Free scan
Troubleshooting

Website tracking issues, diagnosed

Pick the symptom you're seeing. Each guide gives you the direct answer, a five-minute check you can run yourself in DevTools, the technical causes, and a remediation checklist — then a free scan verifies it.

Why these pages exist

In our 2026 scan of 3,891 small-business sites, 61% fired at least one tracker before the visitor consented — and sites running a recognized consent platform did worse, not better, at 74% versus 57% for sites with none. Installing a banner is not the same as blocking anything, and every guide below starts from that gap.

21 guidesLast reviewed: September 1, 2026General information, not legal advice

A specific tracker fires before consent

You found the tool in the network tab and want it gated without breaking the marketing that depends on it.

11 guides

The Meta Pixel fires before consentA facebook.com/tr request on page load, before the banner is answered — the most common pre-consent tracker we find.Google Analytics loads before consentgtag.js loads and g/collect beacons fire on first paint — usually a missing Consent Mode default.Google Ads remarketing fires before consentdoubleclick.net / googleadservices.com requests on load — remarketing audiences filling before opt-in.The TikTok Pixel fires before consentanalytics.tiktok.com events on page load — often injected by a store channel app nobody gated.The LinkedIn Insight Tag fires before consentA quiet B2B ad pixel that loads on page view and sets identifiers — found on 327 of the 3,891 sites we scanned.Hotjar records before consenthotjar.com requests and _hjSession cookies on first paint — the recorder starts before anyone opts in.Session replay and CIPA riskRecorders streaming clicks, scrolls, and keystrokes to a vendor — the core pattern of the wiretap-claim wave.Your chat widget loads before consentThe widget opens a WebSocket and sets identity cookies on load — before anyone opens the chat.Klaviyo identifies shoppers before they consentThe onsite script builds a profile from page load, and an email click resolves that browser to a named person.Segment (or your CDP) sends data before consentOne script load, many destinations. Enforce consent at the CDP layer or every destination inherits the gap.Something on my site is identifying anonymous visitors by nameNames arriving for visitors who never filled in a form — a de-anonymization tool matching them against an identity graph.

The consent setup isn't doing its job

The banner, the container, or the platform is supposed to hold trackers back — and the network log says it isn't.

5 guides

Your consent banner isn't blocking trackersThe banner shows — and the network tab shows trackers firing anyway. The most common failure we see.Google Tag Manager fires tags before consentThe container loads, every matching trigger fires, and consent is an opt-in check you have to switch on per tag.Consent Mode is configured but tags still fireConsent Mode changes what Google's tags send, not whether requests happen — and non-Google tags ignore it entirely."Reject all" still leaves cookies setRejection stops future scripts; it rarely deletes what is already stored — and never touches scripts the CMP does not control.I can't edit the <head> on my website builderBuilders limit code injection by plan and apps inject their own scripts — here are the routes that still work.

Evidence, drift, and who is responsible

Questions that come up after a letter, an audit, or a security review — where the answer is a record, not a code change.

5 guides

What a CIPA demand letter is actually claimingA clause-by-clause decode of the standard claims — and which parts are legal questions versus facts you can verify.My agency installed the pixel — am I still responsible?The letters arrive at the business operating the site. What a contract can shift, and the access controls that stop a repeat.How to prove what consent looked like on a past dateA live site only shows today. What counts as dated evidence, what can be salvaged, and how to start the record now.My privacy policy doesn't match the trackers on my siteThe policy is a public statement; the network tab is the observable truth. Build the inventory that reconciles them.Your tracking changed after the auditThe audit said clean — now there are new third-party domains in the network tab. Here's how drift happens.

Don't know which one you have?

That's what the scan is for: RegSentry loads your site in a real browser, records exactly when each third-party tracker first contacts its server, and flags everything that fires before consent — with the fix for each tool.

Scan your site

Free, about 30 seconds, no signup to run it. Continuous monitoring re-runs the same check on a schedule and emails you when a new tracker appears.

Free real-browser scan

See every pre-consent tracker on your site — free, 30 seconds, no signup.

Real browser scan, no signup to run it. You see a summary of the findings; the full report with every tracker unlocks with your email.