fusedeck® vs Stormly

Compare fusedeck® and Stormly on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Google Analytics

Logo: fusedeck®

fusedeck®

Switzerland· Web Analytics

Needs review

Shortlist fusedeck when you need Swiss-operated cookieless-capable web analytics plus tag management and on-site activation (scoring, modals, A/B, server-side ad exports) in one SaaS. Skip when you only need lightweight pageviews (consider Plausible or Simple Analytics) or must self-host open-source analytics (consider Matomo-class tools).

Cookieless + cookie modesServer-side tag managerOn-site activationEU storage (claimed)Swiss HQSaaS (Shared/Owned)
Logo: Stormly

Stormly

Netherlands· Web Analytics

Needs review

Shortlist Stormly when you need Dutch-contracted, e-commerce-first product analytics: SKU-aware report packs, Shopify/Adobe-oriented setup, inbox-style AI anomaly narratives, and a public DPA. Skip when you need cookieless privacy web stats only (consider Plausible, Simple Analytics, or Pirsch), open-source self-hosting, verified ISO/SOC on a public cert page, or a subprocessor chain free of US-group cloud and Azure OpenAI.

E-commerce product analyticsSKU-aware reportsAI anomaly insightsShopify / Adobe CommerceNL entity + public DPASaaS (not self-host)
fusedeck® vs Stormly: Snapshot
FeatureLogo: fusedeck®fusedeck®Logo: StormlyStormly
Country of originSwitzerlandNetherlands
CategoryWeb AnalyticsWeb Analytics
Open sourceNoNo
Self-hostedNoNo
HeadquartersSwitzerlandNetherlands
Legal entityCapture Media AG (imprint); privacy policy controller listed as cptr AG — same Zurich addressMonon B.V. (Lutmastraat 1-3, 1072 JL Amsterdam; KvK 76248747 per Terms)
Governing lawSwiss data protection (FADP) for the operator; German GTC apply to cptr Germany GmbH contracts; confirm order formNetherlands (Dutch law; Amsterdam courts)
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)MediumMedium
Hosting / residencyMain storage claimed in the EU (encrypted). Public subprocessors: AWS EMEA SARL (compute), ClickHouse, Inc. (US) with data on AWS Ireland, Aiven Oy (Finland) DBaaS on AWS, VSHN AG (CH) for Kubernetes on AWS, cptr Hungary Kft. (development). Optional customer exports to Meta/LinkedIn/TikTok/Google are separate transfer paths.Client analytics subprocessors (Security Architecture): Hetzner (EU); Amazon AWS (US company, vendor states EU regions only for encrypted analytics backups); Vultr (US company); Microsoft Azure OpenAI (US company, vendor states EU Azure region). Plans market EU data residency. Controller privacy policy also references Vultr/AWS for account data, AuthSMTP EU + Amazon SES USA for email, Stripe for payments; marketing site uses Google Analytics and Hotjar.
Summary

Cookieless analytics, server-side tagging, and on-site activation from Switzerland—Track, Analyse, and Activate workflows for marketing teams leaving cookie-only stacks.

Dutch SaaS product analytics for e-commerce teams: SKU-aware reports, AI-assisted anomaly and root-cause insights, and Shopify/Adobe Commerce/Segment/GTM-oriented connections under Monon B.V. (Amsterdam).

Tags
At a glance: fusedeck® vs Stormly
At a glanceLogo: fusedeck®fusedeck®Logo: StormlyStormly
HQZurich, SwitzerlandNot listed
Legal entity (public)Capture Media AG (imprint); cptr AG (privacy controller)Not listed
Product typeCookieless analytics + activation SaaSNot listed
Hosting (public)EU storage claimed; AWS + ClickHouse on AWS IrelandHetzner; AWS EU-region backups; Vultr; Azure OpenAI EU region (vendor docs)
Open sourceNoNo
Self-hostedNo (Shared / Owned SaaS stacks)Not listed
Commercial modelPaid monthly SaaS; Shared vs Owned stacksFree tier + monthly plan + custom; trial path on paid
HQ / entityNot listedMonon B.V., Amsterdam, Netherlands
CategoryNot listedE-commerce product analytics (SaaS)
Self-hostNot listedNo
Governing lawNot listedDutch law; Amsterdam courts
Key capabilities: fusedeck® vs Stormly
Key capabilitiesLogo: fusedeck®fusedeck®Logo: StormlyStormly
Cookieless + cookie modesYesNot listed
Server-side tag managerYesNot listed
On-site activationYesNot listed
EU storage (claimed)YesNot listed
Swiss HQYesNot listed
SaaS (Shared/Owned)YesYes
E-commerce product analyticsNot listedYes
SKU-aware reportsNot listedYes
AI anomaly insightsNot listedYes
Shopify / Adobe CommerceNot listedYes
NL entity + public DPANot listedYes

fusedeck®

  • Configurable cookieless and cookie tracking modes

    Full cookie tracking, cookieless user tracking (calculated ID, no device storage), and cookieless session tracking (session-level only, no cross-session recognition) so teams can match consent posture and geo rules. Limit: legal fit of each mode still depends on your counsel and implementation—not a blanket no-consent guarantee for every event design.

  • Server-side tag manager and event control

    Define events, triggers, and selectors; gate which external tags and third parties receive data based on consent and configuration. Reduces reliance on brittle client-only pixels. Limit: marketers still need a clear data and tag taxonomy or complexity moves into fusedeck workspaces.

  • Reports, dashboards, and API exports

    Ready-made reports (behaviour, campaigns, inbound, tag manager, visitors), report builder, dashboards, share links, raw or API export, and optional Looker Studio connectivity for deeper analysis without rebuilding every KPI in a spreadsheet.

  • On-site activation: scoring, modals, A/B tests

    Score sessions, trigger call-to-action modals, run A/B tests, and inject dynamic content so analytics can drive conversion work inside the same product—not only offline reporting.

  • Server-side transfers to ad and CRM systems

    Export audiences and conversion signals server-side toward platforms such as Meta, LinkedIn, and TikTok, plus API hooks to CRM or other systems, while keeping more tag logic off the browser. Limit: those destinations introduce their own processors and transfer assessments.

  • Shared Stack vs Owned Stack infrastructure

    Shared multi-tenant cloud for standard deployments; Owned Stack with vendor-described physically separated infrastructure, white-label domain option, and higher scale for stricter security or traffic needs—still SaaS, not self-hosted open source.

Stormly

  • AI agent for trends, anomalies, and root-cause style digs

    Stormly positions an AI agent that watches connected e-commerce data for trends and anomalies (for example conversion drops or product spikes), then delivers plain-language findings—often to the inbox—with root-cause style exploration for questions like mobile conversion drops or regional return spikes. AI assistant access is plan-dependent; the public DPA documents Azure OpenAI (Microsoft) handling of assistant queries with a 30-day retention window and property stripping rules. Best for merchandising and growth leads who want narrative answers without waiting on a data team.

  • SKU-aware e-commerce report library (plus custom builds)

    Ready reports target commerce questions: New Arrivals Performance (early SKU winners/laggards), Unviewed & Unsold Products, cart abandonment and revenue contribution by product/category, Conversion Journey and funnels by device/region, A/B test insights, Aha Moment Discovery, cross-selling analysis, and broader library items (retention, CLV, forecasting, SQL report, and more). Vendor materials state custom reports are included without a separate fee when a needed view is missing—useful for mid-market retailers that outgrow generic event charts.

  • Shopify, Adobe Commerce, Segment, and GTM-oriented connections

    Homepage setup emphasizes linking Shopify, Adobe Commerce, or Segment quickly, with Google Tag Manager also listed among integrations. The DPA describes additional programmatic paths (JS library, import, custom endpoints, third-party sources). Fits stores already on common commerce stacks; teams on exotic storefronts should validate event coverage and product-feed depth in a pilot before replacing an existing analytics stack.

  • End-user tracking with IP anonymization defaults

    Per the DPA, IP addresses for end-user analytics are not stored in full: the last octet is removed and geo/timezone are derived from the anonymized value. Web integrations automatically capture first-party cookie user ids, page/referrer/UTM context, and device metadata; app properties depend on client or CDP configuration. This is still full product analytics (not cookieless aggregate-only web stats)—clients remain responsible for consent banners and lawful basis for shopper tracking.

  • Public DPA, security architecture, and Dutch contracting

    B2B buyers can download a Data Processing Agreement (effective 2023-09-06) and a Security Architecture page listing subprocessors, encryption expectations, backup retention (analytics backups up to six months), and logical tenant isolation. Contracts and DPA are governed by Dutch law with Amsterdam courts. Useful for EU procurement packages—but US-group subprocessors (AWS, Vultr, Azure OpenAI) still require transfer and CLOUD Act diligence.

Assurance & compliance: fusedeck® vs Stormly
Assurance & complianceLogo: fusedeck®fusedeck®Logo: StormlyStormly
Independent security / no-logs audit
Not found

TOMs and legal opinions on cookieless tracking exist; no independent third-party security audit PDF found on primary trust pages.

Not found

Security Architecture describes encryption, monitoring, isolation, and vulnerability contact (security@stormly.com); no public third-party audit PDF found.

ISO 27001
Not found

No public ISO 27001 certificate located on imprint, privacy, TOM, or subprocessor pages.

Not found

No public ISO 27001 certificate located on official legal/security pages reviewed.

SOC 2 / SOC 3
Not found

No SOC 2/3 report referenced on primary trust pages.

Not found

No public SOC 2/3 report located on official pages reviewed.

GDPR / EU data protection
Vendor claimed

Swiss operator; product data-privacy page claims GDPR/ePrivacy-configurable setups; privacy policy cites FADP and GDPR legal bases. Confirm DPA and configuration for your properties.

Vendor claimed

NL entity; public privacy policy and DPA (GDPR-oriented); IP last-octet anonymization for end-user analytics; SCCs language for restricted transfers in DPA.

US CLOUD Act exposure (indicative)
Partial

Swiss entity / no known US parent, but public subprocessors include AWS and ClickHouse, Inc. (US) with EU residency claims. Indicative medium exposure—not a clean bill of health and not legal advice.

Partial

EU entity / no known US parent, but public client subprocessors include AWS, Vultr, and Microsoft Azure OpenAI (US-group companies). Account path historically also lists Amazon SES and Stripe. Residency claims do not remove US-group legal exposure. Indicative only—not legal advice.

Data processing agreement (B2B)
Vendor claimed

German GTC state processing under an Auftragsverarbeitung with customer as controller and cptr as processor. Obtain the signed DPA + annex for your contracting entity.

Vendor claimed

Downloadable DPA PDF linked from stormly.com/dpa (effective 6 September 2023); audit rights and subprocessor notice described; Security Architecture lists subprocessors.

EU AI Act
Not applicable

Web analytics / marketing activation product; not positioned as an AI system under public materials.

Partial

Product includes an AI assistant via Azure OpenAI; not positioned as a high-risk AI system marketing claim. Buyers should map AI assistant use to their own AI Act / internal AI policy—vendor does not publish a full AI Act conformity package on the pages reviewed.

Considerations & known limitations: fusedeck® vs Stormly
Considerations & known limitationsLogo: fusedeck®fusedeck®Logo: StormlyStormly
AWS and US-domiciled database subprocessor
Medium

Despite Swiss HQ and EU storage claims, compute and DB path use AWS and ClickHouse, Inc. (US company, data on AWS Ireland). Policies that ban US-group cloud providers entirely may fail even if data residency is EU.

Medium

Despite Dutch HQ and EU residency marketing, client data paths publicly include AWS, Vultr, and Microsoft Azure OpenAI. Transfer tooling (SCCs) and encryption of backups are documented, but CLOUD Act / US legal process risk remains a diligence item for sovereignty-sensitive buyers.

Capture Media AG vs cptr AG naming
Low

Imprint still lists Capture Media AG while the privacy policy names cptr AG as controller. Confirm the exact contracting party, invoice entity, and DPA counterparty on the order form.

Not listed
No public independent security audit or ISO/SOC
Medium

TOMs are published, but we found no independent audit report or ISO 27001 / SOC 2 certificate. Security questionnaires and NDA materials may still be required for enterprise purchase.

Not listed
Cookieless modes are not automatic legal clearance
Medium

Cookieless session tracking is positioned for compliance without consent, but full cookie and cookieless user modes, identity features, and ad-platform exports can reintroduce consent and transfer questions. Legal review of your event design remains mandatory.

Not listed
No classical self-host option
Low

Owned Stack is dedicated vendor-operated cloud, not buyer-operated self-hosting. Air-gapped or fully on-prem mandates need another product.

Not listed
No public ISO/SOC or independent auditNot listed
Medium

Enterprise security questionnaires may stall without ISO 27001/SOC 2 packs. DPA offers information/audit rights—plan time for NDA evidence requests.

Azure OpenAI retains assistant context 30 daysNot listed
Medium

AI queries and aggregate report results are stored on Microsoft Azure OpenAI for 30 days per DPA. Property stripping reduces some identifiers, but misconfigured event properties could still expose sensitive content—govern AI use and property hygiene.

Controller privacy policy vs security architecture driftNot listed
Low

Privacy policy (controller, effective 2019) still emphasizes Vultr USA wording in places, while Security Architecture (client data) lists Hetzner/AWS/Vultr/Azure. Ask for a single current subprocessor and region matrix at contract time.

Not a privacy web-analytics substituteNot listed
Low

Full product analytics with cookies/identifiers for web integrations—not a cookieless aggregate counter. Consent UX remains on the client.

Fit

fusedeck®

Best fit when

  • Marketing ops teams that want Track + Analyse + Activate in one stack, not only traffic charts
  • Organisations replacing or supplementing GA4 with cookieless-capable, consent-flexible collection modes
  • Teams that need server-side control over which third-party tags and ad platforms receive data
  • Buyers who want Swiss contracting and public EU hosting claims, and can accept AWS-based SaaS
  • Sites that benefit from scoring, modals, A/B tests, or server-side Meta/LinkedIn/TikTok transfers

Poor fit when

  • Teams that only need simple privacy-first pageview analytics without activation tooling
  • Requirements for open-source or classical self-hosted analytics under buyer-operated infrastructure
  • Procurement policies that forbid US-group cloud subprocessors (AWS / US-domiciled database vendors) entirely
  • Buyers seeking a free production tier or purely DIY setup without commercial SaaS onboarding

Consider instead when

  • When: You only need lightweight, privacy-oriented traffic metrics

    Consider: Plausible Analytics, Simple Analytics, or Friendly Analytics

    Smaller surface area; little or no activation / ad-export stack

  • When: You must self-host or prefer open-source analytics under your operators

    Consider: Matomo-class deployments or Piwik PRO where self-host/on-prem options fit

    fusedeck is SaaS Shared/Owned stack, not a public self-host product

  • When: You need global free-tier depth and Google ecosystem defaults

    Consider: Google Analytics

    Different jurisdiction and subprocessor story; still the default for many teams

  • When: You want a German enterprise analytics brand with strong packaging options

    Consider: etracker or Piwik PRO

    Compare residency, consent tooling, and activation depth side by side

Stormly

Best fit when

  • Merchandising, product, UX, and growth teams on Shopify or Adobe Commerce who need SKU, cart, and assortment analytics without a dedicated data science org
  • Retail brands that want ready e-commerce report templates (new arrivals, unviewed/unsold, funnels, A/B, aha moments) plus vendor-built custom reports
  • EU buyers who want a Dutch legal entity, Amsterdam courts, and a downloadable DPA/Security Architecture package
  • Teams that value AI-generated trend/anomaly narratives delivered to the inbox more than building every chart from a blank event schema
  • Stacks already using Segment or Google Tag Manager as the event pipe into analytics

Poor fit when

  • Publishers or marketing sites that only need lightweight privacy-friendly page analytics (not product/SKU depth)
  • Orgs that require open-source self-hosting or full control of a private analytics warehouse as the default
  • Procurement policies that forbid US-group subprocessors (AWS, Vultr, Microsoft Azure OpenAI) even when EU regions are claimed
  • Assurance programs that require public ISO 27001/SOC 2 evidence before pilot (not found on vendor pages reviewed)
  • Companies operating blockchain products/services—restricted by Stormly’s terms

Consider instead when

  • When: You only need privacy-oriented website metrics (pageviews, sources) rather than SKU-level product analytics

    Consider: Plausible Analytics, Simple Analytics, or Pirsch Analytics

    EU web-analytics peers; different category from e-commerce product analytics

  • When: You need deep general-purpose product analytics, large ecosystem, and mature multi-product SaaS event modeling

    Consider: Mixpanel or Amplitude

    US incumbents; stronger breadth, different jurisdiction and commercial model

  • When: You primarily need free/universal marketing acquisition reporting already embedded in the stack

    Consider: Google Analytics (incumbent) or dual-run GA for marketing + Stormly for product/merch

    GA is not SKU-first product analytics; Stormly is not a GA replacement for every report

Open questions for due diligence

fusedeck®

  • Which legal entity will appear on the contract and DPA for our region (Capture Media AG, cptr AG, cptr Germany GmbH, or another affiliate)?
  • Can the vendor provide the current subprocessor annex, SCCs if any, and confirmation of all AWS regions used for our data?
  • Is an independent security audit, pen-test summary, or ISO/SOC roadmap available under NDA?
  • Which tracking mode and event schema does fusedeck recommend for our CMP and target markets, and what remains after ad-blocker impact?
  • What are Shared vs Owned stack operational differences (isolation, custom domain, support SLAs) for our traffic volume?

Stormly

  • Can Stormly provide a current region map (which data classes live on Hetzner vs Vultr vs AWS) under NDA for our DPIA?
  • Are ISO 27001, SOC 2, or penetration-test summaries available on request for enterprise security review?
  • Which event properties from our Shopify/Adobe feed are excluded from Azure OpenAI prompts by default in our tenant?
  • Do custom report builds and SQL access sit only on the custom tier, and what SLAs apply?
  • Has the 2019 controller privacy policy been superseded for hosting wording relative to the Security Architecture list?