https://faceit.com
Scanned Apr 17, 2026 · 38.5s
Your website score is
Grade
BannerConsent Banner
Yes
Regulatory Compliance
Multi-regulation overview — click any regulation for details
Technical scan only. A passing score does not equal legal compliance. Consult qualified legal counsel for your jurisdiction.
Tag Leak detected 63 user data leaks before consent on faceit.com, including Advertising Tracker, Google (Tracker Tracker), Google Ads and 10 more.
Security Headers
1/6 presentStrict-Transport-Security
Add HSTS header to enforce HTTPS connections and prevent downgrade attacks
Content-Security-Policy
frame-ancestors 'none';
X-Frame-Options
Add X-Frame-Options header to prevent clickjacking attacks
X-Content-Type-Options
Set X-Content-Type-Options to 'nosniff' to prevent MIME type sniffing
Referrer-Policy
Set a Referrer-Policy header to control how much referrer information is shared
Permissions-Policy
Add a Permissions-Policy header to restrict browser features like camera, microphone, and geolocation
Google Consent Mode
V2Consent Parameters
Issues (1)
No default consent call detected — consent mode may not be initialised correctly
Post-Rejection Audit
Reject Button
Found
Post-Rejection Fires
4 vendors
Consent Mode
Advanced
GTM Load
6310ms pre-consent
Google Tag Manager(GTM-MMCLV43)
Loaded 6310ms after page load — before the consent banner was detected (banner appeared at 7949ms). Per a 2022 German court ruling, GTM itself transmits the user's IP to Google pre-consent.
Consent Mode V2: Advanced
Advanced Consent Mode — consent update call fires on rejection and tracking stops correctly.
✓ gtag('consent', 'update') call detected on rejection
Vendors firing after rejection (4)
| Vendor | Category | Timing | URL |
|---|---|---|---|
| TikTok — TikTok Pixel | advertising | 17563ms | analytics.tiktok.com |
| TikTok — TikTok Pixel | advertising | 17568ms | analytics-ipv6.tiktokw.us |
| Usercentrics — Usercentrics CMP | consent_management | 17657ms | consent-api.service.consent.usercentrics.eu |
| Google — GA4 | analytics | 22156ms | region1.google-analytics.com |
Consent Record Audit
Issues detectedConsent record stored after interaction
GDPR Art. 7(1)No consent record written — cannot prove consent was given
No CMP consent cookie or localStorage entry was found after the consent interaction. GDPR requires controllers to demonstrate consent was given.
Consent withdrawal mechanism accessible
GDPR Art. 7(3)No way for users to withdraw consent found on page
No cookie settings link, footer link, or floating consent button was detected. GDPR requires users to withdraw consent as easily as they gave it.
Why this matters
Under GDPR Article 7, controllers must be able to demonstrate that consent was given (Art. 7(1)) and ensure users can withdraw consent at any time, as easily as giving it (Art. 7(3)). Sites with no consent record or no withdrawal mechanism cannot legally rely on consent as a lawful basis.
Tracker categories detected
Critical39
Data was transmitted to a third-party or storage was written on the user’s device before consent. This is a GDPR/ePrivacy violation, not just a script load.
TikTok Pixel7 findingsID trackedanalytics.tiktok.com, analytics-ipv6.tiktokw.us, _tt_enable_cookie, _ttp, tt_sessionId, tt_appInfo, tt_pixel_session_index

analytics.tiktok.com, analytics-ipv6.tiktokw.us, _tt_enable_cookie, _ttp, tt_sessionId, tt_appInfo, tt_pixel_session_index

TikTok Pixel (TikTok) loaded before consent: Sends event data to TikTok for ad measurement

TikTok Pixel (TikTok) loaded before consent: TikTok Pixel IPv6 enrichment and data collection

TikTok Pixel cookie "_tt_enable_cookie" set before consent

TikTok Pixel cookie "_ttp" set before consent

TikTok Pixel (TikTok) wrote "tt_sessionId" to sessionStorage before consent

TikTok Pixel (TikTok) wrote "tt_appInfo" to sessionStorage before consent

TikTok Pixel (TikTok) wrote "tt_pixel_session_index" to sessionStorage before consent

GA4 (Google) loaded before consent: Sends pageview and event data to Google Analytics
Meta Pixel3 findingsID trackedwww.facebook.com, connect.facebook.net, _fbp

www.facebook.com, connect.facebook.net, _fbp

Meta Pixel (Meta) loaded before consent: Meta Pixel tracking endpoint

Meta Pixel (Meta) loaded before consent: Sends user data to Meta for ad targeting and conversion tracking

Meta Pixel cookie "_fbp" set before consent
Advertising Tracker3 findingsaswpsdkeu.com, uct.service.usercentrics.eu, analytics.faceitanalytics.com
aswpsdkeu.com, uct.service.usercentrics.eu, analytics.faceitanalytics.com
advertising tracker at aswpsdkeu.com loaded before consent
advertising tracker at uct.service.usercentrics.eu loaded before consent
advertising tracker at analytics.faceitanalytics.com loaded before consent
Google (tracker) loaded before consent
Google Ads3 findingswww.googleadservices.com, googleads.g.doubleclick.net, pagead2.googlesyndication.com

www.googleadservices.com, googleads.g.doubleclick.net, pagead2.googlesyndication.com

Google Ads (Google) loaded before consent: Google Ads conversion tracking

Google Ads (Google) loaded before consent: Sends conversion data to Google Ads

Google Ads (Google) loaded before consent: Google ad syndication and remarketing
reddit (advertising) loaded before consent
Twitter/X Pixel (X (Twitter)) loaded before consent: Loads Twitter/X conversion tracking script
Reddit Pixel2 findingsalb.reddit.com, _rdt_uuid
alb.reddit.com, _rdt_uuid
Reddit Pixel (Reddit) loaded before consent: Reddit conversion tracking pixel
Reddit Pixel cookie "_rdt_uuid" set before consent
Mixpanel4 findingsapi-js.mixpanel.com, mp_95d82ab970744961d64b38519bf83797_mixpanel, mp_tab_id_mixpanel_95d82ab970744961d64b38519bf83797, mp_gen_new_tab_id_mixpanel_95d82ab970744961d64b38519bf83797
api-js.mixpanel.com, mp_95d82ab970744961d64b38519bf83797_mixpanel, mp_tab_id_mixpanel_95d82ab970744961d64b38519bf83797, mp_gen_new_tab_id_mixpanel_95d82ab970744961d64b38519bf83797
Mixpanel (Mixpanel) loaded before consent: Mixpanel analytics data collection endpoint
Mixpanel cookie "mp_95d82ab970744961d64b38519bf83797_mixpanel" set before consent
Mixpanel (Mixpanel) wrote "mp_tab_id_mixpanel_95d82ab970744961d64b38519bf83797" to sessionStorage before consent
Mixpanel (Mixpanel) wrote "mp_gen_new_tab_id_mixpanel_95d82ab970744961d64b38519bf83797" to sessionStorage before consent

Bing / Microsoft cookie "anon" set before consent — Contains the A, a unique identifier derived from your Microsoft account, which is used for advertising, personalization, and operational purposes. It is also used to preserve your choice to opt out of interest-based advertising from Microsoft if you have chosen to associate the opt-out with your Microsoft account.
X5 findingsguest_id_marketing, guest_id_ads, personalization_id, guest_id, muc_ads
guest_id_marketing, guest_id_ads, personalization_id, guest_id, muc_ads
X cookie "guest_id_marketing" set before consent — This cookie is for advertising when logged out
X cookie "guest_id_ads" set before consent — This cookie is for advertising when logged out
X cookie "personalization_id" set before consent — Unique value with which users can be identified by X. Collected information is used to be personalize X services, including X trends, stories, ads and suggestions.
X cookie "guest_id" set before consent — This cookie is set by X to identify and track the website visitor. Registers if a users is signed in the X platform and collects information about ad preferences.
X cookie "muc_ads" set before consent — These cookies are placed when you come to our website via X. A cookie from X is also placed on our website, with which we can later show a relevant offer on X
TikTok2 findingsttcsid, ttcsid_CVGM0IBC77UAB8G2GGB0

ttcsid, ttcsid_CVGM0IBC77UAB8G2GGB0

TikTok cookie "ttcsid" set before consent — The TikTok cookie ttcsid likely serves as a session identifier, helping to maintain user sessions and track interactions across the platform. Its purpose is probably to manage user authentication or personalize content based on activity, similar to other session-related cookies used by TikTok.

TikTok cookie "ttcsid_CVGM0IBC77UAB8G2GGB0" set before consent — The TikTok cookie ttcsid likely serves as a session identifier, helping to maintain user sessions and track interactions across the platform. Its purpose is probably to manage user authentication or personalize content based on activity, similar to other session-related cookies used by TikTok.

TikTok — TikTok Pixel fires after user rejected consent
Usercentrics — Usercentrics CMP fires after user rejected consent

Google — GA4 fires after user rejected consent
No recognizable consent cookie or storage entry detected after interaction — GDPR Article 7(1) requires controllers to demonstrate consent was given (server-side storage cannot be verified)
No recognizable consent withdrawal mechanism detected — GDPR Article 7(3) requires users can withdraw consent as easily as giving it (cookie settings link or floating button expected)
Warnings29
A tag container or script loaded before consent but tags appear correctly gated (e.g. GTM with Consent Mode v2). Not a violation on its own — review to confirm downstream tags stay blocked.
Google Tag Manager2 findingsID trackedwww.googletagmanager.com

www.googletagmanager.com

Google Tag Manager loads before consent — this is expected and required for GCM v2 to initialise consent defaults before any tags fire

GTM loaded before consent banner — IP address transmitted to Google pre-consent (container: GTM-MMCLV43)
Twitter (social) loaded before consent
Google Tag Manager loads before consent — this is expected and required for GCM v2 to initialise consent defaults before any tags fire
Unknown third-party request to t.co before consent
Unknown was clicked but no consent storage was written — tags may continue firing as if consent was never given
reddit (social) loaded before consent
Unknown third-party request to cdn-frontend.faceit-cdn.net before consent
Unknown third-party request to web.cmp.usercentrics.eu before consent
Unknown third-party request to v1.api.service.cmp.usercentrics.eu before consent
Unknown third-party request to distribution.faceit-cdn.net before consent
Unknown third-party request to cms.faceit-cdn.net before consent
Unknown third-party request to www.google.com before consent
localStorage key "__mplss_rogdzfs1" written before consent
sessionStorage key "__mplss_qf5lvo2q" written before consent
localStorage key "faceit_visited" written before consent
localStorage key "first_visited_faceit" written before consent
localStorage key "__mplss_i69s3t48" written before consent
localStorage key "__mpq_95d82ab970744961d64b38519bf83797_ev:X" written before consent
localStorage key "__mpq_95d82ab970744961d64b38519bf83797_ev:Y" written before consent
localStorage key "__mpq_95d82ab970744961d64b38519bf83797_ev:Z" written before consent
localStorage key "__mpq_95d82ab970744961d64b38519bf83797_ev" written before consent
sessionStorage key "session_landed_page_category" written before consent
sessionStorage key "X3VhX3Nkazoxd3d1U1VKSVNJYUFnTGpXa01NTnpnOi8=:tab-id" written before consent
localStorage key "voiceFeedbackFlag" written before consent
localStorage key "ucData" written before consent
localStorage key "ucString" written before consent
localStorage key "lastExternalReferrer" written before consent
localStorage key "__mplss_3ii8ezjs" written before consent
Info9
Neutral observations — activity we detected that isn’t a violation but is useful context (e.g. essential cookies, CMP initialisation).

Cloudflare Web Analytics (Cloudflare) loaded before consent: Cloudflare Web Analytics beacon — privacy-focused, no cookies
Sentry (Sentry) loaded before consent: Sentry error reporting endpoint
Usercentrics CMP2 findingsapp.usercentrics.eu, consent-api.service.consent.usercentrics.eu
app.usercentrics.eu, consent-api.service.consent.usercentrics.eu
Usercentrics CMP (Usercentrics) loaded before consent: Usercentrics consent management platform — UI and configuration loader
Usercentrics CMP (Usercentrics) loaded before consent: Usercentrics consent service API
Google (cdn) loaded before consent

Cloudflare cookie "_cfuvid" set before consent — The _cfuvid cookie is only set when a site uses this option in a Rate Limiting Rule, and is only used to allow the Cloudflare WAF to distinguish individual users who share the same IP address.

DoubleClick/Google Marketing cookie "test_cookie" set before consent — This cookie is set by DoubleClick (which is owned by Google) to determine if the website visitor's browser supports cookies.
Cloudflare challenge clearance — necessary for site access
Cloudflare bot management — necessary for site operation
Compliant24
Tags that fired only after the user gave consent — working as intended.

Criteo cookie "cto_bundle" set correctly after consent
Google Ads2 findings_gcl_au, _gcl_ls

_gcl_au, _gcl_ls

Google Ads cookie "_gcl_au" set correctly after consent

Google Ads (Google) wrote "_gcl_ls" to localStorage correctly after consent
Google Analytics2 findings_ga, _ga_KTNSTEHPST

_ga, _ga_KTNSTEHPST

Google Analytics cookie "_ga" set correctly after consent

Google Analytics cookie "_ga_KTNSTEHPST" set correctly after consent

DoubleClick/Google Marketing cookie "IDE" set correctly after consent
Marfeel2 findings_sharedID, _sharedID_cst
_sharedID, _sharedID_cst
Marfeel cookie "_sharedID" set correctly after consent
Marfeel cookie "_sharedID_cst" set correctly after consent
ID52 findingsid5, 3pi
id5, 3pi
ID5 cookie "id5" set correctly after consent
ID5 cookie "3pi" set correctly after consent
TripleLift cookie "tluid" set correctly after consent
Platform161 cookie "tuuid" set correctly after consent
bidswitch.net cookie "tuuid_lu" set correctly after consent
Improve Digital2 findingsum, umeh
um, umeh
Improve Digital cookie "um" set correctly after consent
Improve Digital cookie "umeh" set correctly after consent
Xandr2 findingsXANDR_PANID, uuid2
XANDR_PANID, uuid2
Xandr cookie "XANDR_PANID" set correctly after consent
Xandr cookie "uuid2" set correctly after consent
PubMatic2 findingsKTPCACOOKIE, KADUSERCOOKIE
KTPCACOOKIE, KADUSERCOOKIE
PubMatic cookie "KTPCACOOKIE" set correctly after consent
PubMatic cookie "KADUSERCOOKIE" set correctly after consent

Adform cookie "uid" set correctly after consent
The Tradedesk2 findingsTDID, TDCPM
TDID, TDCPM
The Tradedesk cookie "TDID" set correctly after consent
The Tradedesk cookie "TDCPM" set correctly after consent
Federated Media Publishing cookie "ljt_reader" set correctly after consent
Usercentrics CMP (Usercentrics) wrote "uc_user_interaction" to localStorage correctly after consent
Is this your site?
Run a full multi-page scan with monitoring and get detailed remediation steps
Scan faceit.com →This audit is based on publicly observable website behavior. To request removal from the index, email support@tagleak.com