gtmspy audits an online store's tracking setup (analytics and ad tags, consent banner behaviour) when someone requests an audit of that store.
Requests to the audited store are signed with Web Bot Auth
(Signature-Agent: "https://bot.gtmspy.io", tag web-bot-auth). Our public key is at
/.well-known/http-message-signatures-directory. The user agent is Chrome's own, followed by gtmspy/1.0.
We never fake a browser fingerprint or user agent, use stealth tools, solve CAPTCHAs or rotate IP addresses.
Contact bot@gtmspy.io. We add opted-out stores to a list that is never scanned again.