The Tracker Scanner

Every tracker, cookie, and third-party domain on your site, mapped in minutes.

We check what trackers and cookies load, whether a consent tool is present and actually working, which third-party domains show up in your CSP and network calls, and crawl your sitemap to see how far the exposure runs.

Run it now

Paste your homepage address.

Free, one page, usually done in under a minute. This checks trackers, cookies, consent tools, and the third-party domains your homepage talks to. It is not the full audit: a real engagement also crawls your sitemap and tests whether Reject actually works.

How we categorize findings

Every tracker gets the same three questions.

01

What it is

Every finding is identified by vendor and category — analytics, advertising, session recording, functional, or necessary — not just a script filename.

02

What it collects

We map the actual data types each tracker touches: identifiers, behavioral data, precise location, or payment metadata, in plain language.

03

When it fires

We flag whether the script loads before or after a consent decision. Before-consent firing on a non-necessary tracker is the single most common violation we find.

Sample report

Here's what a completed scan looks like.

A homepage-only scan on a site with no consent tool installed. Scroll down to watch the findings unredact.

yourbusiness.com · scanned 2026-08-14

Sample scan report

High risk
6Trackers
6Cookies
6CSP domains
128Pages in sitemap
NoneConsent tool
Trackers found
Google Analytics 4AnalyticsBefore consent

Collects: Page views, session duration, device type, approximate location

Loaded on page render, before any consent choice was made.

Meta PixelAdvertisingBefore consent

Collects: Page URL, button clicks, hashed email for Advanced Matching

Fires on every page, including checkout, ahead of consent.

TikTok PixelAdvertisingBefore consent

Collects: Page URL, device identifiers, purchase events

No consent signal check before the script loads.

HotjarSession RecordingAfter consent

Collects: Mouse movement, clicks, scroll depth, masked form inputs

Correctly gated behind the existing analytics category.

KlaviyoMarketingAfter consent

Collects: Email address if submitted, browsing behavior, purchase history

Loads only after a visitor opts into marketing cookies.

StripePayments (necessary)Before consent

Collects: Transaction metadata, fraud-prevention device fingerprint

Necessary for checkout to function; not required to gate behind consent.

Cookies observed
_gaGoogle AnalyticsAnalytics2 years
_fbpMetaAdvertising90 days
ttclidTikTokAdvertising13 months
hjSessionUserHotjarAnalytics1 year
klaviyo_sessionKlaviyoFunctional30 days
__stripe_midStripeNecessary1 year
Third-party domains (CSP)
www.googletagmanager.comTag manager
connect.facebook.netAdvertising pixel
analytics.tiktok.comAdvertising pixel
script.hotjar.comSession recording
static.klaviyo.comEmail marketing
js.stripe.comPayments (necessary)

Turn this into a policy, or fix what it finds.