See which trackers fire before your visitors say "Accept".
PrivaScan loads your site in a real browser and records every tracker, pixel and cross-border data transfer that runs — before consent. The #1 cause of KVKK & GDPR fines, made visible.
- Pre-consent
- trackers
- Cross-border
- transfers
- Cookies
- & storage
- KVKK · GDPR
- mapped
Built for the regulations that carry the biggest fines
Loading your site in a real browser…
Recording every network request, cookie and storage write. This takes 15–30 seconds.
From a URL to a defensible privacy record
No setup, no sign-up. Paste an address and see the data flows in seconds.
Paste a URL
Enter any public page — your homepage, a landing page, a checkout.
We load it for real
The page runs in a real browser while we record every request, cookie and storage write.
We classify the risk
Trackers are matched to vendors and categories; pre-consent and cross-border flows are flagged.
You get the evidence
A prioritized list with fix steps and a verifiable report — proof you can hand to auditors.
Pre-consent tracking
- Analytics fired on load
- Ad & social pixels
- Tag managers
- Before any consent
Cross-border transfers
- Data sent to the US
- Russia / China endpoints
- KVKK Art. 9 risk
- GDPR Chapter V risk
Session recording
- Hotjar / Clarity
- Yandex Webvisor
- FullStory / Mouseflow
- Screen replay of users
Storage & Shadow IT
- Cookies (incl. HttpOnly)
- localStorage / IndexedDB
- Unexpected 3rd parties
- Leftover plugins & CDNs
Evidence and risk indicators — not legal advice
PrivaScan surfaces the technical signals behind KVKK/GDPR risk and maps them to the relevant articles. It is an evidence and monitoring tool, not a law firm or a guarantee of compliance.
A whole-site, evidence-grade privacy scan
Not just your homepage — and honest about exactly what an automated scan can and can't prove.
Whole-site crawl
Reads your sitemap and scans across the site — prioritising the highest-risk pages (login, checkout, forms), not just the front page.
Behind-login scanning
Add a dedicated, encrypted test account and PrivaScan logs in to catch trackers that only fire in member areas.
Real-browser detection
Loads each page in real Chrome and records every request, cookie and storage key before anything is clicked — so it's all pre-consent.
Verifiable evidence file
Every report is a tamper-evident PDF (SHA-256) anyone can verify at /verify — plus a GDPR Art. 30 data inventory.
Continuous monitoring
Re-scan on a schedule and get emailed the moment a new tracker or data flow appears.
Expert DPO review
A human reviewer verifies what automation cannot — whether "Reject" truly blocks trackers, and whether transfers have a stated basis.
What the scan reliably sees
- Known client-side trackers firing before consent (3,900+ signatures)
- CNAME-cloaked first-party trackers & lazy-loaded (on-scroll) ones
- Cross-border destinations measured by server location (geo-IP)
- Whether Reject / Accept actually change what fires
When PrivaScan flags a tracker, it really did fire — strong, verifiable evidence.
What no automated scan can prove
- What a server-side tag actually sends (we flag likely collectors, can't confirm)
- Trackers not in the signature list, or that fire only on deep interaction
- The legal validity of consent / whether your basis is correct (→ DPO review)
- DPAs, retention, policy text — off-page facts
Cross-border regions are measured by tracker server location where possible. Absence of findings is good hygiene — not proof of compliance.
The bridge between your Legal and IT teams
Your lawyer can't see the technical leaks; your developer can't read the legal risk. PrivaScan translates one into the other.
Prioritized findings
Trackers sorted critical-first, each tied to the vendor, category and the article it touches.
Data mapping inventory
A ready GDPR Art. 30 processing table: what data, by whom, for what, to where.
Developer fix steps
Concrete remediation — e.g. block Google Tag Manager until consent — not vague warnings.
Verifiable evidence
A dated, SHA-256-sealed report you can show a regulator: "we audit regularly".
Start free, get full-site evidence when you need to
Run single-page scans for free. Move to monitoring and full-site evidence when you are ready.
Scan
On-demand
- Single-page scans, unlimited
- Pre-consent tracker detection
- Cross-border transfer flags
- Cookies & web-storage inspection
- No sign-up required
Monitor
Continuous
- Everything in Scan
- Daily scheduled re-scans
- Email alerts on new trackers
- Full-site crawl (up to 25 pages)
- Privacy findings report (PDF)
Compliance
Full-site + KVKK/GDPR
- Everything in Monitor
- Full-site crawl (up to 250 pages)
- Up to 10 sites
- GDPR Art. 30 data inventory (PDF)
- Priority support
Questions, answered
Isn't a cookie banner enough to be compliant?
Which laws does this cover?
How does the scan work?
Is this legal advice?
Do you store the pages I scan?
What is your site leaking right now?
Run a free scan and see the trackers that fire before consent. No account, no credit card.