nilly vs Vantevo Analytics

Compare nilly and Vantevo Analytics on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Fathom Analytics, Google Analytics

Logo: nilly

nilly

Switzerland· Web Analytics

Needs review

Shortlist nilly when you want Swiss-entity, cookieless, ultra-light site analytics with realtime dashboards, city geo, custom events, unlimited sites, and an API—without GA4 consent weight. Skip when you need self-host/open source, enterprise audit packs, or deep marketing-suite analytics; consider Plausible Analytics, Simple Analytics, or etracker instead.

Cookieless trackingSwiss-hosted (claimed)Swiss entitySub-1 kB scriptREST APISaaS only
Logo: Vantevo Analytics

Vantevo Analytics

Italy· Web Analytics

Needs review

Shortlist Vantevo when you want Italian-operated, cookie-less site analytics with a flat dashboard, goals/events, optional GA historical import, and beta ecommerce funnel events under a public DPA. Skip when you need multi-day returning-visitor identity, self-hosting/open source, or enterprise-grade public certifications—consider Plausible/Simple Analytics/Pirsch for lighter peers, or Piwik PRO for self-host/compliance-heavy programs.

Cookie-less trackingSingle-dashboard metricsEcommerce events (beta)GA history importPublic DPAItalian operator
nilly vs Vantevo Analytics: Snapshot
FeatureLogo: nillynillyLogo: Vantevo AnalyticsVantevo Analytics
Country of originSwitzerlandItaly
CategoryWeb AnalyticsWeb Analytics
Open sourceNoNo
Self-hostedNoNo
HeadquartersSwitzerlandItaly
Legal entityLyo GmbH, Europaallee 41, 8004 Zürich (CHE-417.675.763)Netforce Srl, Via Po' 136/A, 43124 Parma PR, Italy
Governing lawSwitzerland (terms)Italian law (controller established in Italy; Terms governed by place of establishment)
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)MediumMedium
Hosting / residencyVendor FAQ: analytics servers in Switzerland (multiple locations). Public site reverse-DNS: KreativMedia/METANET Zürich. Customer-account subprocessors named in privacy policy: Stripe (US payments), Mailerlite (email). Avatars via Gravatar. No full public subprocessor list for backups/monitoring/CDN.Vendor claims EU servers and EU backups. Public DPA names OVH Datacenter Roubaix and an AWS datacenter for storage/processing. Additional third parties: Stripe (payments), Crisp (support chat), optional Google Analytics and Search Console APIs when customers connect them.
Summary

Swiss privacy-first web analytics (Lyo GmbH): cookieless, sub-1kB tracking with realtime dashboards, city-level geo, custom events, unlimited sites, and a REST API as a lightweight Google Analytics alternative.

Italian cookie-less web analytics from Netforce Srl (Parma): single-dashboard traffic, events, goals, and ecommerce funnels with EU processing claims and a public DPA.

Tags
At a glance: nilly vs Vantevo Analytics
At a glanceLogo: nillynillyLogo: Vantevo AnalyticsVantevo Analytics
HQZürich, Switzerland (Lyo GmbH)Parma, Italy (Netforce Srl)
Legal entityLyo GmbH (CHE-417.675.763)Not listed
Product modelSaaS web analytics (not self-hosted)Not listed
TrackingCookieless; no IP/fingerprint claimsNot listed
Hosting (claimed)Switzerland (multi-site)Not listed
Commercial modelTraffic-based plans; trial; no permanent free tierView-based subscription after free trial
Live site notekandur.one (nilly branding; nilly.io DNS failed at research)Not listed
Product typeNot listedCookie-less web analytics SaaS
Self-host / OSSNot listedNo (SaaS only; not open source)
Hosting (public DPA)Not listedOVH Roubaix + AWS datacenter; EU processing claims
Notable limitNot listedNo multi-day returning visitors; max 50 sites/account (Terms)
Key capabilities: nilly vs Vantevo Analytics
Key capabilitiesLogo: nillynillyLogo: Vantevo AnalyticsVantevo Analytics
Cookieless trackingYesNot listed
Swiss-hosted (claimed)YesNot listed
Swiss entityYesNot listed
Sub-1 kB scriptYesNot listed
REST APIYesNot listed
SaaS onlyYesNot listed
Cookie-less trackingNot listedYes
Single-dashboard metricsNot listedYes
Ecommerce events (beta)Not listedYes
GA history importNot listedYes
Public DPANot listedYes
Italian operatorNot listedYes

nilly

  • Sub-1 kB cookieless tracking script

    Vendor documents a client script under 1 kB with no cookies, no IP tracking, and no fingerprinting for site visitors. Suited to teams that want aggregate traffic metrics without analytics cookie banners; still get counsel for your jurisdiction and CMP setup.

  • Realtime dashboard with geo, tech, and campaigns

    Dashboards cover live visitors, overview metrics, top pages, referrers, UTM campaigns, geography from continent to city, and device/browser/OS breakdowns—enough for content and acquisition decisions without a full product-analytics suite.

  • Custom events, CSV export, and email reports

    Define custom events for conversion-style actions, export statistics as CSV, and receive email reports. Fits operators who need lightweight conversion signals and offline analysis rather than session replay or multi-step funnels.

  • REST API for stats, websites, and account

    Documented API endpoints (Bearer API key) manage stats queries (pageviews, visitors, referrers, events, geo, devices, and more), websites, and account objects—useful for internal dashboards or automations on traffic-based plans that include API access.

  • Unlimited websites on traffic-based plans

    Public pricing model is pageview-tier SaaS with unlimited websites per account and a short free trial—not a permanent free tier. Good for agencies or multi-brand operators who outgrow per-site free plans elsewhere; confirm current tiers on the vendor site.

Vantevo Analytics

  • Daily-rotating hash visitor counting (no analytics cookies)

    Visitor uniqueness for a day is derived from HASH(salt + domain + IP + User-Agent) with a salt that rotates every 24 hours; IP and User-Agent are not retained after hashing, per the DPA and docs. No cookies, localStorage, or browser cache for the analytics session—and therefore no multi-day new/returning visitor split. Fits privacy-led sites that prioritize aggregate trends over identity graphs.

  • Single-page traffic dashboard

    Unique visitors, sessions, page views, bounce rate, duration, entry/exit pages, geography, devices, languages, referrals, and UTM campaigns appear on one overview without multi-level custom report builders. Aimed at agencies and SMEs that want operational metrics without a full-time analytics specialist.

  • Custom events, goals, and automatic link/download tracking

    Track button clicks, scrolls, form submits, custom event names with metadata, and conversion goals; outbound links and file downloads can be auto-captured with HTML attributes to exclude specific URLs. Useful for content and lead-gen sites measuring meaningful actions without cookie tags.

  • Ecommerce funnel events (beta script)

    Optional vantevo-ecommerce.js records wishlist, view item, cart add/remove, checkout stages, payment type, coupons, variants/categories, and purchase—docs mark the ecommerce section as still in beta. Best for shops that need privacy-oriented funnel visibility and can accept beta maturity.

  • Universal Analytics import and multi-platform install paths

    Connect Google Analytics to import page statistics from January 2018 onward into the same calendar view (with documented metric gaps and API limits). Ship via head script, WordPress plugin, React/Vue/npm packages, Shopify/Wix theme paste, hybrid apps, or server-side event APIs—plus optional Search Console connection for keyword/impression views.

Assurance & compliance: nilly vs Vantevo Analytics
Assurance & complianceLogo: nillynillyLogo: Vantevo AnalyticsVantevo Analytics
Independent security / no-logs audit
Not found

No public third-party audit report found for tracking claims.

Not found

No public third-party audit PDF or no-logs attestation found on security/docs pages searched.

ISO 27001
Not found

No vendor ISO 27001 certificate published on product site (underlying Swiss host DCs may be certified separately).

Not found

No ISO 27001 certificate or registry evidence found on the public site.

SOC 2 / SOC 3
Not found
Not found

No SOC 2/3 report referenced on public trust/legal pages.

GDPR / EU data protection
Vendor claimed

Swiss entity; privacy policy includes GDPR rights language; cookieless visitor tracking claimed. Confirm DPA for B2B.

Vendor claimed

Italian controller (Netforce Srl); cookie-less visitor model and EU hosting asserted on docs/GDPR pages; public DPA available. Vendor “100% GDPR compliant” wording is a claim, not independent legal certification.

US CLOUD Act exposure (indicative)
Partial

Swiss operator, no known US parent, Swiss-claimed analytics hosting; US SaaS subprocessors Stripe (payments) and Gravatar (avatars) on customer path. Not legal advice.

Partial

EU entity / no known US parent, but DPA lists AWS alongside OVH Roubaix; Stripe and optional Google APIs are US-group services. Not a clean EU-only infrastructure story. Not legal advice.

Data processing agreement (B2B)
Not found

No public DPA download found; request from vendor.

Vendor claimed

Public DPA at vantevo.io/dpa; Terms state DPA forms part of the main agreement (customer controller, Netforce processor).

EU AI Act
Not applicable

Web analytics product; not marketed as an AI system.

Not applicable

Web analytics SaaS; not marketed as an AI system product.

Swiss Made Software / Swiss Web labels
Vendor claimed

Cited on About and Swiss Union member page as recognition/labels—not a security audit.

Not listed
Considerations & known limitations: nilly vs Vantevo Analytics
Considerations & known limitationsLogo: nillynillyLogo: Vantevo AnalyticsVantevo Analytics
Brand/domain transition (nilly.io vs kandur.one)
Medium

Product still branded nilly, but the live marketing/API host is kandur.one; nilly.io did not resolve in DNS during research. Verify tracking domains, docs, and status before production cutover.

Not listed
US SaaS on customer account path
Medium

Stripe (payments) and Gravatar (avatars) are US-group services. Visitor metrics are claimed Swiss-hosted and non-personal, but account/billing data is not Switzerland-only end-to-end.

Not listed
Thin public assurance pack
Medium

No public ISO 27001/SOC 2, independent security audit, or DPA page found. Fine for many SMB shortlists; friction for regulated enterprise questionnaires.

Not listed
No self-host or open-source edition
Low

Cannot run on your own infra or audit server code from a public repo. Hard limit for sovereignty programs that require self-host.

Low

No public self-host option. Continuity depends on Netforce operations, OVH/AWS, and export/delete workflows (JSON/CSV return or delete timelines in DPA/Terms).

Small independent operator
Low

Founder-owned Swiss GmbH without VC narrative—positive for independence, but buyers should assess support SLAs, roadmap continuity, and single-vendor concentration.

Not listed
AWS (and other US-group services) in data pathNot listed
Medium

Despite Italian HQ and EU hosting marketing, the DPA explicitly stores data at OVH Roubaix and an AWS datacenter. Stripe payments and optional Google integrations add further US-group processors. Organizations with strict “no US cloud” policies need written clarification of regions, SCCs, and residual access risk.

No public ISO/SOC or independent auditNot listed
Medium

Shortlisting relies on vendor security measures described in the DPA (encryption, backups, breach notification windows) without published certs or third-party audit reports. Security questionnaires and NDA evidence may be required for regulated buyers.

No multi-day visitor identity by designNot listed
Low

Daily salt rotation and cookie-less design prevent classic returning-visitor and cross-device analysis. This is a privacy feature for many buyers and a hard product limit for others.

Ecommerce module still betaNot listed
Medium

Official ecommerce docs mark the section as beta/incomplete for final publication. Do not assume GA ecommerce parity or long-term event stability without a pilot.

View overage and website caps in TermsNot listed
Low

Recording can pause after plan-specific overage tolerances; Terms also set a 50-website maximum per account. Align marketing “unlimited domains” language with contract terms before large agency rollouts.

Fit

nilly

Best fit when

  • Privacy-conscious SMBs and indie sites replacing GA4 with aggregate metrics only
  • Teams that want Swiss legal entity and Swiss-located analytics servers
  • Operators running many sites who benefit from unlimited websites on traffic tiers
  • Builders who need a simple REST API for pageviews, referrers, geo, and events
  • Sites prioritizing minimal JS weight and fewer analytics consent prompts

Poor fit when

  • Organizations that must self-host or review open-source analytics code
  • Buyers needing published ISO 27001/SOC 2 or a full public DPA/subprocessor pack
  • Marketing teams requiring session replay, heatmaps, or advanced e-commerce/ad sync suites
  • Enterprises that need SSO/SCIM, formal SLAs, and large-vendor assurance paperwork as table stakes

Consider instead when

  • When: You want open-source and/or self-host privacy analytics with a larger community

    Consider: Plausible Analytics or Pirsch Analytics

    nilly is proprietary SaaS only.

  • When: You want another European cookieless SaaS with a simple product story

    Consider: Simple Analytics

    Dutch peer; compare geo depth, API, and residency claims side by side.

  • When: You need deeper marketing, shop, and tag/consent analytics for EU enterprises

    Consider: etracker

    German suite-oriented alternative; heavier than nilly's lightweight dashboard.

  • When: You depend on free unlimited scale and Google ads/ecosystem integration

    Consider: Google Analytics (GA4)

    Different privacy and residency tradeoffs; not a sovereignty shortlist.

Vantevo Analytics

Best fit when

  • EU/Italian teams replacing Google Analytics for marketing-site KPIs without analytics cookies
  • Agencies needing a simple multi-site dashboard clients can read without GA training
  • Shops that want privacy-oriented funnel events (cart → checkout → purchase) and accept beta maturity
  • Migrations that need to pull Universal Analytics page history into a privacy-first tool
  • Stacks using WordPress, Shopify, React/Next, Vue/Nuxt, or server-side event APIs

Poor fit when

  • Requirements for multi-day returning visitors, cross-device identity, or ad-platform audience sync
  • Mandatory self-hosting, open-source code audit, or on-prem only deployments
  • Procurement that requires public ISO 27001/SOC 2 evidence and independent security audits before shortlist
  • Heavy product analytics / cohort experimentation beyond site and ecommerce funnel events
  • Accounts that need more than the Terms’ 50-website cap without vendor exception

Consider instead when

  • When: You want a well-known lightweight EU privacy analytics tool with strong community presence

    Consider: Plausible Analytics or Simple Analytics

    Compare ecommerce depth, GA import, and commercial packaging side by side.

  • When: You need self-host or enterprise compliance packaging

    Consider: Piwik PRO (or Matomo self-host outside this catalog’s EU-SaaS peers)

    Vantevo is SaaS-only with no public self-host edition found.

  • When: You need full product analytics and long-horizon cohorts

    Consider: Mixpanel or similar product analytics suites

    Different category: identity-rich product instrumentation vs privacy-first site metrics.

  • When: You specifically want German-market privacy analytics peers

    Consider: Pirsch Analytics or etracker (catalog peers)

    Validate feature parity on ecommerce and import paths.

Open questions for due diligence

nilly

  • Will Lyo GmbH sign a B2B DPA and provide a current full subprocessor list (including backups, monitoring, CDN)?
  • Is analytics data retained only on Swiss hosts, or are any DR/replicas outside Switzerland?
  • What is the durable public domain for tracking scripts and API (kandur.one vs nilly.io) for the next 12 months?
  • Are there enterprise features (SSO, roles, retention controls, MSA/SLA) beyond self-serve traffic plans?
  • Can the vendor provide any independent security assessment under NDA?

Vantevo Analytics

  • Which exact AWS region(s) and services are in production, and are standard contractual clauses / transfer impact assessments available on request?
  • Is a current subprocessor list (beyond DPA/privacy mentions of OVH, AWS, Stripe, Crisp, Google) available under NDA?
  • Are ISO 27001, SOC 2, or independent penetration-test summaries available for enterprise procurement?
  • What is the production roadmap and support SLA for ecommerce events leaving beta?
  • How should multi-brand agencies interpret “unlimited domains” marketing versus the Terms’ 50-website cap—exceptions available?