Skip to content
StackPatrol
The full tour

Everything in a StackPatrol report

A clean, shareable map of your third-party stack — built for technical teams and the DPOs they answer to. Free to start, no signup.

Free for everyone

The map, on every scan

No account, no credit card. Paste a URL and get a full vendor report in under a minute.

See what loads before consent

The single most decision-relevant signal for a DPO: which advertising, analytics and tracking vendors fire on the very first page load — before the visitor ever answers the cookie banner. First-party services are separated out so the headline count reflects only third-party trackers. A plain-language finding, not a legal verdict.

18 third-party trackers loaded before consent
18 before consent8 non-EU

Detect third-party scripts as they load

Trackers, analytics, tag managers, fonts, CDNs and embeds. A headless browser loads your actual pages and records every outbound request.

Google AnalyticsCloudflareMeta PixelHotjarSegmentStripe

Map vendors by region

US, EU, EEA, UK or Unknown for every vendor found.

US-owned8
EU-based4
Unknown2

Discover EU alternatives

Curated European replacements for the most common US tools. Fewer transfer-mechanism questions to answer.

Consent Assurance · paid

Does the banner actually work?

The findings a visitor can't Google on their own site: what the policy forgot, and whether Reject all is respected. Free scans show the disclosure-gap count; the full findings come with a paid plan.

Consent Assurance

Compare disclosure sources with observed services

StackPatrol reads your cookie policy, privacy policy and DPA. Paid reports can also inspect the configured vendor view exposed by supported consent managers without saving consent. The report separates exact service matches, qualified provider or parent matches, and observed services with no match. These are technical prompts to review, not legal findings.

3 services have no match in the checked disclosure sources
Provider-only references are shown separately, so a company name is not presented as an exact service disclosure.
Consent Assurance

Observe what follows a Reject-all interaction

StackPatrol activates an explicit Reject-all control on a clean visit, then separates interaction evidence, stored CMP or TCF state and later network traffic. Paid reports name non-essential services observed after the evidence boundary without claiming that a legally valid rejection was independently confirmed.

2 trackers kept firing after “Reject all”
Google Analytics and Google Ad Manager kept sending requests even after the consent banner’s reject button was clicked.

Weekly monitoring timestamps when a post-reject signal first appears and when a later scheduled run no longer observes it.

Paid reports & registers

Evidence you can hand over

The provenance, register and infrastructure detail a DPO needs to document a finding — not just a score.

Paid

See exactly where each tracker loads

For every vendor, the report shows which page it fired on and whether it ran before or after consent — the evidence a DPO needs to document a finding, not just a score.

Found on
Meta Pixel (US)
example.com/health/psychological-support
before consent14:32:07
Paid

Observed external services and transfer review worksheet

Technical observations that can support updates to processing records and vendor registers. Legal and organisational fields require customer verification. The CSV keeps legal and organisational fields empty for the customer to complete.

EU / EEA ownership
7
Adequacy / DPF signal
7
Customer review required
10
Paid

Check hosting, email & DNS jurisdiction

A site can run its trackers from the EU yet still host itself, its email or its DNS on a US-owned provider. StackPatrol resolves your origin hosting, email (MX) and authoritative DNS (NS) providers, classifies each by ownership region, and flags EU–US Data Privacy Framework certification for US vendors — the sovereignty signals a vendor list alone misses.

Hosting
Amazon AWS US
Email (MX)
Google Workspace US
DNS (NS)
Cloudflare US
Pro & Agency monitoring

See changes at each scheduled check

Turn a one-off scan into a standing watch: weekly re-checks, a durable timeline and email alerts.

Pro & Agency

Build a dated history of observed changes

StackPatrol re-scans your sites every week and keeps a durable history of what each scheduled run observed: when a service first appeared, when it went away and every score change in between. When a change is detected, you get an email alert and a dated timeline entry for the next audit. Export the history to CSV or JSON.

Sample alert
+ New vendor detected: Intercom (US)
First seen 11 Jul 2026 · Found on example.com · Weekly re-scan · View timeline →
Pro & Agency

Watch your privacy & cookie policies for changes

Each monitored scan also finds and fingerprints your privacy policy, cookie policy, DPA and terms — even when they live on a parent-company domain. We track the date each page says it was last updated and detect when the content actually changes. The most useful signal: when your vendor stack shifts but the privacy policy stays frozen, the alert flags a possible documentation gap.

Policy may be out of date
2 new vendors since last scan, but the privacy policy hasn’t changed since 14 Mar 2025.

See it on your own site

Every free scan includes what loads before consent, the vendors your policy forgot and a region-classified vendor map. Upgrade any time for monitoring and reports.