← All research

Sites with no privacy policy anyone can find

2026-09-28 · OrangeStealth Security

A missing privacy policy is easy to dismiss as a website housekeeping issue. A prospective customer may see something more serious: a company that collects contact details, account information or product usage data without explaining how that information is handled.

In OrangeStealth Security's September 25, 2026 aggregate, 42.2% of the US B2B SaaS 5-50 population, representing 460 sites, had no privacy policy we could find. The sample size was N = 1091. That observation does not establish that every company lacks a policy internally or is violating a legal requirement. It means a visitor could not readily locate one through the public site evidence available during the scan.

The trust problem appears before the security review

Privacy policies are often treated as legal documents that only matter after a buyer becomes serious. In practice, they can become part of the buyer's first credibility check. A customer may want to know what happens after submitting a demo request. An enterprise reviewer may look for basic disclosures before asking detailed questions about vendors, subprocessors, retention or contractual safeguards.

J
Joshua Pi'Rwot@pirwot

Two lists tangled together here. Bento grids and radial orbs date a site. No TOS, no privacy policy, fake testimonials and no real demo cost

September 22, 2026 · Excerpt; read original

When that document cannot be found, the buyer has to fill in the blank. They cannot tell whether the policy is missing, hidden, outdated or simply linked from a page the scan did not discover. None of those possibilities proves weak internal security. The visible gap still creates avoidable uncertainty at the exact moment the company is asking for trust.

The issue also affects internal teams. Sales may answer privacy questions one prospect at a time. Security may receive requests for information that should already be available publicly. Legal may have approved language that never reached the website. A small publishing omission can therefore produce extra work across several functions.

What the public finding does and does not mean

This research used passive, public-data-only observations from a monthly refresh generated on 2026-09-25. The population was US B2B SaaS 5-50, with a sample size of N = 1091. Results were k-anonymised, and no company is named. We did not log in, submit forms or test private systems.

A public website observation is not proof of abuse, compromise or backend behavior. It also cannot determine whether a company has an unpublished policy, gives disclosures through contracts or collects no personal information on a particular page. The finding is narrower: no discoverable privacy policy was identified through the public evidence examined.

That distinction matters because the appropriate response is verification, not alarm. The goal is to make an accurate disclosure easy for ordinary visitors and reviewers to find.

A hypothetical buyer journey

Consider a procurement reviewer evaluating a software vendor. The reviewer opens the homepage, checks the footer and visits the contact or signup page. The form requests a name, business email and company information, but there is no visible privacy link nearby. A site search does not reveal a policy.

The reviewer now has several unanswered questions. Who controls the submitted data? Why is it collected? Is it shared with service providers? How can someone request access or deletion where applicable? The vendor may have sound answers, but the website has made those answers harder to obtain. The reviewer may pause, send another questionnaire or ask the vendor's sales contact for documentation.

E
EzekielVision@johnxx555

This website raises serious privacy concerns. It requires users to provide a private email address, yet the web app has no Privacy Policy at all.

September 26, 2026 · Excerpt; read original

This is a hypothetical example, not a claim about any scanned company. It shows how a modest disclosure gap can turn into friction even when no security incident has occurred.

What to actually do about it

  1. Check the common paths. Look at the homepage footer, signup and contact forms, account creation flow, cookie interface and any legal or trust center page. Confirm that the link works without authentication and is understandable on mobile.
  2. Match the policy to current practices. Ask the people responsible for legal, security, marketing and product data to confirm that the published text reflects what the business actually collects, why it is collected, how it is shared and how inquiries are handled. Do not copy another company's policy.
  3. Put disclosure beside collection. A footer link is useful, but forms and signup flows should also provide clear access to the relevant notice when information is requested.
  4. Assign an owner and review trigger. Product changes, new analytics services, new subprocessors and changes to retention practices can make an old policy inaccurate. Give one role responsibility for coordinating updates.
  5. Recheck the public view. Use the free public checker at https://orangestealth.com/check for an outside view of visible signals. For broader external exposure and disclosure review, an External Security Posture Assessment can examine the public footprint in context.

Start by opening your own homepage as a visitor and trying to find the policy without using internal knowledge. If the path is unclear, fix the path first, then verify that the document behind it is accurate.