What the tracker categories mean
Published September 27, 2026
Every company and every cookie on this site gets sorted into one category. It's meant to answer a specific question at a glance — "is this a company that exists to advertise to me, or one doing something more mundane, like serving a font?" — but categories always simplify a messier reality, so it's worth knowing exactly what each one covers and where the edges are fuzzy.
Company categories
A company's category describes its main role on a typical page, not everything it's capable of. That matters because a single company, especially a large one, often runs several different businesses under different domains — Google is the clearest example, and it's split accordingly rather than given one label for everything it does.
| Category | What it means | Example |
|---|---|---|
| Advertising | Serves ads, tracks ad clicks/conversions, or runs the auctions and identity infrastructure behind ad targeting. | Google Ads, Criteo, The Trade Desk |
| Analytics | Measures visits, behavior, or performance — traffic counting, session recording, heatmaps, error tracking. | Google Analytics, Hotjar, Microsoft Clarity |
| Social | Embeds, widgets or pixels from a social platform — share buttons, embedded posts, "log in with" buttons, or a platform's own ad-conversion pixel. | Meta (Facebook/Instagram), YouTube |
| Consent | The consent banner platform itself, and the scripts that run it. | OneTrust, Cookiebot |
| CDN | Content delivery and infrastructure — serving images, fonts, scripts or video faster and more reliably, with no tracking purpose of its own. | Cloudflare |
| Functional | Everything else that makes the page work as intended without falling into the categories above: maps, payment widgets, chat support, captchas. | Google's core google.com/gstatic.com infrastructure (kept separate from Google Ads and Google Analytics) |
| Unclassified | A domain we've seen but haven't identified yet, or one with too little data to categorize confidently. Not counted as a tracker in the site's headline numbers. | — |
Three of these — advertising, analytics and social — are what this site counts as "tracking" in its headline statistics, because they're the categories built around following a visitor's behavior for a purpose beyond the page they're currently on. Consent, CDN and functional companies can still set cookies and still see your IP address, but that's incidental to what they're there to do, not the point of it.
The CDN/functional split is the one worth a second look: a CDN literally serves the file (an image, a script, a font) and nothing more; a functional company runs something interactive — a map, a chat widget, reCAPTCHA — that needs to know something about the visit to work at all. Both are treated as non-tracking here because neither is built to profile you across sites, but "non-tracking" doesn't mean "invisible": a chat widget or embedded map can still load a cookie and contact its own servers.
Categorizing companies this precisely means a domain nobody has looked at yet defaults to "unclassified" rather than being guessed into a category it might not deserve — which is also why a page for a small, unclassified company or cookie stays out of search results here until there's enough evidence, one way or the other, to say something real about it.
Cookie categories
Cookies are categorized on a related but separate scale, closer to how a consent banner would group them for you to choose from:
| Category | What it means | Example |
|---|---|---|
| Advertising | Set to target, measure or retarget ads. | _fbp, IDE |
| Analytics | Set to measure traffic or behavior, without an advertising purpose on its own. | _ga, _gid |
| Functional | Supports a feature the visitor is using — remembering a language, a video player's volume, an open chat session. | — |
| Necessary | Falls under the "strictly necessary" exemption discussed in what counts as valid consent — session identifiers, load balancing, fraud/security cookies, and the cookie that records the visitor's own consent choice. | — |
| Unclassified | Not yet matched against a source that tells us its purpose. | — |
Where we can, cookie descriptions and categories come from the Open Cookie Database, an open, community-maintained list, supplemented by cookies we've researched and documented ourselves when the database doesn't cover them. A cookie's category here describes its most common documented purpose — a cookie can behave slightly differently site to site depending on how it's configured, and a "functional" cookie on one site could in principle be repurposed for tracking on another, though that's the exception rather than the rule for well-known cookies.
Why this matters when you're checking a site
If you're looking at a site's own report on this site, or checking one yourself with browser DevTools, the categories are the fastest way to separate "this is expected and low-risk" from "this is the thing consent rules are actually about." A CDN or functional company loading before you've clicked anything is normal and rarely the subject of a complaint. An advertising or analytics company doing the same thing, particularly one that also sets a long-lived cookie (see how cookie lifetimes work), is exactly the scenario the ePrivacy Directive's consent requirement targets. Browse every company we track or every cookie in the dictionary to see how a given name is categorized.