Skip to content

Session replay from Hotjar (Contentsquare)

Hotjar and website tracking lawsuits

Hotjar records visitor sessions, including mouse movement, scrolling, and keystrokes, and turns them into replays and heatmaps.

Free, about a minute, no signup for your score.

What Suitcast knows about Hotjar

Critical risk

Type
Session replay
Complaints naming it, 12 months
2

Requests the scanner matches to it

  • static.hotjar.com
  • script.hotjar.com
  • .hotjar.com
  • .hotjar.io

The short answer

Hotjar is a session replay tool from Hotjar (Contentsquare). Suitcast rates its risk under the California Invasion of Privacy Act, CIPA, as critical, because complaints describe scripts like it recording visitors before they consent. It is named in 2 verified complaints in the last 12 months. The fix is to load it only after a visitor accepts, or to remove it when it is not used.

Why complaints name it

Session recording tools like this are the central example in California privacy complaints, which describe them as wiretapping a visitor's interaction with the page.

The act allows $5,000 per violation, which is why firms look for scripts that run the moment a page opens.

The fix

How to stop Hotjar firing before consent

Written for the person who runs the site, with the setting to change.
  1. In Hotjar, turn on the setting that waits for consent, and fire the script only after accept through your consent plugin or Google Tag Manager consent mode.

  2. If no one on your team reviews the recordings, remove Hotjar.

How the scan checks this

  1. Loads your pages like a first visit. A real browser, nothing clicked, nothing accepted.
  2. Checks every request before the banner is answered. A request to static.hotjar.com is matched to Hotjar and recorded with the millisecond it fired.
  3. Clicks reject and watches again. When the banner has a reject button, the scan presses it; if Hotjar keeps firing, the report says so.

Scanner rules and limits are on the methodology page.

Trend

Complaints naming Hotjar, month by month

Verified tracking complaints whose text names this script, by the month they were filed.

Website accessibility (ADA) Website tracking (CIPA)

October 2025 to September 2026, current month to date

Court records

Latest verified complaints naming Hotjar

Newest first. Every row links to the court record.
  1. Tracking

    Sanchez v. QuinStreet, Inc.

    S.D. California. Attributed to California

    Court recordfor Sanchez v. QuinStreet, Inc. (opens in a new tab)
  2. Tracking

    Del Salto v. Rolex Watch U.S.A., Inc.

    N.D. California, filed by Potter Handy, LLP. Attributed to New York

    Court recordfor Del Salto v. Rolex Watch U.S.A., Inc. (opens in a new tab)

Same type

Other session replay tools the scanner checks

Scripts of the same kind carry the same pattern in complaints, and the same fix.

Questions owners ask

Whether Hotjar is a problem, how to check your site, and where the counts come from.
Is having Hotjar on my site illegal?
No. The complaints do not claim the script is illegal; they claim it recorded a visitor before the visitor consented, or kept recording after the visitor declined. Loading Hotjar only after consent, or removing it when it is not used, is what removes the pattern the complaints describe.
How do I know if Hotjar fires before consent on my site?
Run the free scan. It loads your pages without clicking anything and checks every request that leaves the browser against its tracker catalog, recording the millisecond each match fired. If Hotjar appears, it fired before consent. When your banner has a reject button, the scan clicks it and reports whether the script kept firing.
Where do the case counts on this page come from?
From the complaint text of verified California Invasion of Privacy Act filings. When a complaint names this script, the case is linked to it. Complaints that are not yet available in the public record are not counted, so the number is a floor.

Does Hotjar fire before consent on your site?

The free scan checks every request your pages make before the banner is answered, shows the millisecond Hotjar fired, and whether it kept firing after reject.

Free, about a minute, no signup for your score.

Suitcast identifies risk indicators. It is not legal advice and does not determine compliance.