Use case · EU businesses

GDPR-compliant analytics for EU businesses: what actually matters

GDPR-compliant analytics for an EU business means two separate things: under the ePrivacy rules, not storing or reading identifiers on visitors' devices without consent (so cookieless tracking can run without a banner), and under GDPR, processing as little personal data as possible, with a lawful basis, a DPA and a way to honor deletion requests. No tool is "compliant" on its own — your configuration and privacy notice matter too.

Updated

European businesses face two rulebooks. The ePrivacy Directive (implemented nationally, e.g. PECR in the UK, TTDSG/TDDDG in Germany) requires consent before storing or reading information on a device unless it's strictly necessary — which is why cookie-based analytics usually needs a banner. GDPR then governs any processing of personal data, including IP addresses, wherever it happens.

VisitTrack is designed around both. In cookieless mode nothing is stored on the device: the visitor id is a server-side hash of site, IP and user agent with a salt that rotates daily, and the IP is never stored. Data lives in VisitTrack's databases on EU infrastructure, a DPA is available at /dpa, and personal data you add yourself (identify traits) can be deleted per person. This page is general information, not legal advice.

What EU businesses should check in any analytics tool

  1. 1.Does it store or read anything on the device?

    That's the ePrivacy question. Cookies, localStorage and fingerprinting all count. VisitTrack's cookieless mode writes nothing — no cookie, no localStorage, no sessionStorage.

  2. 2.What personal data is stored, and for how long?

    IP addresses, user ids and traits are personal data. VisitTrack never stores IPs; identify traits are only stored if you send them, are never shown on public dashboards, and can be deleted per person.

  3. 3.Where is the data processed?

    VisitTrack stores analytics data in its own databases on EU infrastructure. The IP-to-location lookup is the one step that uses a geolocation provider.

  4. 4.Is there a DPA and a sub-processor list?

    Under GDPR Article 28 you need a data processing agreement with your analytics processor. VisitTrack publishes one at /dpa; see also /gdpr.

  5. 5.What do you lose without a stored identifier?

    In cookieless mode, returning visitors after 24 hours count as new, and multi-day journeys and attribution are limited — unless your app sends the first touch back at signup. Know the trade-off before choosing.

Questions EU businesses ask about analytics

Can we remove the cookie banner?
For analytics, cookieless mode is designed to run without consent under ePrivacy, because nothing is stored or read on the device. Any other cookies you set (ads, chat widgets, embeds) still need their own assessment.
Is Google Analytics legal in the EU?
Several EU data-protection authorities (Austria, France, Italy) ruled in 2022 that specific Google Analytics setups breached GDPR transfer rules. The EU–US Data Privacy Framework adopted in July 2023 changed the transfer picture for certified US companies, but GA4 still uses cookies and generally needs consent. Check current guidance with your counsel.
What about visitors outside the EU?
Hybrid mode applies cookieless tracking to visitors in the EU/EEA, UK and Switzerland (and anyone whose location can't be determined), and standard tracking for everyone else.
How do we handle a deletion request?
Delete the person from the People tab or via the API with a write key; their user id and traits are removed from every visitor record and the deletion is logged in Settings → Activity.

How to set up GDPR-friendly analytics with VisitTrack

  1. Choose a tracking mode

    Settings → General → Tracking mode: cookieless (nothing stored anywhere), hybrid (cookieless in the EU/EEA, UK and Switzerland) or standard (a first-party _vt_vid cookie — generally needs consent in the EU). The server enforces the site-wide mode for every script tag. See cookieless mode.

    <script defer data-site="SITE_ID" data-cookieless src="https://visitrack.app/tracker.js"></script>
  2. If you choose hybrid, add the attribute

    data-hybrid makes the script store nothing until the server has checked the visitor's country.

    <script defer data-site="SITE_ID" data-hybrid src="https://visitrack.app/tracker.js"></script>
  3. Keep attribution across days without cookies

    Add a hidden data-vt-first-touch field to signup forms, or read window.visitrack.attribution(), and send the first touch back at signup. Payments are then credited to the original source even though nothing was stored on the device.

  4. Sign the DPA and update your privacy notice

    Review the DPA, list VisitTrack as a processor in your privacy policy, and describe what's collected (paths, referrers, UTMs, approximate location, device type — see /gdpr).

  5. Be deliberate with personal data

    Only send identify traits you need, mask personal text if you enable session replays (form fields are always masked), and keep replays' 30-day automatic deletion in mind for your records of processing.

Example: switching a German online shop from GA4 to cookieless analytics

A shop that showed a consent banner; roughly half of visitors declined analytics cookies.

Example: switching a German online shop from GA4 to cookieless analytics
MetricValueWhat it tells you
Visitors measured before (GA4, after consent)~11,000/monthOnly visitors who accepted cookies
Visitors measured after (cookieless)~22,500/monthEveryone, bots filtered out
Consent bannerKept only for ad pixelsAnalytics no longer needs consent
Returning-visitor shareLower than beforeCookieless counts returns after 24 h as new
Attributed revenueWithin the same dayPlus cross-day via first touch captured at checkout
Personal data stored by analyticsNone by defaultNo IPs; traits only if the shop sends them

Illustrative numbers for a typical site of this kind, not real customer data.

The shop sees roughly twice as many visitors — not because traffic grew, but because declined-consent visitors were invisible before. The trade-off is weaker multi-day visitor history, which the first-touch handoff at checkout recovers for the decisions that matter.

VisitTrack vs GA4, Matomo and Plausible for EU compliance

Third-party details as of October 2026; this is not legal advice.

VisitTrack vs GA4, Matomo and Plausible for EU compliance
VisitTrackGA4MatomoPlausible
Stores identifiers on the deviceNot in cookieless modeYes (cookies)Configurable (cookieless option)No
Consent banner for analyticsNot needed in cookieless modeGenerally needed in the EUNot needed in its cookieless configurationNot needed
IP storageNever storedNot logged or stored (per Google)Configurable anonymizationNot stored
Data locationEU infrastructureGoogle infrastructureSelf-hosted or Matomo Cloud (EU)EU
Self-hostingNoNoYesCommunity Edition

If you need full data sovereignty on your own servers, self-hosted Matomo is the established choice. If you want hosted, cookieless analytics with revenue attribution, VisitTrack fits. See VisitTrack vs Matomo, vs Plausible and the cookie banner checker.

What VisitTrack costs for an EU business

Cookieless mode often reveals more traffic than consent-gated tools reported — budget from your server logs or a week of cookieless data.

VisitTrack pricing by traffic profile
ProfileEvents / monthPlanPriceNotes
Small business site~9,000Up to 10k events/mo$5/mo or $50/yrA few thousand visitors
Online shop~140,000Up to 250k events/mo$29/mo or $290/yr~25k visitors
Mid-size company, several sites~950,000Up to 1M events/mo$59/mo or $590/yrCorporate site, shop, blog

Every feature is on every plan; the price only follows monthly events (pageviews, custom events and payments, counted across all your sites). Bot and AI-crawler hits and session replays are never billed. Yearly billing is ten months' price for twelve, every plan starts with a 14-day free trial with no card, and there's a one-time lifetime deal from $59.

Frequently asked questions

Is VisitTrack GDPR compliant?

VisitTrack is built for GDPR: it never stores IP addresses, stores data on EU infrastructure, offers a DPA, and supports per-person deletion. Compliance also depends on your configuration and privacy notice, so review both with counsel.

Do I need a cookie banner for VisitTrack?

Not in cookieless mode, which stores and reads nothing on the visitor's device — the trigger for consent under the ePrivacy Directive. Standard mode uses a first-party cookie and generally needs consent in the EU. General information, not legal advice.

Where is VisitTrack data stored?

In VisitTrack's own PostgreSQL databases on EU infrastructure. Data is never sold, never shared with ad networks and never used to train models.

What is hybrid mode?

A tracking mode that is cookieless for visitors in the EU/EEA, UK and Switzerland — and anyone whose location can't be determined — and stores a first-party id for everyone else, so you keep multi-day journeys outside Europe.

How accurate is cookieless analytics?

Pageviews, sources, pages, countries, devices, events, goals and funnels are fully accurate. Unique visitors are accurate within a day; returning visitors after 24 hours count as new, and cross-domain tracking isn't available.

Can I honor a GDPR erasure request?

Yes. Delete the person in the People tab or with the API; their user id and traits are removed from all visitor records, while anonymous traffic totals stay unchanged.

Does VisitTrack use fingerprinting?

No persistent fingerprint is created. In cookieless mode a server-side hash of site, IP and user agent with a salt that changes daily gives a same-day visitor id; the inputs aren't stored and ids can't be linked across days.

Related

See which channels actually bring paying customers

VisitTrack is cookie-free analytics with revenue attribution built in. One script tag, no consent banner, live in two minutes. 14 days free, no card required.