Technical audit · 2026-06-06

yaga.ee

Estonian Secondhand Marketplace

An Estonian C2C secondhand marketplace. GTM and the Facebook Pixel load 736 ms before Cookiebot. Facebook sends 10 requests over a 47-second session. Sentry uses an EU instance — a deliberate choice.

Timeline of the leak

+346 ms · before the banner
Google Maps API — key AIzaSyDQQj4fXgkexlApFDckAeTMz65ShjAbFPQ. Data goes to Google, USA.
+348 ms · before the banner
Google User Content (lh3.googleusercontent.com) — user profile photos served via Google. USA.
+419 ms · before the banner
Google Fonts (fonts.gstatic.com) — Roboto. The IP address goes to Google, USA.
+1180 ms · before the banner
Sentry EU (ingest.de.sentry.io) — error monitoring. Germany, data stays in the EU.
+1537 ms · before the banner
GTM (GTM-P7QZL64G) — 736 ms before Cookiebot.
+1558 ms · before the banner
Facebook Pixel (fbevents.js, ID: 1378234733239717) — 715 ms before Cookiebot.
+2273 ms · banner
Cookiebot loads via GTM (implementation=gtm).
+2328 ms
Google Ads collect (page_view) — data goes to Google, USA.
+2614 ms
GA4 collect — G-XHXVNW7707. Data goes to Google, USA.
+17321 ms
mpc2-prod-23.a.run.app — Google Cloud Run. Yaga's own backend, hosted on Google infrastructure.
+17328 ms
Facebook PageView — the page URL is transmitted to Meta.

Declared versus actual

Google — mentioned as an authentication provider — заявлен
Facebook — mentioned as an authentication provider — заявлен
+ Google Maps API — не заявлен
+ Google Ads (AW-833230941) — не заявлен
+ Google User Content (lh3.googleusercontent.com) — не заявлен
+ mpc2-prod-23.a.run.app (Google Cloud Run) — не заявлен

Transfer timings

+346 ms maps.googleapis.com

Google Maps API with an exposed key

+1537 ms www.googletagmanager.com

GTM-P7QZL64G — 736 ms before Cookiebot

+1558 ms connect.facebook.net

Facebook Pixel — 715 ms before Cookiebot

+2273 ms consent.cookiebot.com

Cookiebot loading via GTM

+17328 ms www.facebook.com

Facebook PageView — 10 requests over the session

Detected trackers

Indicators of GDPR non-compliance

Context

Yaga OÜ (registration code 14203706, Tallinn) is an Estonian C2C secondhand marketplace, comparable to Vinted. The policy, updated 01.09.2025, describes the processing of user data, including transaction data, in detail. HAR: 175 requests, 15 domains. A 47-second session involving browsing of listings.

GTM and Facebook ahead of Cookiebot — a 736 ms gap

GTM loads at +1537 ms; the Facebook Pixel at +1558 ms. Cookiebot appears at +2273 ms. The gap is 736 ms. Cookiebot, moreover, loads via GTM (implementation=gtm) — meaning GTM should have been blocked until Cookiebot ran, not the reverse. The configuration inverts the intended logic: the consent tool depends on the very tool it is supposed to control.

Facebook — 10 requests in 47 seconds

Facebook sends 10 requests over the session: script loading, pixel configuration, PageView events, and the SDK. The last request occurs at +41758 ms. Facebook records every significant moment of the session, including views of specific listings (view_item_list, view_item).

Google User Content — profile photos via Google

User profile photos are loaded from lh3.googleusercontent.com — meaning Yaga uses Google OAuth for authentication and stores links to Google-hosted photos. On every visit to the home page, the user’s IP address is transmitted to Google via requests for other users’ avatars.

mpc2-prod — Google Cloud Run

mpc2-prod-23-is5qnl632q-ue.a.run.app is Google Cloud Run, Google’s PaaS platform. Yaga hosts part of its backend on Google Cloud (region ue — US East). This is not a tracker, but the fact of data transfer to Google Cloud USA infrastructure should be disclosed.

Sentry EU — the correct choice

ingest.de.sentry.io is Sentry’s EU instance, based in Germany. This is the fourth site in the series — after IIZI, Zalando, and SmartPost — where error monitoring has been deliberately kept within the EU.

Conclusion

Yaga is an Estonian C2C platform with a detailed privacy policy. But GTM loads 736 ms before Cookiebot, Facebook sends 10 requests over the session, and the Google Maps API, using an exposed key, transmits data immediately. Loading Cookiebot via GTM is an architectural error: a consent tool cannot load through the very tool it is meant to control.

Evidence
Original (audit)
HAR file: ee/yaga-ee-2026-06-06.har
SHA-256: ecc2fb19ba3ff16a7c6f94b454a99d5c79f878032b8b4eb1a445736f8c7b2498
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Estonian Data Protection Inspectorate (AKI) — write to info@aki.ee

Important: AKI only handles submissions in Estonian. Translate the letter before sending.

To: Estonian Data Protection Inspectorate (AKI)
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website yaga.ee.

2. Circumstances
I visited the website yaga.ee and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 6 June 2026 (open methodology, reproducible measurements) documents the following indications:

1) GTM (+1537 ms) and the Facebook Pixel (+1558 ms) load 736 ms before Cookiebot (+2273 ms). Google Maps API (+346 ms) and Google User Content (+348 ms) fire immediately. The GA collect call goes out at +2614 ms; the Facebook PageView call at +17328 ms.

2) Cookiebot appears after 2273 ms. By this point, GTM, Facebook Pixel, Google Maps, Google Fonts, Sentry, and Google User Content are already active. Facebook sends 10 requests over a 47-second session.

3) The privacy policy mentions Google and Facebook as authentication providers. Google Maps API, Google Ads, and mpc2-prod (Google Cloud Run) are not mentioned as data recipients.

4) Google Maps API, GA4, Google Ads, and Facebook — servers located in the USA. mpc2-prod.a.run.app — Google Cloud Run, USA. No transfer mechanism is specified.

Full technical documentation is published at: https://gdpru.eu/en/audits/ee-yaga-ee/

3. Provisions violated
GDPR Art. 6(1), Art. 5(1)(a); GDPR Art. 7; GDPR Art. 13(1)(e); GDPR Art. 13(1)(f), Chapter V

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]