ClauseReport blog

What we check, and why

What ClauseReport checks for — a plain-English guide to every privacy-policy and terms-of-service signal in our model.

Completeness ·2 min read

Does your website have a privacy policy? Why a linked policy matters

A linked privacy policy is the most basic privacy signal a website can have — and a surprising number of sites are missing one. Here's what ClauseReport checks and why it matters.

Read more →
Consistency ·2 min read

Tracker vs. disclosure: the gap between what a site does and says

ClauseReport's flagship check compares the trackers actually loading on your page against what your privacy policy discloses. The gap is where the risk lives.

Read more →
Disclosure ·2 min read

Cookie disclosure: does your policy explain the cookies you set?

If your site uses cookies, visitors expect the policy to say so. ClauseReport checks whether cookies and similar technologies are explained.

Read more →
Completeness ·2 min read

What data do you collect? Describing the categories you gather

A core function of a privacy policy is telling people what personal data you collect. ClauseReport checks whether those categories are described.

Read more →
Completeness ·2 min read

How is the data used? Stating your purposes for processing

Collecting data is only half the story — policies should explain why. ClauseReport checks whether purposes of processing are described.

Read more →
Completeness ·2 min read

Who do you share data with? Disclosing third parties and processors

Most sites pass data to service providers and platforms. ClauseReport checks whether the policy describes third-party sharing.

Read more →
Completeness ·2 min read

Data retention: how long do you keep personal data?

Keeping data forever is a liability. ClauseReport checks whether your policy states how long personal data is retained.

Read more →
Rights ·2 min read

User rights: access, correction, and deletion in your policy

Depending on where your users live, they may have rights to access, correct, or delete their data. ClauseReport checks whether those rights are described.

Read more →
Rights ·2 min read

'Do Not Sell or Share My Personal Information': the CCPA signal

California consumers can opt out of the sale or sharing of their personal information. ClauseReport notes whether that language is present.

Read more →
Completeness ·2 min read

Children's privacy and COPPA: does your policy address minors?

Sites that may reach children carry extra obligations. ClauseReport checks whether the policy addresses children's privacy.

Read more →
Completeness ·2 min read

International data transfers: does your policy address cross-border data?

If your tools or users span borders, data crosses them too. ClauseReport checks whether international transfers are addressed.

Read more →
Completeness ·2 min read

Can people reach you about privacy? Contact methods in your policy

Privacy rights are meaningless if there's no way to exercise them. ClauseReport checks whether the policy gives a contact method.

Read more →
Completeness ·2 min read

Terms of service: why every site should link one

Terms of service set the rules between you and your visitors. ClauseReport checks whether a terms or terms-of-use page is linked from your site.

Read more →
Disclosure ·2 min read

What trackers is your website running? Fingerprinting analytics and ad pixels

Most sites load more third-party trackers than their owners realize. ClauseReport fingerprints the analytics, advertising, and session-recording tools running on your page.

Read more →
Completeness ·2 min read

The 'last updated' date: why a stale policy is a red flag

A missing or years-old 'last updated' date suggests a policy hasn't kept pace with the business. ClauseReport checks for a recent effective date.

Read more →
Hygiene ·2 min read

Broken privacy policy links: the silent compliance gap

A privacy policy that returns a 404 is worse than none at all — it signals neglect. ClauseReport verifies that the linked policy actually loads.

Read more →
Hygiene ·2 min read

[COMPANY NAME] still in your privacy policy? Catching template placeholders

Generated and copied policies often ship with placeholder text that was never filled in. ClauseReport flags leftover bracketed placeholders and boilerplate.

Read more →
Hygiene ·2 min read

Is your privacy policy actually about your business? Spotting boilerplate

A generic, copy-pasted policy can be worse than none — it describes practices that aren't yours. ClauseReport checks for specificity.

Read more →