Your cookie scan tells you which cookies exist on your site. The Providers tab tells you who is behind them - every third-party company detected on your pages, what it does, and where to find its privacy documents. If you (or your Data Protection Officer) have ever had to build a vendor list for a privacy review, this is that list, built from what actually runs on your site.
You will find it on each site's Cookies & Scripts page, in the Providers tab.
What it shows
Each provider appears as one entry, even when it works through several domains (for example, Google Ads evidence from googleadservices.com, googlesyndication.com and doubleclick.net merges into a single Google Ads entry). Expand an entry to see:
- What it does - a one-sentence description of the provider's role (advertising, analytics, support chat, payments and so on).
- Cookies - the cookie names your scan attributed to this provider.
- Scripts & hosts - the third-party domains its scripts and cookies came from.
- Category - the consent category the provider's cookies fall under (necessary, functional, analytics or marketing).
- Privacy policy and Data processing agreement - links to the provider's own published pages. Some providers do not publish a standalone DPA page; those entries say "No public DPA page" instead of guessing at a link.
How providers are detected
The tab is built from your latest completed scan. Kukie combines three signals:
- Cookies matched against Kukie's known-cookie database (for example
_fbpresolves to Meta Pixel). - The third-party domains that scripts and cookies were observed coming from (for example
static.hotjar.comresolves to Hotjar). - Distinctive cookie name patterns (for example a cookie starting with
_hjbelongs to Hotjar even if that exact cookie is not in the database yet).
Your own domain is never listed - only third parties - and the Kukie consent script itself is excluded.
Unmatched providers
Kukie's registry covers over 230 of the most common providers across advertising, analytics, consent tools, chat and support, email marketing, payments, video, hosting, security, reviews and more. Still, some detected companies are not in it. They are still shown - marked Unmatched, with the domain or vendor name and the evidence the scan collected - rather than being hidden. Review these manually: check what the domain does, whether you recognise the service, and whether your privacy policy should mention it. Unmatched entries deliberately carry no links, because Kukie will not guess at a company's legal pages.
Keeping it up to date
The inventory always reflects your latest completed scan. If you have removed a service from your site, run a fresh scan from the Scan Now button and the entry disappears with it. If you have never scanned the site, the tab offers to run your first scan.
What it is not
The Providers tab lists what was observed on your pages - it is not a legal assessment. Whether a given provider needs a data processing agreement, a mention in your privacy policy, or a different consent category depends on how you use it. The Policy alignment check on the Legal Documents page compares this same detection against your published privacy policy, and the linked provider pages give you the source documents - but the judgement calls remain yours (and, where it matters, your legal adviser's).
