For privacy & legal
Trackingplan inspects every hit for PII leaks, Consent Mode mis-fires and vendors firing without permission — across web, mobile and server-side. The audit a DPO would do manually, on every hit, automatically, with the legal context attached.
PII in payloads and URLs
Emails, names, IDs and addresses travelling in parameters, page paths or referrers, to any provider.
Consent Mode & CMP
The consent state on every hit, checked against what actually fired: analytics, ads, personalisation.
Vendors before opt-in
Pixels and SDKs that load or fire before the banner is answered, per market and per platform.
Evidence, ready for legal
Findings land in your privacy channel with the hits, the vendor, the market and the regulation involved.
Sounds familiar?
New tags, vendors, markets, releases, consent rules. One small change can quietly change what data is collected, where it goes, or when it’s collected.
Trackingplan reads the consent state travelling with every hit, on every device, checks every vendor and every payload against it continuously, and reports breaches with the exact hits — so the fix is a tag change, not an investigation.
Consent monitoring
Instantly spot when tags, pixels, or SDKs fire without proper consent, preventing inaccurate data and reducing privacy risks.
Since 14:20, the Google Ads conversion tag fires on page load for visitors in Germany, before the banner is answered, with ad_storage set to granted: 1,236 hits so far. France, Spain and the UK still wait for the answer. GA4 respects the default and is unaffected.
Cause: the 14:20 CMP update changed the default consent state for the de region to granted. One default to set back in the CMP, or in the Consent Mode initialization.
Ask it what matters
The agent works from every hit, investigates what changed, and delivers the evidence: the affected hits, vendor, market, consent state, and regulation involved.
Privacy audit for this week — anything I need to flag to legal?
Two things for legal, one for you.
1 · PII: Hotjar receives the hashed email on /account since Tuesday’s release — 2,140 sessions so far.
2 · Consent: the Meta pixel fires before consent for 3% of DE sessions; the CMP answers ~400 ms after the tag.
3 · FYI: two cookies set this week aren’t declared in the CMP: _ttp (TikTok) and _uetsid (Bing).
Nothing else changed: no new vendors, consent rate stable at 71% in the EU.
Consent states in real traffic
See how users’ consent choices are applied in real-time, ensuring every event aligns with their preferences.
Is any pixel firing before consent in the EU?
One, and only on part of the traffic. The Meta pixel fires before consent on 3% of DE sessions: the CMP answers about 400 ms after the tag has already loaded. GA4, TikTok and Google Ads wait correctly everywhere.
No new vendors this week, and the EU consent rate is stable at 71%.
PII leak monitoring
Prevent compliance risks by monitoring sensitive data, ensuring no personal or sensitive data from your users is being collected or forwarded to your analytics tools.
Which third-party tools received PII they shouldn’t this week?
Two vendors, neither of them supposed to see it. Hotjar received a hashed email as a session attribute on /account — 2,140 sessions since Tuesday’s template change. FullStory received a shipping address in a custom event on the confirmation page, 180 hits, all after consent.
Nothing went to an ad platform in the clear. Both values are already masked in this sample workspace. Drop the Hotjar attribute and stop sending the address event to FullStory; the checkout dataLayer can keep them for first-party use.
CMP across regions
Track your CMP across geographies and regulations, gaining full visibility into user consent and ensuring GDPR, CCPA, and global privacy rules are always respected.
_ttp is set by TikTok – Base Pixel on every page, 240 ms after load; _uetsid by Bing – UET on /checkout. Neither tag existed in the container before yesterday’s 18:40 publish. The other 45 cookies still match the CMP declaration, purpose and retention included.
To fix: add both cookies to the CMP with their purpose, and put the two tags behind the marketing consent trigger, as the other pixels are.
FAQ
The Trackingplan SDK only inspects the network requests that your site or app already sends to third‑party vendors (e.g., Google Analytics, HubSpot, Mixpanel, Google Ads), and forwards to our backend only the events required for anomaly detection, already anonymized on-device.
These requests are parsed locally in the browser or app, where anonymization and masking are applied as configured. Only the processed, non-identifiable event data is transmitted to Trackingplan’s servers. Once received, events are parsed, modeled, and continuously monitored to detect anomalies that may indicate implementation issues, whether in your own tracking or introduced by third-party tools. Through our web interface, teams can explore the detected schema, review alerts, and inspect sample events to debug tracking errors with full visibility and control.
Additionally, we do not introduce new identifiers, nor store IP addresses or fingerprinting data, as these are stripped before processing.
For a complete overview of our privacy and security measures, please visit our Privacy & Security documentation.
At Trackingplan, we are committed to full transparency in how we handle data and protect user privacy. Our platform is designed with privacy, security, and compliance at its core, ensuring that our clients maintain complete control over their data while meeting the strictest privacy regulations.
The Trackingplan SDK only observes the network requests your site or app already sends to third-party services—such as Google Analytics, HubSpot, Mixpanel, or Google Ads. These requests are parsed locally within the user’s browser or mobile app, where any necessary anonymization or masking is applied according to your configuration. Only processed, anonymized events—never raw or identifiable data—are forwarded to Trackingplan’s backend, strictly for anomaly detection purposes.
Client data remains fully encrypted and logically isolated at all times. Our infrastructure runs on hardened AWS PaaS services, with encryption enforced both in transit and at rest. Fine-grained IAM roles and resource-level permissions ensure strict access control, while all customer data is automatically deleted after 90 days by default.
Security is not just technical—it’s built into our processes. Every code change is peer-reviewed and deployed via CI/CD pipelines. Our team enforces two-factor authentication (2FA), maintains detailed audit logs, and ensures 24/7 system monitoring with on-call coverage to guarantee availability. GDPR principles are embedded into our design, and we offer optional Data Processing Agreements (DPAs) to support legal and regulatory compliance.
Through Trackingplan’s web interface, clients can inspect data schemas, review alerts, and analyze sample events in real time—empowering teams to debug implementation issues and safeguard data quality, without ever compromising user privacy.
For a complete overview of our privacy and security measures, please visit our Privacy & Security documentation.
No. The Trackingplan installation script is specifically engineered to be lightweight, non-intrusive, and secure—comparable to those used by trusted observability tools like Datadog and Sentry. At under 10KB, it loads asynchronously and does not block or delay the execution of any existing page elements or scripts.
The script is served directly as source code to eliminate the risk of unauthorized changes. It has been thoroughly reviewed by some of the most security-conscious clients in the industry, including data-driven organizations and privacy-focused teams. For companies that require additional assurance, we offer access to the decompiled version of the script under a signed non-disclosure agreement (NDA).
Designed with privacy and performance in mind, the script works only on declared endpoints—intercepting requests to third-party vendor domains that you’ve explicitly selected for monitoring. It performs anonymization and masking locally within the browser or app, without relying on external dependencies or introducing new cookies, storage mechanisms, or cross-site tracking.
Trackingplan's script never collects more data than your site or app already sends to analytics providers. It simply observes outgoing requests and ensures that only anonymized, relevant data needed for anomaly detection reaches our backend—without interfering with your application or compromising user privacy.
For a complete overview of our privacy and security measures, please visit our Privacy & Security documentation.
Trackingplan infrastructure runs exclusively on hardened cloud infrastructure in the EU — AWS (Frankfurt), ClickHouse Cloud (Frankfurt), Cloudflare's edge network, and Microsoft Azure for AI.
All customer data is processed and stored in the EU.
All endpoints are protected via AWS WAF, TLS 1.2+ encryption, and AES‑256 at rest.
For a complete overview of our privacy and security measures, please visit our Privacy & Security documentation.
No, Trackingplan does not store or collect any personal data.
We are fully committed to respecting user privacy and maintaining compliance with global privacy regulations such as GDPR and CCPA. Trackingplan only observes the data your site or app is already sending to analytics or marketing tools—and only for the purpose of monitoring tracking quality and detecting implementation issues.
Here’s how Trackingplan handles identifiers and user data:
In short: Trackingplan never introduces new tracking mechanisms, never stores personal data, and never builds user profiles. We act only as a passive observer of the data you're already sending to your vendors, with strict safeguards in place to prevent access to personally identifiable information (PII).
If you have questions about how Trackingplan handles data privacy or want to review the decompiled script under NDA, please contact our support team. For a complete overview of our privacy and security measures, please visit our Privacy & Security documentation.
Book a demo
This isn’t a sales call. It’s a chance to understand what matters most to you, discuss any data quality concerns you may have, and share practical ways Trackingplan could support your goals, if it makes sense.