Skip to content

Legal

Domain scan disclosure

Last updated August 24, 2026.

Purpose

This page explains how OptinStack domain scans work, how subscription tiers affect how many pages we scan, and what you should expect when comparing scan results over time.

It supplements our Terms and Conditions and Privacy Policy. It is not legal advice for your business.

How we discover pages

When you start a scan, we first load the registered hostname over HTTPS and follow a normal redirect to its canonical hostname, such as apex to www. We then attempt to load that hostname’s sitemap.xml. If a valid sitemap is available, we extract same-host page URLs listed there.

If the root sitemap is a sitemap index (a list of child sitemap files), we fetch those child sitemaps on the same hostname and merge page URLs from them, subject to published fetch and discovery limits.

If no sitemap is found or it cannot be read, we fall back to crawling links on your homepage over HTTPS.

We filter out URLs that do not match the scanned hostname.

Public hostnames and reverse proxies

Domain scans are performed against the public hostname registered in your workspace. You are responsible for registering the hostname visitors actually use in their browser.

If your site is served through a reverse proxy, edge worker, CDN, or platform domain mapping, register the public proxy hostname rather than a private origin hostname. OptinStack does not inspect private origin infrastructure unless it is publicly reachable through the registered hostname.

Webflow and Framer development hostnames may receive Free or paid coverage before a production domain is available. Each entitlement includes one self-service reassignment to a registered target; additional changes require review.

Scanner access and blocking controls

The scanner must be able to load the registered hostname over HTTPS. Firewalls, bot protection, authentication walls, geographic rules, rate limits, or other access controls may block scanning or produce incomplete results.

You are responsible for allowing scanner access where needed and for reviewing scan output. OptinStack does not scan logged-in areas, private origins, or pages that cannot be reached through the public site.

Compared to your plan limit

Each scan analyzes at most the number of pages allowed by the plan tier for that hostname. That is not a full-site audit unless the number of unique discoverable URLs on your hostname is less than or equal to your tier limit.

The dashboard may show how many pages were discovered versus how many were scanned (for example, “25 of 2,775 pages”) so you can see when coverage is partial.

  • Free, up to 25 pages per scan with a 12-hour cooldown by default
  • Pro, up to 100 pages per scan with a 12-hour cooldown by default
  • Business, up to 350 pages per scan
  • Enterprise, up to 1,000 pages per scan

How we choose which pages to scan

After discovery, URLs are normalized (for example: HTTPS only, fragments removed, duplicate paths collapsed, and your site root canonicalized to a single homepage URL).

If your homepage is in the discovered set, it is scanned first. We then prioritize common privacy-policy and legal-notice paths (such as privacy, cookie policy, and terms pages when present in the discovered set), then sort remaining URLs in stable alphabetical order. We scan up to your tier limit from the start of that ordered list.

For the same discovered URL set and hostname, this produces predictable, repeatable page selection. Free, Pro, Business, and Enterprise use the same ordering; higher plans scan more pages from the beginning of that list.

Publishing scan results

Scans store tracker inventory in your workspace for review. Live site enforcement updates only when you publish from the dashboard (Publish in the sidebar or Settings).

Published tracker rules reflect only what we detected on pages we actually scanned (plus any trackers you add manually). They do not verify trackers on unscanned pages. You remain responsible for accuracy across your full property.

What stays consistent

Re-running a scan on the same hostname with the same tier, before your sitemap or homepage links change, should select the same pages and produce comparable tracker inventory for those pages.

Activating a higher plan adds pages from the same ordered list; the first 25 Free pages remain the first pages in the Business scan set.

When results can differ

Tracker counts and categories can still change between scans even when the same URLs are selected. Reasons include:

  • Your sitemap or homepage links changed, adding or removing URLs or changing which URLs fall within your tier limit.
  • Your site serves different scripts, embeds, or tags on a page (A/B tests, geo rules, consent state, or marketing tags loading conditionally).
  • Third-party resources time out, fail to load, or respond differently during automated browsing.
  • Pages behind login, paywalls, or multi-step flows that our scanner cannot reach without credentials.
  • Very large sites where your tier limit scans only a subset of discovered URLs, trackers on unscanned pages will not appear until you upgrade or add them manually.

Large sites

Sites with thousands of URLs in a sitemap (for example large location or catalog sites) may have more discoverable pages than your tier allows. We scan an ordered subset after homepage and privacy-policy or legal-notice path pinning, not the entire sitemap.

If your inventory review requires broader coverage, upgrade to a higher tier, adjust your sitemap and internal linking strategy, or supplement automated scans with manual tracker entries in your workspace.

Sites larger than your plan

We scan up to your tier limit from the ordered list described above. Trackers on pages we do not reach in that run will not appear in the scan report or in published configuration until you scan a higher tier or add them manually.

Upgrade to a higher tier to scan more pages from the same ordered list, or add trackers manually for pages outside the scan set.

Scan page selection consistency

When your discovered URL set has not changed and you use the same tier, we select the same pages in the same order.

If you add or remove sitemap entries, change homepage links, or upgrade tier, the selected set may change.

Tracker count differences

Even when the same pages are scanned, trackers can differ if your site loads tags conditionally, third-party resources fail or time out during the scan, or you changed marketing scripts between runs.

A different page set (because the sitemap changed or a different tier was used) will also change totals.

Your responsibilities

You are responsible for ensuring your consent banner, consent preferences, and policy disclosures reflect trackers in use on your properties.

Automated scans are an aid, not a guarantee of complete detection. Review scan results, investigate unscanned sections of your site, and update configurations when your stack changes.

Automatic category assignments, including any designation of a tracker as necessary or essential, are estimates only and may be incorrect. You remain solely responsible for determining the correct legal category of every tracker and for ensuring that only strictly necessary trackers load before consent where required by law.

Questions about scans or tiers: OptinStack hello@optinstack.com.

Public Ray single-page scans

Ray is a separate public scanner for one public HTTPS page at a time. By submitting a URL, you confirm that you are authorized to request automated access to that page. Ray does not authenticate to private areas and is not a full-site audit, security assessment, or determination of legal compliance.

The submitted URL, browser observations, technical findings, report identifier, expiry time, and request metadata needed for security and abuse prevention may be processed to run the scan and provide the report.

A completed Ray report is available through an unlisted report URL for seven (7) days. Anyone who receives that URL may be able to view the report during that period, so do not submit private URLs or share the report link with unintended recipients. The report is no longer available through the public report endpoint after expiry.

Rate limits, bot checks, access controls, timeouts, conditional page behavior, and third-party failures may prevent a scan or make its findings incomplete. Ray output is informational and must be reviewed in the context of your implementation.

AI-assisted features

Domain scans themselves are deterministic: OptinStack loads pages with automated browsing and matches observed trackers against our curated library. Scan results do not use artificial intelligence.

On Business and Enterprise plans, optional AI-assisted features may send limited technical or styling context to third-party providers when you explicitly request them. Nothing is saved to your configuration until you review and approve it.

For sub-processor questions about OpenAI or Google Cloud Translation, contact OptinStack hello@optinstack.com.

  • AI-assisted tracker classification (OpenAI): when an editor requests a suggestion, limited tracker metadata and public-page observations may be submitted for automated categorization, including cookie or storage names, script URLs, tracker descriptions, vendor names, domains, request URLs, page paths, and script attribution. The feature may use hosted web search to identify providers. It is not intended to submit visitor consent records, raw IP addresses, payment information, or account credentials.
  • AI banner design (OpenAI): styling context you provide or extract from a public page may be used to generate draft banner layouts. An editor must review a draft before saving it to the project.
  • Optional banner translations (Google Cloud Translation): banner and preferences text you choose to translate may be sent to Google Cloud Translation.

Changes

We may improve discovery or selection logic over time. Material changes will be reflected on this page with an updated "Last updated" date.