webtracking.org
D 48/100

Hotjar

Session replay and heatmaps with EU hosting and suppression tooling — but recordings are inherently high-collection and need consent plus careful masking.

verified 2026-06-08 · grade set per the published methodology

How the grade breaks down

Data minimization 2/5

How little it collects, and whether collection is purpose-bound.

Consent honoring 3/5

Whether it respects GPC, consent state, and tracking-prevention signals.

Identifier strategy 2/5

Cookieless vs. persistent IDs, cross-site linkage, fingerprinting risk.

Residency & sharing 3/5

Where data lives and whether it is shared with third parties.

Transparency 2/5

How verifiable and documented its real behavior is.

At a glance

Category session-replay
Cookieless no
Consent for lawful use required
Data residency eu
Shares w/ third parties optional
Sends PII by default optional
Honors GPC no
Open source no

Hotjar records sessions and builds heatmaps. It hosts in the EU and provides data-suppression and input-masking controls, which it is better at than some peers, but session replay is inherently high-collection: without disciplined masking it can capture sensitive content. It uses cookies and requires consent in most jurisdictions, and does not honor GPC by default. A defensible choice for UX research when masking and consent are configured properly.

Sources & basis for grade

Grades reflect documented behavior, vendor documentation, and ad.rip scans as of the date above. Each assessment is reproducible and vendors may request correction.

  • Hotjar privacy / data-suppression documentation
  • Hotjar input-masking docs