digistats Analytics vs Stormly

Compare digistats Analytics and Stormly on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Google Analytics

Logo: digistats Analytics

digistats Analytics

Switzerland· Web Analytics

Needs review

Shortlist digistats when you want managed Swiss cookieless analytics with multi-site, events, API, and CSV on every listed tier and you accept SaaS-only operations. Skip when you need self-host/OSS, GA4-depth product analytics, or published ISO 27001/SOC 2—consider Plausible, Simple Analytics, Pirsch, or Matomo instead.

Cookieless trackingNo stored visitor IPsSwiss data centerUnlimited websitesAPI + CSV exportManaged SaaS
Logo: Stormly

Stormly

Netherlands· Web Analytics

Needs review

Shortlist Stormly when you need Dutch-contracted, e-commerce-first product analytics: SKU-aware report packs, Shopify/Adobe-oriented setup, inbox-style AI anomaly narratives, and a public DPA. Skip when you need cookieless privacy web stats only (consider Plausible, Simple Analytics, or Pirsch), open-source self-hosting, verified ISO/SOC on a public cert page, or a subprocessor chain free of US-group cloud and Azure OpenAI.

E-commerce product analyticsSKU-aware reportsAI anomaly insightsShopify / Adobe CommerceNL entity + public DPASaaS (not self-host)
digistats Analytics vs Stormly: Snapshot
FeatureLogo: digistats Analyticsdigistats AnalyticsLogo: StormlyStormly
Country of originSwitzerlandNetherlands
CategoryWeb AnalyticsWeb Analytics
Open sourceNoNo
Self-hostedNoNo
HeadquartersSwitzerlandNetherlands
Legal entitydigistats Analytics Ltd., Täfernstrasse 2A, CH-5405 Dättwil AG (UID CHE-296.235.462)Monon B.V. (Lutmastraat 1-3, 1072 JL Amsterdam; KvK 76248747 per Terms)
Governing lawSwiss law; venue Bremgarten AG (per AGB)Netherlands (Dutch law; Amsterdam courts)
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)MediumMedium
Hosting / residencyPrivacy policy: customer data processed/stored in Switzerland, not in the USA or outside the EU; pricing lists Switzerland Data Center. Hosting provider legal name not in a public subprocessor list. Payment subprocessors: Stripe, Inc. (USA) and Coinbase (crypto; German entity listed in AGB).Client analytics subprocessors (Security Architecture): Hetzner (EU); Amazon AWS (US company, vendor states EU regions only for encrypted analytics backups); Vultr (US company); Microsoft Azure OpenAI (US company, vendor states EU Azure region). Plans market EU data residency. Controller privacy policy also references Vultr/AWS for account data, AuthSMTP EU + Amazon SES USA for email, Stripe for payments; marketing site uses Google Analytics and Hotjar.
Summary

Swiss cookieless web analytics SaaS from digistats Analytics Ltd.: realtime traffic, city-level geo, events, and multi-site dashboards without storing cookies, IPs, or fingerprints.

Dutch SaaS product analytics for e-commerce teams: SKU-aware reports, AI-assisted anomaly and root-cause insights, and Shopify/Adobe Commerce/Segment/GTM-oriented connections under Monon B.V. (Amsterdam).

Tags
At a glance: digistats Analytics vs Stormly
At a glanceLogo: digistats Analyticsdigistats AnalyticsLogo: StormlyStormly
HQDättwil AG, SwitzerlandNot listed
Legal entitydigistats Analytics Ltd. (CHE-296.235.462)Not listed
HostingSwitzerland data center (host brand not named publicly)Not listed
DeploymentManaged SaaS onlyNot listed
Open sourceNoNo
Commercial modelFree low-traffic tier + pageview-based subscriptionFree tier + monthly plan + custom; trial path on paid
HQ / entityNot listedMonon B.V., Amsterdam, Netherlands
CategoryNot listedE-commerce product analytics (SaaS)
Hosting (public)Not listedHetzner; AWS EU-region backups; Vultr; Azure OpenAI EU region (vendor docs)
Self-hostNot listedNo
Governing lawNot listedDutch law; Amsterdam courts
Key capabilities: digistats Analytics vs Stormly
Key capabilitiesLogo: digistats Analyticsdigistats AnalyticsLogo: StormlyStormly
Cookieless trackingYesNot listed
No stored visitor IPsYesNot listed
Swiss data centerYesNot listed
Unlimited websitesYesNot listed
API + CSV exportYesNot listed
Managed SaaSYesNot listed
E-commerce product analyticsNot listedYes
SKU-aware reportsNot listedYes
AI anomaly insightsNot listedYes
Shopify / Adobe CommerceNot listedYes
NL entity + public DPANot listedYes
SaaS (not self-host)Not listedYes

digistats Analytics

  • Cookieless script without stored IPs or fingerprints

    Vendor docs describe a sub-1 kB tag that measures traffic without cookies, without retaining visitor IPs (IP used only for live geo lookup), and without fingerprinting—aimed at sites that want analytics without a consent banner for non-essential cookies.

  • Realtime dashboard with geo, tech, events, and channels

    Live visitor and pageview views plus city-level geography, browser/OS/device signals, custom conversion events, referrer/search/social acquisition, landing pages, and continuous site reachability (online status)—enough for content and marketing ops, not a full product-analytics suite.

  • Ad-blocker-resistant capture (vendor claim)

    Marketing materials contrast digistats with Google Analytics being stripped by major blockers and state digistats is not blocked by common ad-block extensions. Useful for traffic completeness debates; treat as first-party claim until you validate on your stack.

  • Multi-site SaaS with API, email reports, and CSV on every tier

    Published plans include unlimited websites and events, API access, email reports, Swiss data-center storage, and CSV export—even on the free low-traffic tier—so agencies can run multiple client properties without plan-gated feature cliffs.

  • Swiss entity and Swiss analytics data center

    Operated by digistats Analytics Ltd. (Dättwil AG); privacy policy commits to storing customer data in Switzerland. Managed hosting only—no self-hosted edition in public materials.

Stormly

  • AI agent for trends, anomalies, and root-cause style digs

    Stormly positions an AI agent that watches connected e-commerce data for trends and anomalies (for example conversion drops or product spikes), then delivers plain-language findings—often to the inbox—with root-cause style exploration for questions like mobile conversion drops or regional return spikes. AI assistant access is plan-dependent; the public DPA documents Azure OpenAI (Microsoft) handling of assistant queries with a 30-day retention window and property stripping rules. Best for merchandising and growth leads who want narrative answers without waiting on a data team.

  • SKU-aware e-commerce report library (plus custom builds)

    Ready reports target commerce questions: New Arrivals Performance (early SKU winners/laggards), Unviewed & Unsold Products, cart abandonment and revenue contribution by product/category, Conversion Journey and funnels by device/region, A/B test insights, Aha Moment Discovery, cross-selling analysis, and broader library items (retention, CLV, forecasting, SQL report, and more). Vendor materials state custom reports are included without a separate fee when a needed view is missing—useful for mid-market retailers that outgrow generic event charts.

  • Shopify, Adobe Commerce, Segment, and GTM-oriented connections

    Homepage setup emphasizes linking Shopify, Adobe Commerce, or Segment quickly, with Google Tag Manager also listed among integrations. The DPA describes additional programmatic paths (JS library, import, custom endpoints, third-party sources). Fits stores already on common commerce stacks; teams on exotic storefronts should validate event coverage and product-feed depth in a pilot before replacing an existing analytics stack.

  • End-user tracking with IP anonymization defaults

    Per the DPA, IP addresses for end-user analytics are not stored in full: the last octet is removed and geo/timezone are derived from the anonymized value. Web integrations automatically capture first-party cookie user ids, page/referrer/UTM context, and device metadata; app properties depend on client or CDP configuration. This is still full product analytics (not cookieless aggregate-only web stats)—clients remain responsible for consent banners and lawful basis for shopper tracking.

  • Public DPA, security architecture, and Dutch contracting

    B2B buyers can download a Data Processing Agreement (effective 2023-09-06) and a Security Architecture page listing subprocessors, encryption expectations, backup retention (analytics backups up to six months), and logical tenant isolation. Contracts and DPA are governed by Dutch law with Amsterdam courts. Useful for EU procurement packages—but US-group subprocessors (AWS, Vultr, Azure OpenAI) still require transfer and CLOUD Act diligence.

Assurance & compliance: digistats Analytics vs Stormly
Assurance & complianceLogo: digistats Analyticsdigistats AnalyticsLogo: StormlyStormly
Independent security / no-logs audit
Not found

Vendor claims no IP storage and no fingerprints; no public third-party audit PDF found.

Not found

Security Architecture describes encryption, monitoring, isolation, and vulnerability contact (security@stormly.com); no public third-party audit PDF found.

ISO 27001
Not found

Not claimed on reviewed pages. Host partner ISO 14001 (environmental) is not an ISMS cert.

Not found

No public ISO 27001 certificate located on official legal/security pages reviewed.

SOC 2 / SOC 3
Not found
Not found

No public SOC 2/3 report located on official pages reviewed.

GDPR / EU data protection
Vendor claimed

Swiss entity; privacy policy cites DSG and GDPR/DSGVO, cookieless design, Swiss storage. Not legal advice.

Vendor claimed

NL entity; public privacy policy and DPA (GDPR-oriented); IP last-octet anonymization for end-user analytics; SCCs language for restricted transfers in DPA.

US CLOUD Act exposure (indicative)
Partial

Swiss Ltd, no known US parent, analytics residency claimed in Switzerland; billing via Stripe, Inc. (US) and Coinbase. EuropeanStack assessment — not a vendor certification. Not legal advice.

Partial

EU entity / no known US parent, but public client subprocessors include AWS, Vultr, and Microsoft Azure OpenAI (US-group companies). Account path historically also lists Amazon SES and Stripe. Residency claims do not remove US-group legal exposure. Indicative only—not legal advice.

Data processing agreement (B2B)
Partial

Privacy policy describes Art. 28-style processing on behalf of customers; dedicated public DPA download not found — request signed DPA.

Vendor claimed

Downloadable DPA PDF linked from stormly.com/dpa (effective 6 September 2023); audit rights and subprocessor notice described; Security Architecture lists subprocessors.

EU AI Act
Not applicable

Web analytics product; not positioned as an AI system product.

Partial

Product includes an AI assistant via Azure OpenAI; not positioned as a high-risk AI system marketing claim. Buyers should map AI assistant use to their own AI Act / internal AI policy—vendor does not publish a full AI Act conformity package on the pages reviewed.

Considerations & known limitations: digistats Analytics vs Stormly
Considerations & known limitationsLogo: digistats Analyticsdigistats AnalyticsLogo: StormlyStormly
No public independent security audit
Medium

Cookieless and no-IP claims are first-party only. Security questionnaires that require audit reports will need vendor outreach or a different product.

Not listed
US-linked payment subprocessors
Medium

AGB names Stripe, Inc. (San Francisco) for cards and Coinbase for crypto. Billing and account data may leave the pure Swiss analytics path even if telemetry stays in Switzerland.

Not listed
Hosting provider not named publicly
Low

Switzerland data-center claim without a published host legal name or full subprocessor list complicates transfer and residual-risk assessments.

Not listed
No self-host or open-source path
Medium

Cannot pin collector versions, run fully air-gapped, or satisfy hard self-host mandates. Operational dependency on digistats uptime and roadmap.

Not listed
Registration path may be restricted
Low

At research time the login UI stated registrations were disabled and /developers redirected to login. Confirm trial and API access before scheduling migration.

Not listed
US-group cloud and AI subprocessorsNot listed
Medium

Despite Dutch HQ and EU residency marketing, client data paths publicly include AWS, Vultr, and Microsoft Azure OpenAI. Transfer tooling (SCCs) and encryption of backups are documented, but CLOUD Act / US legal process risk remains a diligence item for sovereignty-sensitive buyers.

No public ISO/SOC or independent auditNot listed
Medium

Enterprise security questionnaires may stall without ISO 27001/SOC 2 packs. DPA offers information/audit rights—plan time for NDA evidence requests.

Azure OpenAI retains assistant context 30 daysNot listed
Medium

AI queries and aggregate report results are stored on Microsoft Azure OpenAI for 30 days per DPA. Property stripping reduces some identifiers, but misconfigured event properties could still expose sensitive content—govern AI use and property hygiene.

Controller privacy policy vs security architecture driftNot listed
Low

Privacy policy (controller, effective 2019) still emphasizes Vultr USA wording in places, while Security Architecture (client data) lists Hetzner/AWS/Vultr/Azure. Ask for a single current subprocessor and region matrix at contract time.

Not a privacy web-analytics substituteNot listed
Low

Full product analytics with cookies/identifiers for web integrations—not a cookieless aggregate counter. Consent UX remains on the client.

Fit

digistats Analytics

Best fit when

  • EU/EEA/Swiss websites replacing Google Analytics primarily for privacy and consent simplification
  • Agencies needing unlimited websites on a single traffic-based plan with shareable simple dashboards
  • Content and marketing teams that need realtime pageviews, city-level geo, channels, and custom events
  • Buyers who want Swiss legal entity and Swiss analytics residency without running self-hosted Matomo
  • Teams that value a sub-1 kB script and vendor claims of better ad-blocker survival than GA tags

Poor fit when

  • Organizations that must self-host or review open-source collector code
  • Product/growth stacks needing GA4-class funnels, identity stitching, Ads linkage, or warehouse export
  • Procurement that requires public ISO 27001, SOC 2, or independent no-logs audit evidence
  • Buyers who cannot accept US-linked payment processors (Stripe/Coinbase) for billing data

Consider instead when

  • When: You need open-source and optional self-hosting with a large community

    Consider: Plausible Analytics or Matomo

    Plausible is cookieless SaaS + self-host; Matomo is the full self-host suite.

  • When: You want another lightweight EU cookieless SaaS without Swiss seat as a requirement

    Consider: Simple Analytics or Pirsch Analytics

    NL and DE peers in the same category band.

  • When: You need enterprise analytics, tag manager, and formal compliance packaging

    Consider: Piwik PRO or Matomo Cloud

    Heavier stacks with more modules and B2B assurance artifacts.

  • When: You are comparing global privacy-analytics brands rather than Swiss residency

    Consider: Fathom Analytics

    Different ownership and data-path story—verify residency independently.

Stormly

Best fit when

  • Merchandising, product, UX, and growth teams on Shopify or Adobe Commerce who need SKU, cart, and assortment analytics without a dedicated data science org
  • Retail brands that want ready e-commerce report templates (new arrivals, unviewed/unsold, funnels, A/B, aha moments) plus vendor-built custom reports
  • EU buyers who want a Dutch legal entity, Amsterdam courts, and a downloadable DPA/Security Architecture package
  • Teams that value AI-generated trend/anomaly narratives delivered to the inbox more than building every chart from a blank event schema
  • Stacks already using Segment or Google Tag Manager as the event pipe into analytics

Poor fit when

  • Publishers or marketing sites that only need lightweight privacy-friendly page analytics (not product/SKU depth)
  • Orgs that require open-source self-hosting or full control of a private analytics warehouse as the default
  • Procurement policies that forbid US-group subprocessors (AWS, Vultr, Microsoft Azure OpenAI) even when EU regions are claimed
  • Assurance programs that require public ISO 27001/SOC 2 evidence before pilot (not found on vendor pages reviewed)
  • Companies operating blockchain products/services—restricted by Stormly’s terms

Consider instead when

  • When: You only need privacy-oriented website metrics (pageviews, sources) rather than SKU-level product analytics

    Consider: Plausible Analytics, Simple Analytics, or Pirsch Analytics

    EU web-analytics peers; different category from e-commerce product analytics

  • When: You need deep general-purpose product analytics, large ecosystem, and mature multi-product SaaS event modeling

    Consider: Mixpanel or Amplitude

    US incumbents; stronger breadth, different jurisdiction and commercial model

  • When: You primarily need free/universal marketing acquisition reporting already embedded in the stack

    Consider: Google Analytics (incumbent) or dual-run GA for marketing + Stormly for product/merch

    GA is not SKU-first product analytics; Stormly is not a GA replacement for every report

Open questions for due diligence

digistats Analytics

  • Will digistats provide a signed Art. 28 DPA and a current subprocessor list including the Swiss host legal entity?
  • Is new customer registration open, and what are current free-tier and trial terms?
  • Is public API documentation available without a production account?
  • Are any independent security assessments available under NDA?
  • Do email reports or other support tools introduce additional SaaS subprocessors beyond Stripe/Coinbase?

Stormly

  • Can Stormly provide a current region map (which data classes live on Hetzner vs Vultr vs AWS) under NDA for our DPIA?
  • Are ISO 27001, SOC 2, or penetration-test summaries available on request for enterprise security review?
  • Which event properties from our Shopify/Adobe feed are excluded from Azure OpenAI prompts by default in our tenant?
  • Do custom report builds and SQL access sit only on the custom tier, and what SLAs apply?
  • Has the 2019 controller privacy policy been superseded for hosting wording relative to the Security Architecture list?