Free GDPR and privacy compliance
checker for your website
Paste your website URL. We scan for tracking scripts, cookie consent signals, privacy policy links, HTTPS, and fingerprinting, then give you a score out of 100 with findings by severity.
- Free tool, no signup
- Results in seconds
- GDPR, trackers & cookie consent check
What we scan
Five checks, one clear report
Our scanner loads your page the way a browser would and looks for the technical privacy signals regulators and privacy-conscious users care about.
Trackers and behavioral analytics
We flag third-party scripts from session replay, heatmap, and product analytics tools. Many record clicks, scrolls, or full session replays on third-party servers, which usually means stricter GDPR consent requirements and heavier page weight.
Cookie consent and GDPR signals
If high-impact trackers load without an obvious cookie banner or consent UI, we flag it. If a banner is present, we note it but cannot verify that scripts wait for consent before loading.
Privacy policy
We look for a visible link (for example "Privacy Policy" or "Datenschutz") and whether the linked page responds. Missing or broken policy links are a common compliance gap.
Security
HTTPS usage and mixed content (HTTP resources on HTTPS pages). Secure transport is expected for any site handling user data.
Fingerprinting
Patterns associated with canvas or WebGL fingerprinting in inline scripts. These techniques can identify visitors without traditional cookies.
Tracker detection
17+ trackers we detect
Behavioral analytics, session replay, and marketing tools that typically require explicit consent under GDPR.
- Hotjar (Contentsquare)
- Microsoft Clarity
- FullStory
- Lucky Orange
- Crazy Egg
- Smartlook
- LogRocket
- Mouseflow
- PostHog
- Inspectlet
- Heap
- Pendo
- Google Analytics 4
- Meta Pixel
- Segment
- Mixpanel
- Amplitude
How it works
From URL to report in under a minute
Step 1
Enter your URL
Public https:// sites only. We cannot scan localhost, staging behind auth, or internal IP addresses.
Step 2
We analyze the live page
Scripts, network requests, consent-related markup, privacy policy links, and security signals, similar to how a browser loads your homepage.
Step 3
Get your score and report
Issues grouped by severity with plain-language recommendations. Score 85+ to earn a shareable Privacy Friendly certificate.
Scoring
Understanding your privacy score
You start at 100. High, medium, and low findings reduce your score based on severity. Sites that score 85 or higher can earn a shareable Privacy Friendly certificate.
A high score means we did not detect common technical red flags on the scanned page at that moment. It does not guarantee full GDPR, CCPA, or ePrivacy compliance, especially for backends, email platforms, or apps we cannot see from a single public URL.
Who it's for
Built for teams who care about privacy
E-commerce stores
Shopify and e-commerce stores evaluating Microsoft Clarity, Hotjar, or similar tools.
SaaS & indie founders
Founders comparing privacy-first analytics to cookie-heavy enterprise stacks.
Marketers
Optimizing UX without aggressive cookie banners that hurt sign-up rates.
Product & compliance teams
Auditing tracking scripts before a launch, fundraise, or compliance review.
Fix findings, or start with privacy-first heatmaps
Many scans flag session recording and cookie-based analytics. heatmapp gives you heatmaps and AI insights in plain language, with cookieless-friendly tracking and a lightweight script.