webtracking.org
Privacy Scorecard

Vendor right to respond

Every grade on the scorecard rests on documented, reproducible claims — which means every grade is correctable when the documentation or the behavior says otherwise. This page is the formal route: what qualifies, what evidence we accept, and what we commit to in return.

corrections@webtracking.org

Who may request a correction

The graded vendor, or someone authorized to speak for it — an employee, counsel, or an agency of record. Write from a company domain or otherwise establish that you represent the vendor. Anyone else who spots a factual error is welcome to report it through the same address; it will be verified the same way, but the formal right-to-respond commitments below apply to vendors.

What evidence is accepted

Grades are built only from documented, reproducible sources, so corrections must be too. Any of the following can move a grade:

Vendor documentation

Your public docs, privacy policy, or changelog showing the entry describes behavior your product does not have — or no longer has. Marketing copy alone does not move a dimension; the documented mechanism does.

DPA & sub-processor list

Your data-processing agreement, controller/processor posture, sub-processor disclosures, or residency commitments, where the entry mischaracterizes them.

A reproducible scan

A network capture or ad.rip scan demonstrating what your tool actually sends — requests, cookies, parameters — that contradicts the entry. It must be reproducible by us on a default deployment.

Note that entries grade the default, documented behavior of a tool, per the methodology. Evidence that a hardened, non-default configuration behaves better confirms the entry's implementation caveat — it does not contradict the grade.

The re-scoring process

  1. Email corrections@webtracking.org with the entry, the specific claim you dispute, and the evidence. We acknowledge receipt and confirm what is being reviewed.
  2. We re-run the assessment against the evidence: re-reading the cited documentation and, where behavior is in question, re-scanning a default deployment.
  3. If the correction is substantiated, the affected dimensions are re-scored under the published methodology, the entry is updated, and its verified-on date is reset.
  4. If the disagreement is not a factual error — a difference of judgment about a documented behavior — we record the vendor’s position on the entry rather than change the grade.

What we commit to

Ten business days

We acknowledge and resolve correction requests within 10 business days of receiving the evidence. If verification genuinely needs longer — for example, reproducing a complex deployment — we say so before the deadline, with a date.

Corrections are public

Substantiated corrections are applied to the entry, reset its verified-on date, and are noted in the next issue of the newsletter. We correct at the same volume we graded.

A correction request never requires — and never triggers — any commercial conversation. Grades are independent of sponsorship, affiliate status, and everything else, per the published methodology.