Alceris Analytics vs Stormly

Compare Alceris Analytics and Stormly on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Google Analytics, Mixpanel

Logo: Alceris Analytics

Alceris Analytics

Germany· Web Analytics

Needs review

Shortlist when you need German-operated, cookieless pageview/event analytics with a free monthly allowance and one-line install. Skip when you need self-hosting, open-source core, enterprise cert packs, or deep product analytics—consider Plausible, Simple Analytics, Pirsch, or Matomo instead.

Cookieless by designEU-operated (Germany)Realtime dashboardFree tier (volume-capped)SaaS only (no self-host)
Logo: Stormly

Stormly

Netherlands· Web Analytics

Needs review

Shortlist Stormly when you need Dutch-contracted, e-commerce-first product analytics: SKU-aware report packs, Shopify/Adobe-oriented setup, inbox-style AI anomaly narratives, and a public DPA. Skip when you need cookieless privacy web stats only (consider Plausible, Simple Analytics, or Pirsch), open-source self-hosting, verified ISO/SOC on a public cert page, or a subprocessor chain free of US-group cloud and Azure OpenAI.

E-commerce product analyticsSKU-aware reportsAI anomaly insightsShopify / Adobe CommerceNL entity + public DPASaaS (not self-host)
Alceris Analytics vs Stormly: Snapshot
FeatureLogo: Alceris AnalyticsAlceris AnalyticsLogo: StormlyStormly
Country of originGermanyNetherlands
CategoryWeb AnalyticsWeb Analytics
Open sourceNoNo
Self-hostedNoNo
HeadquartersGermanyNetherlands
Legal entityManuel Bauer, Innere Passauer Str. 45, 94315 Straubing, Germany (VAT DE353601960)Monon B.V. (Lutmastraat 1-3, 1072 JL Amsterdam; KvK 76248747 per Terms)
Governing lawGermanyNetherlands (Dutch law; Amsterdam courts)
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)MediumMedium
Hosting / residencyVendor claims analytics data is stored and served only on European servers and aggregated on arrival. Named external paths: Paddle (paid billing MoR) and optional Google Search Console. No official named infrastructure/subprocessor inventory beyond those; public site IP/ASN currently associated with netcup GmbH (Germany). DNS nameservers observed on Hetzner.Client analytics subprocessors (Security Architecture): Hetzner (EU); Amazon AWS (US company, vendor states EU regions only for encrypted analytics backups); Vultr (US company); Microsoft Azure OpenAI (US company, vendor states EU Azure region). Plans market EU data residency. Controller privacy policy also references Vultr/AWS for account data, AuthSMTP EU + Amazon SES USA for email, Stripe for payments; marketing site uses Google Analytics and Hotjar.
Summary

German cookieless website analytics SaaS: aggregate pageviews, events, and UTM campaigns without cookies or IP logs, operated from Straubing with EU-oriented hosting claims.

Dutch SaaS product analytics for e-commerce teams: SKU-aware reports, AI-assisted anomaly and root-cause insights, and Shopify/Adobe Commerce/Segment/GTM-oriented connections under Monon B.V. (Amsterdam).

Tags
At a glance: Alceris Analytics vs Stormly
At a glanceLogo: Alceris AnalyticsAlceris AnalyticsLogo: StormlyStormly
HQStraubing, GermanyNot listed
Legal entityManuel Bauer (sole operator)Not listed
DeploymentHosted SaaS onlyNot listed
Open sourceProduct SaaS closed; WP plugin on WordPress.orgNo
Commercial modelFree volume-capped tier; paid via PaddleFree tier + monthly plan + custom; trial path on paid
Governing lawGermany (per terms)Dutch law; Amsterdam courts
HQ / entityNot listedMonon B.V., Amsterdam, Netherlands
CategoryNot listedE-commerce product analytics (SaaS)
Hosting (public)Not listedHetzner; AWS EU-region backups; Vultr; Azure OpenAI EU region (vendor docs)
Self-hostNot listedNo
Key capabilities: Alceris Analytics vs Stormly
Key capabilitiesLogo: Alceris AnalyticsAlceris AnalyticsLogo: StormlyStormly
Cookieless by designYesNot listed
EU-operated (Germany)YesNot listed
Realtime dashboardYesNot listed
Free tier (volume-capped)YesNot listed
SaaS only (no self-host)YesYes
E-commerce product analyticsNot listedYes
SKU-aware reportsNot listedYes
AI anomaly insightsNot listedYes
Shopify / Adobe CommerceNot listedYes
NL entity + public DPANot listedYes

Alceris Analytics

  • Cookieless aggregation without IP storage

    Per the privacy policy, Alceris does not set cookies, session IDs, or similar client storage; IPs are not logged; the full User-Agent is not stored. Only aggregated fields such as page URL, referrer, parsed browser/OS, language, and timezone-based country are retained—aimed at sites that want stats without an analytics cookie banner.

  • One-line async script, deferred events, WordPress plugin

    Install via a single async script from alceris.com with your site data-id (docs include a deferred alceris() queue so early events are not lost). WordPress operators can use the official plugin and paste the dashboard site ID. SaaS-only—there is no self-hosted server package.

  • Realtime pageviews and custom events with metadata

    Pageviews and events are processed immediately into the dashboard. Custom events are sent with alceris('event', name, { ...metadata }), useful for button clicks, form steps, or content attributes without building a full product-analytics stack.

  • UTM campaigns, outbound links, and cross-domain flows

    UTM parameters are extracted for campaign reporting; outbound link clicks are tracked automatically; cross-domain tracking follows visitors across owned domains. Scope is web traffic measurement—not session replay or heatmaps.

  • Optional Google Search Console and first-party proxy

    Connect Search Console to import query impressions, clicks, and terms (data removed on unlink). Docs also describe reverse-proxying script.js and the img.alceris.com data endpoint through your own domain so ad-blockers are less likely to drop hits—at the cost of operating that proxy yourself.

Stormly

  • AI agent for trends, anomalies, and root-cause style digs

    Stormly positions an AI agent that watches connected e-commerce data for trends and anomalies (for example conversion drops or product spikes), then delivers plain-language findings—often to the inbox—with root-cause style exploration for questions like mobile conversion drops or regional return spikes. AI assistant access is plan-dependent; the public DPA documents Azure OpenAI (Microsoft) handling of assistant queries with a 30-day retention window and property stripping rules. Best for merchandising and growth leads who want narrative answers without waiting on a data team.

  • SKU-aware e-commerce report library (plus custom builds)

    Ready reports target commerce questions: New Arrivals Performance (early SKU winners/laggards), Unviewed & Unsold Products, cart abandonment and revenue contribution by product/category, Conversion Journey and funnels by device/region, A/B test insights, Aha Moment Discovery, cross-selling analysis, and broader library items (retention, CLV, forecasting, SQL report, and more). Vendor materials state custom reports are included without a separate fee when a needed view is missing—useful for mid-market retailers that outgrow generic event charts.

  • Shopify, Adobe Commerce, Segment, and GTM-oriented connections

    Homepage setup emphasizes linking Shopify, Adobe Commerce, or Segment quickly, with Google Tag Manager also listed among integrations. The DPA describes additional programmatic paths (JS library, import, custom endpoints, third-party sources). Fits stores already on common commerce stacks; teams on exotic storefronts should validate event coverage and product-feed depth in a pilot before replacing an existing analytics stack.

  • End-user tracking with IP anonymization defaults

    Per the DPA, IP addresses for end-user analytics are not stored in full: the last octet is removed and geo/timezone are derived from the anonymized value. Web integrations automatically capture first-party cookie user ids, page/referrer/UTM context, and device metadata; app properties depend on client or CDP configuration. This is still full product analytics (not cookieless aggregate-only web stats)—clients remain responsible for consent banners and lawful basis for shopper tracking.

  • Public DPA, security architecture, and Dutch contracting

    B2B buyers can download a Data Processing Agreement (effective 2023-09-06) and a Security Architecture page listing subprocessors, encryption expectations, backup retention (analytics backups up to six months), and logical tenant isolation. Contracts and DPA are governed by Dutch law with Amsterdam courts. Useful for EU procurement packages—but US-group subprocessors (AWS, Vultr, Azure OpenAI) still require transfer and CLOUD Act diligence.

Assurance & compliance: Alceris Analytics vs Stormly
Assurance & complianceLogo: Alceris AnalyticsAlceris AnalyticsLogo: StormlyStormly
Independent security / no-logs audit
Not found

No public third-party audit of cookieless/no-IP claims found

Not found

Security Architecture describes encryption, monitoring, isolation, and vulnerability contact (security@stormly.com); no public third-party audit PDF found.

ISO 27001
Not found

No ISO 27001 claim on public site/security pages (none published)

Not found

No public ISO 27001 certificate located on official legal/security pages reviewed.

SOC 2 / SOC 3
Not found

No SOC 2/3 report referenced publicly

Not found

No public SOC 2/3 report located on official pages reviewed.

GDPR / EU data protection
Vendor claimed

German controller; cookieless/no-IP design claims on privacy policy (last updated 2022). Not legal advice—confirm with counsel and DPA.

Vendor claimed

NL entity; public privacy policy and DPA (GDPR-oriented); IP last-octet anonymization for end-user analytics; SCCs language for restricted transfers in DPA.

US CLOUD Act exposure (indicative)
Partial

EU sole proprietor, no known US parent; vendor EU-hosting claims and DE-associated hosting for the public site. Optional Google Search Console involves Google; Paddle handles payments; infrastructure subprocessors not fully named. Indicative only—not legal advice.

Partial

EU entity / no known US parent, but public client subprocessors include AWS, Vultr, and Microsoft Azure OpenAI (US-group companies). Account path historically also lists Amazon SES and Stripe. Residency claims do not remove US-group legal exposure. Indicative only—not legal advice.

Data processing agreement (B2B)
Not found

No public DPA page or in-product DPA download found; ask vendor before production use

Vendor claimed

Downloadable DPA PDF linked from stormly.com/dpa (effective 6 September 2023); audit rights and subprocessor notice described; Security Architecture lists subprocessors.

EU AI Act
Not applicable

Web analytics measurement product; not marketed as an AI system

Partial

Product includes an AI assistant via Azure OpenAI; not positioned as a high-risk AI system marketing claim. Buyers should map AI assistant use to their own AI Act / internal AI policy—vendor does not publish a full AI Act conformity package on the pages reviewed.

Considerations & known limitations: Alceris Analytics vs Stormly
Considerations & known limitationsLogo: Alceris AnalyticsAlceris AnalyticsLogo: StormlyStormly
Solo / small-operator continuity
Medium

Imprint shows an individual operator in Straubing. Terms provide service as-is with email support on reasonable effort and reserve the right to modify or discontinue the service. Practical impact: backup exports and an exit plan matter more than with a large SaaS vendor.

Not listed
Thin public compliance packaging
Medium

No ISO/SOC claims, no independent audit, no public DPA template, and no named infrastructure subprocessor list despite terms referring to third-party hardware/storage vendors. Practical impact: slower security review for regulated buyers.

Not listed
Optional Google Search Console path
Low

Connecting Search Console pulls query metrics from Google into Alceris. Leave it disconnected if US providers are out of policy for any analytics-adjacent data.

Not listed
Billing via Paddle MoR
Low

Paid plans are contracted with Paddle, not Alceris directly. Review Paddle's terms and data role for finance/procurement.

Not listed
WordPress plugin maintenance signal
Low

WordPress.org lists the plugin as not tested with the latest major WP releases and few active installs. Prefer manual script install or re-test thoroughly on your WP version.

Not listed
US-group cloud and AI subprocessorsNot listed
Medium

Despite Dutch HQ and EU residency marketing, client data paths publicly include AWS, Vultr, and Microsoft Azure OpenAI. Transfer tooling (SCCs) and encryption of backups are documented, but CLOUD Act / US legal process risk remains a diligence item for sovereignty-sensitive buyers.

No public ISO/SOC or independent auditNot listed
Medium

Enterprise security questionnaires may stall without ISO 27001/SOC 2 packs. DPA offers information/audit rights—plan time for NDA evidence requests.

Azure OpenAI retains assistant context 30 daysNot listed
Medium

AI queries and aggregate report results are stored on Microsoft Azure OpenAI for 30 days per DPA. Property stripping reduces some identifiers, but misconfigured event properties could still expose sensitive content—govern AI use and property hygiene.

Controller privacy policy vs security architecture driftNot listed
Low

Privacy policy (controller, effective 2019) still emphasizes Vultr USA wording in places, while Security Architecture (client data) lists Hetzner/AWS/Vultr/Azure. Ask for a single current subprocessor and region matrix at contract time.

Not a privacy web-analytics substituteNot listed
Low

Full product analytics with cookies/identifiers for web integrations—not a cookieless aggregate counter. Consent UX remains on the client.

Fit

Alceris Analytics

Best fit when

  • Small-to-medium websites that want aggregate traffic and event stats without analytics cookies
  • Teams replacing GA for basic reporting (pages, referrers, UTMs) under a German legal entity
  • Operators who value a free volume-capped tier and Paddle-billed paid upgrades
  • Sites that may reverse-proxy the script/data endpoints to reduce ad-blocker loss
  • WordPress sites willing to validate the plugin against their WP version

Poor fit when

  • Organisations that must self-host analytics or run an open-source core under their own ops
  • Buyers needing public ISO 27001/SOC 2, independent audits, or a ready DPA/subprocessor pack
  • Product teams requiring funnels, session replay, heatmaps, or multi-product analytics depth
  • Procurement processes that reject solo-operator vendors or optional US integrations (Google Search Console)

Consider instead when

  • When: You want a more established cookieless SaaS brand with stronger public compliance packaging

    Consider: Plausible Analytics or Simple Analytics

    Similar lightweight privacy analytics category; different ownership and documentation maturity

  • When: You need self-hosted or on-prem control of the analytics stack

    Consider: Matomo (self-hosted) or catalog Matomo hosting variants

    Alceris is cloud-only; proxying the script still sends data to Alceris

  • When: You need German-hosted open-source cookieless analytics with a different product surface

    Consider: Pirsch Analytics

    Peer German privacy-analytics option for side-by-side evaluation

  • When: You need full GA4-class product and marketing analytics depth

    Consider: Google Analytics (accept its data model) or a heavier EU suite

    Alceris intentionally stays narrow

Stormly

Best fit when

  • Merchandising, product, UX, and growth teams on Shopify or Adobe Commerce who need SKU, cart, and assortment analytics without a dedicated data science org
  • Retail brands that want ready e-commerce report templates (new arrivals, unviewed/unsold, funnels, A/B, aha moments) plus vendor-built custom reports
  • EU buyers who want a Dutch legal entity, Amsterdam courts, and a downloadable DPA/Security Architecture package
  • Teams that value AI-generated trend/anomaly narratives delivered to the inbox more than building every chart from a blank event schema
  • Stacks already using Segment or Google Tag Manager as the event pipe into analytics

Poor fit when

  • Publishers or marketing sites that only need lightweight privacy-friendly page analytics (not product/SKU depth)
  • Orgs that require open-source self-hosting or full control of a private analytics warehouse as the default
  • Procurement policies that forbid US-group subprocessors (AWS, Vultr, Microsoft Azure OpenAI) even when EU regions are claimed
  • Assurance programs that require public ISO 27001/SOC 2 evidence before pilot (not found on vendor pages reviewed)
  • Companies operating blockchain products/services—restricted by Stormly’s terms

Consider instead when

  • When: You only need privacy-oriented website metrics (pageviews, sources) rather than SKU-level product analytics

    Consider: Plausible Analytics, Simple Analytics, or Pirsch Analytics

    EU web-analytics peers; different category from e-commerce product analytics

  • When: You need deep general-purpose product analytics, large ecosystem, and mature multi-product SaaS event modeling

    Consider: Mixpanel or Amplitude

    US incumbents; stronger breadth, different jurisdiction and commercial model

  • When: You primarily need free/universal marketing acquisition reporting already embedded in the stack

    Consider: Google Analytics (incumbent) or dual-run GA for marketing + Stormly for product/merch

    GA is not SKU-first product analytics; Stormly is not a GA replacement for every report

Open questions for due diligence

Alceris Analytics

  • Will the vendor sign a B2B DPA and provide a current named subprocessor list (hosting, backups, email)?
  • Which exact EU data-centre operators and regions process customer analytics data today?
  • Is there any independent assessment of the no-cookie / no-IP-storage claims?
  • What is the support SLA or roadmap process for a solo-operated product?
  • Is the WordPress plugin still maintained for current WordPress majors?

Stormly

  • Can Stormly provide a current region map (which data classes live on Hetzner vs Vultr vs AWS) under NDA for our DPIA?
  • Are ISO 27001, SOC 2, or penetration-test summaries available on request for enterprise security review?
  • Which event properties from our Shopify/Adobe feed are excluded from Azure OpenAI prompts by default in our tenant?
  • Do custom report builds and SQL access sit only on the custom tier, and what SLAs apply?
  • Has the 2019 controller privacy policy been superseded for hosting wording relative to the Security Architecture list?