All checks
Compliance & Privacylowprivacy-policy-omits-named-recipientcompares every page we scan against the others

Your privacy policy does not appear to name a service the site uses

This site loads older TLS versions, and the privacy policy at the published policy URL does not appear to mention it by name or by the company behind it.

Why it matters

This site loads older TLS versions, and the privacy policy at the published policy URL does not appear to mention it by name or by the company behind it. Services like these receive visitor data — at minimum an IP address, usually a persistent identifier — so they are recipients of personal data, and telling people who receives their data is the core of what a privacy policy is for. A policy that describes your data sharing only in general terms may still cover this adequately; a policy generated from a template before these tools were added usually does not, which is the common case and worth checking. Confirm the policy reflects the tools you actually run, and add the ones it misses.

How ShipReady detects it

What the published privacy policy says, against what the site actually does. SITE-scoped because that is the only scope that can hold two pages at once: the policy is on /privacy and the trackers are on the homepage. Costs no extra requests — every page it reads was already fetched by the crawl. Silent unless a privacy policy page was actually crawled AND that page returned enough text to be a document rather than an app shell. Both gates matter: "your policy does not mention Hotjar" is a serious thing to say to someone, and saying it because the crawler never fetched their policy — or fetched a client-rendered shell of it — would be indefensible.

Detection is deterministic. ShipReady reports this only when it observes the condition directly, and prefers to miss a real problem over inventing one. Rule version 1.0.0.

How to fix it

This is the prompt ShipReady puts in your report — written to be pasted straight into Cursor, Claude Code, or whichever assistant built the app.

Your site runs one or more third-party services, and your privacy policy does not appear to name them or the companies behind them. These services receive your visitors' data, so they are recipients of personal data and belong in the policy. Add a section listing each third party you actually use, what it does, and what it receives — analytics, advertising, session recording, error tracking, email, payments and hosting are the usual ones — and link to each provider's own privacy policy. Then check the reverse direction too: generated policies routinely list services the site does not use, or describe practices (data retention periods, international transfer safeguards) nobody implemented. The policy should describe your real stack. If you would rather not maintain a vendor list, a policy that describes the CATEGORIES of recipients and links to a separate, easier-to-update cookie or subprocessor page is a common and workable pattern — but the page it links to then has to actually exist and be current.

Frequently asked questions

What does "Your privacy policy does not appear to name a service the site uses" mean?
This site loads older TLS versions, and the privacy policy at the published policy URL does not appear to mention it by name or by the company behind it.
How serious is it?
ShipReady rates this low. Worth fixing. Small individually, and they accumulate.
How do I fix it?
Paste the fix prompt on this page into Cursor, Claude Code or your AI editor. It is the same prompt ShipReady puts in your report.
Can I check my own site?
Yes — ShipReady scans up to ten pages of any public site for free and reports this alongside every other check. The free report lists every issue it finds and shows full evidence and a fix prompt for the critical and high-severity ones; medium and low findings are counted and unlock on Pro.

Related checks

Run this check on your site

ShipReady checks this and 193 other things across up to ten pages of your site, with an AI-ready fix for each. Free, no signup.