An average and a mechanism answer different questions
In our Website Privacy Index, independent ecommerce has the highest mean privacy score of the three verticals: 24.0 out of 100 across 8,386 sites, against hospitality at 18.6 and restaurants at 9.9.
It also has the smallest share of sites that actually hold tracking back. 14 of those 8,386 ecommerce sites reached the Gated tier, 0.2%. Hospitality, with a lower average, gated 5.1% of its 704 sites. That is roughly twenty times the ecommerce share, from a vertical that scores six points worse on the mean.
Both cuts come from the same crawl and the same scan, January to September 2026, so the gap is a real difference in practice rather than a difference in method.
The four tiers
The index sorts every site by the mechanism the scan observed. The tiers describe that mechanism, not the company, and not a legal status.
- Gated. Consent platform detected, Consent Mode v2 observed, no tracking seen before consent or after denial.
- Partial. Consent platform detected, but with gaps.
- Exposed. No consent platform detected, though a privacy or cookie preferences link was found.
- Unprotected. No consent platform and no privacy preferences link detected.
Where ecommerce actually lands
| Tier | Sites | Share |
|---|---|---|
| Gated | 14 | 0.2% |
| Partial | 131 | 1.6% |
| Exposed | 6,808 | 81.2% |
| Unprotected | 1,433 | 17.1% |
Rawsoft Website Privacy Index, ecommerce edition. n = 8,386 sites scanned January to September 2026.
The Exposed row is the story. Four in five ecommerce sites had a privacy or cookie preferences link the scanner could find, and no consent platform it could detect. That is a very different posture from the restaurant cut, where 82.4% of sites had neither.
A link is not a gate
A footer link to a preferences page or a privacy policy is information. It tells a visitor where their choices live, and often it is the only thing on the page that acknowledges tracking happens at all.
A gate is a decision point that tags wait on. Requests are held back until a choice exists, and the choice changes what fires.
One can exist without the other, and from a dashboard they look the same. Both produce a site that appears to be handling privacy. Only one of them changes what leaves the browser before a visitor has agreed to anything. We took the same distinction apart from the tooling side in a cookie banner is not a consent tool.
Why the average hides it
The index page states the reason plainly: the score awards points where a vendor is simply absent, which is why tiers are assigned from observed mechanism rather than from the score.
A site running fewer third-party tags has less to fail on. That earns points without anyone having made a decision about consent. So a higher mean is not evidence of a gate, and reading it as one is the specific mistake this whole piece is about. The index does not decompose why ecommerce scores higher, and neither will we.
The small group that did run a platform
145 of the 8,386 ecommerce sites had a consent platform detected. Of those, 67 still fired tracking before consent or after a refusal.
That base is small, so treat it as an indication rather than a rate. It points the same way as the whole-index figure on the banner results page, where 620 of 1,475 sites with a platform detected tracked anyway.
The check, on your own site
- Fresh private window, network tab open before the page loads, touch nothing. Look for analytics and ad requests. If they go out before you have chosen anything, there is no gate, whatever the footer links to.
- Now open the preferences link, decline everything, reload, and browse. Look again. If the same requests go out, the link is recording a preference that nothing downstream reads.
Neither check needs a tool, and both give you an answer in the time it takes to load three pages.
The principle
A preferences link is where a choice can be recorded. A consent gate is where it gets enforced. A score cannot tell you which one a site has, and an average across a vertical certainly cannot.
Our free privacy scan runs the same method on any domain in about a minute, with no account. Run it on your own site, or book a data and tracking audit if you want the whole tag layer reviewed rather than the front page.
Not legal advice. Rawsoft determines what a system technically does: which tags fire, when, under what consent state, and what data is transmitted. We do not determine which laws apply to your organization, how a regulator would read them, or whether your organization is in compliance. Those are determinations for your counsel. Everything above describes behavior an automated scan observed on public pages at the time of the scan, and nothing in it is a legal conclusion about any site.