Say I'm a vegetarian restaurant, and I contract out my delivery service.
One day the delivery service starts adding free sausages to every delivery on an opt-out basis.
By the time you realize, they'll already have delivered adulterated meals. You won't have a lot of customers left!
People are often vegetarian for ethical reasons. In a similar way, many people have Ethical Opinions (tm) about Analytics as well. They don't like it when other people collect private information about themselves, and refuse to Do Unto Others.
But even if you're fine with analytics in general: When intermediaries and other transitive dependencies (like software libraries) start injecting analytics on an opt-out basis, you simply can't control what's going on. And that's before we talk about the ethics and legality of third parties modifying content in-flight.
In the EU, the law actually codifies the ethics at play here (GDPR). Several people point out that cloudflare disables this 'feature' for the EU. This makes a lot of sense, because it would have been a huge mess for everyone impacted to have to go to their customers with a "sorry, we leaked your PII, here's how we'll make you whole"; as well as possibly lawsuits against cloudflare to recover those damages upstream.
For delivery service, it's typically done with a closed box so you get exactly what has been prepared.
Here you told them to unpack the food and repack it (TLS termination), filtering order (WAF), reheating pre-made food (cache) and they offer service to even prepare food or part of the food (edge compute). When your food is not available they will serve their own (error pages), with their brand visible. At that level of service, it's not so surprising to have extra stuff included.
If you are vegan and care about your customers (conservative on data collection and JS), maybe you should use a vegan architecture and not give your last-mile to the cheapest (free-tier) all-purpose repacking kitchen and delivery service.