You need data. Regulators need consent.
Gretelfy helps you have both. Know exactly what fires before consent — and fix it before it becomes a problem.
Multiple team members adding tags
Marketing, product, and dev teams all add tracking scripts. Nobody has full visibility into what fires before consent.
No visibility into pre-consent firing
Your tag manager shows what's configured, not what actually executes before a visitor consents. There's a critical difference.
Consent Mode v2 uncertainty
Google made Consent Mode v2 mandatory for EU traffic. Misconfigured signals mean either GDPR violations or lost measurement data. Both are expensive.
New deployments break compliance silently
A GTM update, a new pixel, a hardcoded script tag — any change can bypass your consent implementation without anyone noticing.
What Gretelfy shows your marketing team
Full visibility into what your tracking scripts actually do — not just what your tag manager says they should do.
Every tracking script classified
Google Analytics, Meta Pixel, TikTok, Criteo, Hotjar — every script identified by vendor, categorized by purpose, and checked against consent state.
Consent Mode v2 validated
Gretelfy checks all four required parameters (ad_storage, analytics_storage, ad_user_data, ad_personalization) in both default and updated states.
Tag management verification
Identify scripts loaded via GTM vs hardcoded in HTML. Hardcoded scripts bypass consent configuration — we flag them immediately.
Alerts when deployments break consent
Get notified within hours when a new script starts firing before consent. Email and Slack integration keeps your team informed.
Know which data is legally defensible
Your Gretel Score shows exactly where you stand. Violations are mapped to specific tags so you know what to fix in GTM.
PII leak detection
Detect when email addresses, phone numbers, or other PII is accidentally passed to third-party scripts via URL parameters or request payloads.
Consent Mode v2 — validated, not assumed
Google made Consent Mode v2 mandatory for EU traffic through Google Ads and Analytics. Misconfigured signals mean one of two expensive mistakes:
Signals say "granted" when user rejected
Active GDPR violation. Tracking data collected without valid consent.
Signals say "denied" when user accepted
Lost Google Ads measurement data. Conversion tracking, remarketing, and attribution all break.
Gretelfy tests the actual gtag() consent signals against real user consent choices. No guesswork.
Gretelfy validates all 4 parameters:
ad_storageanalytics_storagead_user_dataad_personalization