All Vendors
deanon
HockeyStack

HockeyStack

Marketed as "cookieless" and "privacy-friendly" while deploying FingerprintJS for device fingerprinting — more persistent and invasive than cookies, impossible for users to clear. 41+ third-party vendors on their website with only ~20 disclosed. 12 vendors fire pre-consent including identity resolution services.

27 IOCs104 detections2% pre-consent101 sites
90
Vendor Risk Score

How This Briefing Works

This report opens with key findings, then maps the gaps between what HockeyStack discloses and what BLACKOUT observed at runtime. From there: what it means for your organization, what to do about it, and the detection data and evidence underneath.

Key Findings

Key Findings

104 detections across 101 sites2% pre-consent activity1 critical disclosure gap
CRITICAL

Privacy Marketing Mismatch

Uses FingerprintJS for device fingerprinting which is MORE persistent and invasive than cookies, cannot be cleared by users, and fires pre-consent

GDPR Art 5(1)(a)ePrivacy Directive Art 5(3)CCPA 1798.100
MEDIUM

Pre-Consent Activity

HockeyStack was observed loading and executing before user consent was obtained on 2% of sites where it was detected.

GDPRePrivacy
HIGH

Subprocessor Disclosure Gap

41 vendors detected at runtime on hockeystack.com including 20+ not in any disclosure list

GDPR Art 28GDPR Art 13CCPA 1798.110
HIGH

Pre-Consent Tracking

12 vendors fire pre-consent including fingerprinting and identity resolution services

GDPR Art 6GDPR Art 7ePrivacy Directive Art 5(3)
HIGH

Undisclosed Party

Not in privacy policy

Disclosure Gaps

Claims vs. Observed Behavior

4 gaps
1 CRIT2 HIGH1 MED
Classified:BTI-X01BTI-X02BTI-X04BTI-X05BTI-X08

Privacy Marketing Mismatch

GDPR Art 5(1)(a) · ePrivacy Directive Art 5(3) · CCPA 1798.100CRITICAL
They Claim

Cookieless tracking technology is privacy-friendly

Observed Behavior

Uses FingerprintJS for device fingerprinting which is MORE persistent and invasive than cookies, cannot be cleared by users, and fires pre-consent

Trust Portal lists Fingerprint.js as subprocessor; runtime scans show FingerprintJS firing pre-consent on hockeystack.com

Subprocessor Disclosure Gap

GDPR Art 28 · GDPR Art 13 · CCPA 1798.110HIGH
They Claim

Trust Portal lists 11 subprocessors as comprehensive data processor list

Observed Behavior

41 vendors detected at runtime on hockeystack.com including 20+ not in any disclosure list

BLACKOUT runtime scan detected Leadfeeder, RB2B, Cheq, Contentsquare, Adform, VWO and others not listed in Trust Portal or Privacy Policy

Dual Disclosure Lists

GDPR Art 13 · GDPR Art 14MEDIUM
They Claim

Privacy Policy and Trust Portal provide vendor transparency

Observed Behavior

Privacy Policy lists different vendors than Trust Portal subprocessor list, creating confusion about actual data processors

Privacy Policy mentions Google Analytics, Facebook Pixel, Hotjar; Trust Portal lists PostHog, Datadog, Sentry - minimal overlap

Customer Impact

What This Means For You

If HockeyStack is deployed on your site, their "cookieless" technology uses FingerprintJS for device fingerprinting — a technique more persistent than cookies that users cannot clear or detect. Under ePrivacy Directive Art 5(3), fingerprinting requires the same consent as cookies, meaning their privacy-friendly positioning does not reduce your compliance burden. Their website loads 41+ third-party vendors while disclosing only ~20, creating a subprocessor transparency gap you inherit under GDPR Art 28. Twelve vendors fire pre-consent on hockeystack.com including Leadfeeder and RB2B for identity resolution, suggesting consent-first architecture is not operationally enforced. Their Atlas data foundation performs cross-source identity matching while being marketed as privacy-respecting analytics.
Recommended Actions

What To Do About It

Role-specific actions based on observed behavior

If You Use HockeyStack

  • Audit your consent implementation — verify no HockeyStack scripts fire pre-consent, given 12 pre-consent vendors on their own site
  • Review your privacy policy to disclose device fingerprinting via FingerprintJS — 'cookieless' does not mean 'no tracking' and users cannot clear fingerprints
  • Request full subprocessor list including all vendors loaded by the HockeyStack snippet — 41 detected versus ~20 disclosed on their site
  • Assess AI data flows — OpenAI and Google Gemini subprocessors may affect your data residency requirements and AI training opt-out preferences
  • Update data processor agreements to explicitly cover identity resolution and fingerprinting capabilities of their Atlas platform

If You're Evaluating HockeyStack

  • Clarify 'cookieless' versus fingerprinting — FingerprintJS is more invasive than cookies and requires identical consent under ePrivacy Directive
  • Request comprehensive subprocessor list beyond their Trust Portal — their Privacy Policy vendor list differs significantly
  • Confirm pre-consent behavior can be configured to zero tracking before consent on your property
  • Evaluate the identity resolution scope of their Atlas data foundation — it performs cross-source deanonymization despite privacy-friendly marketing
  • Consider the regulatory risk of ISO 27001 and GDPR compliance claims paired with observed pre-consent fingerprinting behavior

Negotiation Leverage

  • Fingerprinting disclosure: HockeyStack uses FingerprintJS, which is more persistent and invasive than cookies. Require contractual disclosure of all fingerprinting techniques used by their platform, with explicit consent requirement documentation for your legal team.
  • Subprocessor transparency: 41+ vendors detected on hockeystack.com versus ~20 disclosed. Require complete subprocessor list covering all third-party code loaded by their tracking snippet on your property, with 30-day advance notice before additions.
  • Cookieless claim verification: Require written technical documentation of what 'cookieless' means in practice — specifically that it involves device fingerprinting, not absence of tracking.
  • Pre-consent SLA: 12 vendors fire pre-consent on their own site including identity resolution services. Require contractual guarantee that their snippet loads zero third-party vendors before consent on your property.
  • AI data flow restrictions: HockeyStack uses OpenAI and Google Gemini as subprocessors. Require contractual commitment that your analytics data is not used for AI model training and specify data residency requirements for AI processing.
Runtime Detections

Runtime Detections

8 BTI-C CODES

BLACKOUT observed this vendor's JavaScript executing in a live browser and classified each hostile behavior using our BTI-C (Behavioral Threat Intelligence — Capability) taxonomy. These are not theoretical risks — each code below was triggered by something we watched this vendor's code actually do.

BTI-C01Defeat Device

Evasion infrastructure, auditor bypass

BTI-C06Behavioral Biometrics

Keystroke/mouse tracking

BTI-C07Session Recording

Full session replay

BTI-C08Cross-Domain Sync

Identity stitching

BTI-C09Consent Bypass

Ignoring CMP signals

BTI-C10Fingerprinting

Device identification

BTI-C14Identity Resolution

PII deanonymization

BTI-C15Tag Manager

Container/loader (neutral)

IOC Manifest

IOC Manifest

12 INDICATORS

Indicators of compromise across 5 categories. Use for detection rules, CSP policies, or Pi-hole blocklists.

TRACK
cdn.jsdelivr.net/npm/hockeystack
Tracking script
TRACK
hockeystack.min.js
Tracking script
TRACK
hockeystack-staging.min.js
Tracking script
Ecosystem

Ecosystem & Supply Chain

HockeyStack operates in the B2B revenue intelligence/attribution space, competing with Bizible, Dreamdata, and 6sense. The platform integrates with CRM (Salesforce, HubSpot), marketing automation (Marketo, Pardot), and ad platforms (Google, LinkedIn, Meta). Their Atlas data foundation performs cross-source identity resolution, matching anonymous visitors to accounts. HockeyStack is loaded via JavaScript snippet on customer websites, deploying FingerprintJS for device identification and sending data to AWS Frankfurt. The platform connects to OpenAI and Gemini for AI features, creating a data flow to LLM providers. On their own website, HockeyStack loads 41+ third-party vendors including identity resolution (Leadfeeder, RB2B), session replay (Contentsquare, Clarity, Hotjar), and ad tracking (Meta, LinkedIn, Reddit, Google). This extensive vendor ecosystem on their marketing site demonstrates the surveillance infrastructure they can enable for customers.
Evidence

Evidence Artifacts

Artifacts collected during analysis, available with evidence-tier access.

HAR Capture

Complete network capture with all requests and responses

IOC Manifest

27 detection signatures across scripts, domains, cookies, and network endpoints

Vendor Details