etracker vs nilly

Compare etracker and nilly on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Google Analytics

Logo: etracker

etracker

Germany· Web Analytics

Needs review

Shortlist etracker when you need German-hosted marketing-grade web analytics with a cookieless default, integrated tag/consent tooling, and optional ad conversion sync. Skip when you must self-host open source (prefer Matomo) or only need lightweight pageview charts (prefer Plausible or similar). Treat ePrivacyseal consent-free claims as vendor-audited posture—confirm with your counsel and DPIA.

Cookieless default trackingEU/DE hosted (IPHH)ePrivacyseal (claimed)Tag + consent suiteAd conversion syncSaaS only (not self-host)
Logo: nilly

nilly

Switzerland· Web Analytics

Needs review

Shortlist nilly when you want Swiss-entity, cookieless, ultra-light site analytics with realtime dashboards, city geo, custom events, unlimited sites, and an API—without GA4 consent weight. Skip when you need self-host/open source, enterprise audit packs, or deep marketing-suite analytics; consider Plausible Analytics, Simple Analytics, or etracker instead.

Cookieless trackingSwiss-hosted (claimed)Swiss entitySub-1 kB scriptREST APISaaS only
etracker vs nilly: Snapshot
FeatureLogo: etrackeretrackerLogo: nillynilly
Country of originGermanySwitzerland
CategoryWeb AnalyticsWeb Analytics
Open sourceNoNo
Self-hostedNoNo
HeadquartersGermanySwitzerland
Legal entityJustRelate Deutschland GmbH (Charlottenburg HRB 218235); product brand JustRelate etracker / etrackerLyo GmbH, Europaallee 41, 8004 Zürich (CHE-417.675.763)
Governing lawNot listedSwitzerland (terms)
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)LowMedium
Hosting / residencyPrimary analytics processing on etracker's own servers in Germany/EU with housing at IPHH Internet Port Hamburg GmbH (vendor: no third-party access to apps/data for housing). Optional customer-enabled outbound paths to Google/Meta/TikTok/Microsoft Ads (conversion upload) and Google Looker Studio connectors—not core storage hosts.Vendor FAQ: analytics servers in Switzerland (multiple locations). Public site reverse-DNS: KreativMedia/METANET Zürich. Customer-account subprocessors named in privacy policy: Stripe (US payments), Mailerlite (email). Avatars via Gravatar. No full public subprocessor list for backups/monitoring/CDN.
Summary

German SaaS web and marketing analytics from JustRelate: cookieless default tracking, integrated tag/consent management, e-commerce and ad conversion sync on EU-hosted servers.

Swiss privacy-first web analytics (Lyo GmbH): cookieless, sub-1kB tracking with realtime dashboards, city-level geo, custom events, unlimited sites, and a REST API as a lightweight Google Analytics alternative.

Tags
At a glance: etracker vs nilly
At a glanceLogo: etrackeretrackerLogo: nillynilly
HQ / legal entityJustRelate Deutschland GmbH, Berlin (product ops Hamburg)Not listed
Product typeWeb & marketing analytics SaaS (+ tag/CMP modules)Not listed
HostingOwn servers, IPHH housing, Hamburg/GermanyNot listed
Open sourceNoNot listed
Self-hostedNoNot listed
Commercial modelUsage-based SaaS licence (hit tiers); trial commonly offeredTraffic-based plans; trial; no permanent free tier
HQNot listedZürich, Switzerland (Lyo GmbH)
Legal entityNot listedLyo GmbH (CHE-417.675.763)
Product modelNot listedSaaS web analytics (not self-hosted)
TrackingNot listedCookieless; no IP/fingerprint claims
Hosting (claimed)Not listedSwitzerland (multi-site)
Live site noteNot listedkandur.one (nilly branding; nilly.io DNS failed at research)
Key capabilities: etracker vs nilly
Key capabilitiesLogo: etrackeretrackerLogo: nillynilly
Cookieless default trackingYesNot listed
EU/DE hosted (IPHH)YesNot listed
ePrivacyseal (claimed)YesNot listed
Tag + consent suiteYesNot listed
Ad conversion syncYesNot listed
SaaS only (not self-host)YesYes
Cookieless trackingNot listedYes
Swiss-hosted (claimed)Not listedYes
Swiss entityNot listedYes
Sub-1 kB scriptNot listedYes
REST APINot listedYes

etracker

  • Cookieless session analytics (consent-oriented default)

    Server-side session tokens link interactions without analytical cookies or device fingerprinting by default; IP truncation and daily-rotating hashes limit long-term recognition. Suits sites that want visit/conversion metrics under legitimate interest while keeping optional hybrid cookies behind consent.

  • Integrated tag and consent management

    One product surface to load etracker and third-party tags and sync them with consent rules, reducing dual maintenance between a separate CMP and GTM. Best when marketers need gated Maps/ads tags without rebuilding the full Google stack.

  • Server-side conversion sync to major ad platforms

    Upload conversions measured in etracker to Google Ads, Meta, TikTok, and Microsoft Ads so bid algorithms receive server-side signals. Customer-controlled outbound path—useful for paid media, but introduces destination-platform processing outside German housing.

  • E-commerce, UX scrollmaps, and multi-level drill-downs

    Shop funnels from product list to order (including vouchers and abandonment), scrollmaps projected on pages, and reports with multi-dimension drill-downs plus attribution model switching. Aimed at merchandising and growth teams, not just pageview counters.

  • First-party tracking domain and BI exports

    Optional own-subdomain tracking (including Let's Encrypt workflow docs) to reduce ad-blocker and ITP loss; connectors/API/SFTP-style raw data paths toward Looker Studio, Power BI, and warehouses. Ops teams still configure domains and data pipelines themselves.

nilly

  • Sub-1 kB cookieless tracking script

    Vendor documents a client script under 1 kB with no cookies, no IP tracking, and no fingerprinting for site visitors. Suited to teams that want aggregate traffic metrics without analytics cookie banners; still get counsel for your jurisdiction and CMP setup.

  • Realtime dashboard with geo, tech, and campaigns

    Dashboards cover live visitors, overview metrics, top pages, referrers, UTM campaigns, geography from continent to city, and device/browser/OS breakdowns—enough for content and acquisition decisions without a full product-analytics suite.

  • Custom events, CSV export, and email reports

    Define custom events for conversion-style actions, export statistics as CSV, and receive email reports. Fits operators who need lightweight conversion signals and offline analysis rather than session replay or multi-step funnels.

  • REST API for stats, websites, and account

    Documented API endpoints (Bearer API key) manage stats queries (pageviews, visitors, referrers, events, geo, devices, and more), websites, and account objects—useful for internal dashboards or automations on traffic-based plans that include API access.

  • Unlimited websites on traffic-based plans

    Public pricing model is pageview-tier SaaS with unlimited websites per account and a short free trial—not a permanent free tier. Good for agencies or multi-brand operators who outgrow per-site free plans elsewhere; confirm current tiers on the vendor site.

Assurance & compliance: etracker vs nilly
Assurance & complianceLogo: etrackeretrackerLogo: nillynilly
Independent security / privacy audit
Vendor claimed

ePrivacyseal materials and vendor pages describe independent ePrivacy Consult audit of consent-free cookieless analytics posture; not a full public penetration-test report. Vendor also claims regular infrastructure pen tests.

Not found

No public third-party audit report found for tracking claims.

ISO 27001
Partial

IPHH housing described as ISO/IEC 27001:2013-certified. No public organisation-level ISO 27001 certificate for etracker/JustRelate analytics found in materials reviewed.

Not found

No vendor ISO 27001 certificate published on product site (underlying Swiss host DCs may be certified separately).

SOC 2 / SOC 3
Not found

No public SOC 2/SOC 3 report located on official trust/security pages reviewed.

Not found
GDPR / EU data protection
Vendor claimed

EU/DE controller-processor setup; cookieless default under legitimate interest; Art. 28 DPA on registration; privacy notice + objection patterns documented.

Vendor claimed

Swiss entity; privacy policy includes GDPR rights language; cookieless visitor tracking claimed. Confirm DPA for B2B.

US CLOUD Act exposure (indicative)
Partial

EuropeanStack assessment: German entity, no known US parent, own-server housing at IPHH (no public AWS/GCP/Azure analytics store) → core exposure low. Partial because optional conversion sync and Google connectors can send data to US-group destinations when enabled by the customer. Not legal advice.

Partial

Swiss operator, no known US parent, Swiss-claimed analytics hosting; US SaaS subprocessors Stripe (payments) and Gravatar (avatars) on customer path. Not legal advice.

Data processing agreement (B2B)
Vendor claimed

Vendor states DPA/AV concludes on account registration; public DPA PDFs and in-app DPA under Settings → Data processing agreement.

Not found

No public DPA download found; request from vendor.

ePrivacyseal (privacy seal)
Vendor claimed

Vendor and ePrivacy listing materials assert seal for consent-free cookieless mode under GDPR/TDDDG. Scope is privacy/consent posture, not a general security cert.

Not listed
EU AI Act
Not applicable

Product is web/marketing analytics, not an AI-system offering as primary positioning.

Not applicable

Web analytics product; not marketed as an AI system.

Swiss Made Software / Swiss Web labelsNot listed
Vendor claimed

Cited on About and Swiss Union member page as recognition/labels—not a security audit.

Considerations & known limitations: etracker vs nilly
Considerations & known limitationsLogo: etrackeretrackerLogo: nillynilly
Consent-free claims still need local legal review
Medium

ePrivacyseal and vendor guidance support cookieless default under TDDDG/GDPR, but hybrid cookies, marketing tags, and non-German supervisory interpretations can change the picture. Operators remain responsible for DPIA and notices.

Not listed
Optional conversion sync / BI connectors to US platforms
Medium

Core storage is claimed German; enabling Google/Meta/TikTok/Microsoft conversion upload or Looker Studio connectors creates additional processing at those destinations. Map each integration in your transfer assessment.

Not listed
Limited public enterprise security certs
Low

No public SOC 2 or org-level ISO 27001 package found; IPHH housing ISO and ePrivacyseal are the main published assurance artefacts. May slow enterprise security questionnaires.

Not listed
SaaS-only, closed source
Low

No self-host path. Exit requires export/API planning; multi-year usage contracts are common in this category—confirm terms on the vendor site.

Not listed
No exhaustive public subprocessor register
Low

Housing (IPHH) is named; a full live subprocessor schedule (support tooling, email, etc.) was not found as a single public table. Request under NDA/procurement if required.

Not listed
Brand/domain transition (nilly.io vs kandur.one)Not listed
Medium

Product still branded nilly, but the live marketing/API host is kandur.one; nilly.io did not resolve in DNS during research. Verify tracking domains, docs, and status before production cutover.

US SaaS on customer account pathNot listed
Medium

Stripe (payments) and Gravatar (avatars) are US-group services. Visitor metrics are claimed Swiss-hosted and non-personal, but account/billing data is not Switzerland-only end-to-end.

Thin public assurance packNot listed
Medium

No public ISO 27001/SOC 2, independent security audit, or DPA page found. Fine for many SMB shortlists; friction for regulated enterprise questionnaires.

No self-host or open-source editionNot listed
Low

Cannot run on your own infra or audit server code from a public repo. Hard limit for sovereignty programs that require self-host.

Small independent operatorNot listed
Low

Founder-owned Swiss GmbH without VC narrative—positive for independence, but buyers should assess support SLAs, roadmap continuity, and single-vendor concentration.

Fit

etracker

Best fit when

  • EU/German organisations replacing GA4 to reduce consent-mode data loss and US-linked analytics storage
  • Performance marketers needing campaign attribution plus server-side conversion upload to major ad platforms
  • E-commerce teams measuring product-to-checkout funnels, vouchers, and abandonment in one privacy-oriented SaaS
  • Agencies managing multi-account portfolios that want integrated tag and consent management without a separate CMP licence stack
  • Publishers and regulated sectors that require a German processor, Art. 28 DPA, and documented objection mechanisms

Poor fit when

  • Teams that must self-host open-source analytics with full infrastructure control (Matomo, Offen, etc.)
  • Sites that only need minimal cookieless pageviews without shop, UX, or paid-media depth
  • Procurement that requires published SOC 2 or organisation-level ISO 27001 for the analytics vendor before shortlisting
  • Buyers expecting a durable free-forever tier comparable to Google Analytics

Consider instead when

  • When: You need open-source self-host or full data-plane control on your own infrastructure

    Consider: Matomo (self-host or Matomo by Stackhero / Friendly Analytics managed)

    etracker is closed-source SaaS only

  • When: You want a lightweight EU cookieless counter without marketing suites

    Consider: Plausible Analytics, Wide Angle Analytics, or digistats Analytics

    Simpler product surface; fewer e-commerce and ad-sync features

  • When: You stay fully inside Google Ads optimisation and accept consent/US-transfer tradeoffs

    Consider: Google Analytics 4

    Deeper Google ecosystem wiring; different privacy posture

nilly

Best fit when

  • Privacy-conscious SMBs and indie sites replacing GA4 with aggregate metrics only
  • Teams that want Swiss legal entity and Swiss-located analytics servers
  • Operators running many sites who benefit from unlimited websites on traffic tiers
  • Builders who need a simple REST API for pageviews, referrers, geo, and events
  • Sites prioritizing minimal JS weight and fewer analytics consent prompts

Poor fit when

  • Organizations that must self-host or review open-source analytics code
  • Buyers needing published ISO 27001/SOC 2 or a full public DPA/subprocessor pack
  • Marketing teams requiring session replay, heatmaps, or advanced e-commerce/ad sync suites
  • Enterprises that need SSO/SCIM, formal SLAs, and large-vendor assurance paperwork as table stakes

Consider instead when

  • When: You want open-source and/or self-host privacy analytics with a larger community

    Consider: Plausible Analytics or Pirsch Analytics

    nilly is proprietary SaaS only.

  • When: You want another European cookieless SaaS with a simple product story

    Consider: Simple Analytics

    Dutch peer; compare geo depth, API, and residency claims side by side.

  • When: You need deeper marketing, shop, and tag/consent analytics for EU enterprises

    Consider: etracker

    German suite-oriented alternative; heavier than nilly's lightweight dashboard.

  • When: You depend on free unlimited scale and Google ads/ecosystem integration

    Consider: Google Analytics (GA4)

    Different privacy and residency tradeoffs; not a sovereignty shortlist.

Open questions for due diligence

etracker

  • Will procurement receive a current subprocessor list covering support, email, and any non-IPHH infrastructure?
  • Does JustRelate publish an organisation-level ISO 27001 or SOC 2 report for the analytics service (beyond IPHH housing)?
  • For your jurisdictions outside Germany, does counsel accept the cookieless legitimate-interest posture without a consent banner?
  • Which optional outbound integrations (ads conversion upload, Looker Studio, third-party tags) will you enable, and how are those transfers documented?

nilly

  • Will Lyo GmbH sign a B2B DPA and provide a current full subprocessor list (including backups, monitoring, CDN)?
  • Is analytics data retained only on Swiss hosts, or are any DR/replicas outside Switzerland?
  • What is the durable public domain for tracking scripts and API (kandur.one vs nilly.io) for the next 12 months?
  • Are there enterprise features (SSO, roles, retention controls, MSA/SLA) beyond self-serve traffic plans?
  • Can the vendor provide any independent security assessment under NDA?