Skip to content

Tracking scripts

Tracking scripts named in website privacy lawsuits

Privacy complaints name specific scripts: ad pixels, session replay and chat tools that run before a visitor agrees. Find the ones on your site and the fix for each.

Free, about a minute, no signup for your score.

43 scripts the scanner recognizes, by risk

  • Critical12 scripts

  • High18 scripts

  • Medium13 scripts

Risk reflects what a script records and how often scripts like it appear in complaints.

The short answer

The Suitcast scanner recognizes 43 tracking scripts by the requests they make: 12 rated critical, 18 high and 13 medium under the California Invasion of Privacy Act, CIPA. 19 of them are named in verified complaints from the last 12 months. Session replay tools, chat widgets that capture typing, and the Meta and TikTok pixels carry the most risk. Each page explains what the script records and how to stop it firing before consent.

By type

8 kinds of script, ordered by risk

Scripts of the same kind record the same things and take the same fix. Open any script for the steps on Shopify, WordPress and Google Tag Manager.

Full catalog

All 43 scripts

Sorted by complaints naming each script in the last 12 months, then by risk.
  • Vendor
    Google
    Type
    Analytics
    CIPA risk
    Medium
    Complaints, 12 months
    10
  • Vendor
    TikTok
    Type
    Advertising pixel
    CIPA risk
    Critical
    Complaints, 12 months
    7
  • Vendor
    Google
    Type
    Advertising pixel
    CIPA risk
    High
    Complaints, 12 months
    7
  • Vendor
    Meta (Facebook and Instagram)
    Type
    Advertising pixel
    CIPA risk
    Critical
    Complaints, 12 months
    6
  • Vendor
    LinkedIn (Microsoft)
    Type
    Advertising pixel
    CIPA risk
    High
    Complaints, 12 months
    3
  • Vendor
    Microsoft
    Type
    Advertising pixel
    CIPA risk
    High
    Complaints, 12 months
    3
  • Vendor
    Pinterest
    Type
    Advertising pixel
    CIPA risk
    High
    Complaints, 12 months
    3
  • Vendor
    Reddit
    Type
    Advertising pixel
    CIPA risk
    High
    Complaints, 12 months
    3
  • Vendor
    Contentsquare
    Type
    Session replay
    CIPA risk
    Critical
    Complaints, 12 months
    2
  • Vendor
    Hotjar (Contentsquare)
    Type
    Session replay
    CIPA risk
    Critical
    Complaints, 12 months
    2
  • Vendor
    Google
    Type
    Other tracking
    CIPA risk
    Medium
    Complaints, 12 months
    2
  • Vendor
    HubSpot
    Type
    Analytics
    CIPA risk
    Medium
    Complaints, 12 months
    2
  • Vendor
    Microsoft
    Type
    Session replay
    CIPA risk
    Critical
    Complaints, 12 months
    1
  • Vendor
    AdRoll (NextRoll)
    Type
    Advertising pixel
    CIPA risk
    High
    Complaints, 12 months
    1
  • Vendor
    Criteo
    Type
    Advertising pixel
    CIPA risk
    High
    Complaints, 12 months
    1
  • Vendor
    Snap Inc.
    Type
    Advertising pixel
    CIPA risk
    High
    Complaints, 12 months
    1
  • Vendor
    Taboola
    Type
    Advertising pixel
    CIPA risk
    High
    Complaints, 12 months
    1
  • Vendor
    X Corp.
    Type
    Advertising pixel
    CIPA risk
    High
    Complaints, 12 months
    1
  • Vendor
    Amplitude
    Type
    Analytics
    CIPA risk
    Medium
    Complaints, 12 months
    1
  • Vendor
    Crazy Egg
    Type
    Session replay
    CIPA risk
    Critical
    Complaints, 12 months
    0
  • Vendor
    FullStory
    Type
    Session replay
    CIPA risk
    Critical
    Complaints, 12 months
    0
  • Vendor
    LogRocket
    Type
    Session replay
    CIPA risk
    Critical
    Complaints, 12 months
    0
  • Vendor
    Lucky Orange
    Type
    Session replay
    CIPA risk
    Critical
    Complaints, 12 months
    0
  • Vendor
    Mouseflow
    Type
    Session replay
    CIPA risk
    Critical
    Complaints, 12 months
    0
  • Vendor
    Quantum Metric
    Type
    Session replay
    CIPA risk
    Critical
    Complaints, 12 months
    0
  • Vendor
    Smartlook (Cisco)
    Type
    Session replay
    CIPA risk
    Critical
    Complaints, 12 months
    0
  • Vendor
    CallRail
    Type
    Call tracking
    CIPA risk
    High
    Complaints, 12 months
    0
  • Vendor
    Drift (Salesloft)
    Type
    Chat widget
    CIPA risk
    High
    Complaints, 12 months
    0
  • Vendor
    Gorgias
    Type
    Chat widget
    CIPA risk
    High
    Complaints, 12 months
    0
  • Vendor
    Intercom
    Type
    Chat widget
    CIPA risk
    High
    Complaints, 12 months
    0
  • Vendor
    Text (LiveChat)
    Type
    Chat widget
    CIPA risk
    High
    Complaints, 12 months
    0
  • Vendor
    Outbrain
    Type
    Advertising pixel
    CIPA risk
    High
    Complaints, 12 months
    0
  • Vendor
    Tidio
    Type
    Chat widget
    CIPA risk
    High
    Complaints, 12 months
    0
  • Vendor
    Zendesk
    Type
    Chat widget
    CIPA risk
    High
    Complaints, 12 months
    0
  • Vendor
    Attentive Mobile
    Type
    Email marketing
    CIPA risk
    Medium
    Complaints, 12 months
    0
  • Vendor
    Heap (Contentsquare)
    Type
    Analytics
    CIPA risk
    Medium
    Complaints, 12 months
    0
  • Vendor
    Klaviyo
    Type
    Email marketing
    CIPA risk
    Medium
    Complaints, 12 months
    0
  • Vendor
    Intuit Mailchimp
    Type
    Email marketing
    CIPA risk
    Medium
    Complaints, 12 months
    0
  • Vendor
    Mixpanel
    Type
    Analytics
    CIPA risk
    Medium
    Complaints, 12 months
    0
  • Vendor
    Optimizely
    Type
    A/B testing
    CIPA risk
    Medium
    Complaints, 12 months
    0
  • Vendor
    Twilio Segment
    Type
    Analytics
    CIPA risk
    Medium
    Complaints, 12 months
    0
  • Vendor
    Wingify (VWO)
    Type
    A/B testing
    CIPA risk
    Medium
    Complaints, 12 months
    0
  • Vendor
    Yotpo
    Type
    Other tracking
    CIPA risk
    Medium
    Complaints, 12 months
    0

Questions owners ask

Why scripts lead to lawsuits, and what the scanner checks.
Why do tracking scripts lead to lawsuits?
Complaints under the California Invasion of Privacy Act argue that a script which records what a visitor does, before the visitor agrees, is eavesdropping or a pen register. The statute allows $5,000 per violation, so firms look for pixels, session replay and chat tools that load the moment a page opens.
Is it illegal to use Google Analytics or the Meta Pixel?
No. The complaints target when a script runs, not the script itself. Loading it only after a visitor accepts in a consent banner, or removing it when it is unused, removes the pattern the complaints describe. Whether a specific setup is lawful is a question for a lawyer.
How does Suitcast know which scripts fire before consent?
The scanner opens your public pages in a real browser without clicking anything and checks every request that leaves the page against this catalog, recording each match. When a banner has a reject button, it clicks it and records which scripts keep firing.
What does the risk level mean?
It reflects what the script collects and how often scripts of its kind appear in complaints. Session replay and chat tools that capture typing, and the Meta and TikTok pixels, are critical. Other advertising pixels are high. Analytics, testing and email scripts are medium.

Which of these fire on your site before consent?

The free scan checks every request your pages make before the banner is answered against this catalog, with the millisecond each one fired.

Free, about a minute, no signup for your score.

Suitcast identifies risk indicators. It is not legal advice and does not determine compliance.