https://bloomingdales.com
Scanned Apr 17, 2026 · 41.7s
Your website score is
Grade
BannerConsent Banner
Yes
Regulatory Compliance
Multi-regulation overview — click any regulation for details
Technical scan only. A passing score does not equal legal compliance. Consult qualified legal counsel for your jurisdiction.
Tag Leak detected 218 user data leaks before consent on bloomingdales.com, including Tealium (Tracker Tracker), Akamai (Analytics Tracker), GA4 and 54 more.
Security Headers
4/6 presentStrict-Transport-Security
max-age=31536000
Content-Security-Policy
upgrade-insecure-requests;
X-Frame-Options
SAMEORIGIN
X-Content-Type-Options
nosniff
Referrer-Policy
Set a Referrer-Policy header to control how much referrer information is shared
Permissions-Policy
Add a Permissions-Policy header to restrict browser features like camera, microphone, and geolocation
Google Consent Mode
Not DetectedGoogle Consent Mode v2 was not found on this page. GCM v2 allows Google's tags to adjust their behavior based on user consent, and is required for compliant advertising measurement in the EU. Without it, your Google Ads and GA4 conversions may be impacted after consent is declined.
Post-Rejection Audit
Reject Button
Found
Post-Rejection Fires
8 vendors
Consent Mode
Not Detected
GTM Load
Not detected
Consent Mode V2: Not Detected
Google Consent Mode was not detected on this site.
Vendors firing after rejection (8)
| Vendor | Category | Timing | URL |
|---|---|---|---|
| Meta — Meta Pixel | advertising | 20429ms | www.facebook.com |
| Pinterest — Pinterest Tag | advertising | 20568ms | ct.pinterest.com |
| Criteo — Criteo | advertising | 20744ms | dis.criteo.com |
| Google — Google Ads | advertising | 20829ms | pagead2.googlesyndication.com |
| FullStory — FullStory | analytics | 20942ms | edge.fullstory.com |
| New Relic — New Relic | analytics | 21305ms | js-agent.newrelic.com |
| New Relic — New Relic | analytics | 21378ms | bam.nr-data.net |
| TikTok — TikTok Pixel | advertising | 27898ms | analytics.tiktok.com |
Consent Record Audit
PassConsent record stored after interaction
GDPR Art. 7(1)Found: OptanonConsent (OneTrust)
Record contains timestamp
Art. 7(1)Timestamp field detected
Record contains consent state
Art. 7(1)Accept/reject state detected
Record contains consent categories
Art. 7(1)Consent categories (analytics, marketing, etc.) not found in record
Consent withdrawal mechanism accessible
GDPR Art. 7(3)Cookie settings link / floating button found
Tracker categories detected
Critical143
Data was transmitted to a third-party or storage was written on the user’s device before consent. This is a GDPR/ePrivacy violation, not just a script load.
TikTok Pixel7 findingsID trackedanalytics.tiktok.com, analytics-ipv6.tiktokw.us, _ttp, _tt_enable_cookie, tt_sessionId, tt_appInfo, tt_pixel_session_index

analytics.tiktok.com, analytics-ipv6.tiktokw.us, _ttp, _tt_enable_cookie, tt_sessionId, tt_appInfo, tt_pixel_session_index

TikTok Pixel (TikTok) loaded before consent: Sends event data to TikTok for ad measurement

TikTok Pixel (TikTok) loaded before consent: TikTok Pixel IPv6 enrichment and data collection

TikTok Pixel cookie "_ttp" set before consent

TikTok Pixel cookie "_tt_enable_cookie" set before consent

TikTok Pixel (TikTok) wrote "tt_sessionId" to sessionStorage before consent

TikTok Pixel (TikTok) wrote "tt_appInfo" to sessionStorage before consent

TikTok Pixel (TikTok) wrote "tt_pixel_session_index" to sessionStorage before consent
Criteo (Advertising Tracker)6 findingsID trackeddynamic.criteo.com, d.criteo.com, sslwidget.criteo.com, widget.us.criteo.com, gum.criteo.com, x.bidswitch.net

dynamic.criteo.com, d.criteo.com, sslwidget.criteo.com, widget.us.criteo.com, gum.criteo.com, x.bidswitch.net

Criteo (advertising) loaded before consent

Criteo (advertising) loaded before consent

Criteo (advertising) loaded before consent

Criteo (advertising) loaded before consent

Criteo (advertising) loaded before consent

Criteo (advertising) loaded before consent
Pinterest Tag3 findingsID trackedct.pinterest.com, s.pinimg.com, _pin_unauth
ct.pinterest.com, s.pinimg.com, _pin_unauth
Pinterest Tag (Pinterest) loaded before consent: Pinterest conversion tracking
Pinterest Tag (Pinterest) loaded before consent: Pinterest tag script loader
Pinterest Tag cookie "_pin_unauth" set before consent
Meta Pixel3 findingsID trackedwww.facebook.com, connect.facebook.net, _fbp

www.facebook.com, connect.facebook.net, _fbp

Meta Pixel (Meta) loaded before consent: Meta Pixel tracking endpoint

Meta Pixel (Meta) loaded before consent: Sends user data to Meta for ad targeting and conversion tracking

Meta Pixel cookie "_fbp" set before consent
Google Analytics4 findingsID trackedregion1.analytics.google.com, www.googletagmanager.com, _ga_GPE5H9XF96, _ga

region1.analytics.google.com, www.googletagmanager.com, _ga_GPE5H9XF96, _ga

GA4 (Google) loaded before consent: Sends pageview and event data to Google Analytics

GA4 (Google) loaded before consent: Google Analytics gtag.js library

Google Analytics cookie "_ga_GPE5H9XF96" set before consent

Google Analytics cookie "_ga" set before consent
Google (Tracker Tracker)7 findingsID trackedstats.g.doubleclick.net, ad.doubleclick.net, 2408678.fls.doubleclick.net, adservice.google.com, 10725945.fls.doubleclick.net, securepubads.g.doubleclick.net, cm.g.doubleclick.net
stats.g.doubleclick.net, ad.doubleclick.net, 2408678.fls.doubleclick.net, adservice.google.com, 10725945.fls.doubleclick.net, securepubads.g.doubleclick.net, cm.g.doubleclick.net
Google (tracker) loaded before consent
Google (tracker) loaded before consent
Google (tracker) loaded before consent
Google (tracker) loaded before consent
Google (tracker) loaded before consent
Google (tracker) loaded before consent
Google (tracker) loaded before consent
Tealium (tracker) loaded before consent
Akamai (Analytics Tracker)2 findingss.go-mpulse.net, c.go-mpulse.net
s.go-mpulse.net, c.go-mpulse.net
Akamai (analytics) loaded before consent
Akamai (analytics) loaded before consent
Adobe (Tracker Tracker)2 findingsadobedc.demdex.net, dpm.demdex.net

adobedc.demdex.net, dpm.demdex.net

Adobe (tracker) loaded before consent

Adobe (tracker) loaded before consent
Google Ads7 findingswww.google.com, www.googleadservices.com, googleads.g.doubleclick.net, pagead2.googlesyndication.com, 549b5655dec66a5e2501ddc9b3fa181c.safeframe.googlesyndication.com, _gcl_au, _gcl_ls

www.google.com, www.googleadservices.com, googleads.g.doubleclick.net, pagead2.googlesyndication.com, 549b5655dec66a5e2501ddc9b3fa181c.safeframe.googlesyndication.com, _gcl_au, _gcl_ls

Google Ads (Google) loaded before consent: Google Consent Mode data collection for ad measurement

Google Ads (Google) loaded before consent: Google Ads conversion tracking

Google Ads (Google) loaded before consent: Sends conversion data to Google Ads

Google Ads (Google) loaded before consent: Google ad syndication and remarketing

Google Ads (Google) loaded before consent: Google ad syndication and remarketing

Google Ads cookie "_gcl_au" set before consent

Google Ads (Google) wrote "_gcl_ls" to localStorage before consent
Bluecore (Advertising Tracker)3 findingsapi.bluecore.com, onsitestats.bluecore.com, siteassets.bluecore.com
api.bluecore.com, onsitestats.bluecore.com, siteassets.bluecore.com
Bluecore (advertising) loaded before consent
Bluecore (advertising) loaded before consent
Bluecore (advertising) loaded before consent
Snapchat Pixel4 findingssc-static.net, tr.snapchat.com, _scid, _scid_r
sc-static.net, tr.snapchat.com, _scid, _scid_r
Snapchat Pixel (Snapchat) loaded before consent: Loads Snapchat conversion tracking script
Snapchat Pixel (Snapchat) loaded before consent: Snapchat pixel tracking endpoint
Snapchat Pixel cookie "_scid" set before consent
Snapchat Pixel cookie "_scid_r" set before consent
FullStory5 findingsedge.fullstory.com, rs.fullstory.com, fs_uid, _fs_sample_user_h, _fs_tab_id
edge.fullstory.com, rs.fullstory.com, fs_uid, _fs_sample_user_h, _fs_tab_id
FullStory (FullStory) loaded before consent: FullStory session recording and digital experience analytics
FullStory (FullStory) loaded before consent: FullStory session recording and digital experience analytics
FullStory cookie "fs_uid" set before consent
FullStory (FullStory) wrote "_fs_sample_user_h" to localStorage before consent
FullStory (FullStory) wrote "_fs_tab_id" to sessionStorage before consent
Advertising Tracker6 findingstrack.coherentpath.com, js.clrt.ai, trk.clinch.co, d1n00d49gkbray.cloudfront.net, tr6.snapchat.com, cs.media.net
track.coherentpath.com, js.clrt.ai, trk.clinch.co, d1n00d49gkbray.cloudfront.net, tr6.snapchat.com, cs.media.net
advertising tracker at track.coherentpath.com loaded before consent
advertising tracker at js.clrt.ai loaded before consent
advertising tracker at trk.clinch.co loaded before consent
advertising tracker at d1n00d49gkbray.cloudfront.net loaded before consent
advertising tracker at tr6.snapchat.com loaded before consent
advertising tracker at cs.media.net loaded before consent
Adobe Analytics2 findingsedge.adobedc.net, AMCV_8D0867C25245AE650A490D4C%40AdobeOrg

edge.adobedc.net, AMCV_8D0867C25245AE650A490D4C%40AdobeOrg

Adobe Analytics (Adobe) loaded before consent: Adobe Analytics data collection

Adobe Analytics cookie "AMCV_8D0867C25245AE650A490D4C%40AdobeOrg" set before consent
TransUnion (tracker) loaded before consent
STG (advertising) loaded before consent
Medallia (analytics) loaded before consent
Rakuten (Advertising Tracker)2 findingsintljs.rmtag.com, consent.linksynergy.com
intljs.rmtag.com, consent.linksynergy.com
Rakuten (advertising) loaded before consent
Rakuten (advertising) loaded before consent
Skai (advertising) loaded before consent
PebblePost (advertising) loaded before consent
Taboola4 findingscdn.taboola.com, trc.taboola.com, taboola_session_id, t_gid
cdn.taboola.com, trc.taboola.com, taboola_session_id, t_gid
Taboola (Taboola) loaded before consent: Taboola content recommendation and native advertising
Taboola (Taboola) loaded before consent: Taboola tracking and recommendation endpoint
Taboola cookie "taboola_session_id" set before consent — Creates a temporary session ID to avoid the display of duplicate recommendations on the page.
Taboola cookie "t_gid" set before consent — This Partitioned cookie gives a user who interacts with Taboola Widget a User ID allowing us to target advertisements and content to this specific user ID.
Dentsu (advertising) loaded before consent
Microsoft Ads3 findingsbat.bing.com, _uetsid, _uetvid

bat.bing.com, _uetsid, _uetvid

Microsoft Ads (Microsoft) loaded before consent: Microsoft Ads (Bing) UET conversion tracking

Microsoft Ads cookie "_uetsid" set before consent

Microsoft Ads cookie "_uetvid" set before consent
Tealium (Analytics Tracker)2 findingscollect.tealiumiq.com, datacloud.tealiumiq.com
collect.tealiumiq.com, datacloud.tealiumiq.com
Tealium (analytics) loaded before consent
Tealium (analytics) loaded before consent
Dynatrace (analytics) loaded before consent
ZetaGlobal (Advertising Tracker)4 findingsd-code.liadm.com, idx.liadm.com, i.liadm.com, rp.liadm.com
d-code.liadm.com, idx.liadm.com, i.liadm.com, rp.liadm.com
ZetaGlobal (advertising) loaded before consent
ZetaGlobal (advertising) loaded before consent
ZetaGlobal (advertising) loaded before consent
ZetaGlobal (advertising) loaded before consent
ID5 (Advertising Tracker)4 findingscdn.id5-sync.com, id5-sync.com, lbs.eu-1-id5-sync.com, lb.eu-1-id5-sync.com
cdn.id5-sync.com, id5-sync.com, lbs.eu-1-id5-sync.com, lb.eu-1-id5-sync.com
ID5 (advertising) loaded before consent
ID5 (advertising) loaded before consent
ID5 (advertising) loaded before consent
ID5 (advertising) loaded before consent
Tapad (tracker) loaded before consent
Taboola (Advertising Tracker)3 findingspips.taboola.com, cds.taboola.com, sync-t1.taboola.com
pips.taboola.com, cds.taboola.com, sync-t1.taboola.com
Taboola (advertising) loaded before consent
Taboola (advertising) loaded before consent
Taboola (advertising) loaded before consent
Google (Advertising Tracker)2 findingsep1.adtrafficquality.google, ep2.adtrafficquality.google
ep1.adtrafficquality.google, ep2.adtrafficquality.google
Google (advertising) loaded before consent
Google (advertising) loaded before consent
PubMatic (Advertising Tracker)2 findingssimage4.pubmatic.com, simage2.pubmatic.com
simage4.pubmatic.com, simage2.pubmatic.com
PubMatic (advertising) loaded before consent
PubMatic (advertising) loaded before consent
IndexExchange (advertising) loaded before consent
Azerion (advertising) loaded before consent
Mediavine (advertising) loaded before consent
Life360 (advertising) loaded before consent
Teads (Advertising Tracker)2 findingssync.outbrain.com, criteo-sync.teads.tv
sync.outbrain.com, criteo-sync.teads.tv
Teads (advertising) loaded before consent
Teads (advertising) loaded before consent
Equativ (advertising) loaded before consent
Nexxen (Advertising Tracker)2 findingscriteo-partners.tremorhub.com, sync.1rx.io
criteo-partners.tremorhub.com, sync.1rx.io
Nexxen (advertising) loaded before consent
Nexxen (advertising) loaded before consent
TripleLift (advertising) loaded before consent
VirtualMinds (advertising) loaded before consent
Criteo2 findingsdis.criteo.com, cto_bundle

dis.criteo.com, cto_bundle

Criteo (Criteo) loaded before consent: Criteo display ad delivery endpoint

Criteo cookie "cto_bundle" set before consent
LiveIntent2 findings_li_ss, lidid
_li_ss, lidid
LiveIntent cookie "_li_ss" set before consent — Sets a unique ID for the visitor, that allows third party advertisers to target the visitor with relevant advertisement. This pairing service is provided by third party advertisement hubs, which facilitates real-time bidding for advertisers.
LiveIntent cookie "lidid" set before consent — Collects data on visitors' behaviour and interaction - This is used to make advertisement on the website more relevant. The cookie also allows the website to detect any referrals from other websites.
Dynatrace5 findingsrxVisitor, dtPC, dtSa, dtCookie, rxvt
rxVisitor, dtPC, dtSa, dtCookie, rxvt
Dynatrace cookie "rxVisitor" set before consent — This cookie is used by RUM API, Dynatrace Real User Monitoring (RUM) gives you the power to know your customers by providing performance analysis in real time.
Dynatrace cookie "dtPC" set before consent — This cookie is used by RUM API, Dynatrace Real User Monitoring (RUM) gives you the power to know your customers by providing performance analysis in real time.
Dynatrace cookie "dtSa" set before consent — This cookie is used by RUM API, Dynatrace Real User Monitoring (RUM) gives you the power to know your customers by providing performance analysis in real time.
Dynatrace cookie "dtCookie" set before consent — This cookie is used by RUM API, Dynatrace Real User Monitoring (RUM) gives you the power to know your customers by providing performance analysis in real time.
Dynatrace cookie "rxvt" set before consent — This cookie is used by RUM API, Dynatrace Real User Monitoring (RUM) gives you the power to know your customers by providing performance analysis in real time.

Adobe Audience Manager cookie "demdex" set before consent — Unique value with which Audience Manager can identify a user. Used, among others, for identification, segmentation, modeling and reporting purposes.
DoubleClick/Google Marketing2 findingsIDE, ar_debug

IDE, ar_debug

DoubleClick/Google Marketing cookie "IDE" set before consent — This cookie is used for targeting, analyzing and optimisation of ad campaigns in DoubleClick/Google Marketing Suite

DoubleClick/Google Marketing cookie "ar_debug" set before consent — Store and track conversions
Mixpanel cookie "mp_bloomingdales_mixpanel" set before consent

Adform cookie "uid" set before consent — Contains a unique ID to identify a user
Tapad3 findingsTapAd_TS, TapAd_DID, TapAd_3WAY_SYNCS
TapAd_TS, TapAd_DID, TapAd_3WAY_SYNCS
Tapad cookie "TapAd_TS" set before consent — Used to determine what type of devices (smartphones, tablets, computers, TVs etc.) is used by a user.
Tapad cookie "TapAd_DID" set before consent — Used to determine what type of devices (smartphones, tablets, computers, TVs etc.) is used by a user.
Tapad cookie "TapAd_3WAY_SYNCS" set before consent — Used for data-synchronization with advertisement networks
TikTok2 findingsttcsid, ttcsid_CCQ62ERC77U6NJS8KG80

ttcsid, ttcsid_CCQ62ERC77U6NJS8KG80

TikTok cookie "ttcsid" set before consent — The TikTok cookie ttcsid likely serves as a session identifier, helping to maintain user sessions and track interactions across the platform. Its purpose is probably to manage user authentication or personalize content based on activity, similar to other session-related cookies used by TikTok.

TikTok cookie "ttcsid_CCQ62ERC77U6NJS8KG80" set before consent — The TikTok cookie ttcsid likely serves as a session identifier, helping to maintain user sessions and track interactions across the platform. Its purpose is probably to manage user authentication or personalize content based on activity, similar to other session-related cookies used by TikTok.

Bing / Microsoft cookie "MUID" set before consent — Identifies unique web browsers visiting Microsoft sites. These cookies are used for advertising, site analytics, and other operational purposes.
ID5 cookie "id5" set before consent — Sets a unique ID for the visitor, that allows third party advertisers to target the visitor with relevant advertisement. This pairing service is provided by third party advertisement hubs, which facilitates real-time bidding for advertisers.
PubMatic2 findingsKADUSERCOOKIE, SPugT
KADUSERCOOKIE, SPugT
PubMatic cookie "KADUSERCOOKIE" set before consent — PubMatic UserId. this identifier to identify each user uniquely. Some of the uses of this anonymous identifier are to support frequency capping, perform UID sync ups with DSP's, DMP's. DMP's / DP's push audicne data against this ID. API publishers sends this ID while making API requests to PubMatic AdServer. UAS Ad Engine also uses this cookie for FCAP purposes.
PubMatic cookie "SPugT" set before consent — This cookie is used to track when the server-side cookie store was last updated for the browser, and it is used in conjunction with the PugT cookie, described below.
Casale Media3 findingsCMID, CMPS, CMPRO
CMID, CMPS, CMPRO
Casale Media cookie "CMID" set before consent — Collects visitor data related to the user's visits to the website, such as the number of visits, average time spent on the website and what pages have been loaded, with the purpose of displaying targeted ads.
Casale Media cookie "CMPS" set before consent — Collects visitor data related to the user's visits to the website, such as the number of visits, average time spent on the website and what pages have been loaded, with the purpose of displaying targeted ads
Casale Media cookie "CMPRO" set before consent — Collects data on visitor behaviour from multiple websites, in order to present more relevant advertisement - This also allows the website to limit the number of times that the visitor is shown the same advertisement.
MediaVine2 findingsmv_tokens, am_tokens
mv_tokens, am_tokens
MediaVine cookie "mv_tokens" set before consent — Sets a unique ID for the visitor that allows third party advertisers to target the visitor with relevant advertisement. This pairing service is provided by third party advertisement hubs which facilitates real-time bidding for advertisers.
MediaVine cookie "am_tokens" set before consent — Presents the user with relevant content and advertisement. The service is provided by third-party advertisement hubs which facilitate real-time bidding for advertisers.
Outbrain cookie "criteo" set before consent — This cookie is set by Outbrain and it is used to analyse technical data about the website

Meta — Meta Pixel fires after user rejected consent
Pinterest — Pinterest Tag fires after user rejected consent

Criteo — Criteo fires after user rejected consent

Google — Google Ads fires after user rejected consent
FullStory — FullStory fires after user rejected consent
New Relic — New Relic fires after user rejected consent

TikTok — TikTok Pixel fires after user rejected consent
Warnings82
A tag container or script loaded before consent but tags appear correctly gated (e.g. GTM with Consent Mode v2). Not a violation on its own — review to confirm downstream tags stay blocked.
Unknown third-party request to assets.bloomingdalesassets.com before consent
Unknown third-party request to images.bloomingdalesassets.com before consent
Unknown third-party request to cdn1.adoberesources.net before consent
Unknown third-party request to cdn.mgln.ai before consent
Unknown third-party request to www.google.com before consent
Unknown third-party request to cdn.clinch.co before consent
Unknown third-party request to widgets.stores-bloomingdales.com before consent
Unknown third-party request to 83436613-prod.rfksrv.com before consent
Unknown third-party request to mgln.ai before consent
Unknown third-party request to product-initjs.prod.rfksrv.com before consent
Unknown third-party request to js.cnnx.link before consent
Unknown third-party request to eu.mgln.ai before consent
Unknown third-party request to prod-east-alweb-mt.rfksrv.com before consent
localStorage key "_boomr_clss" written before consent
sessionStorage key "rxVisitor" written before consent
sessionStorage key "rxvisitid" written before consent
sessionStorage key "rxvt" written before consent
sessionStorage key "dtSa" written before consent
localStorage key "dummy" written before consent
localStorage key "ak_a" written before consent
sessionStorage key "com.adobe.alloy.8D0867C25245AE650A490D4C@AdobeOrgclickData" written before consent
localStorage key "LastSearches" written before consent
localStorage key "__akfp_storage_test__" written before consent
sessionStorage key "correlationIDs" written before consent
localStorage key "commonstorelocation" written before consent
localStorage key "__bc_persist_ls_test__" written before consent
localStorage key "bc_persist_props" written before consent
localStorage key "bluecoreSessionData" written before consent
localStorage key "u_sclid" written before consent
sessionStorage key "u_scsid" written before consent
localStorage key "u_sclid_r" written before consent
sessionStorage key "u_scsid_r" written before consent
localStorage key "lscache-__lscachetest__" written before consent
localStorage key "lscache-cacheBustKey" written before consent
localStorage key "lscache-cacheBustKey-cacheexpiration" written before consent
localStorage key "tealium_timing" written before consent
localStorage key "signal_testlocalstorage" written before consent
sessionStorage key "signal_testsessionstorage" written before consent
localStorage key "lastExternalReferrer" written before consent
localStorage key "signal_browserId" written before consent
localStorage key "signal_sessionId" written before consent
localStorage key "storage_test" written before consent
localStorage key "_mibhv" written before consent
localStorage key "criteo_localstorage_check" written before consent
localStorage key "rm_storage_test_34202261690029656" written before consent
localStorage key "rm_storage_test_6653411127042304" written before consent
localStorage key "rm_storage_test_8524790385437735" written before consent
localStorage key "rm_storage_test_30055136933470983" written before consent
localStorage key "rm_storage_test_02653946170564392" written before consent
localStorage key "rm_storage_test_10511779115853026" written before consent
localStorage key "rm_storage_test_3594168756546062" written before consent
localStorage key "rm_storage_test_8545876882501208" written before consent
localStorage key "__rmco" written before consent
localStorage key "rm_storage_test_6870566239243419" written before consent
localStorage key "rm_storage_test_19462615401810102" written before consent
localStorage key "rm_storage_test_8750407239816168" written before consent
localStorage key "rm_storage_test_5008766800032655" written before consent
sessionStorage key "ExpMetaData" written before consent
sessionStorage key "ExpTagsFired" written before consent
localStorage key "io_temp" written before consent
localStorage key "taboolaStorageDetection" written before consent
localStorage key "_taboolaStorageDetection" written before consent
localStorage key "eng_mt" written before consent
localStorage key "tealium_criteo_userid_sync" written before consent
localStorage key "rm_storage_test_871078913898089" written before consent
localStorage key "rm_storage_test_14140473382413943" written before consent
localStorage key "rm_storage_test_4760203633772424" written before consent
localStorage key "rm_storage_test_421066510093449" written before consent
localStorage key "rm_storage_test_29994861624234703" written before consent
localStorage key "0.7502730140362251" written before consent
localStorage key "_li_duid" written before consent
localStorage key "_uetsid" written before consent
localStorage key "_uetsid_exp" written before consent
localStorage key "_uetvid" written before consent
localStorage key "_uetvid_exp" written before consent
localStorage key "taboola global:user-id" written before consent
localStorage key "1722373:session-data" written before consent
localStorage key "cto_bundle" written before consent
localStorage key "_li_ss" written before consent
sessionStorage key "bluecoreSiteFirstVisit" written before consent
localStorage key "criteo-id5id-fast-track" written before consent
sessionStorage key "dtCookie" written before consent
Info12
Neutral observations — activity we detected that isn’t a violation but is useful context (e.g. essential cookies, CMP initialisation).
OneTrust2 findingscdn.cookielaw.org, OptanonConsent

cdn.cookielaw.org, OptanonConsent

OneTrust (OneTrust) loaded before consent: OneTrust cookie consent management

OneTrust cookie "OptanonConsent" set before consent
Dynatrace (cdn) loaded before consent

OneTrust CMP (OneTrust) loaded before consent: OneTrust geo-lookup — determines which consent banner to show based on user location
Google (cdn) loaded before consent
Snapchat cookie "X-AB" set before consent — This cookie is used by the website’s operator in context with multi-variate testing. This is a tool used to combine or change content on the website. This allows the website to find the best variation/edition of the site.
Google cookie "GCLB" set before consent — This cookie is used in context with load balancing - This optimizes the response rate between the visitor and the site, by distributing the traffic load on multiple network links or servers.
Tripadvisor cookie "RT" set before consent — This cookie is used to identify the visitor through an application. This allows the visitor to login to a website through their LinkedIn application for example.
Taboola cookie "t_pt_gid" set before consent — Assigns a unique User ID that Taboola uses for attribution and reporting purposes, and to tailor recommendations to this specific user.
Akamai bot manager — necessary for site protection
Akamai bot management session — necessary for site protection
Akamai bot management — necessary for site protection
Compliant12
Tags that fired only after the user gave consent — working as intended.
ComScore cookie "pid" set correctly after consent
Smartadserver2 findingsTestIfCookieP, csync
TestIfCookieP, csync
Smartadserver cookie "TestIfCookieP" set correctly after consent
Smartadserver cookie "csync" set correctly after consent
Nativo cookie "opt_out" set correctly after consent
Media.net3 findingsvisitor-id, data-c, data-c-ts
visitor-id, data-c, data-c-ts
Media.net cookie "visitor-id" set correctly after consent
Media.net cookie "data-c" set correctly after consent
Media.net cookie "data-c-ts" set correctly after consent
Magnite2 findingstvid, tv_UICR
tvid, tv_UICR
Magnite cookie "tvid" set correctly after consent
Magnite cookie "tv_UICR" set correctly after consent

Adobe Audience Manager cookie "dpm" set correctly after consent
Neustar cookie "ab" set correctly after consent

OneTrust cookie "OptanonAlertBoxClosed" set correctly after consent
Is this your site?
Run a full multi-page scan with monitoring and get detailed remediation steps
Scan bloomingdales.com →This audit is based on publicly observable website behavior. To request removal from the index, email support@tagleak.com