Publytics vs Stormly

Compare Publytics and Stormly on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Google Analytics

Logo: Publytics

Publytics

Italy· Web Analytics

Needs review

Shortlist when you need cookieless, unsampled publisher analytics with multi-site Network views and a public EU DPA from an Italian SaaS operator. Skip when you need self-hosting, product analytics at GA4/Adobe depth, or product-level ISO/SOC—consider Plausible (simpler privacy analytics / self-host options) or Matomo (self-host ownership) instead.

Cookieless trackingNo default samplingMulti-site NetworkEU-hosted (EuroVPS/Hetzner)Public B2B DPAPublisher-focused UX
Logo: Stormly

Stormly

Netherlands· Web Analytics

Needs review

Shortlist Stormly when you need Dutch-contracted, e-commerce-first product analytics: SKU-aware report packs, Shopify/Adobe-oriented setup, inbox-style AI anomaly narratives, and a public DPA. Skip when you need cookieless privacy web stats only (consider Plausible, Simple Analytics, or Pirsch), open-source self-hosting, verified ISO/SOC on a public cert page, or a subprocessor chain free of US-group cloud and Azure OpenAI.

E-commerce product analyticsSKU-aware reportsAI anomaly insightsShopify / Adobe CommerceNL entity + public DPASaaS (not self-host)
Publytics vs Stormly: Snapshot
FeatureLogo: PublyticsPublyticsLogo: StormlyStormly
Country of originItalyNetherlands
CategoryWeb AnalyticsWeb Analytics
Open sourceNoNo
Self-hostedNoNo
HeadquartersItalyNetherlands
Legal entityPublytics S.r.l. / Publytics SRL, Via Val Leventina 3 INT 1, 20148 Milan (MI), Italy (VAT IT13079420967)Monon B.V. (Lutmastraat 1-3, 1072 JL Amsterdam; KvK 76248747 per Terms)
Governing lawItaly / EU GDPR (processor under published DPA)Netherlands (Dutch law; Amsterdam courts)
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)LowMedium
Hosting / residencyAnalytics infrastructure subprocessors in public DPA: EuroVPS (Euclid Services Ltd, Cyprus) and Hetzner Online GmbH (Germany). Data policy/DPA: EU storage (NL, DE, FI; DPA also IT); no transfer outside the EU for analytics processing. Account path: Stripe (payments), Brevo/Sendinblue (email).Client analytics subprocessors (Security Architecture): Hetzner (EU); Amazon AWS (US company, vendor states EU regions only for encrypted analytics backups); Vultr (US company); Microsoft Azure OpenAI (US company, vendor states EU Azure region). Plans market EU data residency. Controller privacy policy also references Vultr/AWS for account data, AuthSMTP EU + Amazon SES USA for email, Stripe for payments; marketing site uses Google Analytics and Hotjar.
Summary

Cookieless web analytics SaaS for digital publishers: unsampled real-time and historical metrics, multi-site Network views, GA import, and EU-hosted measurement from an Italian company.

Dutch SaaS product analytics for e-commerce teams: SKU-aware reports, AI-assisted anomaly and root-cause insights, and Shopify/Adobe Commerce/Segment/GTM-oriented connections under Monon B.V. (Amsterdam).

Tags
At a glance: Publytics vs Stormly
At a glanceLogo: PublyticsPublyticsLogo: StormlyStormly
HQMilan, ItalyNot listed
Legal entityPublytics S.r.l. (VAT IT13079420967)Not listed
HostingEuroVPS + Hetzner (EU regions)Not listed
DeploymentManaged SaaS (not self-hosted)Not listed
Commercial modelPageview tiers; free trialFree tier + monthly plan + custom; trial path on paid
Open sourceNo (tracker uses MIT library code)No
HQ / entityNot listedMonon B.V., Amsterdam, Netherlands
CategoryNot listedE-commerce product analytics (SaaS)
Hosting (public)Not listedHetzner; AWS EU-region backups; Vultr; Azure OpenAI EU region (vendor docs)
Self-hostNot listedNo
Governing lawNot listedDutch law; Amsterdam courts
Key capabilities: Publytics vs Stormly
Key capabilitiesLogo: PublyticsPublyticsLogo: StormlyStormly
Cookieless trackingYesNot listed
No default samplingYesNot listed
Multi-site NetworkYesNot listed
EU-hosted (EuroVPS/Hetzner)YesNot listed
Public B2B DPAYesNot listed
Publisher-focused UXYesNot listed
E-commerce product analyticsNot listedYes
SKU-aware reportsNot listedYes
AI anomaly insightsNot listedYes
Shopify / Adobe CommerceNot listedYes
NL entity + public DPANot listedYes
SaaS (not self-host)Not listedYes

Publytics

  • Unsampled real-time and daily publisher metrics

    Dashboard and Real-time views show active users (including last-minute and 30-minute windows), top pages, sources, social referrals, and day trends—with minute-level trend comparison documented for real-time. Vendor states no default data sampling, so reports reflect full counted client-side traffic rather than GA-style estimates on large properties.

  • Multi-site Network mode for content portfolios

    Business and Enterprise plans can group properties into Networks (plan caps apply: e.g. up to three Networks on Business, unlimited on Enterprise). Network views mirror site dashboards with split-by-site filters, combined real-time tables, and PDF/CSV export across the portfolio—built for multi-brand publishers rather than single blogs.

  • Cookieless measurement with daily-rotating visitor hash

    Tracking avoids cookies and permanent device IDs. Per the DPA, IP and User-Agent are used only to derive a daily salted hash for unique visitors, then discarded; metrics stay aggregated (URL, referrer, browser/OS, device, country). Designed so many sites can skip consent banners for analytics alone—confirm with counsel for your jurisdictions and any custom IDs you add.

  • Historical import, custom events/dimensions, and API

    Import paths cover GA4 and other tools (Plausible/Fathom mentioned) with support-assisted finalization. Custom events, dimensions, and metrics scale by plan; REST API uses Sanctum Bearer tokens scoped to subscribed sites. Fits teams rebuilding GA-era reporting without rebuilding infrastructure.

  • AI referral traffic reporting

    Dedicated documentation for traffic referred from AI systems (ChatGPT, Gemini, Claude, Perplexity, Copilot, Mistral, Google AI Overviews, Deepseek, and others). Useful for publishers optimizing for answer-engine and AI-overview discovery alongside classic SEO sources.

Stormly

  • AI agent for trends, anomalies, and root-cause style digs

    Stormly positions an AI agent that watches connected e-commerce data for trends and anomalies (for example conversion drops or product spikes), then delivers plain-language findings—often to the inbox—with root-cause style exploration for questions like mobile conversion drops or regional return spikes. AI assistant access is plan-dependent; the public DPA documents Azure OpenAI (Microsoft) handling of assistant queries with a 30-day retention window and property stripping rules. Best for merchandising and growth leads who want narrative answers without waiting on a data team.

  • SKU-aware e-commerce report library (plus custom builds)

    Ready reports target commerce questions: New Arrivals Performance (early SKU winners/laggards), Unviewed & Unsold Products, cart abandonment and revenue contribution by product/category, Conversion Journey and funnels by device/region, A/B test insights, Aha Moment Discovery, cross-selling analysis, and broader library items (retention, CLV, forecasting, SQL report, and more). Vendor materials state custom reports are included without a separate fee when a needed view is missing—useful for mid-market retailers that outgrow generic event charts.

  • Shopify, Adobe Commerce, Segment, and GTM-oriented connections

    Homepage setup emphasizes linking Shopify, Adobe Commerce, or Segment quickly, with Google Tag Manager also listed among integrations. The DPA describes additional programmatic paths (JS library, import, custom endpoints, third-party sources). Fits stores already on common commerce stacks; teams on exotic storefronts should validate event coverage and product-feed depth in a pilot before replacing an existing analytics stack.

  • End-user tracking with IP anonymization defaults

    Per the DPA, IP addresses for end-user analytics are not stored in full: the last octet is removed and geo/timezone are derived from the anonymized value. Web integrations automatically capture first-party cookie user ids, page/referrer/UTM context, and device metadata; app properties depend on client or CDP configuration. This is still full product analytics (not cookieless aggregate-only web stats)—clients remain responsible for consent banners and lawful basis for shopper tracking.

  • Public DPA, security architecture, and Dutch contracting

    B2B buyers can download a Data Processing Agreement (effective 2023-09-06) and a Security Architecture page listing subprocessors, encryption expectations, backup retention (analytics backups up to six months), and logical tenant isolation. Contracts and DPA are governed by Dutch law with Amsterdam courts. Useful for EU procurement packages—but US-group subprocessors (AWS, Vultr, Azure OpenAI) still require transfer and CLOUD Act diligence.

Assurance & compliance: Publytics vs Stormly
Assurance & complianceLogo: PublyticsPublyticsLogo: StormlyStormly
Independent security / no-logs audit
Not found

Searched official site; no public third-party security or no-logs audit PDF found. DPA describes hashing and non-retention of raw IP/UA.

Not found

Security Architecture describes encryption, monitoring, isolation, and vulnerability contact (security@stormly.com); no public third-party audit PDF found.

ISO 27001
Not found

No Publytics product certificate found. Host EuroVPS markets ISO certifications; that is infrastructure provider scope, not Publytics certification.

Not found

No public ISO 27001 certificate located on official legal/security pages reviewed.

SOC 2 / SOC 3
Not found

No public SOC 2/3 report found on official Publytics pages.

Not found

No public SOC 2/3 report located on official pages reviewed.

GDPR / EU data protection
Vendor claimed

Italian controller/processor entity; cookieless design; public Art. 28 DPA; EU hosting named. Not legal advice.

Vendor claimed

NL entity; public privacy policy and DPA (GDPR-oriented); IP last-octet anonymization for end-user analytics; SCCs language for restricted transfers in DPA.

US CLOUD Act exposure (indicative)
Partial

EU entity, no known US parent; analytics hosts EuroVPS + Hetzner in EU with DPA no third-country transfer for service data. Account billing via Stripe (US company). Not a vendor 'safe' claim—EuropeanStack assessment only.

Partial

EU entity / no known US parent, but public client subprocessors include AWS, Vultr, and Microsoft Azure OpenAI (US-group companies). Account path historically also lists Amazon SES and Stripe. Residency claims do not remove US-group legal exposure. Indicative only—not legal advice.

Data processing agreement (B2B)
Vendor claimed

Full public DPA at https://publytics.net/dpa with Annex B subprocessors and Annex C security/transfer instructions.

Vendor claimed

Downloadable DPA PDF linked from stormly.com/dpa (effective 6 September 2023); audit rights and subprocessor notice described; Security Architecture lists subprocessors.

EU AI Act
Not applicable

Web analytics product; AI-referral reporting is measurement of referrers, not an AI system product.

Partial

Product includes an AI assistant via Azure OpenAI; not positioned as a high-risk AI system marketing claim. Buyers should map AI assistant use to their own AI Act / internal AI policy—vendor does not publish a full AI Act conformity package on the pages reviewed.

Considerations & known limitations: Publytics vs Stormly
Considerations & known limitationsLogo: PublyticsPublyticsLogo: StormlyStormly
SaaS-only (no self-host)
Medium

All measurement depends on Publytics cloud availability and vendor roadmap. Teams with residency or air-gap requirements need Matomo/Plausible CE-style self-host alternatives.

Not listed
No public independent security audit
Medium

Hashing and non-retention claims are first-party (DPA/docs). No public third-party audit was found—enterprise security reviews will need questionnaires, DPA audit rights, and possibly NDA materials.

Not listed
Feature depth tied to pageview tiers
Low

Networks, API rate limits, custom dimensions/metrics, retention years, and time granularity differ by Lite/Business/Enterprise. Validate limits against portfolio size before migration.

Not listed
US payment processor on account path
Low

Stripe processes payments (US company). Separate from DPA Annex B analytics hosts, but relevant if procurement treats all vendor SaaS touchpoints as in-scope for CLOUD Act diligence.

Not listed
Customer-injected identifiers can re-identify
Medium

DPA warns controllers not to inject unique user IDs that re-identify visitors via the script. Misconfiguration can undermine the cookieless privacy model.

Not listed
US-group cloud and AI subprocessorsNot listed
Medium

Despite Dutch HQ and EU residency marketing, client data paths publicly include AWS, Vultr, and Microsoft Azure OpenAI. Transfer tooling (SCCs) and encryption of backups are documented, but CLOUD Act / US legal process risk remains a diligence item for sovereignty-sensitive buyers.

No public ISO/SOC or independent auditNot listed
Medium

Enterprise security questionnaires may stall without ISO 27001/SOC 2 packs. DPA offers information/audit rights—plan time for NDA evidence requests.

Azure OpenAI retains assistant context 30 daysNot listed
Medium

AI queries and aggregate report results are stored on Microsoft Azure OpenAI for 30 days per DPA. Property stripping reduces some identifiers, but misconfigured event properties could still expose sensitive content—govern AI use and property hygiene.

Controller privacy policy vs security architecture driftNot listed
Low

Privacy policy (controller, effective 2019) still emphasizes Vultr USA wording in places, while Security Architecture (client data) lists Hetzner/AWS/Vultr/Azure. Ask for a single current subprocessor and region matrix at contract time.

Not a privacy web-analytics substituteNot listed
Low

Full product analytics with cookies/identifiers for web integrations—not a cookieless aggregate counter. Consent UX remains on the client.

Fit

Publytics

Best fit when

  • Content publishers and media sites that want GA3-style reporting without cookies or default sampling
  • Multi-brand portfolios that need Network dashboards, split-by-site filters, and shared exports
  • Teams migrating historical series from GA4 (or Plausible/Fathom) into a privacy-oriented SaaS
  • EU-oriented controllers who want Italian legal entity, published DPA, and EU infrastructure subprocessors named in annexes
  • Editorial/SEO leads who need real-time active users, sources, and AI-referral reporting without operating self-hosted analytics

Poor fit when

  • Organizations that require self-hosted or open-source analytics only
  • Product/growth teams that need GA4/Adobe-class event modeling, experiment stacks, and ads ecosystem integrations
  • Buyers that need verified product ISO 27001/SOC 2 certificates before shortlist (none found for Publytics itself)
  • Very simple single-site blogs that only need minimal privacy metrics—lighter tools may be enough

Consider instead when

  • When: You want open-core privacy analytics with optional self-host

    Consider: Plausible Analytics

    Simpler surface; stronger self-host/open-core path than Publytics SaaS-only model

  • When: You must run analytics on your own infrastructure

    Consider: Matomo (self-host) or Plausible Community Edition

    Publytics is managed cloud only—no official on-prem product

  • When: You need deep product analytics and marketing stack integration

    Consider: Google Analytics or Adobe Analytics

    Trade privacy/EU-hosting priorities for ecosystem breadth

Stormly

Best fit when

  • Merchandising, product, UX, and growth teams on Shopify or Adobe Commerce who need SKU, cart, and assortment analytics without a dedicated data science org
  • Retail brands that want ready e-commerce report templates (new arrivals, unviewed/unsold, funnels, A/B, aha moments) plus vendor-built custom reports
  • EU buyers who want a Dutch legal entity, Amsterdam courts, and a downloadable DPA/Security Architecture package
  • Teams that value AI-generated trend/anomaly narratives delivered to the inbox more than building every chart from a blank event schema
  • Stacks already using Segment or Google Tag Manager as the event pipe into analytics

Poor fit when

  • Publishers or marketing sites that only need lightweight privacy-friendly page analytics (not product/SKU depth)
  • Orgs that require open-source self-hosting or full control of a private analytics warehouse as the default
  • Procurement policies that forbid US-group subprocessors (AWS, Vultr, Microsoft Azure OpenAI) even when EU regions are claimed
  • Assurance programs that require public ISO 27001/SOC 2 evidence before pilot (not found on vendor pages reviewed)
  • Companies operating blockchain products/services—restricted by Stormly’s terms

Consider instead when

  • When: You only need privacy-oriented website metrics (pageviews, sources) rather than SKU-level product analytics

    Consider: Plausible Analytics, Simple Analytics, or Pirsch Analytics

    EU web-analytics peers; different category from e-commerce product analytics

  • When: You need deep general-purpose product analytics, large ecosystem, and mature multi-product SaaS event modeling

    Consider: Mixpanel or Amplitude

    US incumbents; stronger breadth, different jurisdiction and commercial model

  • When: You primarily need free/universal marketing acquisition reporting already embedded in the stack

    Consider: Google Analytics (incumbent) or dual-run GA for marketing + Stormly for product/merch

    GA is not SKU-first product analytics; Stormly is not a GA replacement for every report

Open questions for due diligence

Publytics

  • Will Publytics provide completed security questionnaire, pen-test summary, or ISO evidence under NDA for enterprise procurement?
  • Exact current pageview tier limits, Network caps, and retention for the sites you will migrate?
  • Is GA4 historical import complete for your property structure (events, custom dimensions) or only core traffic series?
  • How are subprocessors for account services (Stripe, Brevo) contractually covered relative to the analytics DPA annex?
  • Any planned US or non-EU hosting options that would change the current EU-only transfer instruction?

Stormly

  • Can Stormly provide a current region map (which data classes live on Hetzner vs Vultr vs AWS) under NDA for our DPIA?
  • Are ISO 27001, SOC 2, or penetration-test summaries available on request for enterprise security review?
  • Which event properties from our Shopify/Adobe feed are excluded from Azure OpenAI prompts by default in our tenant?
  • Do custom report builds and SQL access sit only on the custom tier, and what SLAs apply?
  • Has the 2019 controller privacy policy been superseded for hosting wording relative to the Security Architecture list?