Skip to content
StackPatrol
For agenciesand independent consultants

Ship a privacy audit before the kickoff call ends.

Scan a client site for third-party scripts, trackers, CDNs and non-European vendors. Walk in with a shareable report, walk out with a remediation engagement. White-label PDFs and weekly monitoring on the Agency plan.

Use in client deliverablesWhite-label PDFs on AgencyWeekly monitoring per client

Need a full site audit?

Why agencies run this audit

Most clients have no idea what their own website is loading. The tag manager has been touched by three agencies, four interns and a marketing consultant. StackPatrol finds the mess in seconds.

Client says

What's loading on the site?

Their answer

I think we have Google Analytics. Maybe Hotjar?

Client says

Did you remove Facebook Pixel?

Their answer

We removed it last year. I think.

Client says

How many vendors total?

Their answer

Three? Maybe five? Actually… I'm not sure.

Three minutes with a network tab usually finds twelve more vendors. StackPatrol does the same thing in fifteen seconds and produces a shareable report you can drop into a proposal.

The 9-point checklist

Run a StackPatrol scan, open the report, and walk the client through these nine items.

#1

What third-party domains is the front page contacting?

Look for the unfiltered request list. Anything you can't instantly identify is a candidate for removal.

#2

Which vendors are US-owned?

For European clients, US-owned vendors may require additional transfer review — a transfer impact assessment, supplementary measures, sometimes a cookie-banner update — depending on Data Privacy Framework participation, the contractual setup and the data involved. StackPatrol flags them so you know where to look.

#3

Where is the site hosted, and who runs its email and DNS?

A site can serve EU-only trackers yet still sit on US-owned hosting, email (MX) or DNS (NS). StackPatrol resolves all three and flags EU–US Data Privacy Framework certification for US vendors — infrastructure risk a vendor list alone misses.

#4

Which vendors are unmatched?

Usually a small regional tool, a CDN nobody documented, or a leftover from a campaign that ended years ago. Each one is a question to ask.

#5

Are there duplicate vendors?

It is common to find two analytics tools, two tag managers, two consent platforms. Each duplicate costs money and slows the page.

#6

Are there European alternatives worth proposing?

For each US vendor StackPatrol surfaces, check the suggested European alternative. Many clients will switch if you do the evaluation work for them.

#7

Does “Reject all” actually stop the trackers?

On paid plans StackPatrol clicks “Reject all” in a clean browser context and records every non-essential tracker that keeps firing afterwards — the reject-all verdict. A banner that still loads advertising or analytics after a rejection is the single most defensible finding you can put in front of a client. It's a technical observation, not a legal ruling, but it turns “your banner might not work” into “here are the two trackers that ignored the visitor's no.”

#8

Is every vendor named in the policy?

StackPatrol reads the site's cookie and privacy documents and compares what they name against what the page actually loads, then surfaces any vendor observed loading but absent from every policy — a possible disclosure gap. You no longer have to diff the banner against the vendor list by hand; the report does it and names each gap. It's text matching, not a legal parse, so “not found” means “worth checking” — but it points you straight at the notices that need a review.

Common findings

Patterns we see on most European sites.

!

Google Tag Manager loading a US chatbot, which loads a Cloudflare worker, which writes a cookie set by a US fraud-detection vendor. The dependency tree is the story.

!

"EU-region" Google Analytics that still phones home to google-analytics.com on first request.

!

Old Facebook Pixel from a 2021 campaign, still firing, still sending hashed emails.

!

Three font providers when one would do: Google Fonts + Adobe Fonts + a self-hosted leftover.

How to price your audit

Agencies typically charge for analysis and recommendations, not for the scan. A common structure:

FreeLead magnet

Run a scan, share the report, highlight one or two findings.

4–8 hoursPaid audit

Walk the checklist with the client, write a remediation plan, recommend specific replacements.

2–6 weeksProject

Implement replacements, update the cookie banner, write the privacy policy, set up monitoring.

Frequently asked questions

Can I use StackPatrol scans in client deliverables?

Yes. Reports are shareable via a public URL (/r/<id>) and PDF audit reports are available for €79 each. The Agency plan (€149/month) includes white-label PDF reports you can hand directly to clients. Attribution is appreciated but not required.

Can I monitor client sites over time?

Yes. Pro (€39/month) lets you add up to 5 sites for weekly monitoring. Agency Starter (€89/month) covers 10 sites, Agency (€149/month) covers 30, and Agency Pro (€299/month) covers 100. StackPatrol re-scans each site every week, re-runs the reject-all verdict and disclosure-gap check, and emails you when new vendors appear, when a tracker starts firing after “Reject all”, or when a vendor goes missing from the policy. Each consent violation and its later fix is logged with a timestamp, so you get dated before-and-after proof of exactly when a problem started and when it was resolved — perfect for keeping client-site audits current after implementation.

Does StackPatrol find vendors that only appear on internal pages?

The free scan covers the front page plus one additional internal page to catch vendors that only load deeper in the site. Paid plans let you pin up to 3 (Pro) or 5 (Agency) custom paths per monitored site, useful for checkout, account or thank-you pages where conversion tags hide. The one-time PDF report (€79) crawls up to 20 pages. With a Pro or Agency subscription you can run unlimited scans and build up a full scan history across all your client sites.

Is this enough for a Schrems II / Transfer Impact Assessment?

No. StackPatrol gives you a fast, accurate inventory of front-end vendors and their ownership region, plus where the site is hosted and who runs its email (MX) and DNS (NS) — and, for US vendors, whether they hold an EU–US Data Privacy Framework certification. The boring discovery step, done. The legal analysis (lawful basis, SCCs, supplementary measures) is your job.

How does this compare to BuiltWith or Wappalyzer?

Those are sales-intelligence tools. They tell you which technologies a site uses so you can pitch products to it. StackPatrol is a privacy and digital-sovereignty tool: it classifies vendors and the site's hosting, email and DNS infrastructure by ownership region, explains the jurisdictional risk, and suggests European alternatives.

Try it on a client site now.

Free, no signup, results in under a minute. Drop the report URL into your next proposal.

Need a full site audit?

No account required Shareable report link EU alternatives included