Technical audit · 2026-03-28

puumarket.ee

Estonian Home Improvement and Hardware Retail Chain

853 requests, 13 domains. Google reCAPTCHA fires at the zero-millisecond mark, the Askly chat at +334 ms. A consent banner is wired in, but broken — status 0 on every attempted load. The privacy policy names not a single external data recipient.

Timeline of the leak

+0 ms · on load
Google reCAPTCHA (www.google.com) — webworker.js, status 200. Data to Google, USA. Before the banner.
+28 ms · before consent
www.gstatic.com — reCAPTCHA resources (logo). Data to Google.
+29 ms · before consent
fonts.gstatic.com — the Roboto typeface, status 200. IP address to Google, USA.
+334 ms · before consent
chat.askly.me — a support chat, a config request, status 200. A WebSocket connection at +1156 ms.
+1008 ms · before consent
fonts.googleapis.com — the Flow Circular, Lato, Montserrat, and Roboto font families. IP address to Google, USA.
+9957 ms · banner
cdn.cookie-script.com — the consent banner initiates a request, status 0. Fails to load. GTM and Klaviyo also return status 0.
+31651 ms
partners.lhv.ee — an LHV installment-payment widget for a specific product (price 1602.90, code EE-10363212).
+32135 ms
fast.fonts.net (Monotype) — a commercial font CDN. Data to the USA.

Declared versus actual

+ Google reCAPTCHA (www.google.com, www.gstatic.com) — не заявлен
+ Google Fonts (fonts.googleapis.com, fonts.gstatic.com) — не заявлен
+ The Askly chat (chat.askly.me, sessions.chat.askly.me) — не заявлен
+ Klaviyo (static.klaviyo.com) — не заявлен
+ Google Tag Manager (GTM-TSXS8GB) — не заявлен
+ Monotype / fast.fonts.net — не заявлен

Transfer timings

+0 ms www.google.com

reCAPTCHA webworker. Data to Google, USA

+29 ms fonts.gstatic.com

Roboto. IP address to Google, USA

+334 ms chat.askly.me

Support chat, config + WebSocket

+1008 ms fonts.googleapis.com

4 font families. IP address to Google

+9957 ms cdn.cookie-script.com

Consent banner — status 0, fails to load

+9960 ms static.klaviyo.com

Klaviyo — status 0

+10018 ms www.googletagmanager.com

GTM-TSXS8GB — status 0

+31651 ms partners.lhv.ee

The LHV installment widget

+32135 ms fast.fonts.net

Monotype CDN. USA

Detected trackers

Indicators of GDPR non-compliance

Context

Puumarket AS is an Estonian home improvement and hardware retail chain, registration number 10363212. The site operates as an online store, with a cart, online orders, and a loyalty program. HAR: 853 requests, 13 domains. The session included browsing products.

The central finding of this audit isn’t the trackers — it’s the consent mechanism. Cookie-script is wired into the code and initiates requests to cdn.cookie-script.com at +9957 ms — but every request returns status 0. The banner fails to load at all. Along with it, GTM (GTM-TSXS8GB, status 0) and Klaviyo (status 0) also fail to load. This means Cookie-script, GTM, and Klaviyo are blocked — likely by a CSP or a network error — and in this session, no data went out through them.

But this isn’t user protection — it’s an accidental block. By the time the banner should have appeared, three external services were already running with no consent whatsoever.

What runs before the banner

+0 ms — Google reCAPTCHA (www.google.com/recaptcha/api2/webworker.js) — the first request of the session. Data to Google (USA) before any interaction.

+28 mswww.gstatic.com — reCAPTCHA resources. Google.

+29 msfonts.gstatic.com — the Roboto typeface, status 200. IP address to Google, USA.

+334 mschat.askly.me — an Estonian support-chat service. A config request, status 200, followed by a WebSocket connection (wss://sessions.chat.askly.me) at +1156 ms. An active connection before consent.

+1008 msfonts.googleapis.com — four font families: Flow Circular, Lato, Montserrat, Roboto. IP address to Google, USA.

All five domains — status 200, data transmitted — within the first 10 seconds, before the banner is supposed to appear.

The privacy policy — no recipients named

The policy describes in detail what data Puumarket collects (name, address, phone, email, purchase data, IP address). It declares that data is transferred only where a lawful right exists. It names not a single specific recipient: not Google, not Askly, not Klaviyo, not Monotype. Under Art. 13(1)(e), the user is entitled to know all recipients — the policy does not meet this requirement.

The LHV installment widget

On the product page, a partners.lhv.ee widget loads with parameters for the specific product — price 1602.90, company code EE-10363212. LHV is an Estonian bank, and the data stays within the EEA. This is not a violation, but the fact that information about the product being viewed is transmitted to a bank’s infrastructure, unmentioned in the policy, is worth noting.

Conclusion

Puumarket has a consent banner — but it’s broken and fails to load. By the time it would have appeared, reCAPTCHA, Google Fonts, and Askly had already transmitted data. GTM and Klaviyo were accidentally blocked along with the banner. The privacy policy appears written in good faith, but it doesn’t meet the Art. 13(1)(e) requirement — specific data recipients are named nowhere.

Evidence
Original (audit)
HAR file: ee/puumarket-ee-2026-03-28.har
SHA-256: 5ffbc0ca497fb9c29d766586a763b6b00d4b4b6fc94e1f3d89a21b8693349039
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Estonian Data Protection Inspectorate (AKI) — write to info@aki.ee

Important: AKI only handles submissions in Estonian. Translate the letter before sending.

To: Estonian Data Protection Inspectorate (AKI)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website puumarket.ee.

2. Circumstances
I visited the website puumarket.ee and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 28 March 2026 (open methodology, reproducible measurements) documents the following indications:

1) Google reCAPTCHA (+0 ms), Google Fonts (+29 ms), and the Askly chat (+334 ms) fire within the first seconds of the session — before the cookie-script consent banner appears (+9957 ms). Data goes to the USA before any interaction with the banner.

2) The cookie-script consent banner is wired into the code and initiates requests, but all of them return status 0 — it fails to load. GTM and Klaviyo also return status 0. Meanwhile, reCAPTCHA, Google Fonts, and Askly operate normally (status 200) with no consent whatsoever.

3) The privacy policy does not mention Google reCAPTCHA, Google Fonts, Askly, Klaviyo, GTM, or fast.fonts.net as data recipients. Only data categories are listed, with no specific third parties named.

4) Google (USA), Askly (Estonia/USA), Klaviyo (USA), Monotype/fast.fonts.net (USA) — no data-transfer mechanism is stated for any recipient.

Full technical documentation is published at: https://gdpru.eu/en/audits/ee-puumarket-ee/

3. Provisions violated
GDPR Art. 6(1), Art. 5(1)(a); GDPR Art. 7; GDPR Art. 13(1)(e); GDPR Art. 13(1)(f), Chapter V

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]