
Statable
GDPR CompliantDutch cookieless web analytics running on the vendor's own servers in the Netherlands, with one-click GA4 migration and embeddable live widgets.

GDPR Compliance Data
Not independently verified| GDPR Status | GDPR Compliant |
| HQ Country | Netherlands |
| Ownership | European-owned |
| Foreign Disclosure Exposure | None known |
| Data Hosting Location | European Union"All analytics data is processed and stored on servers located in the Netherlands" (statable.com/gdpr) and "stored exclusively on servers in the Netherlands" at "the NorthC data centre in Oude Meer" (statable.com/privacy). The DPA adds: "The Processor owns and operates the servers on which Visitor Data is stored. NorthC provides the facility in which those servers are housed — rack space, power and physical security — and does not process Visitor Data." All read 2026-08-24. |
| EU Servers Available | |
| Data Processing Agreement | View DPA |
| Sub-processor List | View sub-processors |
| Schrems II Risk | Low Risk |
| SCCs in Place | |
| Last Verified | 24 August 2026 |
How we reached this
Dutch legal entity: Key Arg B.V., KvK 89388496, Herckenrathstraat 1, 2681 DG Monster, South Holland, from statable.com/privacy and /about. Independently owned, no parent company, no outside investors. COMPLIANT rather than PARTIAL because the DPA is published at statable.com/dpa and in force automatically ("By using Statable, you automatically accept this DPA. No separate signature is required"), the sub-processor list is published in full with roles and locations at statable.com/gdpr, and EU-only storage is stated in both the policy and the DPA. Exposure NONE: visitor data sits on hardware the vendor owns in a NorthC colocation facility, and the CDN is Bunny, a Slovenian company, so no US provider sits in the request path. The two US sub-processors touch account data only, Stripe for billing and Google for optional OAuth sign-in, and never visitor analytics data. sccInPlace is on the strength of the privacy policy, which says transfers outside the EEA rely on Standard Contractual Clauses approved by the European Commission; the DPA itself does not mention SCCs, so the two documents do not currently agree on this point. Cookieless: nothing is stored on the visitor's device, and raw IPs are not written to the analytics database, being replaced by a per-site keyed hash of IP, User-Agent, site identifier and date.
About Statable
Cookieless Analytics on the Vendor's Own Hardware
Statable is a drop-in replacement for Google Analytics 4 that reports the numbers most teams actually open GA4 to read: visitors, sessions, pageviews, bounce rate and session duration in real time, broken down by source, page, and audience.
What It Tracks
- Traffic sources including organic, social, paid, UTM campaigns and referrals from AI chatbots, which is still an uncommon breakdown in this category
- Page performance with top pages and entry and exit pages
- Audience by browser, OS, device, country, region and city
- Custom events and goals for conversions
- Live embeddable widgets, including a visitor map, a globe and a live user counter you can put on a public page
- One-click GA4 migration that imports historical data, so switching does not mean starting the charts from zero
Every plan includes every feature and unlimited websites. Pricing is by pageviews: $9/mo for 10K, $19/mo for 100K, $49/mo for 500K and $169/mo for 10M, with roughly 20% off annually. Every account starts with a 30-day trial and no card, and .edu domains and sites on github.io or gitlab.io get permanent free access in exchange for installing a public widget. Note that an otherwise thoroughly Dutch product prices itself in US dollars.
No Cookies, No Banner
Nothing is written to the visitor's device, which is the thing the ePrivacy Directive and PECR actually regulate, so there is no consent banner to serve. Raw IP addresses are never written to the analytics database: the policy describes a keyed hash of IP, User-Agent, site identifier and calendar date, producing a visitor identifier that is unique per website and cannot follow anyone across sites. Global Privacy Control is honoured by default.
Dutch Ownership, and Servers It Actually Owns
Published by Key Arg B.V., KvK 89388496, Herckenrathstraat 1, 2681 DG Monster. Independently owned with no parent company and no outside investors.
The hosting detail is the part worth reading twice. Most tools on this list that say "EU hosted" mean they rent capacity from a cloud provider that happens to have an EU region. Statable's DPA states that it owns and operates the servers itself, housed in the NorthC data centre in Oude Meer, and that NorthC supplies rack space, power and physical security without processing visitor data. That removes an entire processor from the chain rather than relocating it.
Two US sub-processors remain, and both are named: Stripe processes payments, and Google handles OAuth sign-in if a customer picks it over email. Neither touches visitor data, only the account holder's own details. The sub-processor list is published in full at statable.com/gdpr, and the DPA at statable.com/dpa is in force automatically, with no signature to chase.
Where It Fits
This is a direct competitor to Plausible, Simple Analytics and Pirsch, and it is priced in the same bracket. What distinguishes it is the owned hardware and the GA4 historical import; what it gives up against Piwik PRO is the enterprise governance tooling. Compare the field in EU-hosted web analytics software.
Key Features
Pros & Cons
Categories
Replaces
Statable on EuropeanMartech
Statable GDPR & data protection: common questions
Is Statable GDPR compliant?
Yes. On the evidence we checked, Statable meets the requirements European businesses usually need. Statable is a European company headquartered in Netherlands, data is hosted within the European Union, and a Data Processing Agreement is published.
Where does Statable store data?
Statable states: ""All analytics data is processed and stored on servers located in the Netherlands" (statable.com/gdpr) and "stored exclusively on servers in the Netherlands" at "the NorthC data centre in Oude Meer" (statable.com/privacy). The DPA adds: "The Processor owns and operates the servers on which Visitor Data is stored. NorthC provides the facility in which those servers are housed — rack space, power and physical security — and does not process Visitor Data." All read 2026-08-24.". Data is hosted within the European Union.
Does Statable offer a Data Processing Agreement (DPA)?
Yes. Statable publishes a DPA at https://statable.com/dpa. A DPA is required under Article 28 GDPR whenever a provider processes personal data on your behalf.
What a DPA has to cover →Is Statable a European company?
Yes. Statable is headquartered in Netherlands and, as far as we can establish, European-owned.
Who are Statable's sub-processors?
Statable publishes its sub-processor list at https://statable.com/gdpr. Worth reading: a vendor hosting in the EU can still route data through non-EU sub-processors, which is where residency claims usually come apart.
Related Tools

Plausible Analytics
Lightweight, open-source, cookie-free web analytics. Fully GDPR compliant with EU data hosting.

Matomo
Leading open-source web analytics. Self-host in the EU or use cloud with EU hosting.

Mouseflow
Heatmaps, session replay, and behavior analytics. Danish company with EU-only data processing.
Spot an error in the compliance data? Get in touch