A lot of corporate computers have at least an additional CA authority on each computer that they use... if you're using a corporate computer, it's really easy for them to MITM any request, just relaying requests to the public resource, then proxying and using their CA signed cert in the proxy.
From there, everything can be tracked.