Skip to content
https://eventbrite.ca

Compliance

· 13 checks — WCAG, consent & privacy, language, viewport, cookie inventory, and legal pages rolled into one auditable list.
SCORE
84
GRADE
B
FIX
1
REVIEW
2
PASS
7
INFO
3
Checks
13
7 PASS 2 REVIEW 1 FIX
F
Third-Party Trackers
Action
17 trackers detected
FIX
17 trackers detected
Info::
17 third-party trackers detected
Found 12 analytics, 2 advertising, 1 marketing, 1 tag manager trackers.
Got: 17 trackers
Warning::
2 advertising/retargeting trackers detected
Advertising trackers collect user data for ad targeting. Under GDPR, these typically require explicit consent.
Warning::
Trackers detected but no cookie policy found
This page loads 17 trackers but no cookie policy was detected. GDPR requires disclosure when using tracking cookies.
Warning::
Trackers detected but no privacy policy found
Most data protection regulations require a privacy policy when collecting user data via trackers.
Warning::
Session replay tool detected: Hotjar
Session replay tools record user interactions. These require clear disclosure and often explicit consent under GDPR.
C
Compliance Badges
Action
0 compliance badge(s) detected
REVIEW
0 compliance badge(s) detected
Info::
No compliance badges detected
No recognized compliance certification badges or seals were found. This is common — many sites do not display compliance badges.
SOC 2
ISO 27001
PCI DSS
GDPR Certified
HIPAA Compliant
Better Business Bureau
TRUSTe / TrustArc
Privacy Shield
McAfee SECURE / TrustedSite
Norton Secured
Badge detection is based on image alt text, link URLs, and page content. Detection does not verify that certifications are current or valid.
A+
WCAG Compliance
No testable criteria
PASS
No testable criteria
Level A
Level AA

0

Passed

0

Failed

0

Partial

0

Manual review

0

Not tested

Automated testing covers ~30–40% of WCAG criteria. Manual review is recommended for full conformance.

Full WCAG 2.1 AA compliance checklist — paste into a client deliverable or ticket

A
Language & i18n
Lang attribute present
PASS
Lang attribute present
Info::
<html lang> attribute is present
Info::
<html lang> value is valid
Info::
No Content-Language HTTP header
Info::
Language signals are inconsistent
The <html lang> attribute and Content-Language header should agree.
Page Language DetectedContent-Language Header Consistent No

The <html lang> attribute and Content-Language header should agree.

Why this matters

<html lang>, Content-Language, or og:locale disagree — pick one source of truth and align the others.

Learn more

Browsers and assistive tech use different sources for language. When they disagree, behavior is undefined: some pronounce by <html lang>, some by Content-Language. Decide on the canonical language for the page and set all signals to match.

Source: WCAG 2.1 SC 3.1.1

A+
Readability & Typography
Font sizes and tap targets checked
PASS
Font sizes and tap targets checked
A+
Viewport Configuration
Viewport properly configured
PASS
Viewport properly configured
Info::
Viewport meta tag is present
Info::
width=device-width is set
Info::
User zooming is allowed
Viewport Configuration Good
Content
width=device-width
width=device-width

Responsive layout enabled

initial-scale=1

Correct initial zoom level

User zooming allowed

Accessibility-friendly — users can zoom

Regulatory Indicators
3 regulatory indicator(s) detected
INFO
3 regulatory indicator(s) detected
Info::
This is a technical scan, not a legal assessment
BeaverCheck detects technical indicators that may suggest regulatory relevance. This is not a compliance audit and should not be relied upon for legal decisions. Consult qualified legal counsel for compliance assessments.
Info::
CCPA indicators detected (strong confidence)
Indicators suggesting CCPA may be relevant: Text mentions: do not sell; Link text: Do Not Sell or Share My Personal Information. California Consumer Privacy Act — gives California residents rights over their personal data.
Got: 2 indicators: Text mentions: do not sell, Link text: Do Not Sell or Share My Personal Information
Info::
ADA indicators detected (moderate confidence)
Indicators suggesting ADA may be relevant: Accessibility statement page found. Americans with Disabilities Act / Section 508 — requires digital accessibility for people with disabilities.
Got: 1 indicators: Accessibility statement page found
Info::
HIPAA indicators detected (weak confidence)
Indicators suggesting HIPAA may be relevant: Text mentions: phi. Health Insurance Portability and Accountability Act — protects sensitive patient health information.
Got: 1 indicators: Text mentions: phi

This is a technical scan, not a legal assessment.

BeaverCheck detects technical indicators that may suggest regulatory relevance. This should not be relied upon for legal decisions. Consult qualified legal counsel.

CCPA Strong

California Consumer Privacy Act — gives California residents rights over their personal data.

Indicators detected

  • Text mentions: do not sell
  • Link text: Do Not Sell or Share My Personal Information
ADA Moderate

Americans with Disabilities Act / Section 508 — requires digital accessibility for people with disabilities.

Indicators detected

  • Accessibility statement page found
HIPAA Weak

Health Insurance Portability and Accountability Act — protects sensitive patient health information.

Indicators detected

  • Text mentions: phi
Third-Party Data Sharing
7 third-party service(s) detected
INFO
7 third-party service(s) detected
Info::
Data inventory for transparency purposes
This inventory identifies third-party services that receive data from your site visitors. Under regulations like GDPR (Article 30), maintaining records of data processing activities is commonly considered a best practice. This automated scan provides a starting point — it may not capture all data flows.
Info::
7 third-party services across 4 categories
7 third-party services detected across 4 categories: Analytics (2), Tag Management (1), Advertising (3), Marketing (1). Each of these services receives some user data from your site visitors.
Info::
Google Analytics (Analytics)
Detected via script URL. Typically collects: Page views, User behavior, Demographics, Device info, IP address. Privacy policy: https://policies.google.com/privacy. Data Processing Agreement available.
Got: Category: Analytics | Data types: Page views, User behavior, Demographics, Device info, IP address
Info::
Google Tag Manager (Tag Management)
Detected via script URL. Typically collects: Orchestrates other tracking scripts, Page views. Privacy policy: https://policies.google.com/privacy. Data Processing Agreement available.
Got: Category: Tag Management | Data types: Orchestrates other tracking scripts, Page views
Info::
Facebook Pixel (Advertising)
Detected via script URL. Typically collects: Page views, Conversions, User behavior, Ad targeting. Privacy policy: https://www.facebook.com/privacy/policy. Data Processing Agreement available.
Got: Category: Advertising | Data types: Page views, Conversions, User behavior, Ad targeting
Info::
HubSpot (Marketing)
Detected via script URL. Typically collects: Lead tracking, Form submissions, Page views, Email tracking. Privacy policy: https://legal.hubspot.com/privacy-policy. Data Processing Agreement available.
Got: Category: Marketing | Data types: Lead tracking, Form submissions, Page views, Email tracking
Info::
Heap (Analytics)
Detected via script URL. Typically collects: Auto-captured user interactions, Page views, Click data. Privacy policy: https://heap.io/privacy. Data Processing Agreement available.
Got: Category: Analytics | Data types: Auto-captured user interactions, Page views, Click data
Info::
TikTok Pixel (Advertising)
Detected via script URL. Typically collects: Page views, Conversions, Ad targeting. Privacy policy: https://www.tiktok.com/legal/privacy-policy. Data Processing Agreement available.
Got: Category: Advertising | Data types: Page views, Conversions, Ad targeting
Info::
Pinterest Tag (Advertising)
Detected via script URL. Typically collects: Page views, Conversions, Ad targeting. Privacy policy: https://policy.pinterest.com/privacy-policy. Data Processing Agreement available.
Got: Category: Advertising | Data types: Page views, Conversions, Ad targeting
Analytics (2)
Tag Management (1)
Advertising (3)
Marketing (1)
Google Analytics Analytics
Detected by: script URL
Data typically collected:
Page viewsUser behaviorDemographicsDevice infoIP address
Privacy policy → DPA available ✓
Google Tag Manager Tag Management
Detected by: script URL
Data typically collected:
Orchestrates other tracking scriptsPage views
Privacy policy → DPA available ✓
Facebook Pixel Advertising
Detected by: script URL
Data typically collected:
Page viewsConversionsUser behaviorAd targeting
Privacy policy → DPA available ✓
HubSpot Marketing
Detected by: script URL
Data typically collected:
Lead trackingForm submissionsPage viewsEmail tracking
Privacy policy → DPA available ✓
Heap Analytics
Detected by: script URL
Data typically collected:
Auto-captured user interactionsPage viewsClick data
Privacy policy → DPA available ✓
TikTok Pixel Advertising
Detected by: script URL
Data typically collected:
Page viewsConversionsAd targeting
Privacy policy → DPA available ✓
Pinterest Tag Advertising
Detected by: script URL
Data typically collected:
Page viewsConversionsAd targeting
Privacy policy → DPA available ✓

This inventory identifies services receiving visitor data.

Under regulations like GDPR Article 30, maintaining records of data processing is commonly considered a best practice. This scan provides a starting point.

Readability Scores
730 words, Flesch-Kincaid grade 18.9
INFO

Readability Analysis (Flesch-Kincaid)

Grade Level

18.9

Grade 19 (college+)

Reading Ease

32

Difficult

Words

730

Sentences

18

All checks on this page are automated. Results are estimates - run targeted manual reviews when the score affects a release decision.

Send Feedback