Consent and Guard
A website the visitor can trust.
You see what your website actually does. What it sends, what it loads, also when the visitor declines.
The cookie banner, Consent Mode and tag settings tell you how the website should behave. Snowetic checks how it actually behaves. Snowetic Consent shows from real network traffic what your website sends before the visitor's choice, after acceptance and after refusal. Snowetic Guard checks from the same capture what the website loads and whether any of it needs checking. The analysis runs in your browser, and nothing is sent anywhere.
Consent cannot be verifiedfrom the cookie banner.
A website can have a correctly configured cookie banner and Consent Mode, and still something happens that differs from what the settings suggest. A tracking request can be sent before the choice is made. Refusal does not necessarily stop all data transfer. A tag can send personal data in a way no one has noticed. That is why the technical implementation of consent is verified from what actually leaves the browser. The ruling KHO:2026:64 (August 27, 2026) of the Supreme Administrative Court of Finland confirmed that transmitting data read from the user's device is subject to consent.
- 01Refusal has been given, but tracking requests continue.The cookie banner does not show this.Snowetic shows the requests that should not be sent, and their recipients.
- 02Personal data is sent along with the purchase event.An email address or a phone number can travel in a network request in plain text.Snowetic identifies plain-text personal data in the requests and tells you who it is sent to.
- 03The website loads scripts that no one ordered.A third-party script can change without any visible change in the online store itself.Snowetic Guard shows what the website loads and which changes or data transfers need checking.
You see what your website actually sends.
The implementation of consent is verified from traffic, not from settings.
Snowetic Consent shows from real network traffic what your website sends before the visitor's choice, after acceptance and after refusal: tracking requests, cookies set, plain-text personal data and the recipients the data is sent to. Every finding is based on a network request you can check yourself, accompanied by a reference to the relevant legal provision. Fix instructions are targeted at your own environment, and after the fix the same check can be run again to verify the change.
Every finding is backed by evidence.
Snowetic does not infer the situation from settings or tag names, nor from the fact that the website has a particular cookie tool or that a tag is named correctly. In the report you see the network request the finding is based on, and the reference to the legal provision. The result is Indications of a violation, Gray findings or No indications of a violation: a technical finding, not a legal decision.
You see what personal data is sent and to whom.
A mere list of the tags in use does not tell you what is actually transmitted inside them. Plain-text data such as an email address, a name or a phone number is identified in the requests together with the recipient. Simply knowing that the website has Consent Mode or a cookie banner does not tell you this.
The same website in different consent states.
What happened before the choice? What changed after acceptance? What kept happening after refusal? Snowetic compares which requests are sent, which cookies are set and what personal data is transmitted in each state. Whether the visitor's choice is honored is verified from traffic, not assumed from settings.
Fix instructions for the exact environment where the problem is.
The instructions are targeted at the detected cookie tool, the tag management and each tracking tool separately, with alternative implementation methods for Google Tag Manager. No instructions are given as a guess if the loading source cannot be verified. After the fix, the same check can be run again to verify the change.
Nothing is sent anywhere.
The analysis runs in your browser. The capture and the report stay on your computer, and a content security policy technically blocks external connections.
One check, four views.
- SummaryThe overall picture of what happened in each consent state.
- FindingsIndividual requests, cookies, personal data and their recipients.
- SecurityFindings made by Snowetic Guard from the same capture.
- Fix instructionsActions targeted at the detected environment.
The report can be saved as text and as a PDF. Server-side transmissions, such as the Conversions API and webhooks, are not visible in browser traffic, and they are checked separately from the tracking tool's logs.
You see what your website actually loads.
Snowetic identifies changed, anomalous and suspicious code that the visitor does not see on the website.
In an online store, the browser loads code from your own website, from platforms, plugins, analytics services, advertising systems and other third parties. From the same capture as Consent, Snowetic Guard checks the scripts your website loads, changes in them and suspicious data transfers: whether a known library has changed unexpectedly, whether a script shows signs of malicious behavior, whether card or form data is sent to an unexpected recipient, and whether direct IP addresses or misleading domain names appear on the checkout path. A single suspicious sign does not automatically mean malicious code: an uncertain finding is marked for checking, not as an alert.
Anomalous transmission of payment data made visible.
At checkout, the recipient of the data matters. A value in the format of a card number that is sent anywhere other than the payment service's own address is raised for checking or as an alert, depending on the strength of the evidence. The question is simple: does data leave the checkout for a recipient it should not go to?
Unexpected changes in a known library are detected.
A change is detected by comparing the library with a known version. A mere difference in size does not trigger an alert, because vendors update their libraries. The goal is to distinguish a normal update from a change that needs checking.
Suspicious recipients brought into view.
Direct IP addresses, misleading domain names and unknown recipients on checkout paths, each together with the network request.
One sign does not make malicious code.
Obfuscation or listening to keyboard events also occurs in legitimate libraries, so an alert requires a combination. The more serious the claim, the stronger the evidence must be.
Guard uses the same inspection material as Consent.
The content of the scripts is read in your browser. Nothing is sent. Guard is included in the inspection report as its own Security view and does not require a separate capture. To check the online store's checkout, the capture must cover the purchase path all the way to the checkout.
Is there code at the checkout that should not be there? Snowetic checks that.
A check of your own traffic.
The check is made from a capture of your website's network traffic, a HAR file: a recording you make with your own browser by visiting the website first without making a choice, then accepting, and then declining. Each state is recorded separately so that their behavior can be compared reliably. Snowetic's inspection tool guides you through making the capture step by step.
The analysis then runs in your browser and produces a report in four views. When the website is fixed, the same check is run again. Real traffic then shows whether the behavior changed as it should.
Consent shows the situation.Measure keeps measurement in order.
Snowetic Consent checks what your website actually does. Snowetic Measure keeps advertising measurement continuously in order with the same verification method and notices when a change to the website, tags or settings breaks something that worked before. Snowetic Guard checks what your website loads and whether any of it needs checking. Consent shows the situation at the time of the check. Measure continues monitoring after that.
What Snowetic Consent and Guard promise.
Verified from real network traffic, not assumed from settings.
When a refusal is not honored, you see the request that was sent. When personal data is sent, you see the recipient. When there is code at the checkout that should not be there, you see it and where it sends data.
Snowetic Consent is a technical check, not a legal assessment. It does not claim that a website is GDPR compliant, lawful or unlawful, and it does not issue a compliance certificate. A clean technical result alone does not prove lawfulness. Snowetic Guard is a detector of deviations, not a security product that blocks attacks. A clean check result means only that no deviations recognized by Guard were found in the checked traffic. It does not mean that the website could not have other security problems.
In Consent and Guard checks, the analysis runs in your browser, and neither the capture nor the report is sent to Snowetic. Processing in the EU, named subprocessors and the data processing agreement apply to the subscription and to Snowetic's other products. A technical check, not legal advice.
What your website does, not what it should do.
Snowetic is software delivered as a subscription. Consent shows whether the visitor's choice is technically honored. Guard checks the code loaded by the website and anomalous data transfers from the same material. Tell us about your website and your advertising, and we will define the Snowetic setup that keeps your advertising data in order and prepare a quote for you. For a Consent and Guard check, the website address and the cookie tool you use are enough.
Questions and answers
Where is the check data sent?
Nowhere. The analysis runs in your browser, and the capture and the report stay on your computer. A content security policy technically blocks external connections.
Is the result a legal assessment?
No. The result is a technical finding with references to the legal provisions: Indications of a violation, Gray findings or No indications of a violation. Snowetic does not claim that a website is lawful or unlawful.
Does Snowetic Consent see server-side transmissions?
Not events that happen entirely on the server and do not appear in the browser's network traffic. The Conversions API and webhooks are checked separately from the tracking tool's logs.
What does Snowetic Guard do if it finds a suspicious script at the checkout?
It raises the finding for checking or as an alert, depending on the strength of the evidence, and shows the network request the finding is based on. Guard does not block the script or change the website. It tells you what needs checking.
How is the visitor's choice monitored continuously?
Snowetic Consent is a check that can be run again at any time, for example after a change to the website or the consent implementation. Continuous verification in both cookie states is part of Snowetic Measure.
