检查清单
Session replay and heatmaps before Accept: what to check
See whether session replay or heatmap scripts fire before Accept. The audit records hosts, cookies, and beacons. It does not decide permission.
In brief
Session replay and heatmap tools often load early so they can catch the first seconds of a visit. A cookie audit shows whether those scripts, cookies, or beacons appeared before Accept. It does not decide whether counsel would allow that load. First-party wrappers still count for the timing test. ConsentProbe lists the findings. A free US-baseline scan is not an EU or California legal conclusion. This page is testing guidance, not legal advice.
Not legal advice
This guide explains how to observe session replay, heatmap, and similar recording scripts that load before Accept. It is not legal advice (非正式法律意见), not a ruling that any vendor is permitted or forbidden before a choice, and not a GDPR, ePrivacy, or CPRA certificate. ConsentProbe reports are technical observations of what fired. They do not say what counsel would allow.
Last updated September 24, 2026. The before-Accept audit owns the full protocol. The first-party versus third-party guide owns the party labels. The pre-consent checklist owns the multi-step pass. This page stays on replay and heatmap timing.
Short answer
An audit answers whether a session replay or heatmap script, cookie, or beacon appeared before the visitor clicked Accept. It does not answer whether counsel would allow that load. These tools often start early because they try to record the first moments of the session.
In a clean profile, load the page without clicking the banner. Watch Network for recording or heatmap hosts. Open Application, then Cookies and storage, for related IDs. Keep screenshots. A first-party wrapper on your own domain still counts as a before-Accept finding if it sets a recording ID early.
ConsentProbe can list those findings with the request, the cookie, and the screenshot. A free US-baseline scan is not an EU or California legal conclusion. ConsentProbe does not install a CMP. This page is testing guidance, not a permission ruling.
Observation versus legal permission
Keep the two questions in different columns. The runtime test can fill the first and the third. Counsel fills the middle. In the note you hand engineering, write present before Accept. Leave permitted and lawful off the ticket unless a lawyer wrote them.
| Question | Who answers it | What you capture |
|---|---|---|
| Did a session replay or heatmap script, cookie, or beacon appear before Accept? | Runtime test or audit | Host, cookie name, storage key, timestamp, and screenshot |
| Is that load permitted in this jurisdiction? | Counsel or the compliance policy | Outside what a ConsentProbe report claims |
| Was it first-party or third-party? | The same runtime test | Domain context, using the party-label guide for the definitions |
Signals you can see
On Network, flag hosts or paths that look like session recording, heatmaps, or UX analytics. Hotjar, FullStory, and Microsoft Clarity are examples of that class. The names are examples only. This page does not rank vendors or tell you which script to block.
On cookies and storage, flag IDs or session keys written before a choice, including copies on your own domain. A purpose label inside the CMP is a claim. Network timing and the cookie list are what this pass verifies. When you need the first-party versus third-party definitions, open that guide.
Five-step check before Accept
Stop after these five steps if you only need the replay and heatmap inventory. Open the before-Accept audit for the longer protocol, and the pre-consent checklist when you also want Reject and an accept baseline. A later Reject All comparison belongs on the Reject leftovers guide.
- Use a clean browser profile. Do not click Accept or Reject.
- Load the storefront once. Open Network and filter for recording, heatmap, or analytics-looking hosts.
- Open Application, then Cookies and storage. Flag related IDs on your domain and on third-party domains.
- Screenshot the network rows and the cookie list. Write one finding sentence per distinct vendor or ID.
- Optional: compare after Reject All if the claim is that recording stays off. Use the Reject leftovers guide for that depth.
When hand-sorting the hosts gets slow
Sorting replay and heatmap fan-out by hand is slow once themes and apps change. ConsentProbe runs on the URL and stores a labeled pre-consent Fresh inventory. Each finding stays tied to a request, a cookie, or a screenshot.
Use the free US-baseline visit when you want the report format. Use paid EU or California scenarios when those regions are the claims you will show. The free versus paid guide draws that line. ConsentProbe does not install a CMP and does not approve vendors for counsel.
FAQ
Do session replay scripts fire before consent?
Often they try to, so they can record the first seconds. An audit shows whether yours did on a clean visit.
Are heatmaps allowed before Accept?
Permission is a legal call. The audit answers whether they fired before Accept. It does not grant permission.
Do first-party replay cookies skip the timing test?
No. A recording ID on your own domain still counts if it appears before Accept. Party labels live on the first-party versus third-party guide.
Where is the full before-Accept protocol?
The before-Accept audit is the long protocol. The pre-consent checklist is the pass order. This page is the replay and heatmap slice.
Does a free US-baseline decide EU or California permission?
No. A free US-baseline scan shows report format. It is not an EU or California legal conclusion. See the free versus paid guide.
Is this legal advice?
No (非正式法律意见). These are technical observations. ConsentProbe does not replace counsel, and it does not install a CMP.
Limits of this page
This page tells you how to observe session replay and heatmap scripts, cookies, and beacons before Accept. It is not legal advice (非正式法律意见), not a vendor review, and not a certificate under GDPR, ePrivacy, CPRA, or any other rule. ConsentProbe reports stay tied to requests, cookies, and screenshots. A free US-baseline scan is not an EU or California legal conclusion.
Related guides
Open the before-Accept audit for the full protocol, the party-label guide for first-party versus third-party, and the pre-consent checklist for the pass order.
- Pre-Consent Cookie Audit: A Storefront Checklist
- First-party vs third-party cookies before consent: what should you check?
- Pre-consent audit checklist: what to verify before Accept
- Reject All Still Tracking: What to Check After You Say No
- What belongs in a cookie consent audit evidence pack?
- What does a free US-baseline cookie audit prove vs paid EU or California scans?
- Are first-party analytics cookies allowed before Accept?
- Which cookie consent test should you run first?
- ConsentProbe methodology
- Pricing and listed regional products
Sources
These links cover the platform and regulatory context used in this guide. Applicability still depends on the organization and jurisdiction.
保存一次美国基线技术记录
完成自行检查后,可以跑一次免费美国基线审计:在加州以外做一次浏览器访问,把 Cookie、请求和截图存成证据。这次访问不会跑欧盟拒绝/接受,也不会跑加州 GPC。欧盟、加州和 Global 2 可在登录后的账单页购买。