The Font Awesome icon library — 140 requests, 20 nodes, a 52-second recording. The home page, without consent, starts Google analytics, the DoubleClick advertising linkage and the BuySellAds advertising network: the client identifier goes to Google in the third second, before any user choice. The policy names Google Analytics, Stripe and Help Scout, but the advertising technologies BuySellAds and DoubleClick, as well as reCAPTCHA and a third-party font service, are not disclosed in it. Meanwhile the policy states outright that the site does not respond to the Do Not Track signal — and the browser was sending it during capture.
Timeline of the leak
Declared versus actual
Transfer timings
Google Tag Manager, loads the GA4 counter.
BuySellAds advertising network, monetization script.
Stripe payment system.
reCAPTCHA.
GA4 G-BPMS41FJD2, client identifier, page_view.
DoubleClick advertising linkage, the same client identifier.
Third-party font service.
Help Scout support chat.
Detected trackers
- Google Analytics 4 (G-BPMS41FJD2) via region1.google-analytics.com — client identifier, page_view event goes out before consent
- Google DoubleClick (stats.g.doubleclick.net) — advertising linkage, receives the same client identifier
- BuySellAds (m.servedby-buysellads.com) — advertising network, monetization script, not disclosed in the policy
- Google Tag Manager (www.googletagmanager.com), reCAPTCHA (google.com, gstatic.com) — tag loader and check, not disclosed
- Bunny Fonts (fonts.bunny.net) — third-party font service, not disclosed
- Stripe (js.stripe.com, m.stripe.com, m.stripe.network), Help Scout (beacon-v2.helpscout.net) — payments and support, disclosed in the policy
Indicators of GDPR non-compliance
- ePrivacy — Directive 2002/58/EC, Art. 5(3) (in conjunction with GDPR Art. 6(1)(a))There is no consent mechanism on the site: across 140 requests there is not a single request to a consent-management platform, not a single script bearing the marks of a banner, not a single Set-Cookie header. Google analytics, the DoubleClick advertising linkage, the BuySellAds advertising network and reCAPTCHA start from the home page markup at +751…+753 ms, and the first Google Analytics 4 request with the client identifier goes out at +3693 ms — all before any user choice. The policy relegates cookie management to a footer link and to browser settings, and offers opt-out from Google Analytics only via a browser extension.
- GDPR Art. 13(1)(e) — disclosure of recipientsThe policy names Google Analytics, Stripe and Help Scout, but a number of recipients are not disclosed: the advertising network BuySellAds, the advertising node DoubleClick, Google Tag Manager, reCAPTCHA and the third-party font service Bunny Fonts are absent from the document. Meanwhile BuySellAds and DoubleClick are advertising technologies, and the policy states in a separate clause that information about the user is not sold or given to other companies.
- GDPR Art. 21 — right to object (ignoring Do Not Track)The policy states outright that Font Awesome does not respond to the Do Not Track header. During capture the browser was sending the DNT: 1 header, and this affected neither the composition nor the addressing of the requests: analytics, the advertising linkage and the advertising network operated in full. Deliberately ignoring the opt-out-of-tracking signal, in the absence of any other consent mechanism, leaves the user without a working way to object to the collection.
- GDPR Art. 32 — security measuresOf the security headers the site sets strict transport with subdomain inclusion and the preload marker, the frame-embedding ban SAMEORIGIN, the content-type-sniffing ban and a referrer policy, but there is no content-security-policy and no permissions policy. On a page loading advertising and payment third-party code, the absence of a content-security-policy means that the list of trusted script sources is in no way restricted.
Context
fontawesome.com is the site of the Font Awesome icon and font library (controller — Fonticons, Inc.). The site is served through Cloudflare (server: cloudflare). Besides the main domain, the own infrastructure comprises the icon-delivery nodes: site-assets.fontawesome.com, e.fontawesome.com, ka-f.fontawesome.com, use.fortawesome.com.
The recording: 140 requests, 20 nodes, a recording length of 52.4 seconds, taken on 16 August 2026. The recording covers the home page. Besides the own nodes, the page addresses third-party recipients: Google (Tag Manager, Analytics 4, DoubleClick, reCAPTCHA), the BuySellAds advertising network, the Stripe payment system, the Help Scout support chat, the Bunny Fonts font service, and a CloudFront node.
The processing is described by the Font Awesome privacy policy, updated 11 November 2024: sections on data collection when visiting, on the delivery network, on account and payment data, on the user’s choices, on storage and transfer, on GDPR compliance and the EU-U.S. Data Privacy Framework.
Who receives data directly
Google (Analytics, DoubleClick, Tag Manager, reCAPTCHA), BuySellAds, Stripe, Help Scout, Bunny Fonts.
Declared versus actual
The policy names some recipients — but not the advertising technologies. The document is honest in one respect: it names Google Analytics directly, Stripe as the payment system and Help Scout, and also provides a list of other services (AWS, Basecamp and others). But the advertising circuit is absent from the policy. There is neither the BuySellAds advertising network, whose monetization script loads at +753 ms, nor the DoubleClick advertising node receiving the client identifier, nor Google Tag Manager, nor reCAPTCHA, nor the third-party font service Bunny Fonts.
Added weight comes from the fact that the policy, in the section on data transfer, states outright: information about the user is not sold or given to other companies. BuySellAds and DoubleClick are precisely advertising technologies, and their presence contradicts this wording.
There is no consent mechanism, and Do Not Track is deliberately ignored. Across 140 requests there was neither a consent-management platform nor a script bearing the marks of a banner. Google analytics, the DoubleClick advertising linkage, the BuySellAds advertising network and reCAPTCHA are initiated by the home page markup in the first few hundred milliseconds, and the first Google Analytics 4 request with the client identifier goes out at +3693 ms — all before any user choice. Moreover, the policy states outright that the site does not respond to the Do Not Track header. During capture the browser was sending DNT: 1, and this indeed affected neither the composition nor the addressing of the requests. The policy relegates cookie management to a footer link and browser settings, and offers opt-out from Google Analytics only via a browser extension — that is, it shifts it onto the user.
The client identifier goes to the advertising linkage. The GA4 request carries the cid field next to the page URL and title; immediately after, the same identifier goes to stats.g.doubleclick.net — Google’s advertising node. The consent-mode marker gcd in the request corresponds to the default state, but the data is nonetheless sent.
Stripe collects device characteristics in advance. The chain m.stripe.network and m.stripe.com — collection of device characteristics by the payment system — is initiated already on the home page, before any payment step. For a subscription site, the presence of Stripe is justified on the payment page, but not on the first page of the visit.
Security headers are set in part. The site sets strict transport with subdomain inclusion and the preload marker, the frame-embedding ban SAMEORIGIN, the content-type-sniffing ban and a referrer policy. But there is no content-security-policy and no permissions policy. On a page loading advertising and payment third-party code, the absence of a content-security-policy means that the list of trusted script sources is in no way restricted.
Consent: what is proven and what is not
Proven: there is no consent mechanism on the site. Across 140 requests there is not a single request to a consent-management platform and not a single script bearing the marks of a banner. The names of known platforms and general markers in addresses and initiators were checked; zero matches.
Proven: analytics and advertising do not depend on the user’s choice. The scripts for Google Tag Manager, the GA4 counter, DoubleClick, BuySellAds and reCAPTCHA are initiated by the home page markup and run when the browser parses it, at +751…+3697 ms. There is no condition before them.
Proven: the client identifier goes to Google and to the advertising linkage. The cid field stands in the GA4 requests and is repeated in the request to DoubleClick.
Proven: the Do Not Track signal was ignored. The browser was sending DNT: 1, the policy openly admits that the site does not respond to this header, and the composition of the requests confirms it.
Not proven and not asserted: the state of cookies on the device. Cookie headers and response bodies were removed from the published file during sanitisation. All conclusions rest on addresses, initiators, response codes and the composition of requests.
Boundaries of observation
The recording covers the home page of the site. The observation records the browser’s behaviour, not the services’ internal workings: server-side processing, contractual relationships with recipients and settings on their side are not verified by a browser recording.
The icon-delivery nodes site-assets.fontawesome.com, e.fontawesome.com, ka-f.fontawesome.com, use.fortawesome.com and img.fortawesome.com belong to Font Awesome’s own infrastructure and are not treated as third-party recipients. The presence of Stripe is justified by the subscription-payment function, but it is recorded that the collection of device characteristics starts already on the first page.
The file is published sanitised of personal data: cookie headers in requests and response bodies were removed. The conclusion that there is no consent mechanism rests on the absence of requests to consent platforms and of scripts bearing their marks. The full client identifier is not reproduced in the analysis.
The identification of services rests on domains and address patterns: Google Analytics 4 — by analytics.google.com/g/collect and the property G-BPMS41FJD2; DoubleClick — by stats.g.doubleclick.net; Google Tag Manager — by googletagmanager.com; reCAPTCHA — by google.com/recaptcha and gstatic.com; BuySellAds — by servedby-buysellads.com and the file monetization.js; Stripe — by stripe.com and stripe.network; Help Scout — by helpscout.net; the fonts — by fonts.bunny.net; the serving provider — by the server: cloudflare header.
Conclusion
The site of the Font Awesome icon library, on its home page, without consent, starts a full set of analytics and advertising: Google Analytics with the client identifier, the DoubleClick advertising linkage receiving the same identifier, and the BuySellAds advertising network. The privacy policy names Google Analytics, Stripe and Help Scout, but the advertising technologies BuySellAds and DoubleClick, as well as Google Tag Manager, reCAPTCHA and the third-party font service Bunny Fonts, are not disclosed in it — while the document states in a separate clause that information about the user is not given to other companies.
There is no consent mechanism on the site, and the policy states outright that the site does not respond to the Do Not Track signal. The browser was sending this signal during capture, and it was ignored: analytics, the advertising linkage and the advertising network operated in full. The policy shifts opt-out of tracking onto the user — through browser settings and a browser extension. Of the security headers, a content-security-policy and a permissions policy are absent.
Remediation: do not start analytics, the advertising linkage and the advertising network before consent is obtained — introduce a consent mechanism that actually governs their loading, with the option to refuse before they start; name all recipients of web data in the policy individually, including BuySellAds, DoubleClick, Google Tag Manager, reCAPTCHA and Bunny Fonts, with the fields transmitted and the purposes; bring the clause on not giving information to other companies into line with the actual presence of advertising technologies; begin responding to the Do Not Track header or provide an equivalent means of objection on the site itself; set a content-security-policy and a permissions policy.
f1fafd687ce1c3ed4d2ef8fc6fdc0cc136b02f4e40ceaa7eb8293bb7b4da7240Where to file: Jurisdiction determined under Art. 3(2) GDPR —
To: Jurisdiction determined under Art. 3(2) GDPR From: [Your name], [contact email] 1. Subject of the complaint I am filing a complaint regarding the processing of my personal data by the website fontawesome.com. 2. Circumstances I visited the website fontawesome.com and found indications that the processing of my personal data does not comply with the GDPR. The technical analysis published on gdpru.eu on 16 August 2026 (open methodology, reproducible measurements) documents the following indications: 1) There is no consent mechanism on the site: across 140 requests there is not a single request to a consent-management platform, not a single script bearing the marks of a banner, not a single Set-Cookie header. Google analytics, the DoubleClick advertising linkage, the BuySellAds advertising network and reCAPTCHA start from the home page markup at +751…+753 ms, and the first Google Analytics 4 request with the client identifier goes out at +3693 ms — all before any user choice. The policy relegates cookie management to a footer link and to browser settings, and offers opt-out from Google Analytics only via a browser extension. 2) The policy names Google Analytics, Stripe and Help Scout, but a number of recipients are not disclosed: the advertising network BuySellAds, the advertising node DoubleClick, Google Tag Manager, reCAPTCHA and the third-party font service Bunny Fonts are absent from the document. Meanwhile BuySellAds and DoubleClick are advertising technologies, and the policy states in a separate clause that information about the user is not sold or given to other companies. 3) The policy states outright that Font Awesome does not respond to the Do Not Track header. During capture the browser was sending the DNT: 1 header, and this affected neither the composition nor the addressing of the requests: analytics, the advertising linkage and the advertising network operated in full. Deliberately ignoring the opt-out-of-tracking signal, in the absence of any other consent mechanism, leaves the user without a working way to object to the collection. 4) Of the security headers the site sets strict transport with subdomain inclusion and the preload marker, the frame-embedding ban SAMEORIGIN, the content-type-sniffing ban and a referrer policy, but there is no content-security-policy and no permissions policy. On a page loading advertising and payment third-party code, the absence of a content-security-policy means that the list of trusted script sources is in no way restricted. Full technical documentation is published at: https://gdpru.eu/en/audits/global-fontawesome-com/ 3. Provisions violated ePrivacy — Directive 2002/58/EC, Art. 5(3) (in conjunction with GDPR Art. 6(1)(a)); GDPR Art. 13(1)(e) — disclosure of recipients; GDPR Art. 21 — right to object (ignoring Do Not Track); GDPR Art. 32 — security measures 4. Request I request that you investigate the violations described and apply the measures provided for in Article 58(2) GDPR. 5. Attachments The full evidence base — the HAR file, its SHA-256 checksum and the quotation from the site's privacy policy documenting the stated contradiction — is published and verifiable at the link in point 2 above. [Date] [Signature / name]