Back to the tracking audit

How the tracking audit works

The audit opens your public store in a real browser four times, as a new shopper each time. Every number in your report comes from the rules on this page.

What the visit does

Each visit starts with no saved cookies, from the EU, with Hungarian browser settings:

  1. First visit. We open your homepage and touch nothing. Whatever fires here fired before the shopper made any cookie choice.
  2. Reject. We click the reject button on your cookie banner, then reload the page. Whatever fires after the click fired after the shopper said no.
  3. Accept and shop. We accept cookies, open a product, add it to the cart, open the cart and then the checkout page.
  4. Phone. The same accept-and-shop path as an Android phone, up to the cart, so we can compare it with desktop.

We record every request your store sends to tracking platforms (Meta, Google, TikTok and others): the event name, the account ID it carries, and when it fired. We also read which tracking cookies the browser holds (names, domains and lifetimes, never their values). Google PageSpeed measures your homepage on mobile and desktop.

What it never does

  • It never places an order, types personal data, or clicks a pay button. It stops on the checkout page.
  • It never gets around a security check, such as a captcha or bot protection.
  • It only opens public pages and never logs in.

When we give no score

  • Bot protection or an error page blocked our browser. Nothing on such a page tells us about your tracking, so the report says “No score issued” and names who stopped the browser.
  • The browser visit could not run. The page then shows only the page-source check, and that check never has a score.

How the score works

The score starts at 100. Each problem costs points, by how serious it is:

PointsExample
Critical−35A tag still fires after the shopper rejects cookies
High−20An ad tag fires before the shopper chooses anything
Medium−8An event fires twice, or a shopping event is missing
Low−3Tracking scripts are heavy

Findings marked Note cost nothing. Every deduction is shown next to its problem, so you can add them up yourself. The score never goes below 0.

A step we could not do (for example, we found no product link) costs nothing and is marked “Not checked”. When any step is not checked, the score is marked “Provisional”, because it covers only what we saw.

How we judge consent

  • A request counts as sent after rejecting only when we found the reject button and clicked it. A banner with no reject button is reported on its own.
  • A Google request that itself says consent was denied (Consent Mode) is shown as a note, not a problem. Whether it needs consent is debated.
  • A tracking cookie set before a choice or after rejecting costs points only when that tool hasn’t already lost points at that step.
  • The click event Meta sends when we click your banner button is not counted, because it tells us nothing about what happens next.

What the audit can't see

  • Server-side tracking, such as the Meta Conversions API or a server-side tag manager. Data sent from a server needs the shopper's consent too, so ask your developer or agency how yours is set up
  • A completed purchase: we never pay or place an order, so the purchase event is not checked
  • Whether Meta and Google accept the events, or how much revenue tracking gaps cost you
  • Visitors outside the EU, or logged-in shoppers: we visit as a new shopper from the EU

A result is a snapshot

It shows what happened during these visits. Run it again after you change your theme, apps, cookie banner or tags.

This audit is not legal advice. You are responsible for the tracking and consent on your store. Ask a lawyer to review anything marked High or Critical.

How the Free Tracking Audit Works – Method and Scoring | Margyn