Technical audit · 2026-08-16

fontawesome.com

Font Awesome icon and font library

The Font Awesome icon library — 140 requests, 20 nodes, a 52-second recording. The home page, without consent, starts Google analytics, the DoubleClick advertising linkage and the BuySellAds advertising network: the client identifier goes to Google in the third second, before any user choice. The policy names Google Analytics, Stripe and Help Scout, but the advertising technologies BuySellAds and DoubleClick, as well as reCAPTCHA and a third-party font service, are not disclosed in it. Meanwhile the policy states outright that the site does not respond to the Do Not Track signal — and the browser was sending it during capture.

Timeline of the leak

+0 ms · loading the home page
The recording begins on fontawesome.com. Served through Cloudflare (server: cloudflare). Set: strict transport with subdomain inclusion and preload, the frame-embedding ban SAMEORIGIN, the content-type-sniffing ban, the referrer policy strict-origin-when-cross-origin. There is no content-security-policy and no permissions policy. The browser was sending the DNT: 1 header.
+751…+753 ms · third-party services from the markup
From the home page's parser, Google Tag Manager, Stripe, the BuySellAds advertising network (monetization.js) and reCAPTCHA (google.com) start simultaneously. The initiator of all of them is the fontawesome.com page itself.
+813 ms · third-party fonts
fonts.bunny.net — a third-party font service, pulled in from the site's stylesheet.
+3693…+3697 ms · transmission to Google and the advertising linkage
POST to region1.analytics.google.com/g/collect: property G-BPMS41FJD2, client identifier, page URL and title, page_view event. Immediately after — a request to stats.g.doubleclick.net with the same client identifier: Google's advertising linkage.
+12778…+14539 ms · Stripe fingerprinting
The chain m.stripe.network and m.stripe.com — collection of device characteristics by the Stripe payment system, initiated already on the home page, before any payment step.
+14569 ms · support chat
beacon-v2.helpscout.net — the Help Scout support widget, initiated by the home page markup.

Declared versus actual

Controller — Fonticons, Inc. (Font Awesome); privacy policy, updated 11 November 2024 — заявлен
When visiting fontawesome.com, cookies, server logs and other methods are used to collect data about the pages viewed — заявлен
Recipients named: Google Analytics, Stripe (payments), Help Scout, as well as other services (AWS, Basecamp, etc.) — заявлен
Cookie management — the 'Cookie Preferences' link in the footer and browser settings — заявлен
Opt-out from Google Analytics — via a browser extension — заявлен
Font Awesome does not respond to the Do Not Track header — заявлен
Data is stored on servers in the USA; the delivery-network nodes are worldwide — заявлен
Compliance with the GDPR and participation in the EU-U.S. Data Privacy Framework are declared; information about the user is not sold or given to other companies — заявлен
+ BuySellAds — advertising network, monetization script, not named — не заявлен
+ Google DoubleClick — advertising linkage, receives the client identifier, not named — не заявлен
+ Google Tag Manager — the tag loader, not named — не заявлен
+ reCAPTCHA (google.com, gstatic.com) — the check, not named — не заявлен
+ Bunny Fonts — third-party font service, not named — не заявлен
+ Ignoring the Do Not Track signal in the absence of a consent mechanism — не заявлен

Transfer timings

+751 ms www.googletagmanager.com

Google Tag Manager, loads the GA4 counter.

+753 ms m.servedby-buysellads.com

BuySellAds advertising network, monetization script.

+753 ms js.stripe.com

Stripe payment system.

+753 ms www.google.com

reCAPTCHA.

+3693 ms region1.analytics.google.com

GA4 G-BPMS41FJD2, client identifier, page_view.

+3697 ms stats.g.doubleclick.net

DoubleClick advertising linkage, the same client identifier.

+813 ms fonts.bunny.net

Third-party font service.

+14569 ms beacon-v2.helpscout.net

Help Scout support chat.

Detected trackers

Indicators of GDPR non-compliance

Context

fontawesome.com is the site of the Font Awesome icon and font library (controller — Fonticons, Inc.). The site is served through Cloudflare (server: cloudflare). Besides the main domain, the own infrastructure comprises the icon-delivery nodes: site-assets.fontawesome.com, e.fontawesome.com, ka-f.fontawesome.com, use.fortawesome.com.

The recording: 140 requests, 20 nodes, a recording length of 52.4 seconds, taken on 16 August 2026. The recording covers the home page. Besides the own nodes, the page addresses third-party recipients: Google (Tag Manager, Analytics 4, DoubleClick, reCAPTCHA), the BuySellAds advertising network, the Stripe payment system, the Help Scout support chat, the Bunny Fonts font service, and a CloudFront node.

The processing is described by the Font Awesome privacy policy, updated 11 November 2024: sections on data collection when visiting, on the delivery network, on account and payment data, on the user’s choices, on storage and transfer, on GDPR compliance and the EU-U.S. Data Privacy Framework.

Who receives data directly

Google (Analytics, DoubleClick, Tag Manager, reCAPTCHA), BuySellAds, Stripe, Help Scout, Bunny Fonts.

Declared versus actual

The policy names some recipients — but not the advertising technologies. The document is honest in one respect: it names Google Analytics directly, Stripe as the payment system and Help Scout, and also provides a list of other services (AWS, Basecamp and others). But the advertising circuit is absent from the policy. There is neither the BuySellAds advertising network, whose monetization script loads at +753 ms, nor the DoubleClick advertising node receiving the client identifier, nor Google Tag Manager, nor reCAPTCHA, nor the third-party font service Bunny Fonts.

Added weight comes from the fact that the policy, in the section on data transfer, states outright: information about the user is not sold or given to other companies. BuySellAds and DoubleClick are precisely advertising technologies, and their presence contradicts this wording.

There is no consent mechanism, and Do Not Track is deliberately ignored. Across 140 requests there was neither a consent-management platform nor a script bearing the marks of a banner. Google analytics, the DoubleClick advertising linkage, the BuySellAds advertising network and reCAPTCHA are initiated by the home page markup in the first few hundred milliseconds, and the first Google Analytics 4 request with the client identifier goes out at +3693 ms — all before any user choice. Moreover, the policy states outright that the site does not respond to the Do Not Track header. During capture the browser was sending DNT: 1, and this indeed affected neither the composition nor the addressing of the requests. The policy relegates cookie management to a footer link and browser settings, and offers opt-out from Google Analytics only via a browser extension — that is, it shifts it onto the user.

The client identifier goes to the advertising linkage. The GA4 request carries the cid field next to the page URL and title; immediately after, the same identifier goes to stats.g.doubleclick.net — Google’s advertising node. The consent-mode marker gcd in the request corresponds to the default state, but the data is nonetheless sent.

Stripe collects device characteristics in advance. The chain m.stripe.network and m.stripe.com — collection of device characteristics by the payment system — is initiated already on the home page, before any payment step. For a subscription site, the presence of Stripe is justified on the payment page, but not on the first page of the visit.

Security headers are set in part. The site sets strict transport with subdomain inclusion and the preload marker, the frame-embedding ban SAMEORIGIN, the content-type-sniffing ban and a referrer policy. But there is no content-security-policy and no permissions policy. On a page loading advertising and payment third-party code, the absence of a content-security-policy means that the list of trusted script sources is in no way restricted.

Proven: there is no consent mechanism on the site. Across 140 requests there is not a single request to a consent-management platform and not a single script bearing the marks of a banner. The names of known platforms and general markers in addresses and initiators were checked; zero matches.

Proven: analytics and advertising do not depend on the user’s choice. The scripts for Google Tag Manager, the GA4 counter, DoubleClick, BuySellAds and reCAPTCHA are initiated by the home page markup and run when the browser parses it, at +751…+3697 ms. There is no condition before them.

Proven: the client identifier goes to Google and to the advertising linkage. The cid field stands in the GA4 requests and is repeated in the request to DoubleClick.

Proven: the Do Not Track signal was ignored. The browser was sending DNT: 1, the policy openly admits that the site does not respond to this header, and the composition of the requests confirms it.

Not proven and not asserted: the state of cookies on the device. Cookie headers and response bodies were removed from the published file during sanitisation. All conclusions rest on addresses, initiators, response codes and the composition of requests.

Boundaries of observation

The recording covers the home page of the site. The observation records the browser’s behaviour, not the services’ internal workings: server-side processing, contractual relationships with recipients and settings on their side are not verified by a browser recording.

The icon-delivery nodes site-assets.fontawesome.com, e.fontawesome.com, ka-f.fontawesome.com, use.fortawesome.com and img.fortawesome.com belong to Font Awesome’s own infrastructure and are not treated as third-party recipients. The presence of Stripe is justified by the subscription-payment function, but it is recorded that the collection of device characteristics starts already on the first page.

The file is published sanitised of personal data: cookie headers in requests and response bodies were removed. The conclusion that there is no consent mechanism rests on the absence of requests to consent platforms and of scripts bearing their marks. The full client identifier is not reproduced in the analysis.

The identification of services rests on domains and address patterns: Google Analytics 4 — by analytics.google.com/g/collect and the property G-BPMS41FJD2; DoubleClick — by stats.g.doubleclick.net; Google Tag Manager — by googletagmanager.com; reCAPTCHA — by google.com/recaptcha and gstatic.com; BuySellAds — by servedby-buysellads.com and the file monetization.js; Stripe — by stripe.com and stripe.network; Help Scout — by helpscout.net; the fonts — by fonts.bunny.net; the serving provider — by the server: cloudflare header.

Conclusion

The site of the Font Awesome icon library, on its home page, without consent, starts a full set of analytics and advertising: Google Analytics with the client identifier, the DoubleClick advertising linkage receiving the same identifier, and the BuySellAds advertising network. The privacy policy names Google Analytics, Stripe and Help Scout, but the advertising technologies BuySellAds and DoubleClick, as well as Google Tag Manager, reCAPTCHA and the third-party font service Bunny Fonts, are not disclosed in it — while the document states in a separate clause that information about the user is not given to other companies.

There is no consent mechanism on the site, and the policy states outright that the site does not respond to the Do Not Track signal. The browser was sending this signal during capture, and it was ignored: analytics, the advertising linkage and the advertising network operated in full. The policy shifts opt-out of tracking onto the user — through browser settings and a browser extension. Of the security headers, a content-security-policy and a permissions policy are absent.

Remediation: do not start analytics, the advertising linkage and the advertising network before consent is obtained — introduce a consent mechanism that actually governs their loading, with the option to refuse before they start; name all recipients of web data in the policy individually, including BuySellAds, DoubleClick, Google Tag Manager, reCAPTCHA and Bunny Fonts, with the fields transmitted and the purposes; bring the clause on not giving information to other companies into line with the actual presence of advertising technologies; begin responding to the Do Not Track header or provide an equivalent means of objection on the site itself; set a content-security-policy and a permissions policy.

Evidence
Original (audit)
HAR file: global/fontawesome-com-2026-08-16.har
SHA-256: f1fafd687ce1c3ed4d2ef8fc6fdc0cc136b02f4e40ceaa7eb8293bb7b4da7240
Re-check snapshot
Awaiting changes
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.
IMPORTANT: before filing a complaint with the regulator, first contact the company directly and give it 30 days to respond. Without this step the regulator may reject the complaint. Details and a template letter to the company are in the Methodology.
Ready-to-send complaint letter

Where to file: Jurisdiction determined under Art. 3(2) GDPR

To: Jurisdiction determined under Art. 3(2) GDPR
From: [Your name], [contact email]

1. Subject of the complaint
I am filing a complaint regarding the processing of my personal data by the website fontawesome.com.

2. Circumstances
I visited the website fontawesome.com and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 16 August 2026 (open methodology, reproducible measurements) documents the following indications:

1) There is no consent mechanism on the site: across 140 requests there is not a single request to a consent-management platform, not a single script bearing the marks of a banner, not a single Set-Cookie header. Google analytics, the DoubleClick advertising linkage, the BuySellAds advertising network and reCAPTCHA start from the home page markup at +751…+753 ms, and the first Google Analytics 4 request with the client identifier goes out at +3693 ms — all before any user choice. The policy relegates cookie management to a footer link and to browser settings, and offers opt-out from Google Analytics only via a browser extension.

2) The policy names Google Analytics, Stripe and Help Scout, but a number of recipients are not disclosed: the advertising network BuySellAds, the advertising node DoubleClick, Google Tag Manager, reCAPTCHA and the third-party font service Bunny Fonts are absent from the document. Meanwhile BuySellAds and DoubleClick are advertising technologies, and the policy states in a separate clause that information about the user is not sold or given to other companies.

3) The policy states outright that Font Awesome does not respond to the Do Not Track header. During capture the browser was sending the DNT: 1 header, and this affected neither the composition nor the addressing of the requests: analytics, the advertising linkage and the advertising network operated in full. Deliberately ignoring the opt-out-of-tracking signal, in the absence of any other consent mechanism, leaves the user without a working way to object to the collection.

4) Of the security headers the site sets strict transport with subdomain inclusion and the preload marker, the frame-embedding ban SAMEORIGIN, the content-type-sniffing ban and a referrer policy, but there is no content-security-policy and no permissions policy. On a page loading advertising and payment third-party code, the absence of a content-security-policy means that the list of trusted script sources is in no way restricted.

Full technical documentation is published at: https://gdpru.eu/en/audits/global-fontawesome-com/

3. Provisions violated
ePrivacy — Directive 2002/58/EC, Art. 5(3) (in conjunction with GDPR Art. 6(1)(a)); GDPR Art. 13(1)(e) — disclosure of recipients; GDPR Art. 21 — right to object (ignoring Do Not Track); GDPR Art. 32 — security measures

4. Request
I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR.

5. Attachments
The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above.

[Date]                                    [Signature / name]