Scroll

Free tracking scan

See what your website tracks before a patient consents.

Enter any domain. We load the page in a real browser and watch what actually fires — analytics, ad pixels, cookies, and whether anything gates them. Read-only, no signup, 5–15 seconds.

smithplasticsurgery.com Scan
Real browser

Headless Chromium loads the page fresh, cookie-less, like a first-time visitor.

Named evidence

Every finding cites the exact tracker or cookie it saw fire.

HIPAA-framed

Scored against the tracking-technology exposure OCR actually enforces.

smithplastic
surgery.com
first load
Google
Meta
Google Ads
Microsoft
TikTok
Hotjar
LinkedIn
Chat vendor

Someone visits your site…

0network requests
0trackers firing pre-consent
0seconds observed
F
0 / 100

No consent gate stood in front of any of them.

Where your data went

…and their data is already gone, before anyone clicked accept.

Deduplicated by parent company, because eleven hostnames belonging to four companies is not four times less exposure.

3 hostnamesGoogle

Analytics, Ads conversion linker, Tag Manager. Received the page path.

2 hostnamesMeta

Pixel PageView with an advertising cookie already set on another site.

1 hostnameMicrosoft

Clarity session capture, including form-field interaction.

1 hostnameTikTok

Advertising pixel loaded on every page, gated by nothing.

1 hostnameHotjar

Heatmap and recording, keystrokes in form fields captured by default.

Each tag received the URL, and the URL names the procedure. Paired with the IP address and an advertising cookie set weeks ago on a different site, this stops being anonymous traffic and starts being a person associated with a medical interest.

Pages we checked

A tracker on a page that also collects visitor input.

That combination is the exposure OCR guidance is most concerned with. The scan opens the homepage in full, then up to three health-intent pages.

pagetrackerscollects inputstatus
/6noobserved
/rhinoplasty-consultation8yes — embedded formflagged
/contact-us7yes — embedded formflagged
/about6noobserved

Scope: this scan observes fresh, cookie-less loads. It cannot see trackers that load later, only for logged-in visitors, or behind interactions this scanner doesn't perform. Treat a clean result as a starting point, not a compliance certification.

Your site today

observed on this scan
8
trackers firing before consent · 5 companies
ga4 meta pixel google ads gtm clarity tiktok hotjar linkedin

With Consential

deny by default
0
until the visitor makes a choice · every choice written down
Nothing non-essential loads. The decision appends to a log where UPDATE and DELETE are revoked at the database permission level.

Consential blocks every one of these until a visitor agrees.

Get the full report

Named tags, named cookies, with timestamps.

Business contact only — no patient or health information is collected, and we don't store the pages we load. We keep a record of the domain scanned so we can follow up.

Tracking exposure report25 Jul 2026
smithplasticsurgery.com · grade F · 8 trackers · 5 companies

Talk to us

Fix what this scan found.

Consential blocks tracking scripts until consent is granted, keeps an append-only audit trail, and syncs consent into your CRM automatically. Compliance isn't a promise. It's a paper trail.

Consential · scrollytelling prototype Figures illustrative · not a customer's data