net cookie "SEUNCY" set before consent — Registers a unique ID that identifies the user’s device for return visits.

Cookie: SEUNCYDomain: .semasio.netRetention: 179 days
criticalCookieMarketingGumGum

GumGum cookie "vst" set before consent — Used to store the user user intereset

Cookie: vstDomain: .gumgum.comRetention: 1 year
adscale.de3 findings

uu, tu, cct

criticalCookieMarketingadscale.de

adscale.de cookie "uu" set before consent — Used to target ads by registering the user's movements across websites.

Cookie: uuDomain: .adscale.deRetention: 1 year
criticalCookieMarketingadscale.de

adscale.de cookie "tu" set before consent — Used to target ads by registering the user's movements across websites.

Cookie: tuDomain: .ih.adscale.deRetention: 29 days
criticalCookieMarketingadscale.de

adscale.de cookie "cct" set before consent — Necessary for the shopping cart functionality on the website

Cookie: cctDomain: .adscale.deRetention: session
Adobe Audience Manager
Adobe Audience Manager2 findings

demdex, dpm

Adobe Audience Manager
criticalCookieMarketingAdobe Audience Manager

Adobe Audience Manager cookie "demdex" set before consent — Unique value with which Audience Manager can identify a user. Used, among others, for identification, segmentation, modeling and reporting purposes.

Cookie: demdexDomain: .demdex.netRetention: 180 days after last activity or 10 years when opting out
Adobe Audience Manager
criticalCookieMarketingAdobe Audience Manager

Adobe Audience Manager cookie "dpm" set before consent — DPM is an abbreviation for Data Provider Match. It tells internal, Adobe systems that a call from Audience Manager or the Adobe Experience Cloud ID Service is passing in customer data for synchronization or requesting an ID.

Cookie: dpmDomain: .dpm.demdex.netRetention: 180 days
criticalNetwork

No consent banner detected — all cookies and tags fire without user consent

criticalConsent

No "reject all" option found — users cannot refuse non-essential cookies (ICO guidance requires this)

criticalConsent Record

No recognizable consent cookie or storage entry detected after interaction — GDPR Article 7(1) requires controllers to demonstrate consent was given (server-side storage cannot be verified)

criticalConsent Record

No recognizable consent withdrawal mechanism detected — GDPR Article 7(3) requires users can withdraw consent as easily as giving it (cookie settings link or floating button expected)

Warnings9
vendor logo
warningNetwork

Unknown third-party request to 1c5c1ecf7303.535706ac.eu-west-1.token.awswaf.com before consent

Host: 1c5c1ecf7303.535706ac.eu-west-1.token.awswaf.comFired: 334ms after load
vendor logo
warningNetwork

Unknown third-party request to geo.ads.audio.thisisdax.com before consent

Host: geo.ads.audio.thisisdax.comFired: 5525ms after load
warningStorage

localStorage key "csm-hit" written before consent

Key: csm-hitType: localStorageFired: 3087ms after load
warningStorage

sessionStorage key "csmtid" written before consent

Key: csmtidType: sessionStorageFired: 4038ms after load
warningStorage

sessionStorage key "CSM_previousURL" written before consent

Key: CSM_previousURLType: sessionStorageFired: 4042ms after load
warningStorage

localStorage key "csm:adb" written before consent

Key: csm:adbType: localStorageFired: 4223ms after load
warningStorage

localStorage key "a-font-class" written before consent

Key: a-font-classType: localStorageFired: 4289ms after load
warningStorage

sessionStorage key "eelsts" written before consent

Key: eelstsType: sessionStorageFired: 5264ms after load
warningStorage

localStorage key "puff:suppression" written before consent

Key: puff:suppressionType: localStorageFired: 5850ms after load
Info3
Amazon (Cdn)
Amazon (Cdn)2 findings

m.media-amazon.com, a0c6d9c7a936b604bff3c0764992c2b33.profile.fco50-p1.cloudfront.net

Amazon (Cdn)
infoNetworkAmazon (Cdn)

Amazon (cdn) loaded before consent

Host: m.media-amazon.comFired: 3021ms after load
Amazon (Cdn)
infoNetworkAmazon (Cdn)

Amazon (cdn) loaded before consent

Host: a0c6d9c7a936b604bff3c0764992c2b33.profile.fco50-p1.cloudfront.netFired: 6970ms after load
Yahoo! (Cdn)
infoNetworkYahoo! (Cdn)

Yahoo! (cdn) loaded before consent

Host: pbs.yahoo.comFired: 5524ms after load

Is this your site?

Run a full multi-page scan with monitoring and get detailed remediation steps

Scan amazon.com

This audit is based on publicly observable website behavior. To request removal from the index, email support@tagleak.com