Analyzati vs Stormly

Compare Analyzati and Stormly on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Google Analytics

Logo: Analyzati

Analyzati

Spain· Web Analytics

Needs review

Shortlist when you want Spanish/EU-legal SaaS web analytics with cookie-free daily uniques, city geo, AI referral views, and a public DPA—without self-hosting. Skip when you need open source, on-prem, multi-day retention/cohorts, or certified ISO/SOC evidence; consider Plausible Analytics or Matomo instead.

Cookie-free trackingEU entity (Spain)App on AWS ParisPublic DPAAI referral insightsSaaS only
Logo: Stormly

Stormly

Netherlands· Web Analytics

Needs review

Shortlist Stormly when you need Dutch-contracted, e-commerce-first product analytics: SKU-aware report packs, Shopify/Adobe-oriented setup, inbox-style AI anomaly narratives, and a public DPA. Skip when you need cookieless privacy web stats only (consider Plausible, Simple Analytics, or Pirsch), open-source self-hosting, verified ISO/SOC on a public cert page, or a subprocessor chain free of US-group cloud and Azure OpenAI.

E-commerce product analyticsSKU-aware reportsAI anomaly insightsShopify / Adobe CommerceNL entity + public DPASaaS (not self-host)
Analyzati vs Stormly: Snapshot
FeatureLogo: AnalyzatiAnalyzatiLogo: StormlyStormly
Country of originSpainNetherlands
CategoryWeb AnalyticsWeb Analytics
Open sourceNoNo
Self-hostedNoNo
HeadquartersSpainNetherlands
Legal entityIncorporated in Barcelona, Spain (exact legal name not published on pages reviewed)Monon B.V. (Lutmastraat 1-3, 1072 JL Amsterdam; KvK 76248747 per Terms)
Governing lawSpain / EU (GDPR referenced; confirm governing law clause in Terms)Netherlands (Dutch law; Amsterdam courts)
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)MediumMedium
Hosting / residencyVisitor/app data: AWS in Paris (vendor). Marketing site: Namecheap in Amsterdam. Backups described as EU. Other subprocessors named in privacy materials: Stripe (payments), AWS (email), Freshworks (support), hCaptcha (registration).Client analytics subprocessors (Security Architecture): Hetzner (EU); Amazon AWS (US company, vendor states EU regions only for encrypted analytics backups); Vultr (US company); Microsoft Azure OpenAI (US company, vendor states EU Azure region). Plans market EU data residency. Controller privacy policy also references Vultr/AWS for account data, AuthSMTP EU + Amazon SES USA for email, Stripe for payments; marketing site uses Google Analytics and Hotjar.
Summary

Spanish cookie-free web analytics SaaS: real-time traffic, city-level geo, AI referral sources, and event tracking without cookies, stored IPs, or fingerprints.

Dutch SaaS product analytics for e-commerce teams: SKU-aware reports, AI-assisted anomaly and root-cause insights, and Shopify/Adobe Commerce/Segment/GTM-oriented connections under Monon B.V. (Amsterdam).

Tags
At a glance: Analyzati vs Stormly
At a glanceLogo: AnalyzatiAnalyzatiLogo: StormlyStormly
HQ / entityBarcelona, Spain (EU entity claimed; exact registry name not on public pages reviewed)Monon B.V., Amsterdam, Netherlands
Product typeHosted web analytics SaaSNot listed
Open sourceNoNo
Self-hostNoNo
App hostingAWS, Paris (vendor claim)Not listed
Commercial modelFreemium + pageview / site-count tiersFree tier + monthly plan + custom; trial path on paid
DPAPublic; accepted via Terms of ServiceNot listed
CategoryNot listedE-commerce product analytics (SaaS)
Hosting (public)Not listedHetzner; AWS EU-region backups; Vultr; Azure OpenAI EU region (vendor docs)
Governing lawNot listedDutch law; Amsterdam courts
Key capabilities: Analyzati vs Stormly
Key capabilitiesLogo: AnalyzatiAnalyzatiLogo: StormlyStormly
Cookie-free trackingYesNot listed
EU entity (Spain)YesNot listed
App on AWS ParisYesNot listed
Public DPAYesNot listed
AI referral insightsYesNot listed
SaaS onlyYesYes
E-commerce product analyticsNot listedYes
SKU-aware reportsNot listedYes
AI anomaly insightsNot listedYes
Shopify / Adobe CommerceNot listedYes
NL entity + public DPANot listedYes

Analyzati

  • Cookie-free uniques with daily rotating salt

    Counts daily unique visitors by hashing IP + User-Agent + domain with a salt that is destroyed every 24 hours. No cookies, localStorage, or device-persistent IDs; raw IP and full UA are not stored. Trade-off: no multi-day retention or new-vs-returning series.

  • City-level geo without retained IPs

    Derives continent, country, region, and city for maps and rankings from the request IP, then discards the IP. Useful for market mix reporting when you do not need ISP- or coordinate-level precision.

  • AI referral and channel acquisition views

    Breaks down how visitors arrive—search, referring sites, and AI assistants such as ChatGPT, Perplexity, Gemini, and Claude—so content teams can see discovery outside classic SEO referrers.

  • Real-time dashboard, events, export, and API

    Live visitor activity, page performance, device/browser/OS stats, custom events and campaigns, weekly email reports, data export, and API access on published plans. Integrations include a WordPress plugin and Google Tag Manager snippet placement.

  • Public B2B DPA with processor role

    A published Data Processing Agreement (effective August 2022) treats Analyzati as processor and the customer as controller for visitor measurement. Acceptance is tied to product use under the Terms of Service rather than a bespoke countersignature workflow.

Stormly

  • AI agent for trends, anomalies, and root-cause style digs

    Stormly positions an AI agent that watches connected e-commerce data for trends and anomalies (for example conversion drops or product spikes), then delivers plain-language findings—often to the inbox—with root-cause style exploration for questions like mobile conversion drops or regional return spikes. AI assistant access is plan-dependent; the public DPA documents Azure OpenAI (Microsoft) handling of assistant queries with a 30-day retention window and property stripping rules. Best for merchandising and growth leads who want narrative answers without waiting on a data team.

  • SKU-aware e-commerce report library (plus custom builds)

    Ready reports target commerce questions: New Arrivals Performance (early SKU winners/laggards), Unviewed & Unsold Products, cart abandonment and revenue contribution by product/category, Conversion Journey and funnels by device/region, A/B test insights, Aha Moment Discovery, cross-selling analysis, and broader library items (retention, CLV, forecasting, SQL report, and more). Vendor materials state custom reports are included without a separate fee when a needed view is missing—useful for mid-market retailers that outgrow generic event charts.

  • Shopify, Adobe Commerce, Segment, and GTM-oriented connections

    Homepage setup emphasizes linking Shopify, Adobe Commerce, or Segment quickly, with Google Tag Manager also listed among integrations. The DPA describes additional programmatic paths (JS library, import, custom endpoints, third-party sources). Fits stores already on common commerce stacks; teams on exotic storefronts should validate event coverage and product-feed depth in a pilot before replacing an existing analytics stack.

  • End-user tracking with IP anonymization defaults

    Per the DPA, IP addresses for end-user analytics are not stored in full: the last octet is removed and geo/timezone are derived from the anonymized value. Web integrations automatically capture first-party cookie user ids, page/referrer/UTM context, and device metadata; app properties depend on client or CDP configuration. This is still full product analytics (not cookieless aggregate-only web stats)—clients remain responsible for consent banners and lawful basis for shopper tracking.

  • Public DPA, security architecture, and Dutch contracting

    B2B buyers can download a Data Processing Agreement (effective 2023-09-06) and a Security Architecture page listing subprocessors, encryption expectations, backup retention (analytics backups up to six months), and logical tenant isolation. Contracts and DPA are governed by Dutch law with Amsterdam courts. Useful for EU procurement packages—but US-group subprocessors (AWS, Vultr, Azure OpenAI) still require transfer and CLOUD Act diligence.

Assurance & compliance: Analyzati vs Stormly
Assurance & complianceLogo: AnalyzatiAnalyzatiLogo: StormlyStormly
Independent security / no-logs audit
Not found

No public third-party audit PDF or no-logs attestation found on official pages reviewed.

Not found

Security Architecture describes encryption, monitoring, isolation, and vulnerability contact (security@stormly.com); no public third-party audit PDF found.

ISO 27001
Not found

No ISO 27001 certificate claim located on homepage, privacy, or DPA pages.

Not found

No public ISO 27001 certificate located on official legal/security pages reviewed.

SOC 2 / SOC 3
Not found

No SOC 2/3 report claim found on public trust materials.

Not found

No public SOC 2/3 report located on official pages reviewed.

GDPR / EU data protection
Vendor claimed

EU entity (Barcelona); public GDPR/PECR/CCPA compliance pages; anonymisation design documented; controller/processor roles in DPA.

Vendor claimed

NL entity; public privacy policy and DPA (GDPR-oriented); IP last-octet anonymization for end-user analytics; SCCs language for restricted transfers in DPA.

US CLOUD Act exposure (indicative)
Partial

Spanish/EU vendor with no known US parent, but application hosting on AWS (Paris) and US-group subprocessors (Stripe, Freshworks, AWS email, hCaptcha). Residency ≠ ownership. Not legal advice.

Partial

EU entity / no known US parent, but public client subprocessors include AWS, Vultr, and Microsoft Azure OpenAI (US-group companies). Account path historically also lists Amazon SES and Stripe. Residency claims do not remove US-group legal exposure. Indicative only—not legal advice.

Data processing agreement (B2B)
Vendor claimed

Public DPA effective 18 Aug 2022; vendor says acceptance is automatic via product use / ToS—no separate signature required.

Vendor claimed

Downloadable DPA PDF linked from stormly.com/dpa (effective 6 September 2023); audit rights and subprocessor notice described; Security Architecture lists subprocessors.

EU AI Act
Not applicable

Product reports AI *referral traffic*; it is not marketed as a high-risk AI system provider.

Partial

Product includes an AI assistant via Azure OpenAI; not positioned as a high-risk AI system marketing claim. Buyers should map AI assistant use to their own AI Act / internal AI policy—vendor does not publish a full AI Act conformity package on the pages reviewed.

Considerations & known limitations: Analyzati vs Stormly
Considerations & known limitationsLogo: AnalyzatiAnalyzatiLogo: StormlyStormly
AWS and US-group subprocessors
Medium

Measurement app is on AWS Paris; account path also uses Stripe, Freshworks, AWS email, and hCaptcha. EU regions reduce some transfer friction but do not erase US-group provider diligence for many public-sector and bank questionnaires.

Not listed
No public ISO/SOC or independent audit
Medium

Security claims rely on vendor documentation (HTTPS, hashing, firewalls, backups). Organisations with mandatory cert evidence will need vendor outreach or a different shortlist.

Not listed
No multi-day visitor identity
Low

Daily salt rotation blocks persistent uniques. Expect gaps vs Google Analytics for returning users, frequency, and retention—by design.

Not listed
SaaS lock-in / no self-host
Low

No self-host edition found. Exit requires export/API migration to another tool; confirm export completeness in a trial.

Not listed
Exact registry name not on marketing pages
Low

Vendor states Barcelona incorporation but public pages reviewed did not display a full Spanish company registration string—collect CIF/NIF and full legal name during contracting.

Not listed
US-group cloud and AI subprocessorsNot listed
Medium

Despite Dutch HQ and EU residency marketing, client data paths publicly include AWS, Vultr, and Microsoft Azure OpenAI. Transfer tooling (SCCs) and encryption of backups are documented, but CLOUD Act / US legal process risk remains a diligence item for sovereignty-sensitive buyers.

No public ISO/SOC or independent auditNot listed
Medium

Enterprise security questionnaires may stall without ISO 27001/SOC 2 packs. DPA offers information/audit rights—plan time for NDA evidence requests.

Azure OpenAI retains assistant context 30 daysNot listed
Medium

AI queries and aggregate report results are stored on Microsoft Azure OpenAI for 30 days per DPA. Property stripping reduces some identifiers, but misconfigured event properties could still expose sensitive content—govern AI use and property hygiene.

Controller privacy policy vs security architecture driftNot listed
Low

Privacy policy (controller, effective 2019) still emphasizes Vultr USA wording in places, while Security Architecture (client data) lists Hetzner/AWS/Vultr/Azure. Ask for a single current subprocessor and region matrix at contract time.

Not a privacy web-analytics substituteNot listed
Low

Full product analytics with cookies/identifiers for web integrations—not a cookieless aggregate counter. Consent UX remains on the client.

Fit

Analyzati

Best fit when

  • Marketing sites and content properties that need page views, referrers, device mix, and city-level geo without analytics cookies
  • Teams replacing Google Analytics primarily for privacy/consent simplification rather than advanced product analytics
  • Agencies or freelancers who want multi-site hosted analytics with a freemium entry path
  • Buyers who want a published DPA and Spanish/EU legal entity on the order form
  • Content teams tracking discovery from AI assistants alongside classic channels

Poor fit when

  • Product or growth teams that require funnels, multi-day retention, cohorts, or cross-device identity
  • Organisations that mandate open-source code or self-hosted deployment
  • Procurement that will not accept AWS (US-group) or other US SaaS subprocessors even in EU regions
  • Security questionnaires that demand public ISO 27001 / SOC 2 reports or independent no-logs audits
  • Use cases needing session replay, heatmaps, or advertising audience export

Consider instead when

  • When: You need open-source analytics you can self-host and audit

    Consider: Plausible Analytics (self-host option) or Matomo

    Analyzati is SaaS-only with no public source release found.

  • When: You want a comparable cookie-free European SaaS peer for side-by-side trials

    Consider: Plausible Analytics or Simple Analytics

    Compare AI-referrer and geo depth, DPA wording, and hosting/subprocessor lists in each trial.

  • When: You need full-stack product analytics and advertising linkage

    Consider: Google Analytics (incumbent) or a dedicated product analytics suite

    Analyzati deliberately collects a minimal metric set and does not sell ad-tech profiles.

Stormly

Best fit when

  • Merchandising, product, UX, and growth teams on Shopify or Adobe Commerce who need SKU, cart, and assortment analytics without a dedicated data science org
  • Retail brands that want ready e-commerce report templates (new arrivals, unviewed/unsold, funnels, A/B, aha moments) plus vendor-built custom reports
  • EU buyers who want a Dutch legal entity, Amsterdam courts, and a downloadable DPA/Security Architecture package
  • Teams that value AI-generated trend/anomaly narratives delivered to the inbox more than building every chart from a blank event schema
  • Stacks already using Segment or Google Tag Manager as the event pipe into analytics

Poor fit when

  • Publishers or marketing sites that only need lightweight privacy-friendly page analytics (not product/SKU depth)
  • Orgs that require open-source self-hosting or full control of a private analytics warehouse as the default
  • Procurement policies that forbid US-group subprocessors (AWS, Vultr, Microsoft Azure OpenAI) even when EU regions are claimed
  • Assurance programs that require public ISO 27001/SOC 2 evidence before pilot (not found on vendor pages reviewed)
  • Companies operating blockchain products/services—restricted by Stormly’s terms

Consider instead when

  • When: You only need privacy-oriented website metrics (pageviews, sources) rather than SKU-level product analytics

    Consider: Plausible Analytics, Simple Analytics, or Pirsch Analytics

    EU web-analytics peers; different category from e-commerce product analytics

  • When: You need deep general-purpose product analytics, large ecosystem, and mature multi-product SaaS event modeling

    Consider: Mixpanel or Amplitude

    US incumbents; stronger breadth, different jurisdiction and commercial model

  • When: You primarily need free/universal marketing acquisition reporting already embedded in the stack

    Consider: Google Analytics (incumbent) or dual-run GA for marketing + Stormly for product/merch

    GA is not SKU-first product analytics; Stormly is not a GA replacement for every report

Open questions for due diligence

Analyzati

  • What is the full Spanish legal entity name and company registry identifier for the order form?
  • Is a current written subprocessor list available beyond privacy-policy mentions (including backup regions and any CDN)?
  • Can the vendor provide ISO/SOC evidence or a third-party penetration test under NDA?
  • What is the analytics data retention window per plan, and what does the API export include?
  • Which governing law and venue apply under the current Terms of Service?

Stormly

  • Can Stormly provide a current region map (which data classes live on Hetzner vs Vultr vs AWS) under NDA for our DPIA?
  • Are ISO 27001, SOC 2, or penetration-test summaries available on request for enterprise security review?
  • Which event properties from our Shopify/Adobe feed are excluded from Azure OpenAI prompts by default in our tenant?
  • Do custom report builds and SQL access sit only on the custom tier, and what SLAs apply?
  • Has the 2019 controller privacy policy been superseded for hosting wording relative to the Security Architecture list?