What this is, in four minutes
You got an email from someone you have never heard of, about your own website, with a number in it. That is a strange thing to receive. This explains where the number came from.
Listen
What we did
We opened one page of the site the way any visitor opens it, and counted what started collecting information about that visitor. We did not log in. We did not touch anything. We did not look at any page a stranger could not.
Then we looked at the clock. Most sites have a cookie consent box. What we measure is whether it was actually asked first. Usually the collecting starts at about a quarter of a second, and the consent box finishes loading at half a second. Nobody would notice that gap. Everything inside it happened before anyone was asked anything.
Why you could not have seen it yourself
Not in your website builder, not in your admin panel, not in your analytics dashboard. None of them show what is actually running on your own pages. It is only visible from outside, watching the page load the way a stranger's browser loads it.
That is why it is normal not to know. Companies with full-time teams on this have been caught by exactly the same thing.
How it got there
Some of it you chose, on purpose, for a good reason. The rest arrived attached to something else you chose. You signed up for a booking tool, or an ad account, or an email platform. You got the feature you paid for, and it brought its own collecting with it. Nobody separates those two at signup, and nothing separates them afterwards either.
Why we stay independent
Your developer or agency makes any changes, working from what we found: every tracker, where it loads from, and the exact time it fired. Then we open the page again and confirm what held.
We keep that line on purpose. A record is only as strong as the independence of whoever made it. One made by a third party with no hand in the work is one your lawyer, your insurer, or anyone buying the business one day can rely on.
We are not a law firm and nothing here is legal advice.
What a check costs
One page, free. No card, no account, nothing to install. You get the list: every tracker found, what each one collects, where it loads from, the exact time it fired, and the test we run again afterwards. Written so you can forward it straight to whoever runs your site.
We confirm you control the domain before we send it. That takes about thirty seconds and it is there so nobody can pull a report on your business but you.
Words used in the recording
Pre-consent state
What is already running before a visitor has agreed to anything.
Tag / pixel
A small piece of code on a page that sends information to an outside company.
Tag manager
A control panel that loads tags onto your site without anyone editing the page. Anyone with access can add one.
Session recorder
A tool that records what happens on the page — clicks, scrolling, sometimes typing — so it can be replayed later.
Server-side relay
Data sent to an address on your own domain, which your server then forwards to an outside company. Removing the tag from the page does not necessarily stop it.
Consent gating
Holding trackers back until a visitor has actually pressed something on the cookie consent box.