Stormly vs Trackboxx

Compare Stormly and Trackboxx on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Google Analytics

Logo: Stormly

Stormly

Netherlands· Web Analytics

Needs review

Shortlist Stormly when you need Dutch-contracted, e-commerce-first product analytics: SKU-aware report packs, Shopify/Adobe-oriented setup, inbox-style AI anomaly narratives, and a public DPA. Skip when you need cookieless privacy web stats only (consider Plausible, Simple Analytics, or Pirsch), open-source self-hosting, verified ISO/SOC on a public cert page, or a subprocessor chain free of US-group cloud and Azure OpenAI.

E-commerce product analyticsSKU-aware reportsAI anomaly insightsShopify / Adobe CommerceNL entity + public DPASaaS (not self-host)
Logo: Trackboxx

Trackboxx

Germany· Web Analytics

Needs review

Shortlist Trackboxx when you want German-operated, cookie-free hosted analytics with ecommerce and agency-friendly public dashboards. Skip when you need self-host/open-source control or GA-class product analytics—consider Plausible (self-host option) or Matomo instead.

Cookie-free trackingGermany-operatedFrankfurt analytics hostingE-commerce analyticsB2B DPA availableManaged SaaS
Stormly vs Trackboxx: Snapshot
FeatureLogo: StormlyStormlyLogo: TrackboxxTrackboxx
Country of originNetherlandsGermany
CategoryWeb AnalyticsWeb Analytics
Open sourceNoNo
Self-hostedNoNo
HeadquartersNetherlandsGermany
Legal entityMonon B.V. (Lutmastraat 1-3, 1072 JL Amsterdam; KvK 76248747 per Terms)Trackboxx / Christian Pust (sole trader imprint; Halberstadt seat, Grönwohld branch)
Governing lawNetherlands (Dutch law; Amsterdam courts)Not listed
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)MediumMedium
Hosting / residencyClient analytics subprocessors (Security Architecture): Hetzner (EU); Amazon AWS (US company, vendor states EU regions only for encrypted analytics backups); Vultr (US company); Microsoft Azure OpenAI (US company, vendor states EU Azure region). Plans market EU data residency. Controller privacy policy also references Vultr/AWS for account data, AuthSMTP EU + Amazon SES USA for email, Stripe for payments; marketing site uses Google Analytics and Hotjar.Visitor analytics: TK Enterprises Ltd infrastructure in First Colo Frankfurt. CDN: BunnyWay d.o.o. (Slovenia). Payments: Paddle.com Market Ltd (UK). Email/newsletters: Amazon SES (AWS; EU regions primary, possible US). Chat on marketing site: Userlike UG (Germany).
Summary

Dutch SaaS product analytics for e-commerce teams: SKU-aware reports, AI-assisted anomaly and root-cause insights, and Shopify/Adobe Commerce/Segment/GTM-oriented connections under Monon B.V. (Amsterdam).

German cookie-free web analytics SaaS: day-rotating hash tracking, ecommerce and UTM dashboards, hosted analytics in Frankfurt with a published B2B DPA.

Tags
At a glance: Stormly vs Trackboxx
At a glanceLogo: StormlyStormlyLogo: TrackboxxTrackboxx
HQ / entityMonon B.V., Amsterdam, NetherlandsNot listed
CategoryE-commerce product analytics (SaaS)Not listed
Hosting (public)Hetzner; AWS EU-region backups; Vultr; Azure OpenAI EU region (vendor docs)Not listed
Open sourceNoNo
Self-hostNoNo
Commercial modelFree tier + monthly plan + custom; trial path on paidPageview packages; free tier + trial; Paddle checkout
Governing lawDutch law; Amsterdam courtsNot listed
HQNot listedHalberstadt / Grönwohld, Germany
Legal entityNot listedTrackboxx / Christian Pust (imprint)
Product typeNot listedManaged web analytics SaaS
Analytics hostingNot listedFirst Colo, Frankfurt (via TK Enterprises Ltd)
Key capabilities: Stormly vs Trackboxx
Key capabilitiesLogo: StormlyStormlyLogo: TrackboxxTrackboxx
E-commerce product analyticsYesNot listed
SKU-aware reportsYesNot listed
AI anomaly insightsYesNot listed
Shopify / Adobe CommerceYesNot listed
NL entity + public DPAYesNot listed
SaaS (not self-host)YesYes
Cookie-free trackingNot listedYes
Germany-operatedNot listedYes
Frankfurt analytics hostingNot listedYes
E-commerce analyticsNot listedYes
B2B DPA availableNot listedYes

Stormly

  • AI agent for trends, anomalies, and root-cause style digs

    Stormly positions an AI agent that watches connected e-commerce data for trends and anomalies (for example conversion drops or product spikes), then delivers plain-language findings—often to the inbox—with root-cause style exploration for questions like mobile conversion drops or regional return spikes. AI assistant access is plan-dependent; the public DPA documents Azure OpenAI (Microsoft) handling of assistant queries with a 30-day retention window and property stripping rules. Best for merchandising and growth leads who want narrative answers without waiting on a data team.

  • SKU-aware e-commerce report library (plus custom builds)

    Ready reports target commerce questions: New Arrivals Performance (early SKU winners/laggards), Unviewed & Unsold Products, cart abandonment and revenue contribution by product/category, Conversion Journey and funnels by device/region, A/B test insights, Aha Moment Discovery, cross-selling analysis, and broader library items (retention, CLV, forecasting, SQL report, and more). Vendor materials state custom reports are included without a separate fee when a needed view is missing—useful for mid-market retailers that outgrow generic event charts.

  • Shopify, Adobe Commerce, Segment, and GTM-oriented connections

    Homepage setup emphasizes linking Shopify, Adobe Commerce, or Segment quickly, with Google Tag Manager also listed among integrations. The DPA describes additional programmatic paths (JS library, import, custom endpoints, third-party sources). Fits stores already on common commerce stacks; teams on exotic storefronts should validate event coverage and product-feed depth in a pilot before replacing an existing analytics stack.

  • End-user tracking with IP anonymization defaults

    Per the DPA, IP addresses for end-user analytics are not stored in full: the last octet is removed and geo/timezone are derived from the anonymized value. Web integrations automatically capture first-party cookie user ids, page/referrer/UTM context, and device metadata; app properties depend on client or CDP configuration. This is still full product analytics (not cookieless aggregate-only web stats)—clients remain responsible for consent banners and lawful basis for shopper tracking.

  • Public DPA, security architecture, and Dutch contracting

    B2B buyers can download a Data Processing Agreement (effective 2023-09-06) and a Security Architecture page listing subprocessors, encryption expectations, backup retention (analytics backups up to six months), and logical tenant isolation. Contracts and DPA are governed by Dutch law with Amsterdam courts. Useful for EU procurement packages—but US-group subprocessors (AWS, Vultr, Azure OpenAI) still require transfer and CLOUD Act diligence.

Trackboxx

  • Cookie-free day-hash session tracking

    No analytics cookies. Same-day visitor correlation uses hashes of IP, user agent, site ID, and a daily rotating signature (page hashes also include host/path). Hashes expire within 24 hours so multi-day visitor histories and IP recovery are not available by design.

  • Traffic, channel, and live visitor dashboards

    Dashboards cover visits, pageviews, bounce rate, dwell time, devices/browsers, geo down to city, channel mix including AI traffic, outbound link clicks, live visitors on a short refresh interval, and period-over-period comparisons without a heavy analyst UI.

  • E-commerce funnels and revenue breakdowns

    Shop metrics include products sold, cart abandonment, add-to-cart style signals, checkout funnel visibility, and revenue by channel and location—aimed at operators who need store KPIs without a full GA4 ecommerce implementation.

  • UTM, goals, GSC keywords, and public reports

    Campaign UTMs, conversion goals (including auto goals), optional Google Search Console keyword views, shareable public dashboards (URL or iframe), and PDF reports support marketers and agencies who need client-facing summaries.

  • CMS and shop plugins plus GA import

    Documented integrations include WordPress, Shopware, Shopify, JTL, and ePages. Help center also covers script install, excluding own IP/paths, ads tracking patterns, and importing historical Google Analytics data when migrating.

Assurance & compliance: Stormly vs Trackboxx
Assurance & complianceLogo: StormlyStormlyLogo: TrackboxxTrackboxx
Independent security / no-logs audit
Not found

Security Architecture describes encryption, monitoring, isolation, and vulnerability contact (security@stormly.com); no public third-party audit PDF found.

Not found

No public third-party audit PDF or cert registry entry found on primary pages.

ISO 27001
Not found

No public ISO 27001 certificate located on official legal/security pages reviewed.

Not found

No ISO 27001 claim found on imprint, help center, or DPA materials reviewed.

SOC 2 / SOC 3
Not found

No public SOC 2/3 report located on official pages reviewed.

Not found

No SOC 2/3 report referenced on public trust materials reviewed.

GDPR / EU data protection
Vendor claimed

NL entity; public privacy policy and DPA (GDPR-oriented); IP last-octet anonymization for end-user analytics; SCCs language for restricted transfers in DPA.

Vendor claimed

German controller imprint; cookie-free hash model; public DPA; processing described as EU/EEA. Vendor asserts DSGVO fitness—confirm with counsel for your site stack.

US CLOUD Act exposure (indicative)
Partial

EU entity / no known US parent, but public client subprocessors include AWS, Vultr, and Microsoft Azure OpenAI (US-group companies). Account path historically also lists Amazon SES and Stripe. Residency claims do not remove US-group legal exposure. Indicative only—not legal advice.

Partial

EU sole-trader operator, no known US parent; analytics hosting claimed in Frankfurt. Partial/medium because privacy policy names Amazon SES (AWS) for email with possible US transfers; payments via UK Paddle. Not legal advice.

Data processing agreement (B2B)
Vendor claimed

Downloadable DPA PDF linked from stormly.com/dpa (effective 6 September 2023); audit rights and subprocessor notice described; Security Architecture lists subprocessors.

Vendor claimed

Free AV/DPA offered at order and as PDF; annex lists hosting, Paddle, BunnyWay.

EU AI Act
Partial

Product includes an AI assistant via Azure OpenAI; not positioned as a high-risk AI system marketing claim. Buyers should map AI assistant use to their own AI Act / internal AI policy—vendor does not publish a full AI Act conformity package on the pages reviewed.

Not applicable

Web analytics SaaS; not an AI system product for AI Act high-risk classification purposes.

Considerations & known limitations: Stormly vs Trackboxx
Considerations & known limitationsLogo: StormlyStormlyLogo: TrackboxxTrackboxx
US-group cloud and AI subprocessors
Medium

Despite Dutch HQ and EU residency marketing, client data paths publicly include AWS, Vultr, and Microsoft Azure OpenAI. Transfer tooling (SCCs) and encryption of backups are documented, but CLOUD Act / US legal process risk remains a diligence item for sovereignty-sensitive buyers.

Not listed
No public ISO/SOC or independent audit
Medium

Enterprise security questionnaires may stall without ISO 27001/SOC 2 packs. DPA offers information/audit rights—plan time for NDA evidence requests.

Not listed
Azure OpenAI retains assistant context 30 days
Medium

AI queries and aggregate report results are stored on Microsoft Azure OpenAI for 30 days per DPA. Property stripping reduces some identifiers, but misconfigured event properties could still expose sensitive content—govern AI use and property hygiene.

Not listed
Controller privacy policy vs security architecture drift
Low

Privacy policy (controller, effective 2019) still emphasizes Vultr USA wording in places, while Security Architecture (client data) lists Hetzner/AWS/Vultr/Azure. Ask for a single current subprocessor and region matrix at contract time.

Not listed
Not a privacy web-analytics substitute
Low

Full product analytics with cookies/identifiers for web integrations—not a cookieless aggregate counter. Consent UX remains on the client.

Not listed
Consent banner claim is vendor legal opinionNot listed
Medium

Trackboxx argues legitimate interest and no opt-in for its cookie-free tracker alone, while noting some DPOs disagree. Other tags on the site can still force banners. Treat as diligence input, not a legal certificate.

Amazon SES on email pathNot listed
Medium

Privacy policy discloses AWS SES for system/newsletter email with possible US transfers. Distinct from Frankfurt analytics storage, but raises residual US-group process exposure for account communications.

No self-host editionNot listed
Low

Managed SaaS only. Policies that mandate customer-operated infrastructure need a different product.

No public ISO/SOC/independent auditNot listed
Medium

Procurement teams that require cert packs will need questionnaires, DPA annex review, and possibly NDA materials beyond the public site.

Same-day hash limits multi-day user journeysNot listed
Low

By design you cannot rebuild long-lived individual visitor histories across days. Teams needing identity-resolution analytics will find this a hard product limit.

Fit

Stormly

Best fit when

  • Merchandising, product, UX, and growth teams on Shopify or Adobe Commerce who need SKU, cart, and assortment analytics without a dedicated data science org
  • Retail brands that want ready e-commerce report templates (new arrivals, unviewed/unsold, funnels, A/B, aha moments) plus vendor-built custom reports
  • EU buyers who want a Dutch legal entity, Amsterdam courts, and a downloadable DPA/Security Architecture package
  • Teams that value AI-generated trend/anomaly narratives delivered to the inbox more than building every chart from a blank event schema
  • Stacks already using Segment or Google Tag Manager as the event pipe into analytics

Poor fit when

  • Publishers or marketing sites that only need lightweight privacy-friendly page analytics (not product/SKU depth)
  • Orgs that require open-source self-hosting or full control of a private analytics warehouse as the default
  • Procurement policies that forbid US-group subprocessors (AWS, Vultr, Microsoft Azure OpenAI) even when EU regions are claimed
  • Assurance programs that require public ISO 27001/SOC 2 evidence before pilot (not found on vendor pages reviewed)
  • Companies operating blockchain products/services—restricted by Stormly’s terms

Consider instead when

  • When: You only need privacy-oriented website metrics (pageviews, sources) rather than SKU-level product analytics

    Consider: Plausible Analytics, Simple Analytics, or Pirsch Analytics

    EU web-analytics peers; different category from e-commerce product analytics

  • When: You need deep general-purpose product analytics, large ecosystem, and mature multi-product SaaS event modeling

    Consider: Mixpanel or Amplitude

    US incumbents; stronger breadth, different jurisdiction and commercial model

  • When: You primarily need free/universal marketing acquisition reporting already embedded in the stack

    Consider: Google Analytics (incumbent) or dual-run GA for marketing + Stormly for product/merch

    GA is not SKU-first product analytics; Stormly is not a GA replacement for every report

Trackboxx

Best fit when

  • German/EU SMEs and agencies replacing cookie-heavy GA for simpler privacy-oriented traffic stats
  • Online shops that need cart abandonment and revenue-by-channel without a full GA4 ecommerce stack
  • Teams that want public dashboards or PDF reports for clients and partners
  • Sites prioritizing fuller capture when consent banners and blockers suppress third-party analytics
  • Operators who accept managed SaaS and pageview-based packaging over self-hosting

Poor fit when

  • Organizations that must self-host or run open-source analytics under their own keys
  • Product/growth teams needing session replay, heatmaps, or advanced funnel/experiment suites
  • Enterprises requiring published ISO/SOC audit packs and extensive SSO/export documentation before shortlist
  • Buyers who need multi-year individual visitor identity graphs rather than same-day hash sessions

Consider instead when

  • When: You need cookieless EU analytics with an official self-host path

    Consider: Plausible Analytics (Cloud or Community Edition)

    Trade Trackboxx ecommerce/plugin depth for open-source deployability.

  • When: You want maximal privacy minimalism and a very small surface area

    Consider: Simple Analytics

    Simpler feature set; less ecommerce and shop-plugin emphasis than Trackboxx.

  • When: You need deep self-hosted analytics or on-prem control

    Consider: Matomo or Piwik PRO-class platforms

    Heavier ops and UI; stronger fit for full data residency under your infrastructure.

  • When: You depend on Google Ads identity graphs, Audiences, and free unlimited scale

    Consider: Google Analytics

    Keep GA only with full consent/transfer diligence; not a privacy substitute for Trackboxx.

Open questions for due diligence

Stormly

  • Can Stormly provide a current region map (which data classes live on Hetzner vs Vultr vs AWS) under NDA for our DPIA?
  • Are ISO 27001, SOC 2, or penetration-test summaries available on request for enterprise security review?
  • Which event properties from our Shopify/Adobe feed are excluded from Azure OpenAI prompts by default in our tenant?
  • Do custom report builds and SQL access sit only on the custom tier, and what SLAs apply?
  • Has the 2019 controller privacy policy been superseded for hosting wording relative to the Security Architecture list?

Trackboxx

  • Is the DPA annex (subprocessors, TOMs) current relative to Amazon SES and any other processors used in production today?
  • What backup/DR locations and encryption practices apply beyond the First Colo Frankfurt statement?
  • Are enterprise SSO, data export APIs, or retention controls documented for larger buyers?
  • Has any independent penetration test or privacy audit been completed under NDA?