Skip to content
PeekWell
Join now

How Peeky scans your site, from address to report

Peeky opens your public pages the way a visitor would and writes down what happened. Here’s the whole path, with one sample site to follow.

Four steps, start to finish

  1. Add a website

    Type in your address. That’s the whole setup. Peeky only needs a public page to start from.

  2. Peeky reads the public pages

    In an ordinary browser, the way a visitor would. I answer the cookie banner both ways, then read the policies you link to.

  3. You get a report

    Each finding says what I saw, why it matters and what to do next. The fix is written so your developer, or your AI coding tool, can use it as it is.

  4. It runs every month

    With Accreditation, Peeky scans again each month and your badge shows what the latest scan saw.

Four visits, one page

Peeky opens hollowbrook.app, an imaginary site, four times. Each visit answers the banner differently. Pick one and see what the page did.

Says nothing

Hollowbrook’s page with the cookie banner still waiting for an answer.
Requests that started
6
Companies contacted
4
Cookies set
9
Requests on this visit, with the time each started after the page began to load
HostWhat it isTime after load
hollowbrook.appThe page0.00 s
hollowbrook.appStyles and fonts0.20 s
hollowbrook.appImages0.31 s
consent.hollowbrook.appCookie banner script0.40 s
www.googletagmanager.comTag manager1.10 s
www.google-analytics.comAnalytics1.25 s
widget.intercom.ioChat widgetdid not load
connect.facebook.netAd measurementdid not load
static.hotjar.comSession recordingdid not load
cdn.hollowbrook.appVideo playerdid not load

I click nothing. Analytics still starts at 1.25 seconds.

Says no

Hollowbrook’s page with the cookie banner showing that reject was pressed.
Requests that started
6
Companies contacted
4
Cookies set
9
Requests on this visit, with the time each started after the page began to load
HostWhat it isTime after load
hollowbrook.appThe page0.00 s
hollowbrook.appStyles and fonts0.20 s
hollowbrook.appImages0.31 s
consent.hollowbrook.appCookie banner script0.40 s
www.googletagmanager.comTag manager1.10 s
www.google-analytics.comAnalytics1.25 s
widget.intercom.ioChat widgetdid not load
connect.facebook.netAd measurementdid not load
static.hotjar.comSession recordingdid not load
cdn.hollowbrook.appVideo playerdid not load

No change. That’s the finding.

Says yes

Hollowbrook’s page with the cookie banner showing that accept was pressed.
Requests that started
10
Companies contacted
8
Cookies set
14
Requests on this visit, with the time each started after the page began to load
HostWhat it isTime after load
hollowbrook.appThe page0.00 s
hollowbrook.appStyles and fonts0.20 s
hollowbrook.appImages0.31 s
consent.hollowbrook.appCookie banner script0.40 s
www.googletagmanager.comTag manager1.10 s
www.google-analytics.comAnalytics1.25 s
widget.intercom.ioChat widget2.10 s
connect.facebook.netAd measurement2.40 s
static.hotjar.comSession recording2.90 s
cdn.hollowbrook.appVideo player3.20 s

Four more things load and five more cookies appear. That part is expected.

Sends a privacy signal

Hollowbrook’s page with the cookie banner still waiting for an answer.
Requests that started
6
Companies contacted
4
Cookies set
9
Requests on this visit, with the time each started after the page began to load
HostWhat it isTime after load
hollowbrook.appThe page0.00 s
hollowbrook.appStyles and fonts0.20 s
hollowbrook.appImages0.31 s
consent.hollowbrook.appCookie banner script0.40 s
www.googletagmanager.comTag manager1.10 s
www.google-analytics.comAnalytics1.25 s
widget.intercom.ioChat widgetdid not load
connect.facebook.netAd measurementdid not load
static.hotjar.comSession recordingdid not load
cdn.hollowbrook.appVideo playerdid not load

I send the Global Privacy Control signal and click nothing. The page doesn’t react to it.

One finding, with the rule in the margin

This is the finding from the first visit. The card says only what I saw. The margin says which rule it touches.

Visit slip, hollowbrook.app

When
3 June 2026, 09:14
Seen as
a first-time visitor in the EU, ordinary browser
Not clicked
Accept all, Reject all, Manage settings
CriticalTicket
ePrivacy · GDPRCookies

Google Analytics sets a cookie before consent

Google Analytics set _ga on https://hollowbrook.app/ 1.25 seconds after the page loaded, before anyone answered the cookie banner. Non-essential cookies need a visitor’s agreement first, and this is one of the first things regulators have checked, because it shows in the network log.

Read more details on the wiki
GET https://www.google-analytics.com/g/collect?v=2&tid=G-7K2XQ4 204 t+1.25s
Set-Cookie: _ga=GA1.1.6604.1727; Max-Age=63072000; SameSite=Lax
Consent state: banner visible, no interaction
After Reject all: GET https://www.google-analytics.com/g/collect 204

1. ePrivacy Directive, Article 5(3). Storing or reading something on a visitor’s device needs their agreement first, unless it’s strictly necessary. Regulators have treated analytics cookies as needing it.

In plain words

Google Analytics puts a cookie on your visitors’ browsers before they click “accept cookies”. It’s like a shop signing you up for its loyalty card the moment you walk in, before you’ve said whether you want one. Cookies should load only after a visitor agrees to them. This is usually a setting in your cookie banner.2. GDPR, Article 4(11) and Article 7. Agreement means a clear yes from the visitor. Leaving a banner alone isn’t one, and neither is a pre-ticked box.

Load Google Analytics from your consent tool’s accept callback instead of on page load. If you use Google tags, set consent mode to “denied” by default. Re-scan to confirm no request fires before the click.3. The fix changes when the tag loads. What the rule asks of your site is a question for your lawyer.

The Officer’s drawer

Hollowbrook is made up. These are not. Every case links to the authority’s own publication, and to the check that looks for the same thing. The smallest amounts come first.

Where
What was observed
Amount the authority published
Outcome

20 of 20 case files match

  • Case 009CMA (United Kingdom), 2026

    Countdown timers and high-demand messages found misleading

    The CMA said Emma Sleep admitted breaking consumer law by using misleading countdown timers, false high-demand messages and discount claims on its website. A High Court order of 22 May 2026 confirmed the CMA's position.

    Emma Sleep, United Kingdom · Undertakings to the court

    Emma Sleep gave binding undertakings, enforceable by the court, to stop these practices and put compliance measures in place. The was/now pricing part of the case was due at trial from early June 2026.

  • Case 004Garante (Italy), 2025

    Cookie banner reappeared after visitors closed it

    The Garante inspected the company's website, confalonieriauto.it. It found a cookie banner that came back after a visitor clicked X and did not let users give specific, informed consent to non-technical cookies, and a privacy policy that lacked detail on tracking tools.

    Confalonieri S.r.l., Italy · No fine: reprimand

    The Garante issued a formal warning and an order to comply, with no fine.

  • Case 018FTC (United States), 2025

    Alleged: Children's location data collected without parental consent

    The FTC alleged that China-based Apitor, which sells robot toys for children aged 6 to 14, did not notify parents or get their consent before it, or a third party, collected children's location data. The complaint says the app included a third-party software kit called JPush.

    Apitor Technology, China · $500,000, suspended

    A proposed order filed in federal court would require parental notice and consent, with a $500,000 penalty suspended because of the company's inability to pay.

  • Case 020FTC (United States), 2025

    Alleged: Hosting security tools missing despite award-winning security claims

    The FTC alleged that GoDaddy claimed to provide award-winning security while not using multi-factor authentication, not monitoring for security threats and not securing connections to consumer data.

    GoDaddy Inc., United States · Order to fix

    The FTC finalized an order requiring a comprehensive security program, independent assessments and no misrepresentation of its security.

  • Case 017FTC (United States), 2024

    Alleged: Health data shared with ad platforms through tracking pixels

    The FTC alleged that Monument, a New York-based alcohol addiction treatment service that told users their information was 100% confidential, disclosed health details to Meta, Google and other ad platforms through tracking pixels. According to the complaint, as many as 84,000 users were affected.

    Monument, Inc., United States · $2.5 million, suspended

    Under a proposed order that needs federal court approval, Monument would be banned from disclosing health information for advertising. A $2.5 million civil penalty would be suspended because of its inability to pay.

  • Case 019US Department of Justice (United States), 2022

    Alleged: Vaccine portal barriers for screen reader and keyboard users

    After a compliance review, the Justice Department determined that parts of CVS's vaccine registration portal were not accessible to some people with disabilities. Screen reader users met incorrectly labeled form fields, and people not using a mouse would need to press the Tab key hundreds of times to move past one control. CVS denied wrongdoing.

    CVS Pharmacy, Inc., United States · No payment stated

    CVS agreed to bring its vaccine content to WCAG 2.1 AA and to test it regularly.

  • Case 003Garante (Italy), 2025

    Promotional emails sent without documented consent

    The Garante found that the company could not document valid consent for promotional emails sent through partner portals, where consent was recorded only through IP logs. A rights request from the complainant was first blocked by the company's spam filter.

    Noi Compriamo Auto S.r.l., Italy · €45,000

    The Garante fined the company €45,000.

  • Case 005ANSPDCP (Romania), 2024

    Cookies installed before consent, operator identity not shown

    After a complaint, the ANSPDCP found that the company's website did not show the identity of the operator and installed cookies that were not technically necessary before users gave consent.

    Urban Home Development S.R.L., Romania · 10,000 lei

    The authority fined the company 10,000 lei under the e-communications law, issued a warning under the GDPR and ordered the privacy policy and cookie setup corrected.

  • Case 016FTC (United States), 2019

    Alleged: Paid reviews posted on Amazon for a supplement

    The FTC alleged that the supplement seller and its owner paid a website, amazonverifiedreviews.com, to create and post Amazon reviews of their garcinia cambogia product. It also alleged the weight-loss claims were unsubstantiated.

    Cure Encapsulations, Inc., United States · $12.8 million judgment, suspended on payment of $50,000

    The company and its owner settled under a proposed court order, with a $12.8 million judgment suspended on payment of $50,000 and unpaid taxes.

  • Case 006ICO (United Kingdom), 2026

    Millions of marketing texts sent without valid consent

    The ICO found that the Newcastle-upon-Tyne company sent 4,046,947 marketing text messages between February 2023 and February 2024 promoting PPI tax refund services. The messages lacked valid consent and did not meet the soft opt-in rules.

    Allay Claims Ltd, United Kingdom · £120,000

    The ICO fined the company £120,000.

  • Case 007ICO (United Kingdom), 2026

    Marketing emails sent on third-party data without informed consent

    The ICO found that the Bristol company sent 67,772,285 marketing emails between January and July 2023 using third-party data. Recipients had not been given properly informed consent.

    ZMLUK Limited, United Kingdom · £105,000

    The ICO fined the company £105,000.

  • Case 008ICO (United Kingdom), 2026

    Debt-solution texts sent to millions without valid consent

    The ICO found that the Manchester company sent more than 5.5 million marketing texts between April 2022 and May 2025 promoting debt solutions. Some used the sender ID DEMAND, and the messages drew more than 60,000 complaints.

    KRA Consultancy Ltd, United Kingdom · £300,000

    The ICO fined the company £300,000.

  • Case 015FTC (United States), 2026

    Alleged: Employee and incentivised reviews presented as customer reviews

    The FTC alleged that TruHeight relied on reviews written by its own employees and vendors, or by consumers offered a free product or discount for a 5-star review. According to the complaint, it also used fake social media profiles run by bots.

    Vanilla Chip LLC (TruHeight), United States · $4 million judgment, $750,000 payable

    The FTC's final order, approved in July 2026, bars the company and its principals from misrepresenting reviews and buying reviews tied to a sentiment, with a $4 million judgment partially suspended after $750,000 is paid.

  • Case 013California Attorney General (United States), 2024

    Alleged: Customer data sold to marketing cooperatives without notice

    The California Attorney General said its investigation found that DoorDash sold customers' names, addresses and transaction histories through marketing cooperatives. The complaint alleges its privacy policy did not state that this information was disclosed.

    DoorDash, United States · $375,000

    DoorDash agreed to pay a $375,000 civil penalty, review vendor contracts and report annually to the Attorney General.

  • Case 001CNIL (France), 2025

    Advertising cookies set before visitors chose

    The CNIL found that several cookies, particularly for advertising, were placed on visitors' devices as soon as they arrived on shein.com, even before they interacted with the information banner. It also found that clicking Refuse all, or withdrawing consent, did not stop new cookies being placed.

    Infinite Styles Services Co. Limited (SHEIN), Ireland · €150 million

    The CNIL fined the company €150 million on 1 September 2025.

  • Case 002CNIL (France), 2025

    Refusing advertising cookies took more effort than accepting

    The CNIL found that when users created a Google account, it was more difficult to refuse cookies linked to personalised advertising than to accept them. It also found advertisements displayed between emails in Gmail without prior consent.

    Google LLC and Google Ireland Limited, France · €325 million

    The CNIL fined Google LLC €200 million and Google Ireland Limited €125 million, and ordered changes within six months.

  • Case 010California Attorney General (United States), 2025

    Alleged: Tracking cookies kept running after visitors opted out

    The California Attorney General said its investigation found that Healthline kept sharing data with some advertising third parties even when consumers opted out, and shared article titles suggesting a diagnosis to target ads. The complaint alleges the consent banner did not disable tracking cookies when a box was unchecked.

    Healthline Media LLC, United States · $1.55 million

    Healthline agreed to pay $1.55 million in civil penalties and to change its opt-out and data-sharing practices.

  • Case 012CPPA (California, United States), 2025

    Alleged: Opt-out tools did not honour Global Privacy Control

    According to the agency's decision, Tractor Supply's privacy policy did not notify consumers of their rights, job applicants were not told of their privacy rights, its opt-out mechanism did not work effectively, including for opt-out preference signals such as Global Privacy Control, and personal information was disclosed to other companies without privacy contracts.

    Tractor Supply Company, United States · $1,350,000

    Tractor Supply agreed to pay $1,350,000 to resolve the allegations, scan its digital properties for tracking technologies and have a corporate officer or director certify compliance annually for four years.

  • Case 014FTC (United States), 2025

    Alleged: Subscriptions hard to cancel, charges continued afterwards

    The FTC alleged that Chegg did not give subscribers a simple way to cancel auto-renewing subscriptions. It said that since October 2020 nearly 200,000 consumers were charged after asking to cancel.

    Chegg, Inc., United States · $7.5 million

    Chegg agreed to a proposed order requiring $7.5 million for consumer refunds and simple cancellation mechanisms.

  • Case 011California Attorney General (United States), 2022

    Alleged: Data sale not disclosed, opt-out signals not honoured

    The California Attorney General alleged that Sephora did not tell consumers it was selling their personal information and did not honour opt-out requests sent through Global Privacy Control.

    Sephora, United States · $1.2 million

    Sephora agreed to pay $1.2 million, update its disclosures, support the Global Privacy Control signal and report to the Attorney General.

Everything Peeky checks

45 checks, 15 each for the EU, the UK and the US. Cookies and consent are 12 of them. The rest are policies, data rights, reviews and pricing, subscriptions, accessibility, marketing messages and connection basics.

EU

UK

US

Peeky’s blind spots

What Peeky reads

  • Public pages an ordinary browser can open.
  • What loads, and which cookies are set, before a click and after each answer.
  • The policies and notices your pages link to.
  • The headers your server sends back.
  • Prices, countdowns, reviews and renewal terms, as a visitor sees them.

Who can change it: your developer. Who says what it means: your lawyer.

What can’t be seen from outside

  • Anything behind a sign-in.
  • What your team does with data once it has it.
  • Whether you have signed agreements with the companies you use.
  • How quickly you answer a person who asks for their data.
  • What happens when a form is sent.

Who can: your lawyer, the person who looks after privacy for you, and your developer for the systems behind the page.

Public pages only. Peeky never signs in, submits forms, tests passwords or looks for weaknesses. PeekWell is not a security testing service and cannot be used as one.

The sample accreditation page

With Accreditation, you get a public page like this one and a badge to put on your site. Both come from the latest monthly scan. Everything here is sample data for an imaginary site.

hollowbrook.app

Sample page for an imaginary site. Last scan 3 October 2026.

86
of 100
  • 88

    EU

    Banner and policy match what the site does.

  • 85

    UK

    Marketing messages say who sent them.

  • 83

    US

    Opt-out link is in the footer.

Step through the five monthly scans to see the badge switch on and off by itself.

PeekWell score One scan a month on hollowbrook.app. The badge is on from 80 up.

June 2026

PeekWell accreditation: not activePeekWellnot active
Sample badge for hollowbrook.app, an imaginary site.
54

Last scan 3 June 2026

First scan. Most of it is the cookie banner.

July 2026

PeekWell accreditation: not activePeekWellnot active
Sample badge for hollowbrook.app, an imaginary site.
71

Last scan 3 July 2026

Banner fixed. The privacy page still doesn’t name Intercom.

August 2026

PeekWell accreditation: accredited 84%PeekWellaccredited 84%
Sample badge for hollowbrook.app, an imaginary site.
84

Last scan 3 August 2026

Over 80. The badge switches on by itself.

September 2026

PeekWell accreditation: not activePeekWellnot active
Sample badge for hollowbrook.app, an imaginary site.
76

Last scan 3 September 2026

A new chat widget set cookies before anyone said yes. Badge off, on its own.

October 2026

PeekWell accreditation: accredited 86%PeekWellaccredited 86%
Sample badge for hollowbrook.app, an imaginary site.
86

Last scan 3 October 2026

The widget waits for consent now. Badge back on.

Passed means the expected behaviour was observed on the pages scanned. Neither a Passed nor the score says a website is compliant.

Your first look is free and takes about three minutes.

Join now