Cookie policy
Silktide finds the cookies your website sets and asks you to confirm that each one is covered by your privacy or cookie policy. When new cookies appear in later tests, they are flagged for review too.
Why this matters
Privacy laws such as the and the ePrivacy Directive expect you to tell visitors what you set, what they are for, and how long they last - usually in a privacy or cookie policy. Regulators in several countries have fined organisations for undisclosed tracking cookies.
Cookies also change without anyone updating the policy: a new analytics tool, chat widget, or embedded video can quietly add cookies that your published policy never mentions. Reviewing new cookies as they appear keeps your policy honest.
How to fix it
- Review each cookie listed. Work out what sets it and why - your own code, or a third-party service such as analytics or embedded media.
- Make sure your privacy or cookie policy documents it: what it is called, who sets it, its purpose, and how long it lasts.
- Once a cookie is documented, mark it as "In privacy policy" in Silktide. It will no longer be flagged, and your is recorded for review later.
- If a cookie shouldn't exist at all - for example, one left behind by a tool you no longer use - remove the code that sets it instead.
How Silktide tests this
- Load each page in a real browser and record every cookie set while the page loads, whether set by your code or by a third-party service.
- Group identical cookies by their name, the domain they belong to, and their path.
- Flag each cookie you have not yet marked as "In privacy policy".
- When later tests find cookies you haven't reviewed, flag those as new.
Silktide cannot read your policy and match cookies to it automatically - you confirm each one, and Silktide remembers your answer.
Troubleshooting
Cookies reappear after I marked them
A cookie is identified by its name, domain, and path. If a service renames its cookies or moves to a different domain, the renamed cookie counts as new and needs reviewing again.
A cookie I expect isn't listed
Silktide only sees cookies set during a normal page visit. Cookies set after an interaction - logging in, accepting a consent banner - may not appear unless the test performs that interaction.