Bounded piece of work · fixed price
Your privacy notice describes a website that no longer exists
Almost every privacy notice was accurate on the day it was written. Then someone installed a plugin, a host added analytics, a chat widget was trialled and forgotten. Nobody updated the notice, because nobody was looking at the website — they were looking at the document.
We look at the website
We load your site as an ordinary first-time visitor and record what the browser is actually handed to: every third-party service, the country each one processes in, every cookie set before a consent choice is made, and — the check almost nobody runs — whether your cookie banner blocks anything, or simply asks a question while the trackers run regardless.
Then we read your privacy notice against that record, and list every statement in it that is no longer true.
Reviewing a privacy notice against the law tells you whether it is well drafted. Reviewing it against the site tells you whether it is true. Those are different questions, and only one of them is answered by reading documents.
Before we sold this, we ran it on ourselves
Five of the ten checks failed
On 31 August 2026 we ran this scan against cyber-safe.ca. Our notice referred four times to a live chat provider. It stated plainly that we ran no analytics. Both were wrong: a chat service nobody here had ever used was collecting visitor data on every page, and Google Analytics was running on every page, firing before anyone consented to anything. There was an undisclosed payment processor and a consent banner enforcing nothing. We removed what we could, asked our host to remove the rest, and rewrote the notice the same evening.
We tell you that because it is the point. A privacy notice is a statement of fact about your own systems, and the only way to know whether it is true is to check.
We ran it again the same afternoon
The band above records the first pass. What it does not record is what happened when we ran the same ten checks again a few hours later, after we had fixed everything the morning found.
It found four more things. That is not a failure of the first pass. It is what this work is actually like, and it is the reason a scan is worth more than a document review.
Five of ten checks failed.
- A live chat provider nobody here had ever used, loading on every page and collecting visitor data
- A flat statement in our notice that we ran no analytics, while our host injected Google Analytics that fired before anyone consented to anything
- A payment processor we had not named
- A consent banner that asked the question and enforced nothing
Four findings the first pass did not reach.
- A discussion forum from 2022, still live and still indexable, named for a word we tell everyone we are not
- A sample certificate PDF from 2022, still served publicly years after the page that used it was deleted
- Two tracking scripts injected by our host that cannot be switched off from inside WordPress
- Five cookies we could not attribute to anything we knew was running
The forum and the certificate are the interesting pair, because neither was linked from anywhere. Both belonged to a version of this business that stopped existing years ago. Deleting a page does not unpublish the files attached to it, and nobody goes looking for pages nothing links to. The only routes in were a direct address and a search engine — which is to say, the two routes a stranger uses.
We removed both the same day.
What is still open, on our own site
We think you should see this part too, because every real assessment has one. This section has been corrected once, and we have left the correction where you can see it.
We got one of our own findings wrong. We recorded that our host was injecting Google Analytics. It was not. The Analytics tag is ours — configured on this site, in consent mode, storing nothing on a visitor’s device until they accept. We found a tag we had not expected, assumed the platform had put it there, and wrote that down without tracing it to source. That is precisely the mistake this scan exists to catch, and we made it about ourselves. Corrected 5 September 2026.
The host scripts were real, and there was a setting. Three scripts from our host’s content network, and two calls to its telemetry endpoint, loaded on every page before any consent choice. We reported that they could not be switched off from inside the site. They could: Website Metrics, in the hosting control panel rather than in WordPress. Switching it off removed all five immediately. What is still open is the period before that — what was collected while they ran, where it was processed, and how long it is kept. We have asked, and we will publish the answer here.
Five cookies are still unattributed. We know they are set by JavaScript rather than by our server. We do not yet know by what. Guessing would have been easy and would have been the wrong answer to put in a notice.
Both of these are the kind of finding that recurs rather than closes, which is exactly the distinction the findings note draws for your site. We did not leave them out because they are ours.
What we check
Observed on the live site, not taken from a questionnaire.
- Every third party your visitors are handed to, and where each processes
- Every cookie set before any consent is given
- Whether the consent banner actually blocks, or only displays
- Tracking injected by your host that you cannot see from inside your site
- Forms: what they collect, where they send, whether anything is ever deleted
- Payments: who holds the card details, and whether they are named
A short, dated findings note. Three pages, written so you can hand it straight to whoever fixes it.
- Every third party found, with country of processing and whether your notice mentions it
- Cookies set before consent, and which the banner failed to block
- Each line of your notice that no longer matches, with the evidence beside it
- Which findings are one-off fixes and which will drift back
- What we did not examine, stated plainly
Turnaround is two to three working days from the go-ahead.
The two checks that find things. Whether the consent banner blocks anything, and whether your host is injecting tracking you never installed. Almost nobody runs either, because both require opening the site rather than the policy. Both produced findings on our own website.
A banner that asks for consent and enforces nothing is worse than no banner at all: it is a documented control, so everyone assumes it works.
What it costs
One website, up to eight significant pages, one privacy notice. Fixed price, agreed before we start.
CAD $350
Book a website privacy scan — CAD $350
Secure checkout by Stripe · we confirm within one working day and your findings note follows in two to three. Deliberately priced to be an easy decision. The findings usually are not.
Sites drift. Plugins arrive, hosts change platforms, and the notice quietly stops being true again.
CAD $250
Any repeat scan of the same site within twelve months. The findings note records what changed since the last one. Ask us and we will send you the link.
What we do not do
We tell you what is wrong. We do not write your privacy notice.
This is not legal advice and we are not a law firm. We do not draft or redraft privacy notices — we tell you where yours is inaccurate, and you or your counsel put it right. We do not sell the fix, we do not recommend a vendor to carry it out, and we take no fee from anyone who does. We give no assurance on anything we did not examine, and what we did not examine is listed in the note.
This is an assessment, so we will not then remediate what we found. We say so before you book.
Who it is for
Anyone who signed off a privacy notice more than a year ago and has installed anything since. In practice that means most organisations: privacy officers who inherited a notice they did not write, general counsel who are asked to confirm it is current, and boards who have been told everything is fine and would like that checked by somebody with no stake in the answer.
There is no charge for the first conversation and no obligation at the end of it. If we look at your site and there is nothing much to find, we will tell you that rather than pad a report.