Commanders Act vs Sitesights

Compare Commanders Act and Sitesights on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Google Analytics

Logo: Commanders Act

Commanders Act

France· Web Analytics

Needs review

Shortlist when you need an EU-headquartered enterprise stack combining server-side tag management, consent, real-time CDP activation, and independent media attribution (Adloop). Skip when you only need lightweight privacy analytics or open-source self-hosting—consider etracker or fusedeck for narrower EU measurement/tagging scopes, or Matomo-class tools for self-host analytics.

EU-operated (FR)Server-side TMSReal-time CDPIntegrated CMPAdloop attributionSaaS only
Logo: Sitesights

Sitesights

Germany· Web Analytics

Needs review

Shortlist Sitesights when you need German-operated cookieless web analytics with real-time dashboards, funnels, page flow, and a server-side API—especially agencies and SaaS teams that want Hetzner Germany hosting claims without running Matomo. Skip when you need public ISO/SOC audits, long-term visitor identity, session replay, or a fully published subprocessor pack; consider Plausible Analytics or self-hosted Matomo instead.

Cookieless trackingEU-operated (DE)Hetzner Germany (claimed)Server-side APIFunnels + page flowMulti-project / agencies
Commanders Act vs Sitesights: Snapshot
FeatureLogo: Commanders ActCommanders ActLogo: SitesightsSitesights
Country of originFranceGermany
CategoryWeb AnalyticsWeb Analytics
Open sourceNoNo
Self-hostedNoNo
HeadquartersFranceGermany
Legal entityFjord Technologies SAS (trading name Commanders Act), SIREN 527 730 782, ParisDrude, Grossert GbR
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)MediumMedium
Hosting / residencyVendor: EU/France data centers for platform hosting; privacy policy: site data stored in EU. Public DNS: app/platform behind Cloudflare CDN. Hosting provider certs (ISO 27001, SOC 1/2, etc.) claimed on Security product sheet. Full customer-data subprocessor list not published on marketing site.Product databases and app servers claimed in Germany on Hetzner. Marketing site uses Cloudflare (US) CDN. Payments via Paddle. Full product subprocessor/backup list not published on main site.
Summary

French PlatformX MarTech suite from Fjord Technologies: enterprise server-side tag management, integrated consent, real-time CDP, and Adloop media attribution for multi-channel marketing teams.

German cookieless web analytics SaaS with real-time dashboards, events, funnels, and server-side APIs. Operated by Drude, Grossert GbR; product data claimed on Hetzner in Germany.

Tags
At a glance: Commanders Act vs Sitesights
At a glanceLogo: Commanders ActCommanders ActLogo: SitesightsSitesights
HQParis, France (Fjord Technologies SAS)Not listed
SIREN527 730 782Not listed
Founded2010 (as TagCommander / Fjord Technologies)Not listed
DeploymentManaged SaaS (not self-hosted)Not listed
Core suiteTMS + CMP + CDP + AdloopNot listed
Commercial modelDemo / enterprise quote (no public list price)Free start; pageviews + events subscriptions (Paddle)
HQ / entityNot listedDrude, Grossert GbR, Germany
CategoryNot listedWeb analytics (SaaS)
Hosting (product)Not listedHetzner, Germany (vendor docs)
Tracking modelNot listedCookieless; 48h rotating server hash
Open sourceNot listedNo (libs/plugins public; core SaaS proprietary)
Key capabilities: Commanders Act vs Sitesights
Key capabilitiesLogo: Commanders ActCommanders ActLogo: SitesightsSitesights
EU-operated (FR)YesYes
Server-side TMSYesNot listed
Real-time CDPYesNot listed
Integrated CMPYesNot listed
Adloop attributionYesNot listed
SaaS onlyYesNot listed
Cookieless trackingNot listedYes
Hetzner Germany (claimed)Not listedYes
Server-side APINot listedYes
Funnels + page flowNot listedYes
Multi-project / agenciesNot listedYes

Commanders Act

  • Enterprise Tag Manager with server-side destinations and CAPIs

    Collect first-party and omnichannel events, transform/enrich without code, and deliver to 1,200+ destinations including 100+ server-side paths and major CAPIs (Google, Meta, Amazon, TikTok, Snapchat per vendor). GTM-ready server-side integration supports hybrid Google Tag Manager workflows.

  • Integrated consent and privacy governance tooling

    Native CMP/consent features (TrustCommander lineage) with Google Consent Mode support and Google CMP partner listing. Privacy monitoring, data-quality dashboards, filters before partner delivery, and cookie-related scanners help marketing ops control what leaves the property.

  • Real-time CDP: identity resolution, segments, activation

    Unify profiles across sources (including CRM enrichment), build no-code audiences with many filter criteria, push dynamic segment updates into ad and personalization destinations, and support cross-device experience consistency under consent rules.

  • Adloop media optimization and data-driven attribution

    After the 2023 Adloop acquisition, centralize campaign data via API connectors, run behaviour-based attribution as an independent measurement layer versus ad-platform KPIs, set spend/anomaly alerts, and use AI-assisted ad-level recommendations.

  • Operational QA for tagging teams

    No-code QA tooling (live event inspector, debug mode), continuous data-quality monitoring, and role/IP-restricted platform access claims reduce reliance on pure developer debugging when tags and server-side pipelines change.

Sitesights

  • Cookieless 48-hour rotating session hash

    Standard tracking does not set cookies. Sitesights generates a server-side salted hash from IP, User-Agent, and site id with a salt that rotates every 48 hours, so long-term cross-day visitor re-identification is intentionally broken. Useful when teams want essential traffic metrics without a cookie-consent banner solely for analytics—confirm legal basis with counsel for your jurisdiction and data fields (including geo).

  • Sub-1 KB client script plus WordPress and Shopify plugins

    Drop-in client snippet marketed as under 1 KB, with official WordPress and Shopify integration paths for non-engineers. Fits marketing sites and stores that need quick instrumentation without a heavy tag manager stack.

  • Server-side REST API with C# and Node libraries

    Send page views and events from your backend with API-key auth so ad blockers cannot strip the beacon. MIT-licensed C# and Node.js libraries on GitHub speed integration; keep API keys off the client. Preferred path for accuracy-critical SaaS and app backends.

  • Real-time overview with campaign and device filters

    Live dashboard for visitors, pageviews, and sessions with advanced filters, UTM/campaign views, geo, browser, OS, screen size, and daytime patterns. Aimed at operators who want essential marketing analytics in one place rather than a full product-analytics suite.

  • Custom funnels and page-flow journey maps

    Build multi-step funnels and visual page-flow maps to see entry paths, routes, and exits. Helps conversion and UX work without session replay. Depth is journey-oriented, not identity-graph product analytics.

  • Multi-project workspaces with roles for agencies

    Group sites and apps into projects, assign roles/permissions, and invite clients or teammates. Marketing materials reference high ceilings for team seats and properties on paid plans—verify current limits on the official pricing page.

Assurance & compliance: Commanders Act vs Sitesights
Assurance & complianceLogo: Commanders ActCommanders ActLogo: SitesightsSitesights
Independent security / no-logs audit
Not applicable

Not a no-logs VPN/analytics product; marketing data platform processes customer event/profile data by design.

Not found

No public third-party security or no-logs audit PDF located on the official site or docs.

Independent security / pentest program
Vendor claimed

Security product sheet claims external pentests (black/grey box) every six months and customer audit rights; no public audit PDF reviewed.

Not listed
ISO 27001
Partial

Security sheet attributes ISO 27001 (and related) compliance to the hosting provider in France; not verified as Commanders Act's own current certificate.

Not found

No public ISO 27001 certificate found on official pages.

SOC 2 / SOC 3
Partial

Security sheet states hosting provider complies with SOC Type 1 and 2; not verified as vendor-owned SOC 2 report.

Not found

No public SOC 2/3 report found on official pages.

GDPR / EU data protection
Vendor claimed

French controller/processor entity; public privacy policy, named DPO, EU storage claim for site data, integrated consent tooling. Customer DPA terms not fully public on marketing pages.

Vendor claimed

German controller (Drude, Grossert GbR); cookieless hashing and EU hosting claims in docs/privacy. Confirm DPA and legal basis for IP/geo with counsel.

US CLOUD Act exposure (indicative)
Partial

EU entity / no known US parent, but Cloudflare CDN on public app/platform hostnames and incomplete public subprocessor list for customer data path. Not legal advice.

Partial

EU entity / no known US parent; product hosting claimed on Hetzner Germany. Marketing site lists Cloudflare (US); payments via Paddle; full SaaS subprocessor list not public. Indicative only—not legal advice.

Data processing agreement (B2B)
Unknown

Website privacy policy covers visitor/site processing; standard B2B DPA / Art. 28 package not located as a public self-serve download—request in procurement.

Not found

No standalone public DPA download found during research; request under contract for B2B processing.

EU AI Act
Not applicable

Includes AI-assisted ad recommendations; not assessed here as a high-risk AI system product category.

Not applicable

Web analytics product; not marketed as an AI system under the EU AI Act.

Considerations & known limitations: Commanders Act vs Sitesights
Considerations & known limitationsLogo: Commanders ActCommanders ActLogo: SitesightsSitesights
Limited public subprocessor inventory
Medium

Marketing site does not publish a clear list of subprocessors for customer event/CDP data. Cloudflare is observable on public hostnames; backend host is described generically as a French data center. Request written subprocessors, regions, and SCCs before relying on 'EU-only' narratives.

Medium

Hetzner (product) and Cloudflare (marketing site) are documented; backups, email, support, and monitoring vendors for the SaaS are not fully listed. Ask for a current subprocessor annex.

ISO/SOC claims tied to hosting provider
Medium

Security sheet language credits the data-center provider for ISO 27001 and SOC Type 1/2. Do not treat footer logos as proof of Commanders Act's own certifications without certificate IDs.

Not listed
Enterprise SaaS scope and switching cost
Medium

PlatformX spans TMS, CMP, CDP, and media optimization. Implementation (server-side migration, consent redesign, CAPI mapping) is non-trivial; not a drop-in free GTM replacement for all teams.

Not listed
No self-host option
Low

Fully managed SaaS only. Organizations with hard on-prem or open-source requirements need different tools.

Not listed
No public independent security auditNot listed
Medium

ISO 27001, SOC 2, and third-party security audits were not found on public pages. Enterprises may need to commission questionnaires or wait for vendor artifacts under NDA.

US-group CDN on marketing siteNot listed
Low

Privacy policy lists Cloudflare Inc. (US) for the public website CDN. Separate from claimed Hetzner product data path, but relevant to overall vendor surface area.

48-hour hash limits long-term visitor analyticsNot listed
Low

By design, the rotating salt prevents durable cross-day visitor recognition. Teams needing retention cohorts or multi-week funnels by person must model events differently or choose product-analytics tools.

On-premise availability is marketing-only detailNot listed
Low

About page claims on-prem hosting; docs do not provide a self-serve install guide. Treat as sales-assisted until scope is confirmed in writing.

Fit

Commanders Act

Best fit when

  • Marketing ops teams replacing or complementing GTM with governed server-side destinations and CAPIs
  • Enterprises that want tag management, consent, CDP segments, and activation under one French SaaS contract
  • Performance teams needing independent multi-channel attribution and campaign data hub after Adloop
  • Organizations prioritizing an EU legal entity and EU data-center marketing claims for MarTech collection tooling
  • Teams that need no-code QA, data-quality monitoring, and consent-aware partner delivery controls

Poor fit when

  • Solo sites or SMBs that only need free/client-side GTM or lightweight privacy page analytics
  • Buyers requiring open-source or fully self-hosted tag/CDP infrastructure
  • Procurement that must prove vendor-owned ISO 27001/SOC 2 from public certificate registries before RFP (provider-level claims need clarification)
  • Use cases limited to pure product analytics without marketing destination/CAPI complexity

Consider instead when

  • When: You mainly need EU web analytics with lighter tag/consent tooling, not a full CDP + media stack

    Consider: etracker

    German analytics + tag/consent oriented stack; smaller surface than PlatformX

  • When: You want Swiss cookieless analytics plus server-side tagging/activation without a French enterprise CDP suite

    Consider: fusedeck

    Narrower product; different jurisdiction (CH)

  • When: You need free client-side tagging and Google-native defaults, and can accept US hyperscaler jurisdiction

    Consider: Google Tag Manager (and Google marketing stack)

    Often retained in hybrid with Commanders Act server-side

  • When: Self-host open analytics is a hard requirement

    Consider: Matomo (self-host or EU Matomo hosting peers such as Friendly Analytics)

    Not a CDP/CAPI replacement

Sitesights

Best fit when

  • EU teams replacing GA4 with cookieless SaaS and wanting funnels/page-flow beyond a bare traffic counter
  • Agencies and freelancers managing many client sites with projects and role-based invites
  • Engineering-led installs that prefer server-side pageview/event ingestion against ad blockers
  • WordPress or Shopify properties that want official plugin paths plus a light client script
  • Orgs that value a German GbR legal entity and Hetzner Germany hosting claims over US multi-region analytics

Poor fit when

  • Product analytics requiring long-term user identity, cross-device stitching, or CDP-style profiles (48h hash by design)
  • Buyers who need public ISO 27001, SOC 2, or independent audit PDFs before shortlist
  • Teams that require self-serve open-source self-host as the primary deployment (on-prem only claimed, not documented as OSS)
  • UX research needs for heatmaps or session replay
  • Procurement that requires a complete public subprocessor list without an NDA conversation

Consider instead when

  • When: You want a minimal EU cookieless SaaS or a well-known self-host option

    Consider: Plausible Analytics

    Simpler metric set; strong self-host story. Sitesights markets deeper funnels/page-flow and multi-project agency features.

  • When: You need full self-host control, on-prem by default, or mature open-source governance

    Consider: Matomo (self-hosted)

    Heavier stack, deeper feature surface, and you operate the data plane yourself.

  • When: You need identity-rich product analytics, retention cohorts, or event warehouses

    Consider: Mixpanel or similar product-analytics platforms

    Different category—Sitesights is website/app growth analytics, not a full product analytics suite.

  • When: You need heatmaps, recordings, or UX feedback loops

    Consider: Hotjar, Microsoft Clarity, or EU UX-analytics tools

    Sitesights focuses on traffic, events, funnels, and flows—not session replay.

Open questions for due diligence

Commanders Act

  • Will Fjord Technologies provide a current Art. 28 DPA, subprocessor list, and data-flow diagram for PlatformX customer event data?
  • Which legal entity and cloud region process production customer data today, and are backups/DR in the same jurisdiction?
  • Does Commanders Act hold its own ISO 27001 or SOC 2 (certificate number/date), or only rely on hosting-provider attestations?
  • What is the minimum commercial package if the buyer only needs TMS + CMP versus full CDP + Adloop?
  • How are US ad-platform CAPIs and optional Google/Meta connections handled for transfer impact assessments?

Sitesights

  • Will the vendor sign a B2B DPA and provide a complete subprocessor list (backups, email, support, monitoring)?
  • Is the Hetzner Germany residency contractual for all analytics tenant data, including DR/backups?
  • What is the formal on-premise offering (SLA, update model, supported regions) versus SaaS-only?
  • Are any ISO 27001 / SOC 2 / penetration-test reports available under NDA?
  • How should geolocation fields and IP hashing be assessed under your counsel's GDPR legal-basis analysis?