BLACKOUT://VENDOR_INTEL/HOTJAR
VENDOR_DBINTEL READY
session_replay
Hotjar

Hotjar

100Hypocrisy
90Revenue Risk

Executive Summary

Hotjar is a behavior analytics platform acquired by Contentsquare in 2021, providing heatmaps, session recordings, and surveys to over 1.3 million websites. Despite extensive compliance certifications (SOC 2 Type II, ISO 27001, GDPR/CCPA claims), runtime analysis reveals a 52.7% pre-consent tracking rate across 50 detected sites. More critically, Hotjar's own website loads 27 third-party vendors before consent, including advertising pixels (Meta, Google, LinkedIn, Reddit, Twitter) and B2B enrichment tools (Apollo.io) that are not disclosed in their subprocessor list. This creates significant gaps between their privacy marketing (GDPR-ready, CCPA-ready) and actual data collection practices, representing material misrepresentation risk for customers relying on Hotjar's compliance claims.

Revenue Threat Profile

4 COLLAPSE VECTORS

How this vendor creates financial exposure. Each score (0-100) reflects observed runtime behavior and documented business practices.

100

CAC Subsidization

critical

Hotjar captures detailed behavioral data (clicks, scrolls, form interactions) that feeds into customer analytics decisions. When this same data is simultaneously shared with undisclosed advertising platforms and B2B enrichment services, it corrupts the measurement chain. Customers believe they are getting first-party behavioral insights, but the data is also flowing to third parties who may use it for competitive intelligence or cross-site tracking.

55

Signal Corruption

high

The presence of Apollo.io (B2B visitor identification) and multiple advertising pixels on Hotjar's own website demonstrates the platform participates in the demand signal leakage ecosystem. Website visitors—including Hotjar's own customers and prospects—have their data captured and potentially enriched for sales outreach by third parties. This same infrastructure may be present on customer sites using Hotjar.

100

Legal Tail Risk

critical

Session recordings and heatmaps capture detailed user interactions that could include sensitive information inadvertently displayed or entered. With 27 third-party vendors loading pre-consent on their own site, the attack surface extends to every undisclosed data recipient. Each advertising pixel and analytics tool represents a potential data breach vector that Hotjar has not disclosed to users.

0

GTM Attack Surface

low

The gap between Hotjar's compliance marketing (SOC 2, ISO 27001, GDPR-ready, CCPA-ready) and their actual 52.7% pre-consent tracking rate creates direct liability for customers. Organizations using Hotjar while representing GDPR compliance to their own users may be inadvertently making false statements. The undisclosed subprocessors on Hotjar's own website demonstrate they do not practice what they market.

Profile: hotjarFirst Seen: 2025-12-25Last Updated: 2026-01-22
Confidence:HIGH

Profile by BLACKOUT Threat Intelligence