nilly vs Stormly

Compare nilly and Stormly on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Google Analytics

Logo: nilly

nilly

Switzerland· Web Analytics

Needs review

Shortlist nilly when you want Swiss-entity, cookieless, ultra-light site analytics with realtime dashboards, city geo, custom events, unlimited sites, and an API—without GA4 consent weight. Skip when you need self-host/open source, enterprise audit packs, or deep marketing-suite analytics; consider Plausible Analytics, Simple Analytics, or etracker instead.

Cookieless trackingSwiss-hosted (claimed)Swiss entitySub-1 kB scriptREST APISaaS only
Logo: Stormly

Stormly

Netherlands· Web Analytics

Needs review

Shortlist Stormly when you need Dutch-contracted, e-commerce-first product analytics: SKU-aware report packs, Shopify/Adobe-oriented setup, inbox-style AI anomaly narratives, and a public DPA. Skip when you need cookieless privacy web stats only (consider Plausible, Simple Analytics, or Pirsch), open-source self-hosting, verified ISO/SOC on a public cert page, or a subprocessor chain free of US-group cloud and Azure OpenAI.

E-commerce product analyticsSKU-aware reportsAI anomaly insightsShopify / Adobe CommerceNL entity + public DPASaaS (not self-host)
nilly vs Stormly: Snapshot
FeatureLogo: nillynillyLogo: StormlyStormly
Country of originSwitzerlandNetherlands
CategoryWeb AnalyticsWeb Analytics
Open sourceNoNo
Self-hostedNoNo
HeadquartersSwitzerlandNetherlands
Legal entityLyo GmbH, Europaallee 41, 8004 Zürich (CHE-417.675.763)Monon B.V. (Lutmastraat 1-3, 1072 JL Amsterdam; KvK 76248747 per Terms)
Governing lawSwitzerland (terms)Netherlands (Dutch law; Amsterdam courts)
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)MediumMedium
Hosting / residencyVendor FAQ: analytics servers in Switzerland (multiple locations). Public site reverse-DNS: KreativMedia/METANET Zürich. Customer-account subprocessors named in privacy policy: Stripe (US payments), Mailerlite (email). Avatars via Gravatar. No full public subprocessor list for backups/monitoring/CDN.Client analytics subprocessors (Security Architecture): Hetzner (EU); Amazon AWS (US company, vendor states EU regions only for encrypted analytics backups); Vultr (US company); Microsoft Azure OpenAI (US company, vendor states EU Azure region). Plans market EU data residency. Controller privacy policy also references Vultr/AWS for account data, AuthSMTP EU + Amazon SES USA for email, Stripe for payments; marketing site uses Google Analytics and Hotjar.
Summary

Swiss privacy-first web analytics (Lyo GmbH): cookieless, sub-1kB tracking with realtime dashboards, city-level geo, custom events, unlimited sites, and a REST API as a lightweight Google Analytics alternative.

Dutch SaaS product analytics for e-commerce teams: SKU-aware reports, AI-assisted anomaly and root-cause insights, and Shopify/Adobe Commerce/Segment/GTM-oriented connections under Monon B.V. (Amsterdam).

Tags
At a glance: nilly vs Stormly
At a glanceLogo: nillynillyLogo: StormlyStormly
HQZürich, Switzerland (Lyo GmbH)Not listed
Legal entityLyo GmbH (CHE-417.675.763)Not listed
Product modelSaaS web analytics (not self-hosted)Not listed
TrackingCookieless; no IP/fingerprint claimsNot listed
Hosting (claimed)Switzerland (multi-site)Not listed
Commercial modelTraffic-based plans; trial; no permanent free tierFree tier + monthly plan + custom; trial path on paid
Live site notekandur.one (nilly branding; nilly.io DNS failed at research)Not listed
HQ / entityNot listedMonon B.V., Amsterdam, Netherlands
CategoryNot listedE-commerce product analytics (SaaS)
Hosting (public)Not listedHetzner; AWS EU-region backups; Vultr; Azure OpenAI EU region (vendor docs)
Open sourceNot listedNo
Self-hostNot listedNo
Governing lawNot listedDutch law; Amsterdam courts
Key capabilities: nilly vs Stormly
Key capabilitiesLogo: nillynillyLogo: StormlyStormly
Cookieless trackingYesNot listed
Swiss-hosted (claimed)YesNot listed
Swiss entityYesNot listed
Sub-1 kB scriptYesNot listed
REST APIYesNot listed
SaaS onlyYesYes
E-commerce product analyticsNot listedYes
SKU-aware reportsNot listedYes
AI anomaly insightsNot listedYes
Shopify / Adobe CommerceNot listedYes
NL entity + public DPANot listedYes

nilly

  • Sub-1 kB cookieless tracking script

    Vendor documents a client script under 1 kB with no cookies, no IP tracking, and no fingerprinting for site visitors. Suited to teams that want aggregate traffic metrics without analytics cookie banners; still get counsel for your jurisdiction and CMP setup.

  • Realtime dashboard with geo, tech, and campaigns

    Dashboards cover live visitors, overview metrics, top pages, referrers, UTM campaigns, geography from continent to city, and device/browser/OS breakdowns—enough for content and acquisition decisions without a full product-analytics suite.

  • Custom events, CSV export, and email reports

    Define custom events for conversion-style actions, export statistics as CSV, and receive email reports. Fits operators who need lightweight conversion signals and offline analysis rather than session replay or multi-step funnels.

  • REST API for stats, websites, and account

    Documented API endpoints (Bearer API key) manage stats queries (pageviews, visitors, referrers, events, geo, devices, and more), websites, and account objects—useful for internal dashboards or automations on traffic-based plans that include API access.

  • Unlimited websites on traffic-based plans

    Public pricing model is pageview-tier SaaS with unlimited websites per account and a short free trial—not a permanent free tier. Good for agencies or multi-brand operators who outgrow per-site free plans elsewhere; confirm current tiers on the vendor site.

Stormly

  • AI agent for trends, anomalies, and root-cause style digs

    Stormly positions an AI agent that watches connected e-commerce data for trends and anomalies (for example conversion drops or product spikes), then delivers plain-language findings—often to the inbox—with root-cause style exploration for questions like mobile conversion drops or regional return spikes. AI assistant access is plan-dependent; the public DPA documents Azure OpenAI (Microsoft) handling of assistant queries with a 30-day retention window and property stripping rules. Best for merchandising and growth leads who want narrative answers without waiting on a data team.

  • SKU-aware e-commerce report library (plus custom builds)

    Ready reports target commerce questions: New Arrivals Performance (early SKU winners/laggards), Unviewed & Unsold Products, cart abandonment and revenue contribution by product/category, Conversion Journey and funnels by device/region, A/B test insights, Aha Moment Discovery, cross-selling analysis, and broader library items (retention, CLV, forecasting, SQL report, and more). Vendor materials state custom reports are included without a separate fee when a needed view is missing—useful for mid-market retailers that outgrow generic event charts.

  • Shopify, Adobe Commerce, Segment, and GTM-oriented connections

    Homepage setup emphasizes linking Shopify, Adobe Commerce, or Segment quickly, with Google Tag Manager also listed among integrations. The DPA describes additional programmatic paths (JS library, import, custom endpoints, third-party sources). Fits stores already on common commerce stacks; teams on exotic storefronts should validate event coverage and product-feed depth in a pilot before replacing an existing analytics stack.

  • End-user tracking with IP anonymization defaults

    Per the DPA, IP addresses for end-user analytics are not stored in full: the last octet is removed and geo/timezone are derived from the anonymized value. Web integrations automatically capture first-party cookie user ids, page/referrer/UTM context, and device metadata; app properties depend on client or CDP configuration. This is still full product analytics (not cookieless aggregate-only web stats)—clients remain responsible for consent banners and lawful basis for shopper tracking.

  • Public DPA, security architecture, and Dutch contracting

    B2B buyers can download a Data Processing Agreement (effective 2023-09-06) and a Security Architecture page listing subprocessors, encryption expectations, backup retention (analytics backups up to six months), and logical tenant isolation. Contracts and DPA are governed by Dutch law with Amsterdam courts. Useful for EU procurement packages—but US-group subprocessors (AWS, Vultr, Azure OpenAI) still require transfer and CLOUD Act diligence.

Assurance & compliance: nilly vs Stormly
Assurance & complianceLogo: nillynillyLogo: StormlyStormly
Independent security / no-logs audit
Not found

No public third-party audit report found for tracking claims.

Not found

Security Architecture describes encryption, monitoring, isolation, and vulnerability contact (security@stormly.com); no public third-party audit PDF found.

ISO 27001
Not found

No vendor ISO 27001 certificate published on product site (underlying Swiss host DCs may be certified separately).

Not found

No public ISO 27001 certificate located on official legal/security pages reviewed.

SOC 2 / SOC 3
Not found
Not found

No public SOC 2/3 report located on official pages reviewed.

GDPR / EU data protection
Vendor claimed

Swiss entity; privacy policy includes GDPR rights language; cookieless visitor tracking claimed. Confirm DPA for B2B.

Vendor claimed

NL entity; public privacy policy and DPA (GDPR-oriented); IP last-octet anonymization for end-user analytics; SCCs language for restricted transfers in DPA.

US CLOUD Act exposure (indicative)
Partial

Swiss operator, no known US parent, Swiss-claimed analytics hosting; US SaaS subprocessors Stripe (payments) and Gravatar (avatars) on customer path. Not legal advice.

Partial

EU entity / no known US parent, but public client subprocessors include AWS, Vultr, and Microsoft Azure OpenAI (US-group companies). Account path historically also lists Amazon SES and Stripe. Residency claims do not remove US-group legal exposure. Indicative only—not legal advice.

Data processing agreement (B2B)
Not found

No public DPA download found; request from vendor.

Vendor claimed

Downloadable DPA PDF linked from stormly.com/dpa (effective 6 September 2023); audit rights and subprocessor notice described; Security Architecture lists subprocessors.

EU AI Act
Not applicable

Web analytics product; not marketed as an AI system.

Partial

Product includes an AI assistant via Azure OpenAI; not positioned as a high-risk AI system marketing claim. Buyers should map AI assistant use to their own AI Act / internal AI policy—vendor does not publish a full AI Act conformity package on the pages reviewed.

Swiss Made Software / Swiss Web labels
Vendor claimed

Cited on About and Swiss Union member page as recognition/labels—not a security audit.

Not listed
Considerations & known limitations: nilly vs Stormly
Considerations & known limitationsLogo: nillynillyLogo: StormlyStormly
Brand/domain transition (nilly.io vs kandur.one)
Medium

Product still branded nilly, but the live marketing/API host is kandur.one; nilly.io did not resolve in DNS during research. Verify tracking domains, docs, and status before production cutover.

Not listed
US SaaS on customer account path
Medium

Stripe (payments) and Gravatar (avatars) are US-group services. Visitor metrics are claimed Swiss-hosted and non-personal, but account/billing data is not Switzerland-only end-to-end.

Not listed
Thin public assurance pack
Medium

No public ISO 27001/SOC 2, independent security audit, or DPA page found. Fine for many SMB shortlists; friction for regulated enterprise questionnaires.

Not listed
No self-host or open-source edition
Low

Cannot run on your own infra or audit server code from a public repo. Hard limit for sovereignty programs that require self-host.

Not listed
Small independent operator
Low

Founder-owned Swiss GmbH without VC narrative—positive for independence, but buyers should assess support SLAs, roadmap continuity, and single-vendor concentration.

Not listed
US-group cloud and AI subprocessorsNot listed
Medium

Despite Dutch HQ and EU residency marketing, client data paths publicly include AWS, Vultr, and Microsoft Azure OpenAI. Transfer tooling (SCCs) and encryption of backups are documented, but CLOUD Act / US legal process risk remains a diligence item for sovereignty-sensitive buyers.

No public ISO/SOC or independent auditNot listed
Medium

Enterprise security questionnaires may stall without ISO 27001/SOC 2 packs. DPA offers information/audit rights—plan time for NDA evidence requests.

Azure OpenAI retains assistant context 30 daysNot listed
Medium

AI queries and aggregate report results are stored on Microsoft Azure OpenAI for 30 days per DPA. Property stripping reduces some identifiers, but misconfigured event properties could still expose sensitive content—govern AI use and property hygiene.

Controller privacy policy vs security architecture driftNot listed
Low

Privacy policy (controller, effective 2019) still emphasizes Vultr USA wording in places, while Security Architecture (client data) lists Hetzner/AWS/Vultr/Azure. Ask for a single current subprocessor and region matrix at contract time.

Not a privacy web-analytics substituteNot listed
Low

Full product analytics with cookies/identifiers for web integrations—not a cookieless aggregate counter. Consent UX remains on the client.

Fit

nilly

Best fit when

  • Privacy-conscious SMBs and indie sites replacing GA4 with aggregate metrics only
  • Teams that want Swiss legal entity and Swiss-located analytics servers
  • Operators running many sites who benefit from unlimited websites on traffic tiers
  • Builders who need a simple REST API for pageviews, referrers, geo, and events
  • Sites prioritizing minimal JS weight and fewer analytics consent prompts

Poor fit when

  • Organizations that must self-host or review open-source analytics code
  • Buyers needing published ISO 27001/SOC 2 or a full public DPA/subprocessor pack
  • Marketing teams requiring session replay, heatmaps, or advanced e-commerce/ad sync suites
  • Enterprises that need SSO/SCIM, formal SLAs, and large-vendor assurance paperwork as table stakes

Consider instead when

  • When: You want open-source and/or self-host privacy analytics with a larger community

    Consider: Plausible Analytics or Pirsch Analytics

    nilly is proprietary SaaS only.

  • When: You want another European cookieless SaaS with a simple product story

    Consider: Simple Analytics

    Dutch peer; compare geo depth, API, and residency claims side by side.

  • When: You need deeper marketing, shop, and tag/consent analytics for EU enterprises

    Consider: etracker

    German suite-oriented alternative; heavier than nilly's lightweight dashboard.

  • When: You depend on free unlimited scale and Google ads/ecosystem integration

    Consider: Google Analytics (GA4)

    Different privacy and residency tradeoffs; not a sovereignty shortlist.

Stormly

Best fit when

  • Merchandising, product, UX, and growth teams on Shopify or Adobe Commerce who need SKU, cart, and assortment analytics without a dedicated data science org
  • Retail brands that want ready e-commerce report templates (new arrivals, unviewed/unsold, funnels, A/B, aha moments) plus vendor-built custom reports
  • EU buyers who want a Dutch legal entity, Amsterdam courts, and a downloadable DPA/Security Architecture package
  • Teams that value AI-generated trend/anomaly narratives delivered to the inbox more than building every chart from a blank event schema
  • Stacks already using Segment or Google Tag Manager as the event pipe into analytics

Poor fit when

  • Publishers or marketing sites that only need lightweight privacy-friendly page analytics (not product/SKU depth)
  • Orgs that require open-source self-hosting or full control of a private analytics warehouse as the default
  • Procurement policies that forbid US-group subprocessors (AWS, Vultr, Microsoft Azure OpenAI) even when EU regions are claimed
  • Assurance programs that require public ISO 27001/SOC 2 evidence before pilot (not found on vendor pages reviewed)
  • Companies operating blockchain products/services—restricted by Stormly’s terms

Consider instead when

  • When: You only need privacy-oriented website metrics (pageviews, sources) rather than SKU-level product analytics

    Consider: Plausible Analytics, Simple Analytics, or Pirsch Analytics

    EU web-analytics peers; different category from e-commerce product analytics

  • When: You need deep general-purpose product analytics, large ecosystem, and mature multi-product SaaS event modeling

    Consider: Mixpanel or Amplitude

    US incumbents; stronger breadth, different jurisdiction and commercial model

  • When: You primarily need free/universal marketing acquisition reporting already embedded in the stack

    Consider: Google Analytics (incumbent) or dual-run GA for marketing + Stormly for product/merch

    GA is not SKU-first product analytics; Stormly is not a GA replacement for every report

Open questions for due diligence

nilly

  • Will Lyo GmbH sign a B2B DPA and provide a current full subprocessor list (including backups, monitoring, CDN)?
  • Is analytics data retained only on Swiss hosts, or are any DR/replicas outside Switzerland?
  • What is the durable public domain for tracking scripts and API (kandur.one vs nilly.io) for the next 12 months?
  • Are there enterprise features (SSO, roles, retention controls, MSA/SLA) beyond self-serve traffic plans?
  • Can the vendor provide any independent security assessment under NDA?

Stormly

  • Can Stormly provide a current region map (which data classes live on Hetzner vs Vultr vs AWS) under NDA for our DPIA?
  • Are ISO 27001, SOC 2, or penetration-test summaries available on request for enterprise security review?
  • Which event properties from our Shopify/Adobe feed are excluded from Azure OpenAI prompts by default in our tenant?
  • Do custom report builds and SQL access sit only on the custom tier, and what SLAs apply?
  • Has the 2019 controller privacy policy been superseded for hosting wording relative to the Security Architecture list?