---
title: "Know What Every Vendor Script on Your Site Actually Collects"
canonical_url: https://ot.webclat.com/use-cases/know-what-vendor-scripts-collect
description: "Build a living, auto-refreshed inventory of every third-party script and cookie on your domains with OneTrust's tag discovery - no more guessing."
source: Webclat | OneTrust Solutions (OneTrust partner, independent consultancy)
---

# Know what every vendor script on your site actually collects

**In short:** Most sites accumulate third-party scripts, chat widgets, heatmap tools, and ad pixels, faster than anyone tracks them, leaving no current answer to what data leaves the site and to whom. Webclat runs OneTrust's cookie and tag discovery to build a living, auto-refreshed inventory of every script and vendor touching a domain. New scripts get flagged on arrival, so the inventory stays current instead of being rebuilt from memory before each review.

## The situation

"Someone added a chat widget, a heatmap tool, and three ad pixels over the years, and nobody has a current list of what's actually running."

## The pain

You can't answer what data leaves your site and to whom with confidence - and that's exactly the question an auditor, a partner's security review, or a regulator asks first.

## What we implement

We run a full site scan and configure OneTrust's cookie and tag discovery to build a living inventory of every script, cookie, and vendor touching your domains - a form of data mapping.

## What you get

- A current, exportable list of every third-party script on the site, refreshed automatically instead of rebuilt from memory before each review.
- Vendor scripts classified by what they actually do, so a guess of "it's probably just analytics" becomes a documented answer.
- New scripts added later get flagged instead of quietly joining the page unreviewed.

## Illustrative scenario

A team that discovered a legacy retargeting pixel still firing two years after the campaign ended might see that kind of surprise close permanently once new scripts get flagged on arrival. (Illustrative scenario - not a measured result.)

## Common questions

### Does this cover scripts added through Google Tag Manager, not just the page directly?

Yes. The scan covers both directly embedded scripts and ones fired through tag managers.

### What happens when you find something we didn't know was there?

It gets classified and flagged for your team's decision. We don't remove anything without sign-off.

## Related use cases

- [Vendor list under control](https://ot.webclat.com/use-cases/vendor-list-under-control)
- [Stop guessing which tags fire before consent](https://ot.webclat.com/use-cases/stop-guessing-which-tags-fire)

Contact: ot@webclat.com | (813) 694-4451 | https://ot.webclat.com/#contact
