Technical audit · 2026-06-06

loverte.com

Estonian online perfume and cosmetics store

An Estonian perfume store with 24 external domains. Google reCAPTCHA launches at +51 ms, and Klaviyo, with 14 requests, at +1644 ms. No consent banner is recorded in the HAR — only internal GDPR-related requests to GraphQL.

Timeline of the leak

+51 ms · before consent
Google reCAPTCHA (api.js + recaptcha__ru.js) — IP to Google, US. The browser's Russian locale is recorded.
+703 ms · before consent
Nosto (api.nosto.com) — a personalization platform, 3 GraphQL requests. Finland/US.
+1644 ms · before consent
Klaviyo (static.klaviyo.com) — email marketing and tracking. 14 requests during the session. US.
+1659 ms
loverte.com/graphql?query=gdprCookieData — an internal request for GDPR settings. Not a banner.
+2575 ms · before consent
GTM (GTM-N8Q799) + GA4 (G-BMZWHV927B) — load before any banner appears.
+2849 ms
Instagram CDN (scontent-hel3-1.cdninstagram.com) — photos from an Instagram feed. Meta, US.
+3981 ms
Facebook Pixel (fbevents.js, ID: 457353994820689) — loads.
+3987 ms
kk-resources.com/leadtag.js — an unidentified tracker. Jurisdiction unknown.
+4289 ms
Google Ads DoubleClick (viewthroughconversion) — a conversion pixel.
+4660 ms
Facebook PageView — page URL data goes out to Meta, US.

Declared versus actual

+ Google reCAPTCHA — не заявлен
+ Nosto (api.nosto.com) — не заявлен
+ Klaviyo (14 requests) — не заявлен
+ Facebook Pixel (ID: 457353994820689) — не заявлен
+ kk-resources.com (leadtag.js) — не заявлен
+ Adobe Typekit (use.typekit.net) — не заявлен
+ Instagram CDN — не заявлен
+ Google Ads / DoubleClick — не заявлен

Transfer timings

+51 ms www.google.com

reCAPTCHA, recaptcha__ru.js. US

+703 ms api.nosto.com

Personalization, 3 GraphQL requests

+1644 ms static.klaviyo.com

Klaviyo tracking, 14 requests

+2575 ms www.googletagmanager.com

GTM-N8Q799

+3981 ms connect.facebook.net

Facebook Pixel fbevents.js

+3987 ms s.kk-resources.com

leadtag.js — unidentified tracker

+4289 ms googleads.g.doubleclick.net

Conversion pixel

+4660 ms www.facebook.com

PageView — page URL to Meta

Detected trackers

Indicators of GDPR non-compliance

Context

loverte.com is an Estonian online perfume and cosmetics store, operated by Loverte OÜ. The site runs on Magento/Adobe Commerce and serves the Estonian market (/et/). HAR: 310 requests, 24 domains. The session was captured on the perfume catalog page.

The banner — code exists, no banner appears

The site makes requests to its own GraphQL endpoint with the parameter gdprCookieData — at +1659, +4062, and +4793 ms. This means GDPR-related logic exists in the code. But no actual consent banner is recorded in the HAR — not a single request to an external CMP (Cookiebot, Usercentrics, privacy-center, or similar). By the time these requests occur, reCAPTCHA, Nosto, Klaviyo, and GTM had already been running.

kk-resources.com — an unfamiliar recipient

s.kk-resources.com/leadtag.js (+3987 ms) — this domain is not mentioned in the policy and is not a known public service. Judging by its name (leadtag), this is a lead-generation tracker. Its jurisdiction and operator are unknown from the HAR.

Klaviyo — 14 requests

Klaviyo launches at +1644 ms and generates 14 requests during the session: script loading, company font configuration, full forms, geo-IP detection. This is an email-marketing platform that builds a visitor profile before the visitor has purchased or subscribed to anything.

Instagram CDN

The Instagram feed on the homepage loads images from Meta’s servers (scontent-hel3-1.cdninstagram.com) — the user’s IP is transmitted to Meta (US) on every visit to the homepage. Images with -hel3- in the domain point to a Helsinki CDN node, but the data still passes through Meta’s infrastructure.

The document describes cookie types (session, functional, analytics, marketing) without naming specific recipients. It mentions Google Analytics in general terms. Nosto, Klaviyo, Facebook Pixel, Adobe Typekit, and kk-resources.com — not a single specific name is given. Under Art. 13(1)(e), the user must know all recipients of their data.

Conclusion

310 requests, 24 domains, no consent banner recorded. reCAPTCHA starts at the 51st millisecond. Klaviyo begins building a visitor profile from the 1644th millisecond. Facebook receives a PageView with the page URL. The policy describes cookie categories but names not a single specific recipient. This is a typical picture for an average Estonian online store — much like euronics.ee earlier in the series, just with a different vendor mix.

Evidence
Original (audit)
HAR file: ee/loverte-com-2026-06-06.har
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Estonian Data Protection Inspectorate (AKI) — write to info@aki.ee

Important: AKI only handles submissions in Estonian. Translate the letter before sending.

To: Estonian Data Protection Inspectorate (AKI)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website loverte.com.

2. Circumstances
I visited the website loverte.com and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 6 June 2026 (open methodology, reproducible measurements) documents the following indications:

1) Google reCAPTCHA (+51 ms), Nosto (+703 ms), Klaviyo (+1644 ms), and GTM (+2575 ms) launch before any consent banner appears. The site makes a GDPR-related request to its own GraphQL endpoint at +1659 ms — but this is not a banner, it's an internal configuration check. No banner ever appears in the HAR.

2) No consent banner appears in the HAR. Requests to /graphql?query=gdprCookieData indicate the site queries GDPR settings — but no actual consent banner was recorded. The Facebook Pixel sends a PageView at +4660 ms.

3) The policy is a Cookie Policy that does not name specific recipients. Nosto, Klaviyo, kk-resources.com, Adobe Typekit, and Instagram CDN are not mentioned. Only Google Analytics is mentioned, in general terms.

4) Google (US), Facebook (US), Klaviyo (US), Nosto (Finland/US), Adobe Typekit (US), kk-resources.com (unknown jurisdiction) — a data-transfer mechanism is not specified for any of them.

Full technical documentation is published at: https://gdpru.eu/en/audits/ee-loverte-com/

3. Provisions violated
GDPR Art. 6(1), Art. 5(1)(a); GDPR Art. 7; GDPR Art. 13(1)(e); GDPR Art. 13(1)(f), Chapter V

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]