Every tracker, cookie, and third-party domain on your site, mapped in minutes.
We check what trackers and cookies load, whether a consent tool is present and actually working, which third-party domains show up in your CSP and network calls, and crawl your sitemap to see how far the exposure runs.
Paste your homepage address.
Every tracker gets the same three questions.
What it is
Every finding is identified by vendor and category — analytics, advertising, session recording, functional, or necessary — not just a script filename.
What it collects
We map the actual data types each tracker touches: identifiers, behavioral data, precise location, or payment metadata, in plain language.
When it fires
We flag whether the script loads before or after a consent decision. Before-consent firing on a non-necessary tracker is the single most common violation we find.
Here's what a completed scan looks like.
A homepage-only scan on a site with no consent tool installed. Scroll down to watch the findings unredact.
Sample scan report
Collects: Page views, session duration, device type, approximate location
Loaded on page render, before any consent choice was made.
Collects: Page URL, button clicks, hashed email for Advanced Matching
Fires on every page, including checkout, ahead of consent.
Collects: Page URL, device identifiers, purchase events
No consent signal check before the script loads.
Collects: Mouse movement, clicks, scroll depth, masked form inputs
Correctly gated behind the existing analytics category.
Collects: Email address if submitted, browsing behavior, purchase history
Loads only after a visitor opts into marketing cookies.
Collects: Transaction metadata, fraud-prevention device fingerprint
Necessary for checkout to function; not required to gate behind consent.