What it is
Segment collects events once and routes them to destinations: analytics, advertising, warehouses, email. That means a single script on your page can be feeding an advertising platform even though the library itself is classified as analytics.
The consent question is therefore not "is Segment allowed" but "which destinations are allowed". A destination list that includes an ad platform makes the same page an advertising collection point.
What a scan matches
A verification scan drives a real browser and records the outbound requests observed during its configured journeys, so Segment is identified by request hosts and paths rather than by source-code claims. Requests on unvisited paths, after unperformed interactions or solely on the server remain outside that observation.
- segment.com
- segment.io
- segmentapis.com
Cookies are classified by name before domain because many analytics and advertising tags write first-party cookies through the page, which places a vendor-related identifier on your domain. Matching known names helps attribute those values without assuming that every first-party cookie came from your own application.
| Cookie | What it is for |
|---|---|
| ajs_user_id | The identified user, once identify() has been called |
| ajs_anonymous_id | The anonymous identifier assigned before identification |
| ajs_* (others) | Analytics.js state, matched by prefix |
Controlling it with consent
No named adapter. Gate the library as a custom script, and use Segment’s own consent management features to control destinations by category where your plan supports them.
Server-side and cloud-mode destinations are outside anything the browser can control. If events reach an advertising destination from your servers, the consent state has to be carried there deliberately.
No named adapter: choose the appropriate control
The product ships named adapters for Google Tag Manager, Google Analytics, the Meta and TikTok pixels, and Klaviyo. Choose the control route that fits this technology: a custom HTTPS script declaration for a browser loader, an individual consent condition inside a tag manager, a platform or app setting, or a click-to-load placeholder for a frame. Server-side integrations need their own enforcement because a browser runtime cannot stop them.
What breaks if it is refused: all downstream destinations for refusing visitors, including ones you may consider necessary. Map them before you gate the library.
Verifying it
Before consent there should be no ajs_anonymous_id. After consent, inspect which destination endpoints are actually contacted. That list, not the Segment library, is what needs mapping to categories.
- Before a choice: optional tracking endpoints and optional identifiers are absent; any intentionally loaded necessary or functional surface matches the control model described above
- After rejecting optional categories: optional activity remains absent and the refusal persists across a reload
- After granting the relevant category: the expected loader or embed appears and the feature behaves normally
- After withdrawing: new optional activity stops; where the vendor supports a consent signal, verify that the signal is sent as well as checking network behavior
Common questions
Is Segment analytics or advertising?
Neither on its own. The scanner classifies the library as analytics because that is what it is sold as, but its actual consent implications come from its destinations. Audit those.
Does blocking Segment break my data warehouse loads?
It stops the browser-side events that feed them for refusing visitors. That is the intended outcome, but it is worth knowing before you gate it rather than after the first monthly report.
Sources and verification
Verified on . Product-behaviour statements were checked against the current implementation and tests. The links below are the verification basis recorded for this article. They support the stated facts, not a legal conclusion for every site or configuration; recheck changing vendor behaviour before relying on it in production.
- Twilio Segment: Analytics.js and first-party browser state
Vendor documentation
Checked
See what your own site is loading
A browser scan reports the requests and storage it observed during the sampled journey. Use configured workspace scans to compare the states and pages that matter to your implementation.