检查清单

Cookie audit vs privacy policy claims: do they match?

开始免费审计

Compare privacy-policy cookie claims with Fresh and Reject evidence. Not a policy rewrite, not a second audit hub, and not legal advice.

In brief

A cookie audit records runtime cookies and requests. A privacy policy states what the business says it does. Treat cookie and tracking sentences as claims, then check them on Fresh and after Reject. ConsentProbe can store both packs. A free US-baseline scan is not an EU or California legal conclusion. This page is not a second cookie-audit hub, not a privacy-policy rewrite, and not legal advice.

Not legal advice

This FAQ explains how to observe whether a privacy policy's cookie and tracking sentences match runtime cookies and requests on Fresh and Reject visits. It is not legal advice, not a privacy-policy drafting guide, not a counsel review of any policy text, and not a GDPR, ePrivacy, CPRA, or other compliance certificate. ConsentProbe reports are technical observations of what fired. They do not say what counsel would allow in a policy. Observation is not counsel permission.

Last updated September 29, 2026. The before-Accept audit owns the general protocol. The CMP claims guide owns banner UI versus runtime. The testing hub owns which test is next. The evidence pack owns the file fields. The pre-consent checklist owns the pass order. This page does not rewrite those guides, and it is not a second cookie-audit hub.

Short answer

A cookie audit checks runtime cookies and requests. A privacy policy states what the business says it does with cookies and tracking. Those are different artifacts. Treat sentences such as "we only set essential cookies before consent" or "marketing pixels load after you Accept" as claims.

Falsify them on a clean visit. Capture cookies and marketing hosts on Fresh, with no Accept. Repeat after Reject All. Compare the pack to the policy wording. If the policy says marketing is off until Accept and Fresh shows ad or analytics hosts, you have a claims-versus-runtime gap. The same falsification idea covers CMP UI on the claims guide. This page covers policy text.

Open the before-Accept audit for the protocol, the hub for which test is next, and the evidence pack when you hand findings to engineering or counsel. This page is not a privacy-policy rewrite and not a second cookie-audit hub. It is not legal advice. Observation is not counsel permission.

Policy claim versus Fresh evidence

The rows below are example claims, not replacement policy text. Write the finding as a policy sentence versus a Fresh or Reject host. Leave legal wording with counsel.

Example privacy-policy cookie claims and what a Fresh or Reject visit can show.
Policy claim (example only)What a cookie audit can showWhere to open next
Only essential cookies before consentNon-essential or marketing hosts or cookies on FreshBefore-Accept audit and the essential-label FAQ
Marketing tags load after AcceptAd or analytics hosts on Fresh or after RejectMarketing-pixels FAQ and the Reject leftovers guide
We honor Reject AllThe same marketing hosts after Reject as on FreshReject leftovers guide and the evidence pack
The CMP or banner manages all cookiesScripts outside the gated path still fireCMP claims guide and the auto-blocking guide

Quote the policy, then capture Fresh and Reject

These steps compare quoted policy sentences with cookies and requests. They do not draft a privacy policy. The before-Accept audit holds the longer first-load method. The CMP claims guide holds a banner-UI mismatch. The report-reading guide holds how to read a finished pack.

  1. Open the live privacy policy. Quote one to three cookie or tracking sentences. Note the page date if one is shown.
  2. Use a clean profile. Load the storefront once. Do not click Accept. Label the pack Fresh. Capture cookies and Network for marketing and analytics hosts.
  3. Open a new clean profile. Click Reject All. Navigate once more. Label the pack Reject. Recapture cookies and Network.
  4. Write one finding sentence per mismatch. Example: the policy says no marketing before Accept, and Fresh shows host X.
  5. Keep the evidence pack. Hand the pack to engineering for gate fixes.
  6. If counsel asks for policy edits, hand them the quoted claims and the finding sentences. This page does not invent those edits.

Where the neighboring pages start

The before-Accept audit is the general runbook. Use it when you have not captured a clean first load yet. This page assumes you can quote policy sentences and label Fresh and Reject.

The CMP claims guide covers banner UI versus runtime. Use it when the mismatch is a category checkbox or an auto-block claim, rather than a sentence in the privacy policy.

The testing hub says which test is next. The evidence pack lists the file fields. The pre-consent checklist holds the pass order. The audit-versus-banner page separates a banner from a runtime audit. The report-reading guide walks a finished pack. This page does not paste those bodies.

Example of a storefront clue, not a customer capture: the policy says marketing tags load after Accept. Fresh Network shows an ad host before any banner click. After Reject and one more navigation, the same host is still there.

When matching policy sentences to Network rows gets slow

Matching policy sentences to Network rows across templates by hand takes a long time. ConsentProbe runs Fresh and Reject on the storefront URL. Each finding stays tied to a request, a cookie, or a screenshot. Compare that pack to the sentences you quoted.

Use the free US-baseline visit when you want the report format. Use paid EU or California scenarios when those regions are the claims. The free versus paid guide draws that line. ConsentProbe does not draft privacy policies, does not install a CMP, and does not issue a certificate.

FAQ

What is cookie audit vs privacy policy claims?

A cookie audit is runtime cookies and requests. A privacy policy is written claims. Compare them. They can disagree.

What if the policy says only essential cookies before consent?

Run Fresh. If marketing or analytics hosts appear, record a claims-versus-runtime finding. The before-Accept audit and the essential-label FAQ are the neighboring pages.

Is this the same as CMP claims vs runtime?

The falsification idea matches. The CMP claims guide covers banner UI. This page covers privacy-policy text.

Will this page rewrite my privacy policy?

No. This page is observation and an evidence handoff. It is not a privacy-policy rewrite.

Where do I start if I have never audited?

Open the testing hub or the before-Accept audit. This page assumes you can quote policy sentences and capture Fresh and Reject.

Is this legal advice?

No. These are technical observations. It is not legal advice. Observation is not counsel permission. ConsentProbe does not replace counsel, and it does not install a CMP.

Limits of this page

This page tells you how to quote cookie and tracking sentences and compare them with Fresh and Reject evidence. It does not rewrite the before-Accept audit, the CMP claims guide, the testing hub, the evidence pack, or the pre-consent checklist. It is not a second cookie-audit hub, not a privacy-policy rewrite, and not legal advice. Observation is not counsel permission. ConsentProbe reports stay tied to requests, cookies, and screenshots. A free US-baseline scan is not an EU or California legal conclusion.

Related guides

Open the before-Accept audit for the general protocol, the CMP claims guide when the mismatch is banner UI, the testing hub for which test is next, the evidence pack for the file fields, and the pre-consent checklist for the pass order.

Sources

These links cover the platform and regulatory context used in this guide. Applicability still depends on the organization and jurisdiction.

保存一次美国基线技术记录

完成自行检查后,可以跑一次免费美国基线审计:在加州以外做一次浏览器访问,把 Cookie、请求和截图存成证据。这次访问不会跑欧盟拒绝/接受,也不会跑加州 GPC。欧盟、加州和 Global 2 可在登录后的账单页购买。

Cookie 审计与隐私政策主张 | ConsentProbe