Piwik PRO vs Tinylytics

Compare Piwik PRO and Tinylytics on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Google Analytics

Logo: Piwik PRO

Piwik PRO

Poland· Web Analytics

Needs review

Shortlist Piwik PRO when you need a managed European analytics controller with integrated consent, tagging, and real-time data activation—and you can accept cloud residency on Azure and/or Elastx. Skip when you require open-source self-hosting (consider Matomo or Friendly Analytics) or only need a minimal cookieless counter (Plausible, Simple Analytics).

EU HQ (Poland)Analytics + tags + consentData activationEU hosting optionsISO 27001 / SOC 2 (claimed)HIPAA BAA (Enterprise)
Logo: Tinylytics

Tinylytics

United Kingdom· Web Analytics

Needs review

Shortlist Tinylytics when you want cookieless page analytics plus bundled uptime/SSL/content checks for a handful of small sites, with primary data on Hetzner in Germany and founder support. Skip when you need self-host/open source, formal ISO/SOC packs, or enterprise multi-tenant governance—consider Plausible Analytics or Simple Analytics instead.

Cookieless analyticsPrimary host: Hetzner DEUptime + SSL monitoringBroken-link crawlsSaaS only (no self-host)Solo-founder UK
Piwik PRO vs Tinylytics: Snapshot
FeatureLogo: Piwik PROPiwik PROLogo: TinylyticsTinylytics
Country of originPolandUnited Kingdom
CategoryWeb AnalyticsWeb Analytics
Open sourceNoNo
Self-hostedNoNo
HeadquartersPolandUnited Kingdom
Legal entityPiwik PRO SA (Wrocław); affiliates Piwik PRO LLC (New York), Piwik PRO GmbH (Berlin)Vincent Ritter Consulting (service brand; terms state not separately incorporated yet)
Governing lawNot listedNot clearly stated as a single governing-law clause on the public terms page; confirm contractually
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)MediumMedium
Hosting / residencyCustomer-selectable regions: Microsoft Azure public cloud (US, Netherlands, Germany, Hong Kong) and Elastx (Sweden, EU-operated). Enterprise private cloud: 60+ Azure regions plus Elastx. Business plan marketing highlights Swedish EU-operated hosting. No classic customer self-host.Primary analytics storage: Hetzner Falkenstein (Germany). CDN/security: Cloudflare. Error monitoring: Sentry.io. Payments: Paddle and Lemon Squeezy (Stripe company). Optional: IPinfo geo fallback for API hits; opt-in AI Insights via xAI and Google Gemini. No public backup-provider detail beyond that stack.
Summary

Polish privacy-first analytics suite combining web and mobile analytics, tag management, consent management, and real-time data activation for regulated teams.

Privacy-first cookieless web analytics for small sites, with bundled uptime/SSL checks, content monitoring, events, and founder support—hosted primarily on Hetzner in Germany.

Tags
At a glance: Piwik PRO vs Tinylytics
At a glanceLogo: Piwik PROPiwik PROLogo: TinylyticsTinylytics
HQWrocław, Poland (Piwik PRO SA)Not listed
Product typeCommercial analytics suite (SaaS / private cloud)Not listed
Open sourceNo (closed source since split from Matomo lineage)Not listed
Self-hostNo classic on-prem; public or private cloud onlyNot listed
Hosting (public)Azure US/NL/DE/HK; Elastx SwedenNot listed
ModulesAnalytics, Tag Manager, Consent Manager, Data ActivationNot listed
Commercial modelBusiness subscription + trial; Enterprise customPaid site-count plans; short trial; no permanent free tier
HQ / operatorNot listedVincent Ritter Consulting, United Kingdom
LaunchedNot listed12 June 2023 (live counters on homepage)
Primary hostingNot listedHetzner, Falkenstein, Germany
DeploymentNot listedManaged SaaS only (not open source, not self-hosted)
DifferentiatorsNot listedAnalytics + uptime/SSL/content monitoring + widgets
Key capabilities: Piwik PRO vs Tinylytics
Key capabilitiesLogo: Piwik PROPiwik PROLogo: TinylyticsTinylytics
EU HQ (Poland)YesNot listed
Analytics + tags + consentYesNot listed
Data activationYesNot listed
EU hosting optionsYesNot listed
ISO 27001 / SOC 2 (claimed)YesNot listed
HIPAA BAA (Enterprise)YesNot listed
Cookieless analyticsNot listedYes
Primary host: Hetzner DENot listedYes
Uptime + SSL monitoringNot listedYes
Broken-link crawlsNot listedYes
SaaS only (no self-host)Not listedYes
Solo-founder UKNot listedYes

Piwik PRO

  • ClickHouse-backed web & mobile analytics

    Session-level web and app analytics with custom reports, funnels, user flows, multi-channel attribution, and calculated metrics. Vendor positions unsampled collection by default with optional sampling for extreme volumes, plus raw export via API, files, and BigQuery—aimed at teams that outgrew pre-aggregated MySQL-style tools.

  • Anonymous tracking when cookies are declined

    Collect privacy-safe behavioral signals without identifiers when visitors refuse cookies or when you configure limited measurement modes. Marketing can still see channels and journeys; personal identifiers and full attribution wait for a valid lawful basis—useful under GDPR/ePrivacy friction.

  • Integrated Consent Manager and Tag Manager

    Capture and store consent, drive tag firing from preferences, and handle visitor data requests in-product. Optional Cookie Information CMP and server-side tagging paths reduce the usual glue code between a separate CMP, GTM, and analytics.

  • Data Activation for real-time personalization

    Segment audiences from live behavior and trigger on-site or outbound actions without exporting every event to a second CDP first. Suited to regulated marketers who want activation on first-party data they control.

  • Selectable cloud residency (Azure + Elastx)

    Public cloud regions include Azure US, NL, DE, and HK plus Elastx Sweden; Enterprise private cloud spans 60+ Azure regions and Elastx. Business plan marketing highlights EU-operated Swedish hosting—pick region in procurement, not after go-live.

  • Regulated-industry packaging (GDPR tooling, HIPAA BAA path)

    DPA available on Business signup; Enterprise adds private cloud, higher action volumes, SLAs, and HIPAA Business Associate Agreements for healthcare marketing analytics. Vendor also claims ISO 27001 and SOC 2—request current certificates in diligence.

Tinylytics

  • Cookie-free unique hits with rotating salts

    Page views and unique hits without tracking cookies or fingerprinting. Uniques combine truncated request signals with a 12-hour rotating salt and one-way hash, reset daily at midnight UTC; visitor IPs are not stored in hits. Suited to indie sites that want trendable uniques without consent banners for analytics cookies.

  • Thunder Clap uptime, SSL, and domain alerts

    In-house multi-region health checks (default every 10 minutes) confirm downtime before emailing, plus SSL expiry notices and domain monitoring. Ultra can shorten intervals. Replaces a separate uptime tool for small fleets—but false downs can occur if WAFs block the Tinylytics monitor user-agent.

  • Daily content crawl for broken links and mixed content

    Subscribed sites can crawl up to 50 pages (two levels deep) on a daily cadence, flagging broken links and mixed HTTP assets on HTTPS pages, with ignore lists and re-check. Ultra adds optional AI spell-check on visible copy—keep it off if AI subprocessors are out of policy.

  • Attribute-based event tracking (beta)

    Enable events on the embed script and mark elements with data-tinylytics-event using category.action names (optional values for downloads). No GTM required; beacon mode helps navigations. Still beta—expect API/schema changes and incomplete capture under aggressive blockers.

  • Public stats, kudos, hit counters, API, and webhooks

    Share passcode-protected public stats, embed hit counters and kudos buttons, export CSV, call the documented API, and push signed webhooks for visits, events, and monitoring. Built for transparent blogs and light automation rather than enterprise BI warehouses.

Assurance & compliance: Piwik PRO vs Tinylytics
Assurance & complianceLogo: Piwik PROPiwik PROLogo: TinylyticsTinylytics
Independent security / no-logs audit
Partial

Vendor states regular external security audits and SOC 2/ISO programs; no public third-party no-logs-style audit PDF reviewed for this draft. Request reports under NDA.

Not found

No public third-party security or no-logs audit report found on official docs.

ISO 27001
Vendor claimed

Asserted on privacy-security and platform pages; certificate not independently re-verified against a public registry for this entry.

Not found

No ISO 27001 claim found on privacy, compliance, or hosting pages.

SOC 2 / SOC 3
Vendor claimed

Vendor claims SOC 2 (comparison content references type II) and SOC 2-certified infrastructure; obtain current report in diligence.

Not found

No SOC 2/3 report or claim found on public site.

HIPAA / BAA
Vendor claimed

HIPAA-oriented offering with BAA on Enterprise path per vendor; not available on all plan tiers.

Not listed
GDPR / EU data protection
Vendor claimed

EU legal entity, residency options, consent tooling, anonymization, and DPA. Compliance depends on customer configuration and purposes.

Vendor claimed

Vendor documents GDPR-oriented design (cookieless, data minimisation, EU primary host, deletion). Not independent certification.

US CLOUD Act exposure (indicative)
Partial

No known US parent (Polish SA). Medium exposure due to Microsoft Azure as public/private cloud subprocessor and optional US region; Elastx Sweden is EU-operated alternative. Not legal advice.

Partial

UK operator, no known US parent, primary host Hetzner DE; partial exposure via Cloudflare, Sentry, Lemon Squeezy/Paddle, optional IPinfo and opt-in US AI APIs. Not legal advice.

Data processing agreement (B2B)
Vendor claimed

Business DPA linked from Business plan signup (piwik.pro/business-dpa/); Enterprise contracts expand terms.

Not found

No public DPA/downloadable processor agreement found; ask the vendor before B2B rollout.

EU AI Act
Not applicable

Analytics/activation platform; not marketed as an AI system provider. Customer AI use of exported data is out of product scope.

Not applicable

Core product is analytics/monitoring; optional AI insights are secondary and opt-in.

Considerations & known limitations: Piwik PRO vs Tinylytics
Considerations & known limitationsLogo: Piwik PROPiwik PROLogo: TinylyticsTinylytics
US-group cloud (Azure) in hosting path
Medium

Even with EU region selection, Azure introduces US-group infrastructure risk. Pin region, review SCCs/subprocessors, and escalate if policy forbids US cloud groups entirely.

Not listed
Closed source and no classic self-host
Medium

Cannot independently audit full source or run fully air-gapped on customer iron. Private cloud still involves vendor-managed stack on Azure/Elastx.

Not listed
Certifications not independently verified here
Low

ISO 27001, SOC 2, and HIPAA are vendor-claimed. Request certificates/reports and BAA text before treating them as assured.

Not listed
Paid plans only after Core sunset
Low

Free Core has been discontinued; evaluation relies on trials and paid Business/Enterprise metering by actions/domains.

Not listed
Compliance depends on configuration
Medium

Anonymous modes and CNIL exemption require correct setup and purpose limitation. Misconfiguration can recreate the same legal exposure teams left GA to avoid.

Not listed
US-group subprocessors on the data pathNot listed
Medium

Cloudflare, Sentry, payment processors (incl. Lemon Squeezy/Stripe group), optional IPinfo and opt-in xAI/Gemini mean the stack is not EU-only end-to-end despite Hetzner primary storage.

Solo-founder operational concentrationNot listed
Medium

Service is provided by Vincent Ritter Consulting / a solo developer. Support is personal and fast for indies, but bus-factor and formal SLA expectations differ from larger vendors.

No public ISO/SOC/audit or DPA packNot listed
Medium

Enterprise security questionnaires will hit gaps until the vendor supplies audits and a B2B DPA under NDA or email.

Scale and feature boundariesNot listed
Low

Content crawls are depth/page limited; event tracking is beta; fair-usage applies to extreme hit volumes; no self-host escape hatch.

Optional AI shares aggregated analyticsNot listed
Low

AI Insights and related AI spell-check are opt-in and send aggregated (not visitor PII per vendor) data to third-party AI providers—leave disabled under strict AI policies.

Fit

Piwik PRO

Best fit when

  • Regulated marketing/analytics teams that want one suite for measurement, consent, tags, and activation under a Polish legal entity
  • Public sector and EU enterprises that need selectable EU residency (e.g. Elastx Sweden or Azure NL/DE) plus a formal B2B DPA
  • Healthcare digital teams evaluating HIPAA-aware analytics with a signed BAA on Enterprise
  • Organizations leaving GA4 primarily for residency, no vendor ad-network reuse, and anonymous pre-consent measurement options
  • Teams that need enterprise reporting depth (custom reports, funnels, flows, attribution) beyond lightweight privacy analytics

Poor fit when

  • Buyers who mandate fully self-hosted open-source analytics with no cloud hypervisor vendor
  • Sites that only need simple cookieless page analytics without tag management or activation
  • Teams that refuse any US-group infrastructure (Azure appears in public hosting options even when EU regions are chosen)
  • Orgs seeking a free forever analytics tier (Core plan sunset; paid Business/Enterprise only)

Consider instead when

  • When: You need open-source code and true on-premises control

    Consider: Matomo (self-host) or Friendly Analytics / Matomo by Stackhero for managed Matomo

    Piwik PRO is proprietary cloud/private-cloud only.

  • When: You want minimal, cookieless EU analytics without enterprise suite complexity

    Consider: Plausible Analytics or Simple Analytics

    Far smaller feature surface; no HIPAA/CDP-style activation packaging.

  • When: You need a German enterprise analytics vendor with long public-sector presence

    Consider: etracker

    Different product depth and packaging—compare consent tooling and activation needs.

Tinylytics

Best fit when

  • Indie blogs, portfolios, and side projects that want simple cookieless stats without Google Analytics
  • Small sites that also want uptime, SSL expiry, and broken-link checks in the same tool
  • Operators who prefer founder-answered support and lightweight embeds over enterprise marketing stacks
  • Teams OK with managed EU primary hosting and willing to review named US-group subprocessors (CDN, payments, optional AI)
  • Agencies managing a modest number of client sites with public stats or kudos-style engagement widgets

Poor fit when

  • Orgs that require self-hosted collectors or open-source audit of the full analytics stack
  • Procurement needing published ISO 27001, SOC 2, independent audits, or a downloadable DPA out of the box
  • Very high-traffic properties needing contractual capacity/SLA commitments beyond fair-usage conversation
  • Policies that ban Cloudflare/Sentry/US payment or optional US AI APIs on any data path
  • Teams that need session replay, heatmaps, or deep advertising attribution (Clarity/GA territory)

Consider instead when

  • When: You need open-source and optional self-hosting of the analytics stack

    Consider: Plausible Analytics

    Estonian product with Cloud plus Community Edition self-host; less bundling of uptime/content monitors.

  • When: You want European cookieless analytics with a simpler analytics-only scope

    Consider: Simple Analytics

    Strong privacy positioning; compare feature depth and monitoring separately.

  • When: You need free-at-scale marketing analytics, ads integrations, or attribution depth

    Consider: Google Analytics (incumbent) — or stay on a privacy tool if GA is disallowed

    Different privacy and sovereignty profile entirely.

  • When: You need session replay or heatmaps and accept that privacy model

    Consider: Microsoft Clarity or specialised replay tools

    Tinylytics deliberately avoids fingerprinting-style session products.

Open questions for due diligence

Piwik PRO

  • What exact subprocessor list and backup/DR locations apply to the contracted region (Azure vs Elastx) today?
  • Can the vendor provide current ISO 27001 certificate scope and SOC 2 Type II report under NDA?
  • For healthcare: which plan tier, region, and BAA wording cover the intended PHI workflows?
  • Does the Business Swedish hosting path avoid Azure entirely for production data, or only for selected components?
  • What residual free/legacy Core accounts remain, and what is the migration deadline for this tenant?

Tinylytics

  • Will Vincent Ritter Consulting sign a GDPR Article 28 DPA and provide a current subprocessor list under contract?
  • Are backups/DR and email delivery fully covered by the named providers, or are there additional hosts?
  • Is there any roadmap for independent security review, SOC 2, or ISO 27001?
  • What contractual terms apply for accounts consistently above the fair-usage hit threshold?
  • For AI Insights: exact retention, regions, and processor terms at xAI and Google for the paid API plans used?