Logo: Stormly

Stormly

Dutch SaaS product analytics for e-commerce teams: SKU-aware reports, AI-assisted anomaly and root-cause insights, and Shopify/Adobe Commerce/Segment/GTM-oriented connections under Monon B.V. (Amsterdam).

Stormly is a SaaS product-analytics platform built for e-commerce teams. It is operated by Monon B.V. in Amsterdam under Dutch law. Merchandising, product, UX, and growth teams connect shop data and use e-commerce-oriented reports plus an AI agent that surfaces trends and anomalies.

It exists to turn store and product event data into ready answers rather than another blank event warehouse. Typical setup is connect data, pick reports, then receive automated insights, often in the inbox.

The concrete differentiator is that SKU-aware e-commerce reporting with one-click style connections for Shopify, Adobe Commerce, Segment, and Google Tag Manager.

E-commerce product analyticsSKU-aware reportsAI anomaly insightsShopify / Adobe CommerceNL entity + public DPASaaS (not self-host)

Shortlist Stormly when you need Dutch-contracted, e-commerce-first product analytics: SKU-aware report packs, Shopify/Adobe-oriented setup, inbox-style AI anomaly narratives, and a public DPA. Skip when you need cookieless privacy web stats only (consider Plausible, Simple Analytics, or Pirsch), open-source self-hosting, verified ISO/SOC on a public cert page, or a subprocessor chain free of US-group cloud and Azure OpenAI.

Key capabilities

Stormly positions an AI agent that watches connected e-commerce data for trends and anomalies (for example conversion drops or product spikes), then delivers plain-language findings—often to the inbox—with root-cause style exploration for questions like mobile conversion drops or regional return spikes. AI assistant access is plan-dependent; the public DPA documents Azure OpenAI (Microsoft) handling of assistant queries with a 30-day retention window and property stripping rules. Best for merchandising and growth leads who want narrative answers without waiting on a data team.

Ready reports target commerce questions: New Arrivals Performance (early SKU winners/laggards), Unviewed & Unsold Products, cart abandonment and revenue contribution by product/category, Conversion Journey and funnels by device/region, A/B test insights, Aha Moment Discovery, cross-selling analysis, and broader library items (retention, CLV, forecasting, SQL report, and more). Vendor materials state custom reports are included without a separate fee when a needed view is missing—useful for mid-market retailers that outgrow generic event charts.

Homepage setup emphasizes linking Shopify, Adobe Commerce, or Segment quickly, with Google Tag Manager also listed among integrations. The DPA describes additional programmatic paths (JS library, import, custom endpoints, third-party sources). Fits stores already on common commerce stacks; teams on exotic storefronts should validate event coverage and product-feed depth in a pilot before replacing an existing analytics stack.

Per the DPA, IP addresses for end-user analytics are not stored in full: the last octet is removed and geo/timezone are derived from the anonymized value. Web integrations automatically capture first-party cookie user ids, page/referrer/UTM context, and device metadata; app properties depend on client or CDP configuration. This is still full product analytics (not cookieless aggregate-only web stats)—clients remain responsible for consent banners and lawful basis for shopper tracking.

B2B buyers can download a Data Processing Agreement (effective 2023-09-06) and a Security Architecture page listing subprocessors, encryption expectations, backup retention (analytics backups up to six months), and logical tenant isolation. Contracts and DPA are governed by Dutch law with Amsterdam courts. Useful for EU procurement packages—but US-group subprocessors (AWS, Vultr, Azure OpenAI) still require transfer and CLOUD Act diligence.

At a glance

HQ / entity
Monon B.V., Amsterdam, Netherlands
Category
E-commerce product analytics (SaaS)
Hosting (public)
Hetzner; AWS EU-region backups; Vultr; Azure OpenAI EU region (vendor docs)
Open source
No
Self-host
No
Commercial model
Free tier + monthly plan + custom; trial path on paid
Governing law
Dutch law; Amsterdam courts

Best fit when

  • Merchandising, product, UX, and growth teams on Shopify or Adobe Commerce who need SKU, cart, and assortment analytics without a dedicated data science org
  • Retail brands that want ready e-commerce report templates (new arrivals, unviewed/unsold, funnels, A/B, aha moments) plus vendor-built custom reports
  • EU buyers who want a Dutch legal entity, Amsterdam courts, and a downloadable DPA/Security Architecture package
  • Teams that value AI-generated trend/anomaly narratives delivered to the inbox more than building every chart from a blank event schema
  • Stacks already using Segment or Google Tag Manager as the event pipe into analytics

Poor fit when

  • Publishers or marketing sites that only need lightweight privacy-friendly page analytics (not product/SKU depth)
  • Orgs that require open-source self-hosting or full control of a private analytics warehouse as the default
  • Procurement policies that forbid US-group subprocessors (AWS, Vultr, Microsoft Azure OpenAI) even when EU regions are claimed
  • Assurance programs that require public ISO 27001/SOC 2 evidence before pilot (not found on vendor pages reviewed)
  • Companies operating blockchain products/services—restricted by Stormly’s terms

Consider instead when

  • When: You only need privacy-oriented website metrics (pageviews, sources) rather than SKU-level product analytics

    Consider: Plausible Analytics, Simple Analytics, or Pirsch Analytics

    EU web-analytics peers; different category from e-commerce product analytics

  • When: You need deep general-purpose product analytics, large ecosystem, and mature multi-product SaaS event modeling

    Consider: Mixpanel or Amplitude

    US incumbents; stronger breadth, different jurisdiction and commercial model

  • When: You primarily need free/universal marketing acquisition reporting already embedded in the stack

    Consider: Google Analytics (incumbent) or dual-run GA for marketing + Stormly for product/merch

    GA is not SKU-first product analytics; Stormly is not a GA replacement for every report

Jurisdiction & ownership

Legal entity
Monon B.V. (Lutmastraat 1-3, 1072 JL Amsterdam; KvK 76248747 per Terms)
Governing law
Netherlands (Dutch law; Amsterdam courts)
US parent / control
No known US parent
CLOUD Act exposure (indicative)
Medium
Hosting / residency
Client analytics subprocessors (Security Architecture): Hetzner (EU); Amazon AWS (US company, vendor states EU regions only for encrypted analytics backups); Vultr (US company); Microsoft Azure OpenAI (US company, vendor states EU Azure region). Plans market EU data residency. Controller privacy policy also references Vultr/AWS for account data, AuthSMTP EU + Amazon SES USA for email, Stripe for payments; marketing site uses Google Analytics and Hotjar.

No known US parent; Dutch entity and contracts. CLOUD Act exposure is indicative medium because US-group providers (AWS, Vultr, Microsoft Azure, and historically SES/Stripe on the account path) appear in public docs despite EU residency marketing. Not legal advice.

  • Independent security / no-logs auditNot found
  • ISO 27001Not found
  • SOC 2 / SOC 3Not found
  • GDPR / EU data protectionVendor claimed
  • +3

Considerations & known limitations

  • MediumUS-group cloud and AI subprocessors

    Despite Dutch HQ and EU residency marketing, client data paths publicly include AWS, Vultr, and Microsoft Azure OpenAI. Transfer tooling (SCCs) and encryption of backups are documented, but CLOUD Act / US legal process risk remains a diligence item for sovereignty-sensitive buyers.

  • MediumNo public ISO/SOC or independent audit

    Enterprise security questionnaires may stall without ISO 27001/SOC 2 packs. DPA offers information/audit rights—plan time for NDA evidence requests.

  • MediumAzure OpenAI retains assistant context 30 days

    AI queries and aggregate report results are stored on Microsoft Azure OpenAI for 30 days per DPA. Property stripping reduces some identifiers, but misconfigured event properties could still expose sensitive content—govern AI use and property hygiene.

  • LowController privacy policy vs security architecture drift

    Privacy policy (controller, effective 2019) still emphasizes Vultr USA wording in places, while Security Architecture (client data) lists Hetzner/AWS/Vultr/Azure. Ask for a single current subprocessor and region matrix at contract time.

  • LowNot a privacy web-analytics substitute

    Full product analytics with cookies/identifiers for web integrations—not a cookieless aggregate counter. Consent UX remains on the client.

Open questions for due diligence

  • Can Stormly provide a current region map (which data classes live on Hetzner vs Vultr vs AWS) under NDA for our DPIA?
  • Are ISO 27001, SOC 2, or penetration-test summaries available on request for enterprise security review?
  • Which event properties from our Shopify/Adobe feed are excluded from Azure OpenAI prompts by default in our tenant?
  • Do custom report builds and SQL access sit only on the custom tier, and what SLAs apply?
  • Has the 2019 controller privacy policy been superseded for hosting wording relative to the Security Architecture list?

Frequently Asked Questions

Stormly is product analytics aimed at e-commerce teams—SKU and shopper-behavior reports, cart/revenue breakdowns, funnels, A/B insights, and an AI agent—not a minimal cookieless pageview counter. If you only need privacy-oriented website metrics (and self-host options in some cases), evaluate EU web-analytics tools such as Plausible, Simple Analytics, or Pirsch instead. If you need Mixpanel/Amplitude-style product analytics with a commerce-first report pack under a Dutch entity, Stormly is in the right category.

Monon B.V. (Amsterdam) is the contracting entity. For client analytics data, the Security Architecture lists Hetzner (EU), AWS (US company; vendor claims EU regions only for encrypted analytics backups), Vultr (US company), and Microsoft Azure OpenAI (US company; vendor claims EU Azure region for AI models). Marketing materials also advertise EU data residency on plans. Account/controller privacy text historically references Vultr/AWS for account storage and backups, EU/US email providers, and Stripe for payments. Treat residency marketing as compatible with US-group cloud and AI providers in the chain—ask for a current subprocessor list and region map in your DPA package.

When users run the AI assistant, the DPA states each query and related aggregate report results are stored on Microsoft Azure OpenAI platforms for 30 days. Documented handling shares event/user property names and contents in aggregate form while omitting a list of identifiers (for example user id, device advertising id, IP, user agent, share codes). Stormly warns clients not to send sensitive personal data via chat and notes that configuring tracking of certain PII can violate terms. Stormly also disclaims liability for Azure OpenAI outcomes—validate acceptable AI use with legal/security before enabling on production catalogs that may embed personal data in properties.

Yes—a downloadable DPA is linked from the legal area (PDF dated September 2023 in the public link reviewed), with SCCs language for restricted transfers and client audit rights described in the agreement. A Security Architecture page covers encryption, isolation, backups, and subprocessors. No public ISO 27001 or SOC 2 certificate or independent audit report was found on the official pages reviewed for this entry; assurance-heavy buyers should request evidence under NDA or via the DPA audit clause rather than assuming certification from EU HQ alone.

Stormly sells subscription SaaS: a free entry plan with limited event volume and basic journey/behavior reports, a higher self-serve/monthly plan with a trial path and broader AI assistant access, and a custom tier for unlimited saved reports, custom SQL/analytics, and dedicated support. Free setup/demo calls are offered. Event caps, AI entitlements, and report limits are the procurement-relevant constraints; confirm current plan matrices on the official pricing page and whether custom report builds are contractually included for your tier.

Skip or deprioritize if you need open-source self-hosting, pure privacy web analytics without product/SKU depth, or a subprocessor graph free of US-group hyperscalers and AI providers. Terms also state that companies using, operating on, or providing blockchain technology are not allowed to use the service. Very large multi-product SaaS orgs that need a deep general event taxonomy and mature reverse-ETL ecosystems may still shortlist Mixpanel/Amplitude alongside or instead of Stormly.