Skip to content
CookieTosser

What does jstor.org track?

Before any consent, jstor.org loaded 2 tracking companies and set 1 advertising or analytics cookie.

That's fewer tracking companies than most sites we scanned: 56% of the 2,450 sites we checked loaded more.

Scanned October 2, 2026 from Germany, loading www.jstor.org once and clicking nothing. How we scan

Tracking companies
2
Tracking cookies
1
Third-party hosts
7
Cookies in total
7

Consent banner

The page loaded OneTrust, a consent management platform. Everything below was recorded before anyone answered it. 2 tracking companies still loaded while it was unanswered.

Companies contacted before consent

1 of the 5 companies it contacted before consent were social media companies.

  • Meta

    connect.facebook.net, www.facebook.com

    3 requestsSocial media
  • Google Analytics

    www.googletagmanager.com

    1 requestAnalytics

Other third parties (content delivery, consent, functional, unclassified)

  • ithaka.org

    static.ithaka.org

    13 requestsUnclassified
  • OneTrust

    cdn.cookielaw.org, geolocation.onetrust.com

    11 requestsConsent banner
  • Amazon Web Services

    xd-f1cf3d4fdb19408ea770fc6f80817dcb.ecs.us-east-1.on.aws

    1 requestContent delivery

Cookies set before consent

The longest-lived tracking cookie it set was _fbp, lasting about 3 months.

CookiePurposeSet byLasts
_fbpAdvertisingjstor.org3 months
_fs_cd_cp_pRdRgnTnF68pCV2FUnclassifiedjstor.orgUnder a day
_fs_ch_st_FSBmUei20MqUiJb9Unclassifiedwww.jstor.orgUnder a day
ReferringRequestIdUnclassifiedwww.jstor.orgSession
UUIDUnclassifiedwww.jstor.org13 months
OptanonConsentFunctionaljstor.org12 months
csrftokenNecessarywww.jstor.org12 months

The page also wrote 2 keys to local storage, which works like a cookie but isn't sent with requests.

Understanding this page

  • How to see which cookies and trackers a website loads

    A hands-on walkthrough for checking what a site sets before you've clicked anything, using Chrome and Firefox's built-in tools, plus how CookieTosser automates the same check every month.

  • What counts as valid cookie consent in the EU

    The rules that actually govern cookie banners — the ePrivacy Directive, the GDPR consent standard, the Planet49 ruling, the strictly-necessary exemption, and what "reject" has to offer compared with "accept.

  • Consent management platforms explained

    What a CMP banner is actually doing behind the scenes, how the IAB's TCF standard and Google's Consent Mode v2 fit in, and why a banner being present is no guarantee that nothing loads before you answer it.