We manually test, implement, and verify website privacy compliance. Our services:
- Privacy Audit: manual review of every tracking technology on your site and testing of every consent state, with recorded evidence
- CIPA Services: opt-in consent blocking for California visitors, tested and verified
- CCPA Services: a working Do Not Sell or Share opt-out with Global Privacy Control honored
- GDPR Services: opt-in consent for EU/UK visitors with granular choices and consent records
- Cookie Banner Services: WCAG 2.1 AA / 2.2 AA testing and remediation of your consent interface
- Consent App: do it yourself with our app for Shopify, WordPress, and all other sites
Every service includes accessibility testing and implementation. We evaluate your consent implementation for WCAG 2.1 AA conformance as it renders on your page.
We can also provide training and consultation for your digital team.
| Key Point | What It Means for You |
|---|---|
| Manual review | A person identifies every cookie, pixel, session replay tool, and script on your site by watching real network activity. |
| Privacy Audit | Our flagship starting point: we test what tracks visitors in every consent state and deliver recorded evidence. |
| Consent implementation | Non-essential tracking is blocked until the visitor chooses, with opt-outs that actually stop tracking. |
| Accessibility included | Your consent interface is tested for WCAG 2.1 AA conformance with a keyboard and screen reader. |
| Preserved evidence | Recorded verification testing and dated reports you keep on file. |
| Fixed pricing | Every service is fixed-price and paid in advance. No sales calls. |
Why is Manual Privacy Testing Necessary?
Most privacy compliance products are automated. A scanner categorizes your cookies, a banner appears, and a dashboard says you’re covered.
We do the opposite. Our work is manual. A person examines your website, watches what actually loads, tests every consent state, and records the evidence.
Automated tools recognize known cookies. They miss custom scripts, storage-based tracking, tags loaded through other tags, and tracking that fires before the consent tool initializes. Manual review is the only way to find these gaps.
What is the Privacy Audit?
The Privacy Audit is our flagship privacy service and the right starting point. It answers two questions: what actually tracks visitors on your website, and does your consent setup actually work?
What we examine:
- Every cookie, pixel, session replay tool, chat widget, and script on your site, manually identified by watching real network activity rather than running a scanner
- What fires on first page view, tested before any consent choice is made
- What continues to fire after a visitor rejects or opts out
- Whether Global Privacy Control signals are honored
- Whether your consent banner and preference center conform to WCAG 2.1 AA as they render in your theme, tested with a keyboard and screen reader
- Whether your privacy policy matches the tracking actually in use
What you receive:
- A full tracking inventory identifying each technology and what it tracks
- Recorded verification testing for each consent state: screen captures with network activity
- A dated report identifying the exact banner version and configuration tested
- Specific findings: what fires when it shouldn’t, what’s inaccessible, what your policy misstates
- A prioritized remediation path, whether we do the work or your team does
Like our WCAG audits, the Privacy Audit is fixed-price, paid in advance, and performed by a person. No sales call required.
Legal Compliance
After the audit, or if you already know your exposure, we do the remediation and verification work for each law.
Accessibility is part of every service below. We evaluate your consent implementation for WCAG 2.1 AA conformance as it renders on your page.
CIPA Services
The California Invasion of Privacy Act (CIPA) is California’s wiretap statute. The technical question is whether any tracking captures visitor interactions before a California visitor consents.
- Manually identify every technology that tracks interactions: session replay, chat widgets, advertising pixels, analytics tags
- Configure consent so non-essential tracking is blocked for California visitors until they opt in
- Test the leak points and fix them: hardcoded scripts that bypass the consent signal, tags that load other tags, tracking that fires before the consent tool initializes
- Evaluate your consent implementation for WCAG 2.1 AA conformance as it renders on your page
- Re-test after implementation and record what loads on first page view
- Deliver dated recordings and reports for your records
Learn more about CIPA compliance requirements.
CCPA Services
The California Consumer Privacy Act (CCPA) gives California residents the right to opt out of the sale and sharing of personal information. It’s an opt-out model, so the work is making opt-outs real rather than decorative.
- Implement a Do Not Sell or Share mechanism on your site
- Manually test Global Privacy Control (GPC) with the actual browser signal, then configure automatic honoring
- Test that opting out stops the relevant tracking rather than just hiding the link
- Evaluate your opt-out mechanism and consent interface for WCAG 2.1 AA conformance as they render on your page
- Align your privacy policy language with your actual tracking inventory
- Deliver recorded evidence of the opt-out working
Learn more about CCPA compliance requirements.
GDPR Services
The General Data Protection Regulation (GDPR) requires opt-in consent before non-essential tracking fires for visitors in the EU and UK.
- Implement opt-in consent: nothing non-essential loads until the visitor agrees
- Configure granular choices by purpose, with no pre-ticked boxes, and manually test each purpose toggle
- Test both directions: nothing fires before consent, and rejection genuinely blocks tracking, verified against network activity rather than the banner’s own reporting
- Evaluate your consent implementation for WCAG 2.1 AA conformance as it renders on your page
- Make withdrawal as easy as acceptance and set up consent record-keeping
- Deliver the recordings and dated reports
Learn more about GDPR compliance requirements.
Cookie Banner Services
The cookie banner is where every legal requirement meets the visitor. Consent collected through an interface a disabled visitor cannot operate is not meaningful consent.
This is where our accessibility expertise and our privacy work are the same work.
- Manually test your banner and preference center against WCAG 2.1 AA and WCAG 2.2 AA as they render in your theme, with a keyboard and screen reader, the same way we test in our WCAG audits
- Test keyboard operability end to end, screen reader announcement, focus management, contrast, and target sizes
- Remediate the issues we find, or provide exact fixes for your developer
- Verify the banner blocks the tracking it claims to block
- Deliver a dated report identifying the exact banner version and configuration tested
Learn more about cookie banner compliance requirements.
How do we test privacy compliance?
We apply our same discipline and rigorous evaluation to meticulously inspect your privacy consent, tracking, and management.
- Network-level verification. We watch the actual requests your site makes in each consent state. A consent tool’s dashboard saying a script is blocked is a claim; the network log is the fact.
- Every consent state, tested separately. Before any choice. After acceptance. After rejection. After withdrawal. With GPC enabled. Each state is loaded fresh and recorded.
- As rendered, not as configured. Banners behave differently inside real themes than in vendor demos. We test yours where your visitors meet it.
- Assistive technology, actually used. Keyboard-only operation and screen reader testing by a person, not an automated accessibility score.
- Evidence you keep. Screen recordings, network captures, dated reports, and Accessible.org documentation naming the exact configuration tested.
DIY Approach: Use Our app.
Our consent app is available for Shopify, for WordPress, and as a general script for all other sites.
It blocks non-essential tracking until the visitor chooses and honors rejection and withdrawal. The banner and preference center are built to conform with WCAG 2.1 AA and WCAG 2.2 AA: fully keyboard navigable, announced correctly to screen readers, with visible focus and adequate contrast.
Pair it with a Privacy Audit if you want your implementation independently verified.
How Our Services Work
We apply our standard process to every client’s custom situation.
Frequently Asked Questions
Why does manual review matter if I already ran a privacy scanner?
Scanners match against databases of known cookies. They miss custom scripts, browser-storage tracking, tags that load other tags, and anything that fires before the consent tool initializes. These are findings we routinely make manually on sites a scan reported as clean.
Can I buy just one service?
Yes. Each service can be scoped individually, such as CIPA verification testing only or accessibility testing of an existing banner. The Privacy Audit is the most common starting point because it tells you which areas actually need work.
I already have a cookie banner. Do I still need this?
A banner being installed and a banner working are different things. The audit confirms whether your setup actually blocks tracking on rejection and opt-out, and gives you the evidence either way.
Do you work with third-party consent platforms?
Yes. We audit, verify, and fix implementations built on any consent tool, or implement with our own app.
How fast is turnaround?
Our standard turnaround time for project completion is 2 weeks. Turnaround depends on the size of your website and the tracking in use. Send your URL and we’ll reply with a fixed price and timeline.
Get Started
Do you need to make sure your website meets all privacy requirements. We’d love to help.
Contact us with your website URL and we’ll reply with a fixed price for the Privacy Audit and other services, including implementation. No sales call required.