Commanders Act vs Pirsch Analytics

Compare Commanders Act and Pirsch Analytics on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Google Analytics

Logo: Commanders Act

Commanders Act

France· Web Analytics

Needs review

Shortlist when you need an EU-headquartered enterprise stack combining server-side tag management, consent, real-time CDP activation, and independent media attribution (Adloop). Skip when you only need lightweight privacy analytics or open-source self-hosting—consider etracker or fusedeck for narrower EU measurement/tagging scopes, or Matomo-class tools for self-host analytics.

EU-operated (FR)Server-side TMSReal-time CDPIntegrated CMPAdloop attributionSaaS only
Logo: Pirsch Analytics

Pirsch Analytics

Germany· Web Analytics

Needs review

Shortlist Pirsch when you want German-operated, cookie-free web analytics with funnels/events, agency white-label, and a public DPA—hosted on Hetzner per vendor docs. Skip when you need free full-product self-host, session replay/heatmaps, or a stack with zero US-group subprocessors; consider Plausible or Simple Analytics instead.

Cookie-free hashingOpen-source core (AGPL)Hetzner DE hosting (claimed)Server-side trackingAgency white-labelPublic DPA/AVV
Commanders Act vs Pirsch Analytics: Snapshot
FeatureLogo: Commanders ActCommanders ActLogo: Pirsch AnalyticsPirsch Analytics
Country of originFranceGermany
CategoryWeb AnalyticsWeb Analytics
Open sourceNoYes
Self-hostedNoNo
HeadquartersFranceGermany
Legal entityFjord Technologies SAS (trading name Commanders Act), SIREN 527 730 782, ParisEmvi Software GmbH (Nickelstraße 1b, 33378 Rheda-Wiedenbrück; HRB 11575, AG Gütersloh)
Governing lawNot listedGermany / EU GDPR
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)MediumMedium
Hosting / residencyVendor: EU/France data centers for platform hosting; privacy policy: site data stored in EU. Public DNS: app/platform behind Cloudflare CDN. Hosting provider certs (ISO 27001, SOC 1/2, etc.) claimed on Security product sheet. Full customer-data subprocessor list not published on marketing site.Analytics: Hetzner Online GmbH, Germany (vendor claims Nuremberg/Falkenstein). Account/ops subprocessors named in privacy policy include AWS SES (Amazon Web Services EMEA), Google Workspace (Google Cloud EMEA), Stripe, Inc. (US), Intuition Machines, Inc. (US CAPTCHA), and Datev eG (DE).
Summary

French PlatformX MarTech suite from Fjord Technologies: enterprise server-side tag management, integrated consent, real-time CDP, and Adloop media attribution for multi-channel marketing teams.

Cookie-free web analytics from Emvi Software GmbH in Germany: hash-based visitor IDs, open-source core, Hetzner-hosted SaaS with funnels, events, and agency white-label.

Tags
At a glance: Commanders Act vs Pirsch Analytics
At a glanceLogo: Commanders ActCommanders ActLogo: Pirsch AnalyticsPirsch Analytics
HQParis, France (Fjord Technologies SAS)Rheda-Wiedenbrück, Germany
SIREN527 730 782Not listed
Founded2010 (as TagCommander / Fjord Technologies)Not listed
DeploymentManaged SaaS (not self-hosted)Not listed
Core suiteTMS + CMP + CDP + AdloopNot listed
Commercial modelDemo / enterprise quote (no public list price)Usage-based (monthly page views); trial available
Legal entityNot listedEmvi Software GmbH
CategoryNot listedWeb analytics (SaaS)
Open sourceNot listedCore library AGPL-3.0; full SaaS commercial
Self-hostNot listedEnterprise on-prem option; not free CE
Primary hosting (claimed)Not listedHetzner Germany (Nuremberg/Falkenstein)
Key capabilities: Commanders Act vs Pirsch Analytics
Key capabilitiesLogo: Commanders ActCommanders ActLogo: Pirsch AnalyticsPirsch Analytics
EU-operated (FR)YesNot listed
Server-side TMSYesNot listed
Real-time CDPYesNot listed
Integrated CMPYesNot listed
Adloop attributionYesNot listed
SaaS onlyYesNot listed
Cookie-free hashingNot listedYes
Open-source core (AGPL)Not listedYes
Hetzner DE hosting (claimed)Not listedYes
Server-side trackingNot listedYes
Agency white-labelNot listedYes
Public DPA/AVVNot listedYes

Commanders Act

  • Enterprise Tag Manager with server-side destinations and CAPIs

    Collect first-party and omnichannel events, transform/enrich without code, and deliver to 1,200+ destinations including 100+ server-side paths and major CAPIs (Google, Meta, Amazon, TikTok, Snapchat per vendor). GTM-ready server-side integration supports hybrid Google Tag Manager workflows.

  • Integrated consent and privacy governance tooling

    Native CMP/consent features (TrustCommander lineage) with Google Consent Mode support and Google CMP partner listing. Privacy monitoring, data-quality dashboards, filters before partner delivery, and cookie-related scanners help marketing ops control what leaves the property.

  • Real-time CDP: identity resolution, segments, activation

    Unify profiles across sources (including CRM enrichment), build no-code audiences with many filter criteria, push dynamic segment updates into ad and personalization destinations, and support cross-device experience consistency under consent rules.

  • Adloop media optimization and data-driven attribution

    After the 2023 Adloop acquisition, centralize campaign data via API connectors, run behaviour-based attribution as an independent measurement layer versus ad-platform KPIs, set spend/anomaly alerts, and use AI-assisted ad-level recommendations.

  • Operational QA for tagging teams

    No-code QA tooling (live event inspector, debug mode), continuous data-quality monitoring, and role/IP-restricted platform access claims reduce reliance on pure developer debugging when tags and server-side pipelines change.

Pirsch Analytics

  • Cookie-free 24-hour visitor hashing

    Recognizes visitors without cookies by hashing IP, User-Agent, date, and a per-site salt into a short ID. The vendor states IPs are not stored and cross-site linkage is blocked by the salt; sessions expire after 24 hours so long-term profiles are not built. Best for sites that want aggregate traffic metrics without a dedicated analytics cookie banner—confirm ePrivacy/TTDSG fit with counsel.

  • Server-side and script integrations

    Instrument via JS snippet, CMS plugins (e.g. WordPress, Shopify, Webflow, Framer), or backend SDKs/API (Go library and other stacks). Server-side collection improves resilience when ad blockers strip client scripts. Tradeoff: backend integration costs more engineering time than a single script tag.

  • Funnels, events, goals, and tag segmentation

    Goes past pageviews with custom events, conversion goals, multi-step funnels, session path exploration, outbound/download/404 tracking, and tags for A/B tests or channel segmentation. Webhooks and email reports push insights into existing tools. Some advanced metrics (e.g. custom event metrics, e-commerce revenue tracking) sit on higher commercial tiers—verify the live feature matrix.

  • Agency white-label and shared dashboards

    Custom domains, themes, logos, and broader white-label options let agencies present analytics under their own brand. Public dashboards and unique access links support clients without full account sprawl; roles/teams scale collaboration. Strong fit for multi-client portfolios; less relevant for a single personal blog.

  • Migration imports, API, and unlimited retention (stated)

    Import historical data from Google Analytics, Plausible, or Fathom; export CSV; use the REST API and SDKs for custom pipelines. Pricing docs state unlimited data retention across Standard, Plus, and Enterprise. Limits are usage-based on monthly page views (events and a share of session extensions count)—plan for growth, not perpetual free volume.

Assurance & compliance: Commanders Act vs Pirsch Analytics
Assurance & complianceLogo: Commanders ActCommanders ActLogo: Pirsch AnalyticsPirsch Analytics
Independent security / no-logs audit
Not applicable

Not a no-logs VPN/analytics product; marketing data platform processes customer event/profile data by design.

Not found

Open-source core allows code review; no public third-party audit PDF located in this research pass.

Independent security / pentest program
Vendor claimed

Security product sheet claims external pentests (black/grey box) every six months and customer audit rights; no public audit PDF reviewed.

Not listed
ISO 27001
Partial

Security sheet attributes ISO 27001 (and related) compliance to the hosting provider in France; not verified as Commanders Act's own current certificate.

Not found

No ISO 27001 certificate or registry entry found on official trust pages reviewed.

SOC 2 / SOC 3
Partial

Security sheet states hosting provider complies with SOC Type 1 and 2; not verified as vendor-owned SOC 2 report.

Not found

No public SOC 2/3 report referenced on official pages reviewed.

GDPR / EU data protection
Vendor claimed

French controller/processor entity; public privacy policy, named DPO, EU storage claim for site data, integrated consent tooling. Customer DPA terms not fully public on marketing pages.

Vendor claimed

German controller/processor Emvi Software GmbH; cookie-free hashing design; public DPA; German Hetzner hosting claims. Vendor also cites CCPA/PECR/Schrems II—treat as claims, confirm with counsel.

US CLOUD Act exposure (indicative)
Partial

EU entity / no known US parent, but Cloudflare CDN on public app/platform hostnames and incomplete public subprocessor list for customer data path. Not legal advice.

Partial

EU entity / no known US parent and Hetzner DE analytics hosting, but privacy policy names AWS SES, Google Workspace, Stripe, and Intuition Machines (US-group services) for email/CAPTCHA/payments. Not legal advice.

Data processing agreement (B2B)
Unknown

Website privacy policy covers visitor/site processing; standard B2B DPA / Art. 28 package not located as a public self-serve download—request in procurement.

Vendor claimed

Downloadable English DPA and German AVV PDFs linked from docs.pirsch.io/privacy.

EU AI Act
Not applicable

Includes AI-assisted ad recommendations; not assessed here as a high-risk AI system product category.

Not applicable

Classical web analytics product; not marketed as an AI system.

Considerations & known limitations: Commanders Act vs Pirsch Analytics
Considerations & known limitationsLogo: Commanders ActCommanders ActLogo: Pirsch AnalyticsPirsch Analytics
Limited public subprocessor inventory
Medium

Marketing site does not publish a clear list of subprocessors for customer event/CDP data. Cloudflare is observable on public hostnames; backend host is described generically as a French data center. Request written subprocessors, regions, and SCCs before relying on 'EU-only' narratives.

Not listed
ISO/SOC claims tied to hosting provider
Medium

Security sheet language credits the data-center provider for ISO 27001 and SOC Type 1/2. Do not treat footer logos as proof of Commanders Act's own certifications without certificate IDs.

Not listed
Enterprise SaaS scope and switching cost
Medium

PlatformX spans TMS, CMP, CDP, and media optimization. Implementation (server-side migration, consent redesign, CAPI mapping) is non-trivial; not a drop-in free GTM replacement for all teams.

Not listed
No self-host option
Low

Fully managed SaaS only. Organizations with hard on-prem or open-source requirements need different tools.

Not listed
US-group account/ops subprocessorsNot listed
Medium

Even with German analytics hosting claims, customer email, CAPTCHA, and payments involve AWS, Google, Stripe, and Intuition Machines. Sovereign or “no US cloud” policies need explicit exception handling or Enterprise architecture review.

No public ISO/SOC or third-party auditNot listed
Medium

Procurement teams that require ISO 27001 or SOC 2 evidence will need vendor questionnaires or NDA materials; public pages did not show those certs.

Open-source core ≠ free full self-hostNot listed
Low

Teams assuming AGPL means free on-prem of the entire product may be surprised; full on-prem is positioned as Enterprise.

Fingerprinting still needs legal fit reviewNot listed
Low

Cookie-free hashing is not automatically lawful everywhere without information/consent analysis. Banner removal should be validated for your jurisdiction and tag stack.

Page-view usage limitsNot listed
Low

Plans are metered on monthly page views (with events and partial session extensions counting). Hitting the cap can restrict dashboard access until upgrade or cycle reset—model traffic before cutover.

Fit

Commanders Act

Best fit when

  • Marketing ops teams replacing or complementing GTM with governed server-side destinations and CAPIs
  • Enterprises that want tag management, consent, CDP segments, and activation under one French SaaS contract
  • Performance teams needing independent multi-channel attribution and campaign data hub after Adloop
  • Organizations prioritizing an EU legal entity and EU data-center marketing claims for MarTech collection tooling
  • Teams that need no-code QA, data-quality monitoring, and consent-aware partner delivery controls

Poor fit when

  • Solo sites or SMBs that only need free/client-side GTM or lightweight privacy page analytics
  • Buyers requiring open-source or fully self-hosted tag/CDP infrastructure
  • Procurement that must prove vendor-owned ISO 27001/SOC 2 from public certificate registries before RFP (provider-level claims need clarification)
  • Use cases limited to pure product analytics without marketing destination/CAPI complexity

Consider instead when

  • When: You mainly need EU web analytics with lighter tag/consent tooling, not a full CDP + media stack

    Consider: etracker

    German analytics + tag/consent oriented stack; smaller surface than PlatformX

  • When: You want Swiss cookieless analytics plus server-side tagging/activation without a French enterprise CDP suite

    Consider: fusedeck

    Narrower product; different jurisdiction (CH)

  • When: You need free client-side tagging and Google-native defaults, and can accept US hyperscaler jurisdiction

    Consider: Google Tag Manager (and Google marketing stack)

    Often retained in hybrid with Commanders Act server-side

  • When: Self-host open analytics is a hard requirement

    Consider: Matomo (self-host or EU Matomo hosting peers such as Friendly Analytics)

    Not a CDP/CAPI replacement

Pirsch Analytics

Best fit when

  • EU sites replacing Google Analytics that need pageviews, campaigns, events, and funnels without analytics cookies
  • Agencies needing multi-site dashboards, client access links, and white-label branding
  • Teams that can instrument server-side or proxy scripts for better ad-blocker resilience
  • Buyers who want a German GmbH, downloadable DPA, and Hetzner-Germany residency claims for analytics data
  • Orgs evaluating Enterprise SAML, raw data access, or on-prem/managed private deployment

Poor fit when

  • Teams that require a free, full-product self-hosted community edition (core library ≠ full SaaS)
  • Product or UX research needing session replay, heatmaps, or persistent cross-site user identity
  • Procurement policies that forbid any US-group subprocessor (email CAPTCHA/billing still touch AWS/Google/Stripe/Intuition Machines)
  • Heavy product-analytics / multi-product identity graphs (closer to Amplitude/Mixpanel class tools)

Consider instead when

  • When: You need a free full-stack self-hosted analytics product with AGPL community edition

    Consider: Plausible Analytics (CE) or other open full products in your shortlist

    Pirsch open-sources the tracking core; on-prem of the full product is Enterprise-scoped.

  • When: You want the simplest possible privacy-first metrics with a Dutch vendor

    Consider: Simple Analytics

    Fewer advanced funnel/white-label features; different packaging tradeoffs.

  • When: You need heatmaps or session replay more than classical web analytics

    Consider: Hotjar, Microsoft Clarity, or EU UX-analytics peers

    Expect heavier consent and data-minimization review.

  • When: You must stay inside Google’s advertising and BigQuery measurement ecosystem

    Consider: Google Analytics / Google Tag Manager stack

    Opposite privacy and transfer posture—only if legal review accepts it.

Open questions for due diligence

Commanders Act

  • Will Fjord Technologies provide a current Art. 28 DPA, subprocessor list, and data-flow diagram for PlatformX customer event data?
  • Which legal entity and cloud region process production customer data today, and are backups/DR in the same jurisdiction?
  • Does Commanders Act hold its own ISO 27001 or SOC 2 (certificate number/date), or only rely on hosting-provider attestations?
  • What is the minimum commercial package if the buyer only needs TMS + CMP versus full CDP + Adloop?
  • How are US ad-platform CAPIs and optional Google/Meta connections handled for transfer impact assessments?

Pirsch Analytics

  • Can Enterprise on-prem exclude AWS SES / Google Workspace / Stripe / CAPTCHA US-group dependencies for the customer’s deployment?
  • Is any ISO 27001, SOC 2, or independent penetration-test summary available under NDA?
  • Exact data centers, backup locations, and encryption-key custody for multi-tenant SaaS—beyond marketing Hetzner claims?
  • Which feature flags on Standard vs Plus vs Enterprise apply to funnels, A/B tags, e-commerce metrics, and white-label depth at contract time?