Use case · EU businesses
GDPR-compliant analytics for EU businesses: what actually matters
Updated
European businesses face two rulebooks. The ePrivacy Directive (implemented nationally, e.g. PECR in the UK, TTDSG/TDDDG in Germany) requires consent before storing or reading information on a device unless it's strictly necessary — which is why cookie-based analytics usually needs a banner. GDPR then governs any processing of personal data, including IP addresses, wherever it happens.
VisitTrack is designed around both. In cookieless mode nothing is stored on the device: the visitor id is a server-side hash of site, IP and user agent with a salt that rotates daily, and the IP is never stored. Data lives in VisitTrack's databases on EU infrastructure, a DPA is available at /dpa, and personal data you add yourself (identify traits) can be deleted per person. This page is general information, not legal advice.
What EU businesses should check in any analytics tool
1.Does it store or read anything on the device?
That's the ePrivacy question. Cookies, localStorage and fingerprinting all count. VisitTrack's cookieless mode writes nothing — no cookie, no localStorage, no sessionStorage.
2.What personal data is stored, and for how long?
IP addresses, user ids and traits are personal data. VisitTrack never stores IPs; identify traits are only stored if you send them, are never shown on public dashboards, and can be deleted per person.
3.Where is the data processed?
VisitTrack stores analytics data in its own databases on EU infrastructure. The IP-to-location lookup is the one step that uses a geolocation provider.
4.Is there a DPA and a sub-processor list?
Under GDPR Article 28 you need a data processing agreement with your analytics processor. VisitTrack publishes one at /dpa; see also /gdpr.
5.What do you lose without a stored identifier?
In cookieless mode, returning visitors after 24 hours count as new, and multi-day journeys and attribution are limited — unless your app sends the first touch back at signup. Know the trade-off before choosing.
Questions EU businesses ask about analytics
- Can we remove the cookie banner?
- For analytics, cookieless mode is designed to run without consent under ePrivacy, because nothing is stored or read on the device. Any other cookies you set (ads, chat widgets, embeds) still need their own assessment.
- Is Google Analytics legal in the EU?
- Several EU data-protection authorities (Austria, France, Italy) ruled in 2022 that specific Google Analytics setups breached GDPR transfer rules. The EU–US Data Privacy Framework adopted in July 2023 changed the transfer picture for certified US companies, but GA4 still uses cookies and generally needs consent. Check current guidance with your counsel.
- What about visitors outside the EU?
- Hybrid mode applies cookieless tracking to visitors in the EU/EEA, UK and Switzerland (and anyone whose location can't be determined), and standard tracking for everyone else.
- How do we handle a deletion request?
- Delete the person from the People tab or via the API with a write key; their user id and traits are removed from every visitor record and the deletion is logged in Settings → Activity.
How to set up GDPR-friendly analytics with VisitTrack
Choose a tracking mode
Settings → General → Tracking mode: cookieless (nothing stored anywhere), hybrid (cookieless in the EU/EEA, UK and Switzerland) or standard (a first-party
_vt_vidcookie — generally needs consent in the EU). The server enforces the site-wide mode for every script tag. See cookieless mode.<script defer data-site="SITE_ID" data-cookieless src="https://visitrack.app/tracker.js"></script>If you choose hybrid, add the attribute
data-hybridmakes the script store nothing until the server has checked the visitor's country.<script defer data-site="SITE_ID" data-hybrid src="https://visitrack.app/tracker.js"></script>Keep attribution across days without cookies
Add a hidden
data-vt-first-touchfield to signup forms, or readwindow.visitrack.attribution(), and send the first touch back at signup. Payments are then credited to the original source even though nothing was stored on the device.Be deliberate with personal data
Only send identify traits you need, mask personal text if you enable session replays (form fields are always masked), and keep replays' 30-day automatic deletion in mind for your records of processing.
Example: switching a German online shop from GA4 to cookieless analytics
A shop that showed a consent banner; roughly half of visitors declined analytics cookies.
| Metric | Value | What it tells you |
|---|---|---|
| Visitors measured before (GA4, after consent) | ~11,000/month | Only visitors who accepted cookies |
| Visitors measured after (cookieless) | ~22,500/month | Everyone, bots filtered out |
| Consent banner | Kept only for ad pixels | Analytics no longer needs consent |
| Returning-visitor share | Lower than before | Cookieless counts returns after 24 h as new |
| Attributed revenue | Within the same day | Plus cross-day via first touch captured at checkout |
| Personal data stored by analytics | None by default | No IPs; traits only if the shop sends them |
Illustrative numbers for a typical site of this kind, not real customer data.
The shop sees roughly twice as many visitors — not because traffic grew, but because declined-consent visitors were invisible before. The trade-off is weaker multi-day visitor history, which the first-touch handoff at checkout recovers for the decisions that matter.
VisitTrack vs GA4, Matomo and Plausible for EU compliance
Third-party details as of October 2026; this is not legal advice.
| VisitTrack | GA4 | Matomo | Plausible | |
|---|---|---|---|---|
| Stores identifiers on the device | Not in cookieless mode | Yes (cookies) | Configurable (cookieless option) | No |
| Consent banner for analytics | Not needed in cookieless mode | Generally needed in the EU | Not needed in its cookieless configuration | Not needed |
| IP storage | Never stored | Not logged or stored (per Google) | Configurable anonymization | Not stored |
| Data location | EU infrastructure | Google infrastructure | Self-hosted or Matomo Cloud (EU) | EU |
| Self-hosting | No | No | Yes | Community Edition |
If you need full data sovereignty on your own servers, self-hosted Matomo is the established choice. If you want hosted, cookieless analytics with revenue attribution, VisitTrack fits. See VisitTrack vs Matomo, vs Plausible and the cookie banner checker.
What VisitTrack costs for an EU business
Cookieless mode often reveals more traffic than consent-gated tools reported — budget from your server logs or a week of cookieless data.
| Profile | Events / month | Plan | Price | Notes |
|---|---|---|---|---|
| Small business site | ~9,000 | Up to 10k events/mo | $5/mo or $50/yr | A few thousand visitors |
| Online shop | ~140,000 | Up to 250k events/mo | $29/mo or $290/yr | ~25k visitors |
| Mid-size company, several sites | ~950,000 | Up to 1M events/mo | $59/mo or $590/yr | Corporate site, shop, blog |
Every feature is on every plan; the price only follows monthly events (pageviews, custom events and payments, counted across all your sites). Bot and AI-crawler hits and session replays are never billed. Yearly billing is ten months' price for twelve, every plan starts with a 14-day free trial with no card, and there's a one-time lifetime deal from $59.
Frequently asked questions
Is VisitTrack GDPR compliant?
VisitTrack is built for GDPR: it never stores IP addresses, stores data on EU infrastructure, offers a DPA, and supports per-person deletion. Compliance also depends on your configuration and privacy notice, so review both with counsel.
Do I need a cookie banner for VisitTrack?
Not in cookieless mode, which stores and reads nothing on the visitor's device — the trigger for consent under the ePrivacy Directive. Standard mode uses a first-party cookie and generally needs consent in the EU. General information, not legal advice.
Where is VisitTrack data stored?
In VisitTrack's own PostgreSQL databases on EU infrastructure. Data is never sold, never shared with ad networks and never used to train models.
What is hybrid mode?
A tracking mode that is cookieless for visitors in the EU/EEA, UK and Switzerland — and anyone whose location can't be determined — and stores a first-party id for everyone else, so you keep multi-day journeys outside Europe.
How accurate is cookieless analytics?
Pageviews, sources, pages, countries, devices, events, goals and funnels are fully accurate. Unique visitors are accurate within a day; returning visitors after 24 hours count as new, and cross-domain tracking isn't available.
Can I honor a GDPR erasure request?
Yes. Delete the person in the People tab or with the API; their user id and traits are removed from all visitor records, while anonymous traffic totals stay unchanged.
Does VisitTrack use fingerprinting?
No persistent fingerprint is created. In cookieless mode a server-side hash of site, IP and user agent with a salt that changes daily gives a same-day visitor id; the inputs aren't stored and ids can't be linked across days.
Related
- Cookieless modeHow it works and what you give up.
- GDPR at VisitTrackWhat's collected and why.
- Data processing agreementArticle 28 terms.
- VisitTrack vs MatomoHosted vs self-hosted compliance.
- Cookie banner checkerDoes your site need one?
- Cookieless trackingThe definition, plainly.
- Analytics for agenciesCookieless client sites.
See which channels actually bring paying customers
VisitTrack is cookie-free analytics with revenue attribution built in. One script tag, no consent banner, live in two minutes. 14 days free, no card required.