Puma

puma.com

Compare

Geo-redirect detected

https://puma.com redirected to https://eu.puma.com/nl/nl/home.

https://puma.com

Scanned Apr 15, 2026 · 39.7s

Your website score is

0/100
Critical

Grade

F0

Banner

Yes

Regulatory Compliance

Multi-regulation overview — click any regulation for details

Technical scan only. A passing score does not equal legal compliance. Consult qualified legal counsel for your jurisdiction.

Tag Leak detected 20 user data leaks before consent on puma.com, including Salesforce (Analytics Tracker), SAP (Advertising Tracker), Facebook and 1 more.

Security Headers

3/6 present

Strict-Transport-Security

max-age=31536000

Content-Security-Policy

Add a Content-Security-Policy header to prevent XSS and code injection attacks

X-Frame-Options

SAMEORIGIN

X-Content-Type-Options

nosniff

Referrer-Policy

Set a Referrer-Policy header to control how much referrer information is shared

Permissions-Policy

Add a Permissions-Policy header to restrict browser features like camera, microphone, and geolocation

Google Consent Mode

Not Detected

Google Consent Mode v2 was not found on this page. GCM v2 allows Google's tags to adjust their behavior based on user consent, and is required for compliant advertising measurement in the EU. Without it, your Google Ads and GA4 conversions may be impacted after consent is declined.

GTM container detected (GTM-TSWKBGX3) but no consent mode initialisation found. Add gtag('consent', 'default', ...) before your GTM snippet.

Post-Rejection Audit

Reject Button

Found

Post-Rejection Fires

0 vendors

Consent Mode

Not Detected

GTM Load

1581ms pre-consent

Google Tag Manager(GTM-TSWKBGX3)

Loaded 1581ms after page load — before the consent banner was detected (banner appeared at 8318ms). Per a 2022 German court ruling, GTM itself transmits the user's IP to Google pre-consent.

Consent Mode V2: Not Detected

Google Consent Mode was not detected on this site.

No tracking vendors detected firing after rejection

Consent Record Audit

Issues detected

Consent record stored after interaction

GDPR Art. 7(1)

Found: OptanonConsent (OneTrust)

Record contains timestamp

Art. 7(1)

Timestamp field detected

Record contains consent state

Art. 7(1)

Accept/reject state detected

Record contains consent categories

Art. 7(1)

Consent categories (analytics, marketing, etc.) not found in record

Consent withdrawal mechanism accessible

GDPR Art. 7(3)

No way for users to withdraw consent found on page

No cookie settings link, footer link, or floating consent button was detected. GDPR requires users to withdraw consent as easily as they gave it.

Why this matters

Under GDPR Article 7, controllers must be able to demonstrate that consent was given (Art. 7(1)) and ensure users can withdraw consent at any time, as easily as giving it (Art. 7(3)). Sites with no consent record or no withdrawal mechanism cannot legally rely on consent as a lawful basis.

Tracker categories detected

Advertising8 vendors
Analytics5 vendors
Marketing9 vendors
Security3
Functional6 vendors
Tag Management1 vendor
Critical7
Salesforce (Analytics Tracker)
criticalNetworkAnalyticsSalesforce (Analytics Tracker)

Salesforce (analytics) loaded before consent

Host: cdn.cquotient.comFired: 937ms after load
SAP (Advertising Tracker)
SAP (Advertising Tracker)3 findings

recommender.scarabresearch.com, static.scarabresearch.com, webchannel-content.eservice.emarsys.net

SAP (Advertising Tracker)
criticalNetworkAdvertisingSAP (Advertising Tracker)

SAP (advertising) loaded before consent

Host: recommender.scarabresearch.comFired: 2210ms after load
SAP (Advertising Tracker)
criticalNetworkAdvertisingSAP (Advertising Tracker)

SAP (advertising) loaded before consent

Host: static.scarabresearch.comFired: 2522ms after load
SAP (Advertising Tracker)
criticalNetworkAdvertisingSAP (Advertising Tracker)

SAP (advertising) loaded before consent

Host: webchannel-content.eservice.emarsys.netFired: 3330ms after load
Facebook
criticalCookieMarketingFacebook

Facebook cookie "s" set before consent — Facebook browser identification, authentication, marketing, and other Facebook-specific function cookies.

Cookie: sDomain: recommender.scarabresearch.comRetention: 90 days
Google
criticalCookieMarketingGoogle

Google cookie "sid" set before consent — Download certain Google Tools and save certain preferences, for example the number of search results per page or activation of the SafeSearch Filter. Adjusts the ads that appear in Google Search.

Cookie: sidDomain: eu.puma.comRetention: 2 years
criticalConsent Record

No recognizable consent withdrawal mechanism detected — GDPR Article 7(3) requires users can withdraw consent as easily as giving it (cookie settings link or floating button expected)

Warnings14
Google Tag Manager
Google Tag Manager2 findingsID tracked

www.googletagmanager.com

Google Tag Manager
warningNetworkTag ManagementGoogle Tag Manager

Google Tag Manager (Google) loaded before consent: Loads the GTM container which may trigger other tags

ID: GTM-TSWKBGX3Host: www.googletagmanager.comFired: 1243ms after load
Google Tag Manager
warningGTMTag ManagementGoogle Tag Manager

GTM loaded before consent banner — IP address transmitted to Google pre-consent (container: GTM-TSWKBGX3)

GA4 (server-side proxy)
warningNetworkGA4 (server-side proxy)

Possible server-side tag proxy at eu.puma.com — analytics data may be forwarded to third parties before consent. Browser scanning cannot verify downstream recipients; audit your GTM Server-side or CNAME configuration.

Host: eu.puma.comFired: 3542ms after load
vendor logo
warningNetwork

Unknown third-party request to puma.api.highstreetapp.com before consent

Host: puma.api.highstreetapp.comFired: 329ms after load
vendor logo
warningNetwork

Unknown third-party request to www.google.com before consent

Host: www.google.comFired: 747ms after load
vendor logo
warningNetwork

Unknown third-party request to cdn.portal-backend.prod.qualibooth.com before consent

Host: cdn.portal-backend.prod.qualibooth.comFired: 929ms after load
vendor logo
warningNetwork

Unknown third-party request to page-metrics.prod.qualibooth.com before consent

Host: page-metrics.prod.qualibooth.comFired: 4147ms after load
warningStorage

localStorage key "scarab.visitor" written before consent

Key: scarab.visitorType: localStorageFired: 2728ms after load
warningStorage

localStorage key "_wp_storage_test" written before consent

Key: _wp_storage_testType: localStorageFired: 3295ms after load
warningStorage

sessionStorage key "wpsStore" written before consent

Key: wpsStoreType: sessionStorageFired: 3306ms after load
warningStorage

localStorage key "wps-1" written before consent

Key: wps-1Type: localStorageFired: 3309ms after load
warningStorage

sessionStorage key "wps-browser-session-1" written before consent

Key: wps-browser-session-1Type: sessionStorageFired: 3309ms after load
warningStorage

localStorage key "wps-user-session" written before consent

Key: wps-user-sessionType: localStorageFired: 3311ms after load
warningStorage

localStorage key "customer_id" written before consent

Key: customer_idType: localStorageFired: 3367ms after load
Info6
OneTrust
OneTrust2 findings

cdn.cookielaw.org, OptanonConsent

OneTrust
infoNetworkConsent MgmtOneTrust

OneTrust (OneTrust) loaded before consent: OneTrust cookie consent management

Host: cdn.cookielaw.orgFired: 929ms after load
OneTrust
infoCookieConsent MgmtOneTrust

OneTrust cookie "OptanonConsent" set before consent

Cookie: OptanonConsentDomain: .eu.puma.com
Cloudflare Web Analytics
infoNetworkAnalyticsCloudflare Web Analytics

Cloudflare Web Analytics (Cloudflare) loaded before consent: Cloudflare Web Analytics beacon — privacy-focused, no cookies

Host: static.cloudflareinsights.comFired: 937ms after load
OneTrust CMP
infoNetworkConsent MgmtOneTrust CMP

OneTrust CMP (OneTrust) loaded before consent: OneTrust geo-lookup — determines which consent banner to show based on user location

Host: geolocation.onetrust.comFired: 1630ms after load
Intershop2 findings

cc-sg, cc-nx-g

infoCookieFunctionalIntershop

Intershop cookie "cc-sg" set before consent — References a cart for anonymous users

Cookie: cc-sgDomain: eu.puma.comRetention: session
infoCookieFunctionalIntershop

Intershop cookie "cc-nx-g" set before consent — References a cart for anonymous users

Cookie: cc-nx-gDomain: eu.puma.comRetention: session
Compliant41
TikTok Pixel
TikTok Pixel7 findingsID tracked

analytics.tiktok.com, analytics-ipv6.tiktokw.us, _ttp, _tt_enable_cookie, tt_sessionId, tt_appInfo, tt_pixel_session_index

TikTok Pixel
CompliantNetworkAdvertisingTikTok Pixel

TikTok Pixel (TikTok) loaded correctly after consent

ID: CD4JCHRC77U8TNJJ05GGHost: analytics.tiktok.comFired: 1207ms after load
TikTok Pixel
CompliantNetworkAdvertisingTikTok Pixel

TikTok Pixel (TikTok) loaded correctly after consent

Host: analytics-ipv6.tiktokw.usFired: 2598ms after load
TikTok Pixel
CompliantCookieAdvertisingTikTok Pixel

TikTok Pixel cookie "_ttp" set correctly after consent

Cookie: _ttpDomain: .tiktok.com
TikTok Pixel
CompliantCookieAdvertisingTikTok Pixel

TikTok Pixel cookie "_tt_enable_cookie" set correctly after consent

Cookie: _tt_enable_cookieDomain: .puma.com
TikTok Pixel
CompliantStorageAdvertisingTikTok Pixel

TikTok Pixel (TikTok) wrote "tt_sessionId" to sessionStorage correctly after consent

Key: tt_sessionIdType: sessionStorageFired: 2527ms after load
TikTok Pixel
CompliantStorageAdvertisingTikTok Pixel

TikTok Pixel (TikTok) wrote "tt_appInfo" to sessionStorage correctly after consent

Key: tt_appInfoType: sessionStorageFired: 2539ms after load
TikTok Pixel
CompliantStorageAdvertisingTikTok Pixel

TikTok Pixel (TikTok) wrote "tt_pixel_session_index" to sessionStorage correctly after consent

Key: tt_pixel_session_indexType: sessionStorageFired: 2541ms after load
Microsoft Clarity
Microsoft Clarity4 findingsID tracked

www.clarity.ms, scripts.clarity.ms, i.clarity.ms, _clck

Microsoft Clarity
CompliantNetworkAnalyticsMicrosoft Clarity

Microsoft Clarity (Microsoft) loaded correctly after consent

ID: ogxxcmic3eHost: www.clarity.msFired: 1207ms after load
Microsoft Clarity
CompliantNetworkAnalyticsMicrosoft Clarity

Microsoft Clarity (Microsoft) loaded correctly after consent

Host: scripts.clarity.msFired: 2023ms after load
Microsoft Clarity
CompliantNetworkAnalyticsMicrosoft Clarity

Microsoft Clarity (Microsoft) loaded correctly after consent

Host: i.clarity.msFired: 2751ms after load
Microsoft Clarity
CompliantCookieAnalyticsMicrosoft Clarity

Microsoft Clarity cookie "_clck" set correctly after consent

Cookie: _clckDomain: .puma.com
Branch
CompliantNetworkAdvertisingBranch

Branch (Branch) loaded correctly after consent

Host: cdn.branch.ioFired: 1889ms after load
Microsoft Ads
CompliantNetworkAdvertisingMicrosoft Ads

Microsoft Ads (Microsoft) loaded correctly after consent

Host: bat.bing.comFired: 3325ms after load
Meta Pixel
Meta Pixel3 findings

connect.facebook.net, s, _fbp

Meta Pixel
CompliantNetworkAdvertisingMeta Pixel

Meta Pixel (Meta) loaded correctly after consent

Host: connect.facebook.netFired: 3546ms after load
Facebook
CompliantCookieMarketingFacebook

Facebook cookie "s" set correctly after consent

Cookie: sDomain: recommender-eu.scarabresearch.comRetention: 90 days
Meta Pixel
CompliantCookieAdvertisingMeta Pixel

Meta Pixel cookie "_fbp" set correctly after consent

Cookie: _fbpDomain: .puma.com
Snapchat Pixel
CompliantNetworkAdvertisingSnapchat Pixel

Snapchat Pixel (Snapchat) loaded correctly after consent

Host: sc-static.netFired: 3546ms after load
Pinterest Tag
CompliantNetworkAdvertisingPinterest Tag

Pinterest Tag (Pinterest) loaded correctly after consent

Host: s.pinimg.comFired: 3547ms after load
Google Ads
Google Ads4 findings

www.googleadservices.com, googleads.g.doubleclick.net, _gcl_au, _gcl_ls

Google Ads
CompliantNetworkAdvertisingGoogle Ads

Google Ads (Google) loaded correctly after consent

Host: www.googleadservices.comFired: 4862ms after load
Google Ads
CompliantNetworkAdvertisingGoogle Ads

Google Ads (Google) loaded correctly after consent

Host: googleads.g.doubleclick.netFired: 4862ms after load
Google Ads
CompliantCookieAdvertisingGoogle Ads

Google Ads cookie "_gcl_au" set correctly after consent

Cookie: _gcl_auDomain: .puma.com
Google Ads
CompliantStorageAdvertisingGoogle Ads

Google Ads (Google) wrote "_gcl_ls" to localStorage correctly after consent

Key: _gcl_lsType: localStorageFired: -25506ms after load
OneTrust
CompliantCookieConsent MgmtOneTrust

OneTrust cookie "OptanonAlertBoxClosed" set correctly after consent

Cookie: OptanonAlertBoxClosedDomain: .eu.puma.com
Google Analytics
Google Analytics5 findings

_ga, _ga_Z9W7F41DQW, FPID, FPLC, FPAU

Google Analytics
CompliantCookieAnalyticsGoogle Analytics

Google Analytics cookie "_ga" set correctly after consent

Cookie: _gaDomain: .puma.com
Google Analytics
CompliantCookieAnalyticsGoogle Analytics

Google Analytics cookie "_ga_Z9W7F41DQW" set correctly after consent

Cookie: _ga_Z9W7F41DQWDomain: .puma.com
Google Analytics
CompliantCookieAnalyticsGoogle Analytics

Google Analytics cookie "FPID" set correctly after consent

Cookie: FPIDDomain: .puma.comRetention: session
Google Analytics
CompliantCookieAnalyticsGoogle Analytics

Google Analytics cookie "FPLC" set correctly after consent

Cookie: FPLCDomain: .puma.comRetention: session
Google Analytics
CompliantCookieMarketingGoogle Analytics

Google Analytics cookie "FPAU" set correctly after consent

Cookie: FPAUDomain: .puma.comRetention: session
Google
CompliantCookieFunctionalGoogle

Google cookie "FPGSID" set correctly after consent

Cookie: FPGSIDDomain: .puma.comRetention: Session
DoubleClick/Google Marketing
DoubleClick/Google Marketing2 findings

test_cookie, IDE

DoubleClick/Google Marketing
CompliantCookieFunctionalDoubleClick/Google Marketing

DoubleClick/Google Marketing cookie "test_cookie" set correctly after consent

Cookie: test_cookieDomain: .doubleclick.netRetention: 1 year
DoubleClick/Google Marketing
CompliantCookieMarketingDoubleClick/Google Marketing

DoubleClick/Google Marketing cookie "IDE" set correctly after consent

Cookie: IDEDomain: .doubleclick.netRetention: 2 years
CompliantCookieMarketingStape

Stape cookie "_gtmeec" set correctly after consent

Cookie: _gtmeecDomain: .puma.comRetention: 3 months
CompliantCookieAnalyticsShopify

Shopify cookie "_s" set correctly after consent

Cookie: _sDomain: .app.linkRetention: 2 years
Snapchat
CompliantCookieFunctionalSnapchat

Snapchat cookie "X-AB" set correctly after consent

Cookie: X-ABDomain: sc-static.netRetention: 1 day
Salesforce
CompliantCookieFunctionalSalesforce

Salesforce cookie "cqcid" set correctly after consent

Cookie: cqcidDomain: eu.puma.comRetention: 1 year
Mediamath
CompliantCookieMarketingMediamath

Mediamath cookie "uuid" set correctly after consent

Cookie: uuidDomain: .cquotient.comRetention: 1 year
TikTok
TikTok2 findings

ttcsid, ttcsid_CD4JCHRC77U8TNJJ05GG

TikTok
CompliantCookieMarketingTikTok

TikTok cookie "ttcsid" set correctly after consent

Cookie: ttcsidDomain: .puma.comRetention: 1 year
TikTok
CompliantCookieMarketingTikTok

TikTok cookie "ttcsid_CD4JCHRC77U8TNJJ05GG" set correctly after consent

Cookie: ttcsid_CD4JCHRC77U8TNJJ05GGDomain: .puma.comRetention: 1 year
CompliantCookieMarketingCreativeCDN

CreativeCDN cookie "g" set correctly after consent

Cookie: gDomain: .creativecdn.comRetention: 364 days
Adform
CompliantCookieMarketingAdform

Adform cookie "c" set correctly after consent

Cookie: cDomain: .creativecdn.comRetention: 60 days till 3650 days
CompliantCookieFunctionalPayPal

PayPal cookie "ts" set correctly after consent

Cookie: tsDomain: .creativecdn.comRetention: 3 years

Is this your site?

Run a full multi-page scan with monitoring and get detailed remediation steps

Scan puma.com

This audit is based on publicly observable website behavior. To request removal from the index, email support@tagleak.com