Piwik PRO vs Stormly

Compare Piwik PRO and Stormly on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Google Analytics, Mixpanel

Logo: Piwik PRO

Piwik PRO

Poland· Web Analytics

Needs review

Shortlist Piwik PRO when you need a managed European analytics controller with integrated consent, tagging, and real-time data activation—and you can accept cloud residency on Azure and/or Elastx. Skip when you require open-source self-hosting (consider Matomo or Friendly Analytics) or only need a minimal cookieless counter (Plausible, Simple Analytics).

EU HQ (Poland)Analytics + tags + consentData activationEU hosting optionsISO 27001 / SOC 2 (claimed)HIPAA BAA (Enterprise)
Logo: Stormly

Stormly

Netherlands· Web Analytics

Needs review

Shortlist Stormly when you need Dutch-contracted, e-commerce-first product analytics: SKU-aware report packs, Shopify/Adobe-oriented setup, inbox-style AI anomaly narratives, and a public DPA. Skip when you need cookieless privacy web stats only (consider Plausible, Simple Analytics, or Pirsch), open-source self-hosting, verified ISO/SOC on a public cert page, or a subprocessor chain free of US-group cloud and Azure OpenAI.

E-commerce product analyticsSKU-aware reportsAI anomaly insightsShopify / Adobe CommerceNL entity + public DPASaaS (not self-host)
Piwik PRO vs Stormly: Snapshot
FeatureLogo: Piwik PROPiwik PROLogo: StormlyStormly
Country of originPolandNetherlands
CategoryWeb AnalyticsWeb Analytics
Open sourceNoNo
Self-hostedNoNo
HeadquartersPolandNetherlands
Legal entityPiwik PRO SA (Wrocław); affiliates Piwik PRO LLC (New York), Piwik PRO GmbH (Berlin)Monon B.V. (Lutmastraat 1-3, 1072 JL Amsterdam; KvK 76248747 per Terms)
Governing lawNot listedNetherlands (Dutch law; Amsterdam courts)
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)MediumMedium
Hosting / residencyCustomer-selectable regions: Microsoft Azure public cloud (US, Netherlands, Germany, Hong Kong) and Elastx (Sweden, EU-operated). Enterprise private cloud: 60+ Azure regions plus Elastx. Business plan marketing highlights Swedish EU-operated hosting. No classic customer self-host.Client analytics subprocessors (Security Architecture): Hetzner (EU); Amazon AWS (US company, vendor states EU regions only for encrypted analytics backups); Vultr (US company); Microsoft Azure OpenAI (US company, vendor states EU Azure region). Plans market EU data residency. Controller privacy policy also references Vultr/AWS for account data, AuthSMTP EU + Amazon SES USA for email, Stripe for payments; marketing site uses Google Analytics and Hotjar.
Summary

Polish privacy-first analytics suite combining web and mobile analytics, tag management, consent management, and real-time data activation for regulated teams.

Dutch SaaS product analytics for e-commerce teams: SKU-aware reports, AI-assisted anomaly and root-cause insights, and Shopify/Adobe Commerce/Segment/GTM-oriented connections under Monon B.V. (Amsterdam).

Tags
At a glance: Piwik PRO vs Stormly
At a glanceLogo: Piwik PROPiwik PROLogo: StormlyStormly
HQWrocław, Poland (Piwik PRO SA)Not listed
Product typeCommercial analytics suite (SaaS / private cloud)Not listed
Open sourceNo (closed source since split from Matomo lineage)No
Self-hostNo classic on-prem; public or private cloud onlyNo
Hosting (public)Azure US/NL/DE/HK; Elastx SwedenHetzner; AWS EU-region backups; Vultr; Azure OpenAI EU region (vendor docs)
ModulesAnalytics, Tag Manager, Consent Manager, Data ActivationNot listed
Commercial modelBusiness subscription + trial; Enterprise customFree tier + monthly plan + custom; trial path on paid
HQ / entityNot listedMonon B.V., Amsterdam, Netherlands
CategoryNot listedE-commerce product analytics (SaaS)
Governing lawNot listedDutch law; Amsterdam courts
Key capabilities: Piwik PRO vs Stormly
Key capabilitiesLogo: Piwik PROPiwik PROLogo: StormlyStormly
EU HQ (Poland)YesNot listed
Analytics + tags + consentYesNot listed
Data activationYesNot listed
EU hosting optionsYesNot listed
ISO 27001 / SOC 2 (claimed)YesNot listed
HIPAA BAA (Enterprise)YesNot listed
E-commerce product analyticsNot listedYes
SKU-aware reportsNot listedYes
AI anomaly insightsNot listedYes
Shopify / Adobe CommerceNot listedYes
NL entity + public DPANot listedYes
SaaS (not self-host)Not listedYes

Piwik PRO

  • ClickHouse-backed web & mobile analytics

    Session-level web and app analytics with custom reports, funnels, user flows, multi-channel attribution, and calculated metrics. Vendor positions unsampled collection by default with optional sampling for extreme volumes, plus raw export via API, files, and BigQuery—aimed at teams that outgrew pre-aggregated MySQL-style tools.

  • Anonymous tracking when cookies are declined

    Collect privacy-safe behavioral signals without identifiers when visitors refuse cookies or when you configure limited measurement modes. Marketing can still see channels and journeys; personal identifiers and full attribution wait for a valid lawful basis—useful under GDPR/ePrivacy friction.

  • Integrated Consent Manager and Tag Manager

    Capture and store consent, drive tag firing from preferences, and handle visitor data requests in-product. Optional Cookie Information CMP and server-side tagging paths reduce the usual glue code between a separate CMP, GTM, and analytics.

  • Data Activation for real-time personalization

    Segment audiences from live behavior and trigger on-site or outbound actions without exporting every event to a second CDP first. Suited to regulated marketers who want activation on first-party data they control.

  • Selectable cloud residency (Azure + Elastx)

    Public cloud regions include Azure US, NL, DE, and HK plus Elastx Sweden; Enterprise private cloud spans 60+ Azure regions and Elastx. Business plan marketing highlights EU-operated Swedish hosting—pick region in procurement, not after go-live.

  • Regulated-industry packaging (GDPR tooling, HIPAA BAA path)

    DPA available on Business signup; Enterprise adds private cloud, higher action volumes, SLAs, and HIPAA Business Associate Agreements for healthcare marketing analytics. Vendor also claims ISO 27001 and SOC 2—request current certificates in diligence.

Stormly

  • AI agent for trends, anomalies, and root-cause style digs

    Stormly positions an AI agent that watches connected e-commerce data for trends and anomalies (for example conversion drops or product spikes), then delivers plain-language findings—often to the inbox—with root-cause style exploration for questions like mobile conversion drops or regional return spikes. AI assistant access is plan-dependent; the public DPA documents Azure OpenAI (Microsoft) handling of assistant queries with a 30-day retention window and property stripping rules. Best for merchandising and growth leads who want narrative answers without waiting on a data team.

  • SKU-aware e-commerce report library (plus custom builds)

    Ready reports target commerce questions: New Arrivals Performance (early SKU winners/laggards), Unviewed & Unsold Products, cart abandonment and revenue contribution by product/category, Conversion Journey and funnels by device/region, A/B test insights, Aha Moment Discovery, cross-selling analysis, and broader library items (retention, CLV, forecasting, SQL report, and more). Vendor materials state custom reports are included without a separate fee when a needed view is missing—useful for mid-market retailers that outgrow generic event charts.

  • Shopify, Adobe Commerce, Segment, and GTM-oriented connections

    Homepage setup emphasizes linking Shopify, Adobe Commerce, or Segment quickly, with Google Tag Manager also listed among integrations. The DPA describes additional programmatic paths (JS library, import, custom endpoints, third-party sources). Fits stores already on common commerce stacks; teams on exotic storefronts should validate event coverage and product-feed depth in a pilot before replacing an existing analytics stack.

  • End-user tracking with IP anonymization defaults

    Per the DPA, IP addresses for end-user analytics are not stored in full: the last octet is removed and geo/timezone are derived from the anonymized value. Web integrations automatically capture first-party cookie user ids, page/referrer/UTM context, and device metadata; app properties depend on client or CDP configuration. This is still full product analytics (not cookieless aggregate-only web stats)—clients remain responsible for consent banners and lawful basis for shopper tracking.

  • Public DPA, security architecture, and Dutch contracting

    B2B buyers can download a Data Processing Agreement (effective 2023-09-06) and a Security Architecture page listing subprocessors, encryption expectations, backup retention (analytics backups up to six months), and logical tenant isolation. Contracts and DPA are governed by Dutch law with Amsterdam courts. Useful for EU procurement packages—but US-group subprocessors (AWS, Vultr, Azure OpenAI) still require transfer and CLOUD Act diligence.

Assurance & compliance: Piwik PRO vs Stormly
Assurance & complianceLogo: Piwik PROPiwik PROLogo: StormlyStormly
Independent security / no-logs audit
Partial

Vendor states regular external security audits and SOC 2/ISO programs; no public third-party no-logs-style audit PDF reviewed for this draft. Request reports under NDA.

Not found

Security Architecture describes encryption, monitoring, isolation, and vulnerability contact (security@stormly.com); no public third-party audit PDF found.

ISO 27001
Vendor claimed

Asserted on privacy-security and platform pages; certificate not independently re-verified against a public registry for this entry.

Not found

No public ISO 27001 certificate located on official legal/security pages reviewed.

SOC 2 / SOC 3
Vendor claimed

Vendor claims SOC 2 (comparison content references type II) and SOC 2-certified infrastructure; obtain current report in diligence.

Not found

No public SOC 2/3 report located on official pages reviewed.

HIPAA / BAA
Vendor claimed

HIPAA-oriented offering with BAA on Enterprise path per vendor; not available on all plan tiers.

Not listed
GDPR / EU data protection
Vendor claimed

EU legal entity, residency options, consent tooling, anonymization, and DPA. Compliance depends on customer configuration and purposes.

Vendor claimed

NL entity; public privacy policy and DPA (GDPR-oriented); IP last-octet anonymization for end-user analytics; SCCs language for restricted transfers in DPA.

US CLOUD Act exposure (indicative)
Partial

No known US parent (Polish SA). Medium exposure due to Microsoft Azure as public/private cloud subprocessor and optional US region; Elastx Sweden is EU-operated alternative. Not legal advice.

Partial

EU entity / no known US parent, but public client subprocessors include AWS, Vultr, and Microsoft Azure OpenAI (US-group companies). Account path historically also lists Amazon SES and Stripe. Residency claims do not remove US-group legal exposure. Indicative only—not legal advice.

Data processing agreement (B2B)
Vendor claimed

Business DPA linked from Business plan signup (piwik.pro/business-dpa/); Enterprise contracts expand terms.

Vendor claimed

Downloadable DPA PDF linked from stormly.com/dpa (effective 6 September 2023); audit rights and subprocessor notice described; Security Architecture lists subprocessors.

EU AI Act
Not applicable

Analytics/activation platform; not marketed as an AI system provider. Customer AI use of exported data is out of product scope.

Partial

Product includes an AI assistant via Azure OpenAI; not positioned as a high-risk AI system marketing claim. Buyers should map AI assistant use to their own AI Act / internal AI policy—vendor does not publish a full AI Act conformity package on the pages reviewed.

Considerations & known limitations: Piwik PRO vs Stormly
Considerations & known limitationsLogo: Piwik PROPiwik PROLogo: StormlyStormly
US-group cloud (Azure) in hosting path
Medium

Even with EU region selection, Azure introduces US-group infrastructure risk. Pin region, review SCCs/subprocessors, and escalate if policy forbids US cloud groups entirely.

Not listed
Closed source and no classic self-host
Medium

Cannot independently audit full source or run fully air-gapped on customer iron. Private cloud still involves vendor-managed stack on Azure/Elastx.

Not listed
Certifications not independently verified here
Low

ISO 27001, SOC 2, and HIPAA are vendor-claimed. Request certificates/reports and BAA text before treating them as assured.

Not listed
Paid plans only after Core sunset
Low

Free Core has been discontinued; evaluation relies on trials and paid Business/Enterprise metering by actions/domains.

Not listed
Compliance depends on configuration
Medium

Anonymous modes and CNIL exemption require correct setup and purpose limitation. Misconfiguration can recreate the same legal exposure teams left GA to avoid.

Not listed
US-group cloud and AI subprocessorsNot listed
Medium

Despite Dutch HQ and EU residency marketing, client data paths publicly include AWS, Vultr, and Microsoft Azure OpenAI. Transfer tooling (SCCs) and encryption of backups are documented, but CLOUD Act / US legal process risk remains a diligence item for sovereignty-sensitive buyers.

No public ISO/SOC or independent auditNot listed
Medium

Enterprise security questionnaires may stall without ISO 27001/SOC 2 packs. DPA offers information/audit rights—plan time for NDA evidence requests.

Azure OpenAI retains assistant context 30 daysNot listed
Medium

AI queries and aggregate report results are stored on Microsoft Azure OpenAI for 30 days per DPA. Property stripping reduces some identifiers, but misconfigured event properties could still expose sensitive content—govern AI use and property hygiene.

Controller privacy policy vs security architecture driftNot listed
Low

Privacy policy (controller, effective 2019) still emphasizes Vultr USA wording in places, while Security Architecture (client data) lists Hetzner/AWS/Vultr/Azure. Ask for a single current subprocessor and region matrix at contract time.

Not a privacy web-analytics substituteNot listed
Low

Full product analytics with cookies/identifiers for web integrations—not a cookieless aggregate counter. Consent UX remains on the client.

Fit

Piwik PRO

Best fit when

  • Regulated marketing/analytics teams that want one suite for measurement, consent, tags, and activation under a Polish legal entity
  • Public sector and EU enterprises that need selectable EU residency (e.g. Elastx Sweden or Azure NL/DE) plus a formal B2B DPA
  • Healthcare digital teams evaluating HIPAA-aware analytics with a signed BAA on Enterprise
  • Organizations leaving GA4 primarily for residency, no vendor ad-network reuse, and anonymous pre-consent measurement options
  • Teams that need enterprise reporting depth (custom reports, funnels, flows, attribution) beyond lightweight privacy analytics

Poor fit when

  • Buyers who mandate fully self-hosted open-source analytics with no cloud hypervisor vendor
  • Sites that only need simple cookieless page analytics without tag management or activation
  • Teams that refuse any US-group infrastructure (Azure appears in public hosting options even when EU regions are chosen)
  • Orgs seeking a free forever analytics tier (Core plan sunset; paid Business/Enterprise only)

Consider instead when

  • When: You need open-source code and true on-premises control

    Consider: Matomo (self-host) or Friendly Analytics / Matomo by Stackhero for managed Matomo

    Piwik PRO is proprietary cloud/private-cloud only.

  • When: You want minimal, cookieless EU analytics without enterprise suite complexity

    Consider: Plausible Analytics or Simple Analytics

    Far smaller feature surface; no HIPAA/CDP-style activation packaging.

  • When: You need a German enterprise analytics vendor with long public-sector presence

    Consider: etracker

    Different product depth and packaging—compare consent tooling and activation needs.

Stormly

Best fit when

  • Merchandising, product, UX, and growth teams on Shopify or Adobe Commerce who need SKU, cart, and assortment analytics without a dedicated data science org
  • Retail brands that want ready e-commerce report templates (new arrivals, unviewed/unsold, funnels, A/B, aha moments) plus vendor-built custom reports
  • EU buyers who want a Dutch legal entity, Amsterdam courts, and a downloadable DPA/Security Architecture package
  • Teams that value AI-generated trend/anomaly narratives delivered to the inbox more than building every chart from a blank event schema
  • Stacks already using Segment or Google Tag Manager as the event pipe into analytics

Poor fit when

  • Publishers or marketing sites that only need lightweight privacy-friendly page analytics (not product/SKU depth)
  • Orgs that require open-source self-hosting or full control of a private analytics warehouse as the default
  • Procurement policies that forbid US-group subprocessors (AWS, Vultr, Microsoft Azure OpenAI) even when EU regions are claimed
  • Assurance programs that require public ISO 27001/SOC 2 evidence before pilot (not found on vendor pages reviewed)
  • Companies operating blockchain products/services—restricted by Stormly’s terms

Consider instead when

  • When: You only need privacy-oriented website metrics (pageviews, sources) rather than SKU-level product analytics

    Consider: Plausible Analytics, Simple Analytics, or Pirsch Analytics

    EU web-analytics peers; different category from e-commerce product analytics

  • When: You need deep general-purpose product analytics, large ecosystem, and mature multi-product SaaS event modeling

    Consider: Mixpanel or Amplitude

    US incumbents; stronger breadth, different jurisdiction and commercial model

  • When: You primarily need free/universal marketing acquisition reporting already embedded in the stack

    Consider: Google Analytics (incumbent) or dual-run GA for marketing + Stormly for product/merch

    GA is not SKU-first product analytics; Stormly is not a GA replacement for every report

Open questions for due diligence

Piwik PRO

  • What exact subprocessor list and backup/DR locations apply to the contracted region (Azure vs Elastx) today?
  • Can the vendor provide current ISO 27001 certificate scope and SOC 2 Type II report under NDA?
  • For healthcare: which plan tier, region, and BAA wording cover the intended PHI workflows?
  • Does the Business Swedish hosting path avoid Azure entirely for production data, or only for selected components?
  • What residual free/legacy Core accounts remain, and what is the migration deadline for this tenant?

Stormly

  • Can Stormly provide a current region map (which data classes live on Hetzner vs Vultr vs AWS) under NDA for our DPIA?
  • Are ISO 27001, SOC 2, or penetration-test summaries available on request for enterprise security review?
  • Which event properties from our Shopify/Adobe feed are excluded from Azure OpenAI prompts by default in our tenant?
  • Do custom report builds and SQL access sit only on the custom tier, and what SLAs apply?
  • Has the 2019 controller privacy policy been superseded for hosting wording relative to the Security Architecture list?