Technical audit · 2026-05-29

hoferpowertrain.com

German Engineering Contractor for Electric Drivetrains

An engineering contractor for electric drivetrains (Weissach, Germany). 63 requests, 27 domains. Webflow, Cloudflare. GTM, Adobe Fonts, Google reCAPTCHA, Weglot, HubSpot, Meta Pixel, LinkedIn Insight Tag — all fire before or without consent. The Cookie-Script CMP appears at +577 ms, by which time most trackers are already active. The policy is auto-generated boilerplate with no mention of specific operators.

Timeline of the leak

+253 ms · Adobe Fonts and GTM — the first wave
use.typekit.net/zgj7pyl.js (Adobe Fonts/Typekit), www.google.com/recaptcha/api.js, cdn.weglot.com/weglot.min.js, www.acuteinspiration-inventive.com/js/805308.js — four external services simultaneously. +290 ms — p.typekit.net/p.gif (a font-usage tracking pixel). +293 ms — GTM-WDTZPGC. +294 ms — pressebox.de.
+481 ms · js-cookie and jQuery from CDNs
cdnjs.cloudflare.com/js-cookie/2.2.1 and d3e54v103j8qbb.cloudfront.net/jquery-3.5.1 — public CDNs, technical dependencies of Webflow.
+577 ms · Cookie-Script CMP
cdn.cookie-script.com/s/f8c1d5de66a5785bff1c71b479f07dbd.js — the Cookie-Script banner loads. In parallel — js.hs-scripts.com/5375305.js (+583 ms), HubSpot starting essentially at the same time as the banner.
+1102 ms · full HubSpot stack
hsadspixel.net, hscollectedforms.net, hs-analytics.net, hs-banner.com — four HubSpot domains simultaneously. +1934 ms — track.hubspot.com/__ptq.gif with browser fingerprint data (resolution, language, bfp hash).
+1959 ms · Cookie-Script analytics
consent.cookie-script.com/analytics?action=firstshown — Cookie-Script records the fact that the banner was shown. IAB TCF vendor-list.json and google-vendors.json load at +2218–2219 ms — the banner is in TCF mode.
+2050 ms · Meta Pixel and LinkedIn Insight Tag
connect.facebook.net/en_US/fbevents.js (ID 794230808053141) and snap.licdn.com/insight.min.js (pid=2375994) — advertising pixels. facebook.com/tr/?ev=PageView (+2790 ms), linkedin /collect and /wa (+2345–2793 ms).

Declared versus actual

+ Google Tag Manager — not mentioned — не заявлен
+ Adobe Fonts / Typekit — not mentioned — не заявлен
+ HubSpot — not mentioned — не заявлен
+ Meta Pixel — not mentioned — не заявлен
+ LinkedIn Insight Tag — not mentioned — не заявлен
+ Google reCAPTCHA — not mentioned — не заявлен
+ Weglot — not mentioned — не заявлен
+ pressebox.de — not mentioned — не заявлен
+ Cookie-Script — not mentioned — не заявлен

Transfer timings

+253 ms use.typekit.net

Adobe Fonts. Typekit. Tracking pixel p.gif. Before the banner.

+254 ms www.google.com / www.gstatic.com

Google reCAPTCHA. Before the banner.

+254 ms cdn.weglot.com

Weglot (translator). Before the banner.

+293 ms www.googletagmanager.com

GTM-WDTZPGC. Tag container. Before the banner.

+583 ms js.hs-scripts.com (+ 8 domains)

HubSpot Marketing Hub. portalId=5375305. Effectively simultaneous with the banner.

+2050 ms connect.facebook.net / www.facebook.com

Meta Pixel. ID 794230808053141. PageView.

+2051 ms snap.licdn.com / px.ads.linkedin.com

LinkedIn Insight Tag. pid=2375994.

Detected trackers

Indicators of GDPR non-compliance

Context

Hofer Powertrain (hofer consulting GmbH) is an engineering contractor specializing in electric drivetrains and powertrains, based in Weissach (Baden-Württemberg). Clients include automakers and Tier 1 suppliers. Webflow, Cloudflare. HAR: 63 requests, 27 domains.

The policy — auto-generated boilerplate

The privacy policy (effective date: 2025-10-01) was generated by the CookieScript Privacy Policy Generator tool — this is explicitly stated in the document text. The policy names not a single specific data recipient: instead of “HubSpot,” “Meta,” “LinkedIn,” it uses abstract phrases like “online analytics tools” and “third party service providers.” GDPR Art. 13(1)(e) requires specific recipients or categories of recipients of personal data to be named.

The first wave — before the banner

At +253–294 ms, before Cookie-Script even loads (+577 ms), the following activate: Adobe Fonts/Typekit with a usage-tracking pixel (p.typekit.net/p.gif), Google reCAPTCHA (www.google.com, www.gstatic.com), Weglot — a translator that transmits the URL and browser language, Google Tag Manager (GTM-WDTZPGC), and pressebox.de — a German press aggregator with a JavaScript counter.

HubSpot — a full marketing stack

At +583 ms, js.hs-scripts.com/5375305.js starts — Hub ID 5375305. It is followed by the full HubSpot Marketing Hub stack: hsadspixel (advertising pixels), hscollectedforms (form-data collection), hs-analytics (behavioral analytics), hs-banner (CRM banners), hsforms and hubapi (forms and API). The final request, track.hubspot.com/__ptq.gif, carries a screen resolution of 1536x864, a browser language of ru, and a fingerprint hash of bfp=2df8a04b.

Meta Pixel and LinkedIn Insight Tag

Meta Pixel (ID 794230808053141) and LinkedIn Insight Tag (pid=2375994) load at +2050–2051 ms and transmit a PageView event carrying the full visited URL to advertising-platform servers in the USA. By this point, Cookie-Script has already been displayed for over a second and a half — consent has not been obtained.

Conclusion

www.hoferpowertrain.com shows a systemic pattern of GDPR non-compliance: nine external advertising and analytics operators are active before consent is obtained, and the privacy policy identifies not a single one of them. For the corporate website of a B2B automotive-industry supplier with access to clients’ sensitive engineering data, this is an unusually high level of violations.

Evidence
Original (audit)
HAR file: de/hoferpowertrain-com-2026-05-29.har
SHA-256: d10e44ea4f1145b40ed45a63e9e8b9e5578f20fe7aef060a4e2acbac43c1d671
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Federal Commissioner for Data Protection (BfDI)file a complaint online →

To: Federal Commissioner for Data Protection (BfDI)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website hoferpowertrain.com.

2. Circumstances
I visited the website hoferpowertrain.com and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 29 May 2026 (open methodology, reproducible measurements) documents the following indications:

1) Google Tag Manager (GTM-WDTZPGC, +293 ms), Adobe Fonts/Typekit (use.typekit.net, +253 ms; p.typekit.net pixel +290 ms), Google reCAPTCHA (www.google.com, +254 ms), Weglot (cdn.weglot.com, +254 ms), and pressebox.de (i2l.pressebox.de, +294 ms) all activate before Cookie-Script (+577 ms). Browser and IP data is transmitted to at least five external operators without consent.

2) HubSpot loads at +583 ms (js.hs-scripts.com/5375305.js) — 6 ms after Cookie-Script, effectively simultaneously. It is followed by 8 additional HubSpot domains: hsadspixel, hscollectedforms, hs-analytics, hs-banner, hsforms, hubapi, track.hubspot.com (__ptq.gif carrying a screen resolution of 1536x864, language ru, fingerprint bfp=2df8a04b). The full HubSpot Marketing Hub stack is active without user consent.

3) Meta Pixel (ID 794230808053141) and LinkedIn Insight Tag (pid=2375994) load at +2050–2051 ms. Facebook's /tr/?ev=PageView and LinkedIn's /collect transmit the visited URL, browser parameters, and advertising-platform identifiers. Cookie-Script has already loaded by this point (+577 ms), but consent has not been obtained.

4) The privacy policy was generated by the CookieScript Privacy Policy Generator tool (explicitly stated in the text). It does not name a single specific service — not HubSpot, not LinkedIn, not Meta, not GTM, not Weglot, not Adobe Fonts. It describes only abstract categories ('analytics tools', 'marketing initiatives'). This violates Art. 13(1)(e): data recipients are not identified.

Full technical documentation is published at: https://gdpru.eu/en/audits/de-hoferpowertrain-com-de/

3. Provisions violated
GDPR Art. 5(1)(a); TDDDG § 25(1); GDPR Art. 5(1)(a); TDDDG § 25(1); GDPR Art. 5(1)(a); TDDDG § 25(1); GDPR Art. 13(1)(e)

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]