Is StackPatrol a GDPR compliance tool?
No. StackPatrol is the technical map your DPO needs before the legal review. It surfaces the third-party services your website loads and where those vendors are based, so legal analysis starts from facts. We don't give legal advice or certify compliance.
How is StackPatrol different from BuiltWith?
BuiltWith is a sales-intelligence tool focused on identifying technology stacks for B2B prospecting. StackPatrol is built for digital sovereignty: it classifies vendors by ownership region (US, EU, China, etc.), explains the jurisdictional picture, and suggests European alternatives. No signup required, and we don't sell the data.
What does the free scan cover?
The free front-page scan requires no account or credit card. It loads the public front page once with a real browser and does not interact with the consent banner. You get a shareable service inventory, EU Independence Score, European alternatives and the count of possible policy-disclosure gaps.
What's the difference between free and Pro?
Free scans cover the front page without consent interaction. Pro (€39/month) unlocks 5-page scans, Accept-all and Reject-all observations, named policy-comparison evidence, a personal dashboard and weekly monitoring for up to 5 sites. Agency Starter covers 10 sites with 5-page scans; Agency and Agency Pro cover 30 or 100 sites with scans of up to 20 pages.
What does monitoring track over time?
Every monitored scan feeds a durable per-site history: when each service was first and last seen, its observed phase, and a timeline of additions, removals and score changes. The same run repeats the Reject-all network test and fingerprints readable privacy, cookie, DPA and terms documents, including documents on a labelled parent-company domain. Alerts can surface service changes, new post-reject signals, disclosure-gap changes and frozen documentation. CSV and JSON exports are available.
What does “loaded before consent” mean?
It's the single most decision-relevant signal for a DPO: which advertising, analytics and tracking vendors fire on the very first page load, before the visitor answers the cookie banner. StackPatrol records the no-interaction load, filters it to genuine tracking categories, and separates first-party services from third-party ones so the headline count reflects only third-party trackers. It's a technical observation of what loaded, not a legal assessment.
What is the Observed external services and transfer review worksheet?
Technical observations that can support updates to processing records and vendor registers. Legal and organisational fields require customer verification. It lists observed external services, ownership and DPF signals, and whether requests appeared before or after consent. Paid plans can export a CSV worksheet with empty customer fields for purpose, role, legal entity, processing location, confirmed mechanism, owner, status and comments.
What is the one-time PDF report?
The paid PDF (€79, one-time) scans up to 20 public pages and delivers an expanded technical service audit as a formatted PDF. It is useful evidence for DPOs, development teams or clients, but it is not a compliance certificate or a complete legal audit. Order it from a scan results page.
How does the policy comparison work?
StackPatrol compares observed services with readable privacy and cookie documents. Paid reports also inspect a consent manager's configured vendor view when one is available, in a separate clean browser context without saving consent. An exact service name or service-specific domain is an exact match. An explicitly curated provider or parent alias is shown separately as a qualified match. No match means worth checking, not proof of non-disclosure. Structured cookie tables can also support exact-name duration checks. Raw cookie and consent values are never retained.
What does the Reject-all result prove?
It proves what StackPatrol observed after activating a restrictive control in that automated run. The report separates whether the control was found, whether the UI interaction completed, whether stored CMP or TCF state changed, and which non-essential services sent later requests. A completed interaction is not automatically a confirmed rejection state, continued traffic is not a legal conclusion, and an incomplete test is never shown as a pass or fail.
How is the EU Independence Score calculated?
For EU- or EEA-owned sites, the score starts at 100 and subtracts weighted service-jurisdiction penalties, a non-EU mix penalty, unmatched-domain penalties and qualifying non-EU infrastructure signals for hosting, email and DNS. Category weights make a tag manager count more than a font, and a matched US DPF signal adjusts rather than settles the review. Separate ownership overrides cap and relabel non-EU-owned first-party sites. The score is an experimental independence signal, not a compliance rating.
Do you store my scan?
Yes. Scan results are saved so you can share a link to your report. If you're signed in, scans are also saved to your personal dashboard. We don't use the data for advertising or sell it to third parties.
Still have a question? Get in touch or run a free scan to see it for yourself.