An Estonian C2C secondhand marketplace. GTM and the Facebook Pixel load 736 ms before Cookiebot. Facebook sends 10 requests over a 47-second session. Sentry uses an EU instance — a deliberate choice.
Timeline of the leak
Declared versus actual
Transfer timings
Google Maps API with an exposed key
GTM-P7QZL64G — 736 ms before Cookiebot
Facebook Pixel — 715 ms before Cookiebot
Cookiebot loading via GTM
Facebook PageView — 10 requests over the session
Detected trackers
- Google Tag Manager (GTM-P7QZL64G)
- Google Analytics GA4 (G-XHXVNW7707)
- Google Ads (AW-833230941)
- Google Maps API
- Google User Content (lh3.googleusercontent.com)
- Facebook Pixel (ID: 1378234733239717)
- Facebook SDK
- Google Fonts (fonts.gstatic.com)
- Sentry EU (ingest.de.sentry.io)
- GrowthBook (api-growthbook.yaga.ee)
- Google Cloud Run (mpc2-prod-23.a.run.app)
Indicators of GDPR non-compliance
- GDPR Art. 6(1), Art. 5(1)(a)GTM (+1537 ms) and the Facebook Pixel (+1558 ms) load 736 ms before Cookiebot (+2273 ms). Google Maps API (+346 ms) and Google User Content (+348 ms) fire immediately. The GA collect call goes out at +2614 ms; the Facebook PageView call at +17328 ms.
- GDPR Art. 7Cookiebot appears after 2273 ms. By this point, GTM, Facebook Pixel, Google Maps, Google Fonts, Sentry, and Google User Content are already active. Facebook sends 10 requests over a 47-second session.
- GDPR Art. 13(1)(e)The privacy policy mentions Google and Facebook as authentication providers. Google Maps API, Google Ads, and mpc2-prod (Google Cloud Run) are not mentioned as data recipients.
- GDPR Art. 13(1)(f), Chapter VGoogle Maps API, GA4, Google Ads, and Facebook — servers located in the USA. mpc2-prod.a.run.app — Google Cloud Run, USA. No transfer mechanism is specified.
Context
Yaga OÜ (registration code 14203706, Tallinn) is an Estonian C2C secondhand marketplace, comparable to Vinted. The policy, updated 01.09.2025, describes the processing of user data, including transaction data, in detail. HAR: 175 requests, 15 domains. A 47-second session involving browsing of listings.
GTM and Facebook ahead of Cookiebot — a 736 ms gap
GTM loads at +1537 ms; the Facebook Pixel at +1558 ms. Cookiebot appears at +2273 ms. The gap is 736 ms. Cookiebot, moreover, loads via GTM (implementation=gtm) — meaning GTM should have been blocked until Cookiebot ran, not the reverse. The configuration inverts the intended logic: the consent tool depends on the very tool it is supposed to control.
Facebook — 10 requests in 47 seconds
Facebook sends 10 requests over the session: script loading, pixel configuration, PageView events, and the SDK. The last request occurs at +41758 ms. Facebook records every significant moment of the session, including views of specific listings (view_item_list, view_item).
Google User Content — profile photos via Google
User profile photos are loaded from lh3.googleusercontent.com — meaning Yaga uses Google OAuth for authentication and stores links to Google-hosted photos. On every visit to the home page, the user’s IP address is transmitted to Google via requests for other users’ avatars.
mpc2-prod — Google Cloud Run
mpc2-prod-23-is5qnl632q-ue.a.run.app is Google Cloud Run, Google’s PaaS platform. Yaga hosts part of its backend on Google Cloud (region ue — US East). This is not a tracker, but the fact of data transfer to Google Cloud USA infrastructure should be disclosed.
Sentry EU — the correct choice
ingest.de.sentry.io is Sentry’s EU instance, based in Germany. This is the fourth site in the series — after IIZI, Zalando, and SmartPost — where error monitoring has been deliberately kept within the EU.
Conclusion
Yaga is an Estonian C2C platform with a detailed privacy policy. But GTM loads 736 ms before Cookiebot, Facebook sends 10 requests over the session, and the Google Maps API, using an exposed key, transmits data immediately. Loading Cookiebot via GTM is an architectural error: a consent tool cannot load through the very tool it is meant to control.
ecc2fb19ba3ff16a7c6f94b454a99d5c79f878032b8b4eb1a445736f8c7b2498Where to file: Estonian Data Protection Inspectorate (AKI) — write to info@aki.ee
Important: AKI only handles submissions in Estonian. Translate the letter before sending.
To: Estonian Data Protection Inspectorate (AKI) From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website yaga.ee. 2. Circumstances I visited the website yaga.ee and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 6 June 2026 (open methodology, reproducible measurements) documents the following indications: 1) GTM (+1537 ms) and the Facebook Pixel (+1558 ms) load 736 ms before Cookiebot (+2273 ms). Google Maps API (+346 ms) and Google User Content (+348 ms) fire immediately. The GA collect call goes out at +2614 ms; the Facebook PageView call at +17328 ms. 2) Cookiebot appears after 2273 ms. By this point, GTM, Facebook Pixel, Google Maps, Google Fonts, Sentry, and Google User Content are already active. Facebook sends 10 requests over a 47-second session. 3) The privacy policy mentions Google and Facebook as authentication providers. Google Maps API, Google Ads, and mpc2-prod (Google Cloud Run) are not mentioned as data recipients. 4) Google Maps API, GA4, Google Ads, and Facebook — servers located in the USA. mpc2-prod.a.run.app — Google Cloud Run, USA. No transfer mechanism is specified. Full technical documentation is published at: https://gdpru.eu/en/audits/ee-yaga-ee/ 3. Provisions violated GDPR Art. 6(1), Art. 5(1)(a); GDPR Art. 7; GDPR Art. 13(1)(e); GDPR Art. 13(1)(f), Chapter V 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]