Skip to content
SilktideHelp

Host privacy

When someone views a page, their browser contacts every server the page loads content from, not just yours. Silktide lists these servers and where in the world they are, so you can check that your privacy policy reflects who receives your visitors' data.

Why this matters

Every request a visitor's browser makes shares data with the receiving server - at minimum their IP address, which counts as under laws like the . Fonts, analytics, embedded videos, and all mean visitor data flowing to companies and countries your visitors have never heard of.

Where those servers are located matters legally: the GDPR restricts transfers of personal data outside the EU unless the destination country provides adequate protection or other safeguards are in place. Many organisations are surprised to learn how many countries their website quietly sends visitor data to.

How to fix it

This check gathers information for you to review; Silktide cannot determine whether a given transfer is lawful for you.

  1. Review each host: do you recognise the service, and do you still use it? Remove third-party content you no longer need - each host removed is one less party receiving visitor data.
  2. Check the location shown against your privacy policy. Transfers outside the EU to countries without an EU adequacy decision may need extra safeguards, such as standard contractual clauses with the provider.
  3. Make sure your privacy policy names the kinds of third parties that receive visitor data and where they process it.
  4. When a host is expected and covered by your policy, it so it isn't raised again.

How Silktide tests this

  1. Load each page in a real browser and record every host the page requests content from - scripts, styles, images, fonts, embedded media - including your own.
  2. Look up the geographic location of each host's server: city, region, and country where available.
  3. Classify each location against EU data-transfer rules: inside the EU, covered by an EU adequacy decision, a United States provider that appears to participate in an EU–US data transfer framework, or none of these.
  4. Highlight where each host is used on the page, so you can find what loads from it.

Troubleshooting

The location looks wrong

Large providers serve content from data centres all over the world, and the location found is where Silktide's test connected to. Your visitors may be served from elsewhere, and the company that owns the server may be subject to different laws than the server's location suggests. Treat the location as a starting point for investigation, not a verdict.

I don't recognise a host

Third-party scripts often load further content from hosts of their own - a tag manager can pull in a dozen services. Use the highlighted elements to trace which part of your page loads from that host.

Learn more

Last updated

Was this page helpful?