All Vendors
scheduling

ChiliPiper

ChiliPiper scheduling platform deploys behavioral tracking, cross-domain synchronization, tag management, and consent bypass capabilities. The platform demonstrates moderate-risk surveillance patterns.

43 IOCs21 detections33% pre-consent19 sites
70
Vendor Risk Score

How This Briefing Works

This report opens with key findings, then maps the gaps between what ChiliPiper discloses and what BLACKOUT observed at runtime. From there: what it means for your organization, what to do about it, and the detection data and evidence underneath.

Key Findings

Key Findings

21 detections across 19 sites33% pre-consent activity
HIGH

Pre-Consent Activity

ChiliPiper was observed loading and executing before user consent was obtained on 33% of sites where it was detected.

GDPRePrivacy
Disclosure Gaps

Claims vs. Observed Behavior

2 gaps

disclosure

MEDIUM
They Claim

Pending privacy policy review

Observed Behavior

Cross-domain tracking during scheduling observed without disclosure verification

Customer Impact

What This Means For You

Customers face GDPR violations from pre-consent tracking during scheduling workflows. Cross-domain synchronization enables ChiliPiper to track users from marketing site through meeting booking, creating profiling without consent. Tag manager functionality creates undisclosed third-party data sharing liability. Behavioral tracking of scheduling patterns may expose deal urgency and competitive evaluation timelines. B2B customers face reputational risk if surveillance of meeting booking behavior becomes public.
Recommended Actions

What To Do About It

Role-specific actions based on observed behavior

If You Use ChiliPiper

  • Implement consent-gating before ChiliPiper tracking activates on scheduling forms
  • Configure cross-domain synchronization to require explicit opt-in before linking marketing and CRM data
  • Deploy tag manager allowlisting to prevent unauthorized script injection via ChiliPiper
  • Enable data minimization controls to limit scheduling data retention to completed meeting cycles only
  • Conduct quarterly audits of cross-domain tracking and tag manager behavior
  • Disable behavioral biometrics features in ChiliPiper settings if available

If You're Evaluating ChiliPiper

  • Request DPA with explicit limitations on cross-domain tracking and CRM data synchronization
  • Verify ChiliPiper honors consent signals before initiating cross-domain user matching
  • Demand contractual prohibition on using customer scheduling patterns for ChiliPiper's own benchmarking products
  • Assess alternative scheduling platforms with privacy-preserving architecture
  • Require technical documentation on tag manager script injection and cross-domain sync methodology
  • Negotiate liability protection for GDPR fines arising from unconsented cross-domain tracking

Negotiation Leverage

  • ChiliPiper cross-domain sync (BTI-C08) enables tracking from marketing through booking—require explicit opt-in before cross-platform linking
  • Tag manager (BTI-C15) enables undisclosed script injection—require contractual restrictions on dynamic tag loading
  • Consent bypass (BTI-C09) during scheduling creates regulatory exposure—demand technical implementation of consent verification before tracking
  • Behavioral biometrics (BTI-C06) profiles scheduling urgency—negotiate contractual prohibition on using customer booking patterns for cross-customer insights
  • Request documentation on data retention periods and third-party data sharing via tag manager integrations
  • Negotiate maximum 90-day retention for scheduling behavioral data with automated deletion for incomplete booking cycles
Runtime Detections

Runtime Detections

4 BTI-C CODES

BLACKOUT observed this vendor's JavaScript executing in a live browser and classified each hostile behavior using our BTI-C (Behavioral Threat Intelligence — Capability) taxonomy. These are not theoretical risks — each code below was triggered by something we watched this vendor's code actually do.

BTI-C06Behavioral Biometrics

Keystroke/mouse tracking

Impact: Captures form interaction patterns, time-to-booking metrics, and scheduling preferences to profile buyer urgency and deal priority.

BTI-C08Cross-Domain Sync

Identity stitching

Impact: Synchronizes scheduling data across marketing sites, landing pages, and CRM systems, enabling cross-platform tracking of buyer journey from awareness to meeting booking.

BTI-C09Consent Bypass

Ignoring CMP signals

Impact: Initializes tracking infrastructure before consent collection during scheduling workflows, creating automatic legal violations.

BTI-C15Tag Manager

Container/loader (neutral)

Impact: Deploys tag management infrastructure that can dynamically inject analytics and conversion tracking beyond declared scheduling functionality.

IOC Manifest

IOC Manifest

41 INDICATORS

Indicators of compromise across 5 categories. Use for detection rules, CSP policies, or Pi-hole blocklists.

TRACK
*calendar.chilipiper.com/chat/embed/assets/index.js*
Tracking script
TRACK
*calendar.chilipiper.com/chat/embed/assets/masterChefUrl-DhXpWMkn.js*
Tracking script
TRACK
*calendar.chilipiper.com/concierge-js/cjs/concierge.js*
Tracking script
TRACK
*calendar.chilipiper.com/chat/embed/env-config.js*
Tracking script
TRACK
*calendar.chilipiper.com/env-config.js*
Tracking script
TRACK
*calendar.chilipiper.com/chat/widget/assets/index-BOShyvQT.js*
Tracking script
TRACK
js.chilipiper.com
Tracking script
TRACK
calendar.chilipiper.com/chat/embed/assets/index.js
Auto-extracted from scan
TRACK
calendar.chilipiper.com/chat/embed/assets/masterChefUrl-DhXpWMkn.js
Auto-extracted from scan
TRACK
calendar.chilipiper.com/concierge-js/cjs/concierge.js
Auto-extracted from scan
TRACK
calendar.chilipiper.com/chat/embed/env-config.js
Auto-extracted from scan
TRACK
calendar.chilipiper.com/chat/widget/assets/index-BOShyvQT.js
Auto-extracted from scan
TRACK
calendar.chilipiper.com/env-config.js
Auto-extracted from scan
Ecosystem

Ecosystem & Supply Chain

ChiliPiper integrates with CRM platforms (Salesforce, HubSpot), marketing automation (Marketo, Pardot), calendar systems (Google Calendar, Outlook), and video conferencing (Zoom, Teams). The platform synchronizes scheduling data with sales engagement platforms and revenue intelligence tools. Cross-domain capabilities enable tracking from form submission through meeting completion. Tag manager functionality allows integration with analytics platforms and conversion pixels.
Evidence

Evidence Artifacts

Artifacts collected during analysis, available with evidence-tier access.

HAR Capture

Complete network capture with all requests and responses

IOC Manifest

43 detection signatures across scripts, domains, cookies, and network endpoints

Vendor Details