60% of Product Hunt sites load a foreign vendor their policy never mentions
Product Hunt seriesOver 30 days in July and August 2026 I scanned 458 products that launched on Product Hunt. 233 of them do both of the things that make this question answerable: they publish a privacy policy, and their homepage loads a third-party service in the visitor's browser.
139 of those 233, or 59.7%, say nothing about international transfers at all. Not a section, not a sentence, not even a stale reference to Privacy Shield.
Those vendors are recipients of personal data in another country. Article 44 sets no volume threshold, and nothing in it turns on whether the request left your server or the visitor's browser 1. The transfer starts when somebody pastes a snippet, not when somebody signs a contract.
This is post three of four built on this Product Hunt launch scan. Post one was about the cookies and post two about what the privacy policies leave out. This one is about the vendors those policies never mention, and post four is about what separates the startups that get this right.
How I counted the 233
The 458 came off the top of Product Hunt's daily leaderboard for 30 consecutive days, 12 July to 10 August 2026. Post one sets out the method in full: I loaded each site in a headless Chrome from inside the EEA, recorded every third-party host it contacted, then found and read its legal pages. Every check was deterministic and no language model made a judgement anywhere in the dataset. These are machine-checkable observations about public pages, not legal verdicts about anyone, and I am not naming the products.
I counted a vendor only where it is unambiguously a separate recipient of personal data, so a font pulled from Google or a site served through Cloudflare did not count. Two things the scan cannot see:
- Where the data landed. I infer it from the vendor's identity, not from a packet I watched arrive, and Google Analytics can be run with EU residency.
- Unusual wording. The transfers check is a broad text match, so a policy that covers transfers in language I did not match reads as silent.
Both errors forgive a gap rather than invent one.
Does your legal documentation match what you ship?
Lawcel watches your product changes and flags the moment your terms or privacy policy fall out of sync, so your legal pages always match what you actually ship.
Try for freeWhat did the 233 sites disclose?
Effort spent on the document did not travel to the page. One product's 3,301-word privacy policy was silent on transfers while eight third-party services loaded on its homepage, one of them a model vendor sitting in the same undisclosed list as the ad pixels. 3,301 words is not a stub. Somebody wrote it, and the page moved afterwards. At the other end sits the ordinary case, the one most readers are in: a 630-word policy, silent on transfers, with Google Analytics and Google Ads loading and a document that does not know about either.
A product's data story and its website's data story are two different systems, and only one of them was designed. One launch in the sample was pitched on agents that run entirely locally, on your own Mac, with nothing leaving the machine. Its 1,639-word policy was silent on transfers while Google Analytics and PostHog loaded on the marketing site. As far as this scan can tell the software does exactly what it claims. The observation is about the website: the same week, the same people, a different set of decisions about where data goes.
Six vendors account for most of the exposure. The disclosure most sites owe is short.
Sites marketing in the EU do better, but not by much. Most Product Hunt launches are American and sell to Americans, and a company offering nothing to anyone in the Union does not owe this disclosure. So take the 160 sites carrying explicit evidence they market in the EU: prices in euro, an EU language option, or an EU country named on the page. Among those, 48.0% loading a third-party service still said nothing about transfers, or 47 of 98, against 59.7% across the whole scan. Close to half, in the group where scope is least arguable.
Certified vendors still have to be disclosed
Every recipient belongs in the policy, including the ones covered by an adequacy decision. Article 13(1)(f) does not ask whether your transfers are lawful. It asks you to publish "the existence or absence of an adequacy decision by the Commission" 1. Certification decides what you write about a vendor. It never decides whether the vendor appears at all.
Most of the vendors above are American, and American organisations can be covered by the Commission's adequacy decision for the EU-US Data Privacy Framework. It reaches organisations "included in the 'Data Privacy Framework List', maintained and made publicly available by the U.S. Department of Commerce" 2. Membership is a fact about one company on one day, so "Google is certified, this is fine" leaves two jobs undone: check that this vendor is on the list, and write that down in the policy.
How to find the vendors your own policy is missing
You can run this check on your own site right now. It needs a browser and your published policy, and it ends with the list of vendors you owe a disclosure for.
- List what loads. Open your marketing site in a fresh browser profile with no extensions, open the network tab, reload, and sort by domain. Do this on more than the homepage: pixels get added to pricing pages and blog templates on their own schedule.
- Split the list in two. A CDN serving a font is a different case from a beacon carrying a client identifier, and only the second is obviously a recipient of personal data.
- Name the mechanism for each recipient. The company, where it processes, and what makes the transfer lawful: an adequacy decision it is covered by, or the Article 46 safeguards you rely on instead.
- Compare that against your policy's transfers section. No such section means you have the same finding as 139 of the sites in this scan. Any vendor you could not name a mechanism for is where the document and the deployment disagree.
A quarterly review will not catch the next one. The events that change the answer are merges: a tag manager container added so marketing can stop asking for deploys, a template that ships with a chat widget in it, a pixel added before a campaign. None of them opens a ticket with the word transfer in it, so the recipient list your policy owes its users is maintained by whoever last edited the HTML rather than by whoever last signed a contract.
Your list will still be incomplete. Every vendor here was visible only because the browser had to ask for it out loud, and the largest recipient in most products is called from your server, where a scan like this one sees nothing. The next post takes on the reasonable objection to all of this: that it is a stage-of-company problem which sorts itself out as you grow.
FAQ
References
About the author
Ulf Aslak Lai
Co-founder, Chief Technology Officer
Ulf is Co-founder and CTO at Lawcel. He leads engineering architecture for connectors, analysis pipelines, and the safeguards needed when automation touches regulated customer content.
- Platform architecture
- Data governance
- ML/AI systems
Related articles
Only 17% of Product Hunt launches ask when they set tracking cookies
I scanned 458 products that launched on Product Hunt over 30 days in July and August 2026, loading each site from an EU location with an empty cookie jar. 292 stored tracking cookies, but only 50 of those (17%) did that after obtaining my consent. Filtering for EU based startups didn't improve this static significantly (26%).
GDPROnly 45% of Product Hunt privacy policies name a legal basis
I scanned 458 products that launched on Product Hunt over 30 days in July and August 2026. 397 published a readable privacy policy, but 217 of those (54.7%) named no legal basis for processing and 258 (65.0%) said nothing about whether data leaves the EEA. The items that did survive are the ones a US privacy notice already has.
StrategyThe most upvoted Product Hunt launches are no more compliant than the least
I scanned 458 products launched on Product Hunt over 30 days in 2026 and split them by upvotes. Across a range from 4 to 999 upvotes, the top and bottom quartiles came out 1.7 points apart on critical gaps. Splitting the same 458 on whether a site shows it markets in the EU moved everything: 5.0% published no policy against 17.8%.
DriftContinuous compliance in Lovable. No plugin required.
If someone on your team shipped a customer-facing tool in Lovable, connect the GitHub repository it already syncs to Lawcel the same way you would connect any other repo, no Lovable plugin is needed. We read every commit the way we read any team's pull request and flag what needs to change in your legal documents, or draft a first document if this build needs one of its own.