Skip to content
CookieTosser

What does heylink.me track?

Before any consent, heylink.me loaded 7 tracking companies and set 17 advertising or analytics cookies.

That's more tracking companies than 86% of the 2,450 sites we scanned.

Scanned October 2, 2026 from Germany, loading heylink.me once and clicking nothing. How we scan

Tracking companies
7
Tracking cookies
17
Third-party hosts
24
Cookies in total
27

Consent banner

The page loaded OneTrust, a consent management platform. Everything below was recorded before anyone answered it. 7 tracking companies still loaded while it was unanswered.

Companies contacted before consent

3 of the 14 companies it contacted before consent were social media companies.

  • 7 requestsAdvertising
  • Google Ads

    www.google.de, stats.g.doubleclick.net, googleads.g.doubleclick.net, ad.doubleclick.net

    5 requestsAdvertising
  • TikTok

    analytics.tiktok.com, analytics-ipv6.tiktokw.us

    8 requestsSocial media
  • Meta

    connect.facebook.net, www.facebook.com

    3 requestsSocial media
  • X (Twitter)

    static.ads-twitter.com, t.co, analytics.twitter.com

    3 requestsSocial media
  • Google Analytics

    www.googletagmanager.com, region1.analytics.google.com

    4 requestsAnalytics
  • Cloudflare Web Analytics

    static.cloudflareinsights.com

    1 requestAnalytics

Other third parties (content delivery, consent, functional, unclassified)

  • freshchat.com

    assetscdn-wchat.au.freshchat.com, wchat.au.freshchat.com

    16 requestsUnclassified
  • freshworksapi.com

    rts-static-prod.freshworksapi.com

    1 requestUnclassified
  • OneTrust

    cdn.cookielaw.org, geolocation.onetrust.com

    9 requestsConsent banner
  • Google

    www.google.com

    3 requestsFunctional
  • jsDelivr

    cdn.jsdelivr.net

    2 requestsContent delivery
  • unpkg

    unpkg.com

    2 requestsContent delivery
  • Cloudflare

    cdnjs.cloudflare.com

    1 requestContent delivery

Cookies set before consent

The longest-lived tracking cookie it set was guest_id, from X (Twitter), lasting about 13 months.

CookiePurposeSet byLasts
_fbpAdvertisingheylink.me3 months
_gcl_auAdvertisingheylink.me3 months
_tt_enable_cookieAdvertisingheylink.me13 months
_ttpAdvertisingtiktok.com (third party)13 months
_ttpAdvertisingheylink.me13 months
_uetsidAdvertisingheylink.me1 day
_uetvidAdvertisingheylink.me13 months
guest_idAdvertisingtwitter.com (third party)13 months
guest_id_adsAdvertisingtwitter.com (third party)13 months
guest_id_marketingAdvertisingtwitter.com (third party)13 months
muc_adsAdvertisingt.co (third party)13 months
MUIDAdvertisingbing.com (third party)13 months
personalization_idAdvertisingtwitter.com (third party)13 months
ttcsidAdvertisingheylink.me13 months
ttcsid_C1902KRQIA5GK7IMV8HGAdvertisingheylink.me13 months
_gaAnalyticsheylink.me13 months
_ga_SLMX7BZBWPAnalyticsheylink.me13 months
_twpidUnclassifiedheylink.me13 months
_twsidUnclassifiedheylink.me13 months
__cf_bmFunctionalt.co (third party)Under a day
__cf_bmFunctionaltwitter.com (third party)Under a day
__cf_bmFunctionalheylink.meUnder a day
__cf_bmFunctionalfreshchat.com (third party)Under a day
_cfuvidFunctionalheylink.meSession
cf_clearanceFunctionalheylink.me12 months
OptanonConsentFunctionalheylink.me12 months
test_cookieFunctionaldoubleclick.net (third party)Under a day

The page also wrote 7 keys to local storage, which works like a cookie but isn't sent with requests.

Understanding this page

  • How to see which cookies and trackers a website loads

    A hands-on walkthrough for checking what a site sets before you've clicked anything, using Chrome and Firefox's built-in tools, plus how CookieTosser automates the same check every month.

  • What counts as valid cookie consent in the EU

    The rules that actually govern cookie banners — the ePrivacy Directive, the GDPR consent standard, the Planet49 ruling, the strictly-necessary exemption, and what "reject" has to offer compared with "accept.

  • Consent management platforms explained

    What a CMP banner is actually doing behind the scenes, how the IAB's TCF standard and Google's Consent Mode v2 fit in, and why a banner being present is no guarantee that nothing loads before you answer it.