I work in data analytics and have been building a website scanner nights and weekends. It reads the public pages of a site and lists the third party services it can identify. I ran it against 22 small SaaS companies and compared what it found to each company's own privacy policy.
I could read the policy on 14 of the 22. Of those 14, 12 had at least one service running that the policy never names. The most common were Google Fonts (8 sites), reCAPTCHA (4), Google Analytics (4), and Google Tag Manager (4).
This does not directly mean any of these companies have a compliance issue. Category level disclosure is generally acceptable, and language like "we use analytics providers" reasonably covers a lot of what I found.
What stood out to me was the consistency. The services that go unnamed are almost always the ones nobody actively picked (Google Fonts, a CAPTCHA widget, an embedded video). I do not think this is negligence, but more so these get added through a theme, a plugin, or a framework and never make it back into the policy.
Small sample here (22 companies from one sourcing pass) so I am not claiming this applies broadly.
For anyone who has launched recently: When you set up your privacy policy, did you list the specific tools you use or keep it general?