hoferpowertrain.com
An engineering contractor for electric drivetrains (Weissach, Germany). 63 requests, 27 domains. Webflow, Cloudflare. GTM, Adobe Fonts, Google reCAPTCHA, Weglot, HubSpot, Meta Pixel, LinkedIn Insight Tag — all fire before or without consent. The Cookie-Script CMP appears at +577 ms, by which time most trackers are already active. The policy is auto-generated boilerplate with no mention of specific operators.
Timeline of the leak
Declared versus actual
Transfer timings
Adobe Fonts. Typekit. Tracking pixel p.gif. Before the banner.
Google reCAPTCHA. Before the banner.
Weglot (translator). Before the banner.
GTM-WDTZPGC. Tag container. Before the banner.
HubSpot Marketing Hub. portalId=5375305. Effectively simultaneous with the banner.
Meta Pixel. ID 794230808053141. PageView.
LinkedIn Insight Tag. pid=2375994.
Detected trackers
- Google Tag Manager (www.googletagmanager.com) — tag container, before the banner
- Adobe Fonts / Typekit (use.typekit.net, p.typekit.net) — fonts with tracking, before the banner
- Google reCAPTCHA (www.google.com, www.gstatic.com) — before the banner
- Weglot (cdn.weglot.com) — translator, before the banner
- HubSpot (js.hs-scripts.com and 8 subdomains) — CRM and marketing, before and after the banner
- Meta Pixel (connect.facebook.net, www.facebook.com) — advertising pixel
- LinkedIn Insight Tag (snap.licdn.com, px.ads.linkedin.com) — advertising pixel
- pressebox.de (i2l.pressebox.de) — press aggregator, before the banner
- Cookie-Script (cdn.cookie-script.com) — CMP
Indicators of GDPR non-compliance
- GDPR Art. 5(1)(a); TDDDG § 25(1)Google Tag Manager (GTM-WDTZPGC, +293 ms), Adobe Fonts/Typekit (use.typekit.net, +253 ms; p.typekit.net pixel +290 ms), Google reCAPTCHA (www.google.com, +254 ms), Weglot (cdn.weglot.com, +254 ms), and pressebox.de (i2l.pressebox.de, +294 ms) all activate before Cookie-Script (+577 ms). Browser and IP data is transmitted to at least five external operators without consent.
- GDPR Art. 5(1)(a); TDDDG § 25(1)HubSpot loads at +583 ms (js.hs-scripts.com/5375305.js) — 6 ms after Cookie-Script, effectively simultaneously. It is followed by 8 additional HubSpot domains: hsadspixel, hscollectedforms, hs-analytics, hs-banner, hsforms, hubapi, track.hubspot.com (__ptq.gif carrying a screen resolution of 1536x864, language ru, fingerprint bfp=2df8a04b). The full HubSpot Marketing Hub stack is active without user consent.
- GDPR Art. 5(1)(a); TDDDG § 25(1)Meta Pixel (ID 794230808053141) and LinkedIn Insight Tag (pid=2375994) load at +2050–2051 ms. Facebook's /tr/?ev=PageView and LinkedIn's /collect transmit the visited URL, browser parameters, and advertising-platform identifiers. Cookie-Script has already loaded by this point (+577 ms), but consent has not been obtained.
- GDPR Art. 13(1)(e)The privacy policy was generated by the CookieScript Privacy Policy Generator tool (explicitly stated in the text). It does not name a single specific service — not HubSpot, not LinkedIn, not Meta, not GTM, not Weglot, not Adobe Fonts. It describes only abstract categories ('analytics tools', 'marketing initiatives'). This violates Art. 13(1)(e): data recipients are not identified.
Context
Hofer Powertrain (hofer consulting GmbH) is an engineering contractor specializing in electric drivetrains and powertrains, based in Weissach (Baden-Württemberg). Clients include automakers and Tier 1 suppliers. Webflow, Cloudflare. HAR: 63 requests, 27 domains.
The policy — auto-generated boilerplate
The privacy policy (effective date: 2025-10-01) was generated by the CookieScript Privacy Policy Generator tool — this is explicitly stated in the document text. The policy names not a single specific data recipient: instead of “HubSpot,” “Meta,” “LinkedIn,” it uses abstract phrases like “online analytics tools” and “third party service providers.” GDPR Art. 13(1)(e) requires specific recipients or categories of recipients of personal data to be named.
The first wave — before the banner
At +253–294 ms, before Cookie-Script even loads (+577 ms), the following activate: Adobe Fonts/Typekit with a usage-tracking pixel (p.typekit.net/p.gif), Google reCAPTCHA (www.google.com, www.gstatic.com), Weglot — a translator that transmits the URL and browser language, Google Tag Manager (GTM-WDTZPGC), and pressebox.de — a German press aggregator with a JavaScript counter.
HubSpot — a full marketing stack
At +583 ms, js.hs-scripts.com/5375305.js starts — Hub ID 5375305. It is followed by the full HubSpot Marketing Hub stack: hsadspixel (advertising pixels), hscollectedforms (form-data collection), hs-analytics (behavioral analytics), hs-banner (CRM banners), hsforms and hubapi (forms and API). The final request, track.hubspot.com/__ptq.gif, carries a screen resolution of 1536x864, a browser language of ru, and a fingerprint hash of bfp=2df8a04b.
Meta Pixel and LinkedIn Insight Tag
Meta Pixel (ID 794230808053141) and LinkedIn Insight Tag (pid=2375994) load at +2050–2051 ms and transmit a PageView event carrying the full visited URL to advertising-platform servers in the USA. By this point, Cookie-Script has already been displayed for over a second and a half — consent has not been obtained.
Conclusion
www.hoferpowertrain.com shows a systemic pattern of GDPR non-compliance: nine external advertising and analytics operators are active before consent is obtained, and the privacy policy identifies not a single one of them. For the corporate website of a B2B automotive-industry supplier with access to clients’ sensitive engineering data, this is an unusually high level of violations.
d10e44ea4f1145b40ed45a63e9e8b9e5578f20fe7aef060a4e2acbac43c1d671Where to file: Federal Commissioner for Data Protection (BfDI) — file a complaint online →
To: Federal Commissioner for Data Protection (BfDI)
From: [Your name], [contact email]
1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website hoferpowertrain.com.
2. Circumstances
I visited the website hoferpowertrain.com and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 29 May 2026 (open methodology, reproducible measurements) documents the following indications:
1) Google Tag Manager (GTM-WDTZPGC, +293 ms), Adobe Fonts/Typekit (use.typekit.net, +253 ms; p.typekit.net pixel +290 ms), Google reCAPTCHA (www.google.com, +254 ms), Weglot (cdn.weglot.com, +254 ms), and pressebox.de (i2l.pressebox.de, +294 ms) all activate before Cookie-Script (+577 ms). Browser and IP data is transmitted to at least five external operators without consent.
2) HubSpot loads at +583 ms (js.hs-scripts.com/5375305.js) — 6 ms after Cookie-Script, effectively simultaneously. It is followed by 8 additional HubSpot domains: hsadspixel, hscollectedforms, hs-analytics, hs-banner, hsforms, hubapi, track.hubspot.com (__ptq.gif carrying a screen resolution of 1536x864, language ru, fingerprint bfp=2df8a04b). The full HubSpot Marketing Hub stack is active without user consent.
3) Meta Pixel (ID 794230808053141) and LinkedIn Insight Tag (pid=2375994) load at +2050–2051 ms. Facebook's /tr/?ev=PageView and LinkedIn's /collect transmit the visited URL, browser parameters, and advertising-platform identifiers. Cookie-Script has already loaded by this point (+577 ms), but consent has not been obtained.
4) The privacy policy was generated by the CookieScript Privacy Policy Generator tool (explicitly stated in the text). It does not name a single specific service — not HubSpot, not LinkedIn, not Meta, not GTM, not Weglot, not Adobe Fonts. It describes only abstract categories ('analytics tools', 'marketing initiatives'). This violates Art. 13(1)(e): data recipients are not identified.
Full technical documentation is published at: https://gdpru.eu/en/audits/de-hoferpowertrain-com-de/
3. Provisions violated
GDPR Art. 5(1)(a); TDDDG § 25(1); GDPR Art. 5(1)(a); TDDDG § 25(1); GDPR Art. 5(1)(a); TDDDG § 25(1); GDPR Art. 13(1)(e)
4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.
5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.
[Date] [Signature / name]