A website privacy audit starts with an inventory. Before anyone can write an accurate privacy policy, configure a consent banner or answer a customer's question, somebody has to list what the site actually loads from other companies. On most sites nobody has that list.
Why the list is usually wrong
Three things make it drift:
- Tag managers. Marketing adds a pixel inside Google Tag Manager. Nothing changes in the site's code, so the developer never sees it.
- Old campaigns. A pixel added for a campaign two years ago keeps loading long after the ad account is closed.
- Plugins and embeds. A chat widget, a video embed or a form plugin brings its own analytics with it.
The result is that the privacy policy describes the site as it was when the policy was written.
Step 1: get the real inventory
Load the page in a real browser and record every request it makes. That is what the tracker inventory endpoint does:
curl "https://seoscoreapi.com/trackers?url=https://example.com" \
-H "X-API-Key: YOUR_KEY" | jq '.trackers[] | {vendor, category, injected}'
Each entry names the vendor, puts it in a category (analytics, advertising, session replay, chat, marketing automation, A/B testing, monitoring), and says whether it was in the page source or injected by something else. summary.third_party_requests is the count of all requests that left your domain.
Run it on more than the homepage. Checkout, booking, contact and login pages are where the sensitive data is, and they often carry different tools.
Step 2: sort the list
Go through it with whoever owns marketing and ask three questions about each entry:
- Do we still use it? If nobody can name the owner, it is a candidate for removal.
- Is it in the privacy policy? Every vendor on the list should be named or covered by a category the policy describes.
- Should it be on this page? Session-replay tools on a page with a payment or medical form deserve a second look.
Step 3: check the consent tool separately
The inventory names the consent manager it finds on the page. It does not test whether your trackers wait for a visitor's choice, because one automated visit can't establish that. Test that by hand: open the site in a private window, decline, and watch the network tab.
Step 4: repeat it
The list goes stale the same way it did before. Run the inventory on a schedule and compare it with the last run. A new vendor appearing is the signal that something was added without the policy being updated.
What this is not
An inventory is a list of facts about what loaded. It isn't a legal opinion, and it doesn't tell you whether a given tool is a problem under any particular law. It gives the person who does make that call an accurate starting point.
Frequently asked questions
Does a privacy audit need a paid tool?
No. A browser's network tab shows the same requests. A tool makes it repeatable and gives you vendor names instead of raw hostnames.
How many pages should I check?
At least the homepage, one content page, and every page with a form or a payment step.
Will removing old pixels speed the site up?
Usually. The inventory reports the bytes each vendor transferred, so you can see which ones cost the most.