Pre-consent tracker audit
See every tracker your site runs before anyone consents
- We load your page the way a new visitor does: fresh browser, no history. We want to check if you are collecting visitors' information on behalf of third-party companies.
- We list every other company your page quietly sent that person's information to, and every cookie it saved onto their computer, before anyone asked them if that was okay.
- We check if the tracking already started before the visitor consented to cookies. If that happens, the answer never mattered. And that is what companies are being sued over.
The problem: your cookie banner probably is not blocking anything
Every company below had a privacy control on its website. A cookie banner, an opt-out link, a preference toggle. In every single case the regulator found the same thing: the control was there, and the tracking carried on anyway. That is the exact gap Snitch measures.
Disney, 2026
Advertising pixels and SDKs on Disney's streaming and ABC properties kept sending personal information to ad partners after visitors had opted out.
Healthline, 2025
Tracking tools shared what visitors were reading with advertisers. It was the largest fine the California Privacy Protection Agency had issued at the time.
Tractor Supply, 2025
The "Do Not Sell" link led to a web form that did not actually stop any tracking, and the site ignored browsers that were already sending an automatic opt-out signal.
Los Angeles Times, 2026
Not a regulator. A class action by visitors over trackers running on the site, settled with final court approval in June 2026.
- What the law allows
- California can fine a business up to $2,663 for each violation, or $7,988 if it was deliberate or involved a child. A violation is counted per person affected, so a store with ten thousand California visitors is not looking at one fine.
- What visitors can claim
- Under California's wiretapping law a visitor can claim $5,000 each, or three times their actual damages, without having to prove they were harmed. That ceiling is what gives these cases their leverage in settlement talks.
- What just changed
- On August 28, 2026 California passed SB 690, which removes one of the two theories visitors have been using to sue over website tracking. It is on the governor's desk until September 30. It does not touch the wiretapping section itself, and it does nothing at all to the regulators who issued every fine above.
- Why a scan is the cheap part
- All of this turns on one mechanical fact: did a tracker run before the visitor agreed. A browser can answer that in twenty seconds. Nobody in the four cases above was surprised by the law. They were surprised by their own website.
Sources: California Privacy Protection Agency enforcement announcements, California Attorney General CCPA enforcement, Goodwin on SB 690. These are actions against other companies. Nothing here predicts any outcome for your site.
The solution: we check whether your site waits for consent before it starts tracking
- You give us your web address, and that is the whole setup: no account, no code to install, nothing to add to your site. We also do not send your information to any third-party company.
- We open your homepage in a brand new browser. It has never been to your site, so it has no cookies and no history. It behaves exactly like a real person landing on your site for the first time.
- We wait about four seconds and write down everything that happens on its own. Every other company your page contacted, the exact millisecond it happened, and every cookie saved onto the visitor.
- Then we stop. We never press Accept on your cookie pop-up, never fill in a form, never buy anything. So every single thing in your report happened before the visitor had agreed to any of it.
The product: a dated report of everything that ran before consent
You get one page, written for the person who has to fix it rather than for a lawyer. It is yours to forward to a developer, an agency, or your own legal counsel, and it is timestamped so it is worth something later.
- A verdict in one line, in plain English, with the reasoning underneath it.
- A timeline of every advertising tool and screen recorder that ran, each marked with the exact millisecond it fired, all of it before anyone was asked anything.
- Every cookie planted on the visitor: what it does, who set it, and how long it stays on their computer.
- Every other company your page contacted, named, and rated by how often that company turns up in filed complaints.
- Whether you have a consent tool at all, and whether Google's consent setting was ever configured, which is the single most common thing people get wrong.
- What to do first, and only that, so there is one thing to go and do.
Which of the four verdicts you get decides what you need to do to be compliant
What it means
A consent tool is installed on your site, so your visitors were promised that nothing would happen until they answered. Advertising or recording tools ran anyway. This is the worst of the four, because the promise is written down and the tracking still went ahead.
What to do first
Open your consent tool's settings and find its list of scripts to block. Almost every tool only blocks what you explicitly name, and a freshly installed one names nothing. Add every tracker we listed, save, then scan again and confirm they are gone.
What it means
There is no consent gate at all. Every tracker starts the second the page opens, and nobody is ever asked anything.
What to do first
Turn on a consent gate before you change anything else. If you are on Shopify it is already built in and free: Settings, then Customer privacy, then turn on the cookie banner and set it to block before consent. Then scan again.
What it means
No advertising pixels and no screen recorders ran on their own, which is the important half. Analytics and non-essential cookies still started before anyone agreed.
What to do first
This one can wait behind the other work on your list. If you sell into the EU or the UK, gate analytics too, because those rules do not have the softer view of it. If you only sell in the US, fix it the next time you touch your tag setup.
What it means
Nothing non-essential ran in the time we watched. Whatever is holding your tags back is doing the job it was installed to do.
What to do first
Scan again after any theme change, any new app, and any edit to your tag manager. This is the kind of thing that breaks quietly: nothing on your site warns you, and you find out from a letter.
Pricing
The homepage scan is free forever and it always will be, including the part that tells you how to fix what it finds. You pay when you want the rest of your site checked, or you want to know the day it breaks again.
Free
$0
- Your homepage, scanned in twenty seconds
- Every tracker and cookie that ran before consent
- A plain-language verdict and the fix
- No account, no card, no limit worth mentioning
Available now. No card, no account.
Full report
$49 once
- Your whole store: product pages, cart, and checkout, where the worst of it usually is
- The reject test: we press Reject All and show you what keeps running anyway
- A dated PDF you can hand to a developer, an agency, or a lawyer. See an example report
- Re-scan free for thirty days so you can prove you fixed it
In build. Leave your address and you get it first, at this price.
Monitor
$19 / month
- Everything in the full report
- Run again every week, on its own
- An email the day something changes, which is the whole point: a new app or a theme update breaks this silently and nothing else tells you
- $190 a year if you pay up front
In build. Leave your address and you get it first, at this price.
Nothing paid is live yet, so there is no checkout to click and we are not taking cards. The free scan is the real thing and it is finished.
Questions people ask before they scan
Is the free scan actually free?
Permanently, including the part that tells you how to fix what it finds. It needs no account, no card and no email address. You pay only when you want your whole store checked rather than one page, or when you want to be told the day it breaks again.
How much of my site does a scan cover?
The free scan reads one page: your homepage. Your product pages, cart and checkout routinely carry more than the homepage does, and that is what the paid report is for. It walks those pages too, and it presses Reject All to show you which trackers keep running afterwards.
Will scanning break anything, or show up in my analytics?
Nothing breaks. The free scan loads your homepage the way any visitor does and touches nothing else. It will appear in your analytics as one visit from a United States address. The paid scan adds one item to a cart, because that is the only way a checkout page can be reached; no order is placed and no contact details are entered, so no order and no abandoned-checkout record is created. The scanning policy lists every request we make.
Do I need to install anything?
There is no script, no app and no tag to add. You give us a web address and we load it from the outside, exactly like a customer would.
I already pay for a cookie banner. Isn't this its job?
That is the thing we check. Consent tools block only the scripts named in their block list, and a freshly installed one names nothing, so the banner appears and the tracking carries on behind it. Disney, Healthline and Tractor Supply all had a privacy control installed at the moment they were fined.
My consent tool offers a free scan. How is this different?
Theirs scans your site in order to build their banner. Ours checks whether the banner already on your site is doing anything. No consent vendor is going to answer that question about its own product.
Do you catch every tracker?
No. The list is curated and it is incomplete. Anything we cannot name is reported as unrecognised and left out of every count and out of the verdict, so a scan understates your exposure rather than exaggerating it. If you spot something we missed, tell us and it goes in the list.
Does a Clean result mean I am compliant?
No, and we will not say it does. Clean means nothing non-essential was observed on the pages checked, in the seconds observed, on that date. It is a written record of what one browser saw on one visit: evidence you can hand to a lawyer, not a certificate, and we are not a law firm.
Can I scan a site I do not own?
The terms require you to own the domain or have permission from whoever does. This is a tool for checking your own site.
What do you keep, and what if the scan is wrong?
The address you submit sits in a server log for 30 days. Free scan results go to your browser and are not stored against you. This site sets no cookies and loads nothing from another company, which you are welcome to verify by scanning it. Paid reports are refunded if we cannot stand behind them.
See which trackers run on your site before anyone consents
Twenty seconds, free, nothing to install. We load your public homepage the way any visitor would, and list everything that ran before the visitor was asked anything.