Offen Fair Web Analytics vs Sitesights

Compare Offen Fair Web Analytics and Sitesights on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Fathom Analytics, Google Analytics, Hotjar, Matomo, Mixpanel

Logo: Offen Fair Web Analytics

Offen Fair Web Analytics

Germany· Web Analytics

Needs review

Shortlist when you want self-hosted, Apache-2.0 analytics that only measures after opt-in, encrypts events in the browser, and lets visitors open their own data in the Auditorium. Skip when you need cookieless full-coverage metrics, session replay/heatmaps, or zero-ops managed EU hosting—consider Plausible, Pirsch, or Friendly Analytics instead.

Opt-in onlyBrowser E2E encryptionSelf-hostedApache-2.0Visitor data accessBerlin-based project
Logo: Sitesights

Sitesights

Germany· Web Analytics

Needs review

Shortlist Sitesights when you need German-operated cookieless web analytics with real-time dashboards, funnels, page flow, and a server-side API—especially agencies and SaaS teams that want Hetzner Germany hosting claims without running Matomo. Skip when you need public ISO/SOC audits, long-term visitor identity, session replay, or a fully published subprocessor pack; consider Plausible Analytics or self-hosted Matomo instead.

Cookieless trackingEU-operated (DE)Hetzner Germany (claimed)Server-side APIFunnels + page flowMulti-project / agencies
Offen Fair Web Analytics vs Sitesights: Snapshot
FeatureLogo: Offen Fair Web AnalyticsOffen Fair Web AnalyticsLogo: SitesightsSitesights
Country of originGermanyGermany
CategoryWeb AnalyticsWeb Analytics
Open sourceYesNo
Self-hostedYesNo
HeadquartersGermanyGermany
Legal entityPublic legal notice lists Frederik Ring, Berlin (offen.software); product authors Frederik Ring and Hendrik Niefeld—no separate GmbH name verified on imprintDrude, Grossert GbR
Governing lawGermany (indicative from Berlin imprint)Not listed
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)LowMedium
Hosting / residencyProduct is operator self-hosted (your VPS/cloud/on-prem). No Offen multi-tenant analytics SaaS or vendor subprocessor list for visitor events. Related marketing site (offen.software) names Hetzner Online GmbH (Germany) as host—not the analytics data path. Optional community deploys include Heroku (operator choice).Product databases and app servers claimed in Germany on Hetzner. Marketing site uses Cloudflare (US) CDN. Payments via Paddle. Full product subprocessor/backup list not published on main site.
Summary

Open-source, self-hosted web analytics with opt-in consent, browser-side end-to-end encryption, and a shared Auditorium so visitors can see and control their own usage data.

German cookieless web analytics SaaS with real-time dashboards, events, funnels, and server-side APIs. Operated by Drude, Grossert GbR; product data claimed on Hetzner in Germany.

Tags
At a glance: Offen Fair Web Analytics vs Sitesights
At a glanceLogo: Offen Fair Web AnalyticsOffen Fair Web AnalyticsLogo: SitesightsSitesights
HQ / authorsBerlin, Germany (Frederik Ring & Hendrik Niefeld)Not listed
LicenseApache-2.0 (code/docs); logo CC-BY-NC-ND-4.0Not listed
DeliverySelf-host only (binary, Docker, community deploys)Not listed
Consent modelOpt-in only; first-party cookiesNot listed
Default retention6 months (configurable shorter)Not listed
Funding noteNLnet NGI support (project-stated)Not listed
HQ / entityNot listedDrude, Grossert GbR, Germany
CategoryNot listedWeb analytics (SaaS)
Hosting (product)Not listedHetzner, Germany (vendor docs)
Tracking modelNot listedCookieless; 48h rotating server hash
Open sourceNot listedNo (libs/plugins public; core SaaS proprietary)
Commercial modelNot listedFree start; pageviews + events subscriptions (Paddle)
Key capabilities: Offen Fair Web Analytics vs Sitesights
Key capabilitiesLogo: Offen Fair Web AnalyticsOffen Fair Web AnalyticsLogo: SitesightsSitesights
Opt-in onlyYesNot listed
Browser E2E encryptionYesNot listed
Self-hostedYesNot listed
Apache-2.0YesNot listed
Visitor data accessYesNot listed
Berlin-based projectYesYes
Cookieless trackingNot listedYes
Hetzner Germany (claimed)Not listedYes
Server-side APINot listedYes
Funnels + page flowNot listedYes
Multi-project / agenciesNot listedYes

Offen Fair Web Analytics

  • Opt-in only collection with first-party cookies

    No analytics events are recorded until the visitor actively consents. Cookies are first-party and the tracker is meant to run on a same-site subdomain so third-party cookie restrictions and cross-site tracking models do not apply. Visitors who never opt in leave no usage trail—expect lower absolute volumes than cookieless tools that measure by default.

  • Browser-side end-to-end encryption of usage events

    Clients encrypt usage data before it leaves the browser; the server stores ciphertext and cannot decrypt events alone. Only the visitor (via their cookie) and the matching operator account can open that visitor's data in the Auditorium. Practical impact: a compromised database or overly broad ops access does not yield plaintext browsing histories the way a typical self-hosted analytics DB would.

  • Auditorium for both operators and visitors

    Operators see aggregates across pages where the installation is active (unique users/sessions, top pages, filters). Each opted-in visitor can open the same style of UI for their own data only, with plain-language metric explanations, and can delete data or fully opt out later. This is the fair design point: measurement is not a one-way glass.

  • Essential metrics without IP or User-Agent capture

    Dashboards cover real-time activity, page views, unique users and sessions, bounce rate, returning users, top pages, referrers, UTM campaign/source, landing and exit pages, weekly retention, and load time. Location is country-level from timezone mapping; mobile share uses orientation capability—not IP geolocation or UA parsing. No heatmaps, session replay, or warehouse-grade product analytics.

  • Lightweight self-host: binary, Docker, SQLite or SQL

    Production installs use a single binary (Linux/Windows/macOS) or the offen/offen image; docs also cover Heroku, Uberspace, and YunoHost. Default store is SQLite; MySQL and Postgres are supported. AutoTLS can request Let's Encrypt certificates. Config is environment variables or offen.env. You own uptime, backups, SMTP for password reset, and the subdomain layout.

  • Multi-site accounts, teams, and short retention

    One installation can cover multiple websites with shared team access. Default retention is six months with automatic deletion; operators can shorten retention (e.g. 12 weeks, 30 days, 7 days) knowing shorter values purge older events on startup. Consent banner appearance is customizable; UI locales include EN, DE, FR, ES, PT, and VI.

Sitesights

  • Cookieless 48-hour rotating session hash

    Standard tracking does not set cookies. Sitesights generates a server-side salted hash from IP, User-Agent, and site id with a salt that rotates every 48 hours, so long-term cross-day visitor re-identification is intentionally broken. Useful when teams want essential traffic metrics without a cookie-consent banner solely for analytics—confirm legal basis with counsel for your jurisdiction and data fields (including geo).

  • Sub-1 KB client script plus WordPress and Shopify plugins

    Drop-in client snippet marketed as under 1 KB, with official WordPress and Shopify integration paths for non-engineers. Fits marketing sites and stores that need quick instrumentation without a heavy tag manager stack.

  • Server-side REST API with C# and Node libraries

    Send page views and events from your backend with API-key auth so ad blockers cannot strip the beacon. MIT-licensed C# and Node.js libraries on GitHub speed integration; keep API keys off the client. Preferred path for accuracy-critical SaaS and app backends.

  • Real-time overview with campaign and device filters

    Live dashboard for visitors, pageviews, and sessions with advanced filters, UTM/campaign views, geo, browser, OS, screen size, and daytime patterns. Aimed at operators who want essential marketing analytics in one place rather than a full product-analytics suite.

  • Custom funnels and page-flow journey maps

    Build multi-step funnels and visual page-flow maps to see entry paths, routes, and exits. Helps conversion and UX work without session replay. Depth is journey-oriented, not identity-graph product analytics.

  • Multi-project workspaces with roles for agencies

    Group sites and apps into projects, assign roles/permissions, and invite clients or teammates. Marketing materials reference high ceilings for team seats and properties on paid plans—verify current limits on the official pricing page.

Assurance & compliance: Offen Fair Web Analytics vs Sitesights
Assurance & complianceLogo: Offen Fair Web AnalyticsOffen Fair Web AnalyticsLogo: SitesightsSitesights
Independent security / architecture audit
Not found

No public third-party audit PDF found; coordinated disclosure via SECURITY.md email only.

Not found

No public third-party security or no-logs audit PDF located on the official site or docs.

ISO 27001
Not found

No public ISO 27001 certification claim found on official site or docs.

Not found

No public ISO 27001 certificate found on official pages.

SOC 2 / SOC 3
Not found

No public SOC 2/3 report found.

Not found

No public SOC 2/3 report found on official pages.

GDPR / EU data protection
Vendor claimed

EU authors; opt-in, data minimization (no IP/UA), visitor access/erasure, short default retention, Datensparsamkeit framing. Self-host means operator remains controller—confirm your legal basis and notice.

Vendor claimed

German controller (Drude, Grossert GbR); cookieless hashing and EU hosting claims in docs/privacy. Confirm DPA and legal basis for IP/geo with counsel.

US CLOUD Act exposure (indicative)
Partial

EuropeanStack assessment: no known US parent; product not delivered as US-hosted vendor SaaS. Operator-chosen infrastructure (including optional Heroku/US cloud) can still create CLOUD Act paths for stored ciphertext/metadata. Not legal advice.

Partial

EU entity / no known US parent; product hosting claimed on Hetzner Germany. Marketing site lists Cloudflare (US); payments via Paddle; full SaaS subprocessor list not public. Indicative only—not legal advice.

Data processing agreement (B2B)
Not applicable

No multi-tenant vendor analytics processing relationship documented; operator self-hosts and is typically controller. Custom development/support via offen.software is separate from a standard SaaS DPA.

Not found

No standalone public DPA download found during research; request under contract for B2B processing.

EU AI Act
Not applicable

Web analytics metrics product; not an AI system product.

Not applicable

Web analytics product; not marketed as an AI system under the EU AI Act.

Considerations & known limitations: Offen Fair Web Analytics vs Sitesights
Considerations & known limitationsLogo: Offen Fair Web AnalyticsOffen Fair Web AnalyticsLogo: SitesightsSitesights
Opt-in undercounts absolute traffic
High

Visitors who never consent generate no events. Growth and content KPIs will not match cookieless tools or GA-style default measurement—treat as design, not a misconfiguration.

Not listed
You own uptime, backups, and secrets
Medium

No managed Offen cloud. Operators must run HTTPS/subdomain layout, set OFFEN_SECRET for stable sessions, configure SMTP for resets, and back up SQLite/SQL—plus avoid reverse proxies that log IPs if minimization is a goal.

Not listed
E2E crypto is vendor-claimed architecture
Medium

Browser-side encryption and server inability to decrypt are core claims from project docs/README, not independently audited in public materials found. Security-sensitive orgs should review source or commission assessment.

Not listed
Hosting choice reintroduces cloud jurisdiction
Medium

Self-host on US-group cloud or Heroku means CLOUD Act/subprocessor analysis shifts to your host even though Offen itself is Berlin-based OSS without a vendor SaaS region map.

Not listed
No public ISO/SOC or audit pack
Low

Procurement checklists that require vendor ISO 27001/SOC 2 will stall; evidence is open source and design docs, not cert registry entries.

Not listed
Essential metrics only
Medium

No heatmaps, session replay, advanced funnels, or product-analytics warehouse features. Wrong tool if the shortlist criterion is UX research depth rather than fair traffic statistics.

Not listed
No public independent security auditNot listed
Medium

ISO 27001, SOC 2, and third-party security audits were not found on public pages. Enterprises may need to commission questionnaires or wait for vendor artifacts under NDA.

Incomplete public subprocessor listNot listed
Medium

Hetzner (product) and Cloudflare (marketing site) are documented; backups, email, support, and monitoring vendors for the SaaS are not fully listed. Ask for a current subprocessor annex.

US-group CDN on marketing siteNot listed
Low

Privacy policy lists Cloudflare Inc. (US) for the public website CDN. Separate from claimed Hetzner product data path, but relevant to overall vendor surface area.

48-hour hash limits long-term visitor analyticsNot listed
Low

By design, the rotating salt prevents durable cross-day visitor recognition. Teams needing retention cohorts or multi-week funnels by person must model events differently or choose product-analytics tools.

On-premise availability is marketing-only detailNot listed
Low

About page claims on-prem hosting; docs do not provide a self-serve install guide. Treat as sales-assisted until scope is confirmed in writing.

Fit

Offen Fair Web Analytics

Best fit when

  • Public-sector, media, NGO, or mission-driven sites that need visitor-visible transparency and strict opt-in
  • EU teams that must keep analytics off third-party trackers and can run a small always-on instance
  • Operators who want first-party subdomain cookies, CSP-aware embedding, and no IP/User-Agent collection
  • Organisations evaluating fair-processing design over maximum measurement coverage
  • Teams comfortable with SQLite or SQL self-host ops (binary or Docker) and publishing their own privacy notice

Poor fit when

  • Product or growth teams that require near-complete traffic measurement without consent friction
  • Needs for heatmaps, session replay, funnels, or ad-ecosystem attribution comparable to Hotjar/Mixpanel/GA
  • Buyers seeking a vendor-managed multi-tenant analytics cloud with SLAs and a signed vendor DPA as processor
  • Large enterprises that require public ISO 27001/SOC 2 or third-party security audit packs before shortlist

Consider instead when

  • When: You want privacy-oriented analytics with managed EU hosting and lower consent friction

    Consider: Plausible Analytics or Pirsch Analytics

    Typically optimised for simpler cookieless or low-friction models and hosted plans; less radical visitor Auditorium design than Offen.

  • When: You need EU hosted privacy analytics with operator support and less self-host burden

    Consider: Friendly Analytics

    European catalog peer oriented to hosted privacy analytics; compare consent model and feature depth to Offen’s opt-in + E2E approach.

  • When: You need deep product analytics, funnels, or session UX tooling rather than fair traffic metrics

    Consider: Hotjar, Mixpanel, or a full GA4 stack (with legal review)

    Different category: richer product/UX analytics, different jurisdiction and subprocessor profile.

Sitesights

Best fit when

  • EU teams replacing GA4 with cookieless SaaS and wanting funnels/page-flow beyond a bare traffic counter
  • Agencies and freelancers managing many client sites with projects and role-based invites
  • Engineering-led installs that prefer server-side pageview/event ingestion against ad blockers
  • WordPress or Shopify properties that want official plugin paths plus a light client script
  • Orgs that value a German GbR legal entity and Hetzner Germany hosting claims over US multi-region analytics

Poor fit when

  • Product analytics requiring long-term user identity, cross-device stitching, or CDP-style profiles (48h hash by design)
  • Buyers who need public ISO 27001, SOC 2, or independent audit PDFs before shortlist
  • Teams that require self-serve open-source self-host as the primary deployment (on-prem only claimed, not documented as OSS)
  • UX research needs for heatmaps or session replay
  • Procurement that requires a complete public subprocessor list without an NDA conversation

Consider instead when

  • When: You want a minimal EU cookieless SaaS or a well-known self-host option

    Consider: Plausible Analytics

    Simpler metric set; strong self-host story. Sitesights markets deeper funnels/page-flow and multi-project agency features.

  • When: You need full self-host control, on-prem by default, or mature open-source governance

    Consider: Matomo (self-hosted)

    Heavier stack, deeper feature surface, and you operate the data plane yourself.

  • When: You need identity-rich product analytics, retention cohorts, or event warehouses

    Consider: Mixpanel or similar product-analytics platforms

    Different category—Sitesights is website/app growth analytics, not a full product analytics suite.

  • When: You need heatmaps, recordings, or UX feedback loops

    Consider: Hotjar, Microsoft Clarity, or EU UX-analytics tools

    Sitesights focuses on traffic, events, funnels, and flows—not session replay.

Open questions for due diligence

Offen Fair Web Analytics

  • Will your traffic and KPI model tolerate opt-in-only measurement after a pilot on a non-critical property?
  • Where will you host the instance (EU on-prem/VPS vs US-group cloud), and who holds OFFEN_SECRET and DB backups?
  • Do procurement rules require third-party audits or ISO/SOC that Offen does not publish?
  • Do you need a signed vendor DPA as processor, or is controller-only self-host acceptable to counsel?
  • Is subdomain + CSP (script-src/frame-src + unsafe-inline styles for the banner) feasible on your main site?

Sitesights

  • Will the vendor sign a B2B DPA and provide a complete subprocessor list (backups, email, support, monitoring)?
  • Is the Hetzner Germany residency contractual for all analytics tenant data, including DR/backups?
  • What is the formal on-premise offering (SLA, update model, supported regions) versus SaaS-only?
  • Are any ISO 27001 / SOC 2 / penetration-test reports available under NDA?
  • How should geolocation fields and IP hashing be assessed under your counsel's GDPR legal-basis analysis?