TagPipes Companion for Chrome Add to Chrome →

Privacy Research

Restaurants and Ecommerce Have the Same Privacy Gap. It Looks Nothing Alike.

Two distributions, side by side

The Website Privacy Index has 40,257 sites in its three industry segments, scored between January and October 2026. Two of them look like mirror images:

  • Restaurants (n = 31,167): Gated 0.4%, Partial 2.2%, Exposed 15.0%, Unprotected 82.4%
  • Ecommerce (n = 8,386): Gated 0.2%, Partial 1.5%, Exposed 81.2%, Unprotected 17.1%

Both score poorly. They just score poorly in opposite columns.

Why the numbers flip

The two big columns measure different things:

  • Unprotected means no consent platform and no privacy preferences link detected. Nothing visible at all.
  • Exposed means a privacy or cookie preferences link was found, but no consent platform was detected behind it.

So restaurants mostly never published a privacy surface. Ecommerce mostly published one and didn't wire it to anything. That's one gap, seen from two directions.

Restaurants: the gap is absence

The index measures page behavior, not causes, so treat this as the most plausible reading rather than a finding. Restaurant site estates are often franchise or multi-unit builds on shared templates, with ordering handed off to another platform. Nobody owns the question of what the site collects, so nothing gets put there. More on that: Why Restaurant Websites Score Worst On Privacy, And It Is Not Carelessness and Your Restaurant Website Is Not One Website.

Ecommerce: the gap is a promise with nothing behind it

Again, inference rather than measurement. Ecommerce platforms, themes and apps commonly ship a preferences link by default, so the surface arrives without the mechanism. The link exists; the gating doesn't. See The Vertical With The Best Privacy Score Gates The Fewest Sites.

Why this breaks sector benchmarking

"How does my industry do?" sounds like a useful question. Here it isn't. Both sectors score badly, for opposite reasons, so copying your sector's typical fix can fix the wrong half. A restaurant that adds a preferences link moves from Unprotected to Exposed and is no better gated. An ecommerce site that adds another policy page changes nothing at all.

Hospitality, the control group

Hospitality (n = 704) is the only segment with meaningful Gated and Partial shares: Gated 5.1%, Partial 18.3%, Exposed 26.6%, Unprotected 50.0%. It's a much smaller sample, so read it as indicative. What it shows is that the same scan, run the same way, does find sites that finished the job. More: Hospitality privacy index.

The two-minute check: which shape are you?

  1. Open your site in a private window and look for a privacy or cookie preferences link. No link at all? You're in the restaurant shape.
  2. If there is a link, open developer tools, refuse anything you're offered, and browse two pages. Requests still going to ad and analytics domains? You're in the ecommerce shape.
  3. Neither? Run the free scan to confirm what the page does before anyone touches the banner.

Source: Rawsoft Website Privacy Index, 47,506 sites scanned and 47,420 scored, January to October 2026. The crawl covers restaurant, hospitality and independent ecommerce sites, so it is not a sample of the whole web.

More from the Website Privacy Index: Do cookie banners work? · Restaurant privacy index · Ecommerce privacy index

Rawsoft provides technical implementation and analysis, not legal advice. Please confirm any regulatory interpretation with your counsel.

About Rawsoft

Rawsoft is an Atlanta-based digital data agency specializing in analytics implementation, privacy and consent management, and media tracking for enterprise brands.

Add Rawsoft as a preferred source on Google

More from the blog

Privacy

Cookie Banner vs. Consent Tool

A banner is a UI. A consent tool is enforcement. The three banner types we see in audits, a two-minute Global Privacy Control test, and the state-by-state reason the implied-consent notice no longer holds.

July 2026Read

Privacy

Your Checkout Is on a Different Domain

If your transaction flow runs on a vendor's domain, the consent your banner captured cannot be read there. Why that happens, why the domain does not decide who is responsible, and how to check your own site in two minutes.

August 2026Read