7 ms·
You can find a nice list of privacy-respecting analytics tools on European Alternatives [0], including mine, Pirsch [1]. I've been in this space for ~3 1/2 yea
by marvinblum 2y ago
You can find a nice list of privacy-respecting analytics tools on European Alternatives [0], including mine, Pirsch [1].
I've been in this space for ~3 1/2 years, so if you have any questions, please let me know :)
[0] https://european-alternatives.eu/category/web-analytics-services https://european-alternatives.eu/category/web-analytics-serv...
[1] https://pirsch.io https://pirsch.io
- eitland 2y agoNot related to you, but from a description in the first link, in the description for Plausible: > Because it does not use cookies their is no need to show cookie banner for this service. This is IMO a rather fundamental misunderstanding of the current situation. I'd be hesitant to using a product from someone who I think have misunderstood completely what the rules are about. (Again, IMO and also IANAL but I have followed GDPR more closely than most people.) GDPR is about collection information, as far as I can see, the technical detailsbof how you do it doesn't matter. It could be pure magic and would still be illegal.
- jgalt212 2y agoAt the end of the day it comes down to enforcement. If the rules make no sense, and they can't be enforced. They might as well not exist.
- Reubensson 2y agoYeah, not using cookies is irrelevant if you use other means to track user. Also people like to think they need to show the "cookie banner" for all cookies regardless of how they are used.
- marvinblum 2y agoCorrect, it's not so much about Cookies, but how data is collected and what is stored. We have done a privacy risk analysis with an external lawyer and data protection officer, and concluded that Pirsch is in line with GDPR as we do not collect nor store personal identifiable information (PII). Processing stuff like IP addresses for example is legal as long as they are not stored and only cached for a reasonable amount of time (a few milliseconds in our case). If you're interested, we have extensive documentation on this. You can reach out to support@pirsch.io to get it :) If anyone is interested in doing something similar. This did cost us about 8,000 € in Germany.
- anonzzzies 2y agoI guess because you store their fingerprint (for uniques) only 24 hours, it is ok?
- marvinblum 2y agoThis also factors in, yes. If we would store it indefinitely, there is the risk of profiling (estimating who someone is by their behaviour).
- michpoch 2y ago> This did cost us about 8,000 € in Germany. The apparently extensive legal assessment you just described costed just 8'000 euro? I am sorry but that had to be some hasty review at best. Do you take the full legal risk in case any of your customers would be found in violation of privacy laws because of using your service? For reference, with similar hourly rates as Germany, reviewing a standard apartment-purchase contract cost me ~3500 euro.
- marvinblum 2y agoWe had someone with a lot of experience in this field working for very large German corporations and got a discount/startup bonus. I wouldn't call it cheap. Imagine starting a business in Germany. How are you suppose to pay 30-50k for legal questions before selling anything?
- account42 2y agoAnalytics and other forms of tracking are not required to do do business. Don't try to skirt the law and you won't have as many legal questions to answer.
- XCSme 2y agoSo, if I run ads or a marketing campaign, I shouldn't be able to know if it brings a positive ROI or not? Let's assume I pay $1000 for Google Search Ads, wouldn't it help the business to know that "from my sales, $800 came from Google Search Ads"? People do this all the time, even in real life, with coupon codes fliers for example.
- uallo 2y agoIt is not entirely clear who wrote these descriptions. Maybe it was not the vendor. At least their website https://plausible.io/ https://plausible.io/ has a much better wording. > No need for cookie banners or GDPR consent > > Plausible is privacy-friendly analytics. All the site measurement is carried out absolutely anonymously. Cookies are not used and no personal data is collected. There are no persistent identifiers. No cross-site or cross-device tracking either. Your site data is not used for any other purposes. All visitor data is exclusively processed with servers owned and operated by European companies and it never leaves the EU.
- input_sh 2y agoGDPR is about collecting personally identifiable information, which is distinct from aggregate data that you can't trace back to the individua. Recital 26: > The principles of data protection should therefore not apply to anonymous information, namely information which does not relate to an identified or identifiable natural person or to personal data rendered anonymous in such a manner that the data subject is not or no longer identifiable. So details definitely matter. Some self-hosted analytics do this by getting rid of the last octet of the IP address, though I doubt that's been tested in courts.
- anonzzzies 2y agoIf you can figure how many unique visitors your have, you have a problem. That must somehow fingerprint you.
- tonyhart7 2y agoAnonim jwt guest literally did this same thing noo??? I mean if you just track anonim data what I mean is you can track unique visitor of your app without privacy breach because you use anonim data
- input_sh 2y agoI posted a quotation straight from the recital of the GDPR that says anonymised data does not matter. I even gave a reference that you can look up. The recital even ends with this: > This Regulation does not therefore concern the processing of such anonymous information, including for statistical or research purposes. There is no ambiguity here, aggregate data is completely fine as long as I can't trace it back to you with a reasonable amount of effort.
- anonzzzies 2y agoA DPO would disagree with you depending on the circumstance; if you know a user is unique then you have a fingerprint; if you keep that fingerprint forever, when the user comes back to the site, it's trivial to know it is that user.
- wongarsu 2y agoYou need consent for (not functionally necessary) cookies because of the ePrivacy Directive (the "cookie law"). Additionally, you also need consent for processing, storing or sharing personally identifying information (PII) because of the GDPR. Usually you do both in the same consent popup. Plausible doesn't store visitor's IPs or any other PII, and doesn't set any cookies. The reasoning given in the quoted paragraph is incomplete, but the result is correct. You only need to mention them in your privacy policy, they don't require any opt-in popups
- robin_reala 2y agoPII isn’t a concept in GDPR. GDPR talks about personal data, which on its own might not be identifying, but which in combination with other personal data can successfully identify a person.
- youngtaff 2y agoRegardless of whether they store it Plausible is exposed to the visitors IP address though isn't it?
- birjolaxew 2y agoI've actually had this discussion with Plausible directly back in 2022[1], and more recently with the lawyer they had write a blog post[2] on the topic. I wrote an article on it, that was recently discussed here on HN [3]. The response from Plausible is essentially "we've checked with legal council, and stand by the statement". The conversation with the lawyer started out well, but he stopped responding when I asked about the ePD, not GDPR. There generally seems to be a lot of confusion, even in legal circles, about what ePD requires informed consent for. Many think that only PII requires consent, or think that anonymization bypasses it. That amount of confusion makes it very easy for a layman (e.g. Plausible) to find _someone_ willing to back up their viewpoint. The EDPB released a guideline in 2023 that explicitly states that what Plausible et al. are doing is covered by the ePD's consent requirement, but that's a little too late: the implementations in member countries already differs massively on whether it's covered[4]. 1: https://github.com/plausible/analytics/discussions/1963 https://github.com/plausible/analytics/discussions/1963 2: https://plausible.io/blog/legal-assessment-gdpr-eprivacy https://plausible.io/blog/legal-assessment-gdpr-eprivacy 3: https://news.ycombinator.com/item?id=42792485 https://news.ycombinator.com/item?id=42792485 4: https://matomo.org/faq/general/eprivacy-directive-national-implementations-and-website-analytics/ https://matomo.org/faq/general/eprivacy-directive-national-i...
- taw9838373 2y ago> There generally seems to be a lot of confusion, even in legal circles, about what ePD requires informed consent for. That seems to be true, going by this comment section and the other ones I've seen. It's hard to get a non-hyperbolic answer to the question: if everyone is so confused, what's the real-world consequence of best-effort implementation? Some would say it's the ultimate responsibility of the app owner to understand the law, but how much further can you go than hiring a lawyer? If more diligence needed to be done than that none of us would get anything built, we'd all just be running around researching the laws around these dumb popups. What are the real-world consequences of making a mistake here? What kind of boundary would you have to trip over to actually get the authorities to prosecute you for not having a consent popup or doing it badly?
- progmetaldev 2y ago
- velcrovan 2y agoI'm curious: running a static website with no JS-based analytics whatsoever — only Apache logs in standard format (so including IP address and user agent string) — does GDPR require consent banners in this case? If so, doesn't essentially every website require consent banners due to the way websites work?
- deleted 2y ago[deleted]
- xorcist 2y agoGDPR does not require a consent banner. If you want to process the user's personal data outside what is strictly necessary, you need permission. One way to get that permission is for the user to specifically consent to it. It does not have to be a banner. (In fact, many banners out there are probably not enough for informed consent anyway, as they provide no information about what data is collected or any reasonable way to opt out.) Personally identifiable information has nothing to do with javascript, or analytics. Do you have GET requests with parameters containing enough to identify a specific individual? Then your logs are sensitive and you must have a valid contract, informed consent, or provide some important service where this information is necessary. There are gray areas which can make this difficult, but you the basic idea is enough information to identify an individual. A basic website where you log that IP address A viewed home.html is not enough. The knowledge that a 55 year old woman with particular name on a particular street address has an interest in photograhy and shoe size 9 probably is. The line is somewhere in between.
- tasuki 2y agoIf I install the Apache web server and accidentally expose the machine to the internet, am I violating GDPR by not having a cookie banner on the "Apache Default Page"?
- eitland 2y agoProbably not. But of you can still find a way to identify users from server logs, then probably yes.
- randomQ11333 2y agohow do you calculate the session duration? is it the delta between two page hits or similar events? i tried a couple of the smaller analytics tools, like plausible, simpleanalytics, umami etc... and one thing that i always disliked was the way the session duration was calculated - i have a lot of longer articles where the visitor stays for a long time and then leaves. most of these tools will count that as a bounce, as there is no two hits to calculate the delta between. but for me it is a very important metric to get accurate numbers on, which is impossible with that implementation for sites like mine (very few but long page visits, not a lot of navigation between pages). do you handle this the same way? that would be a feature i'd be willing to switch my current tool out for.
- marvinblum 2y agoYeah, we also use the delta. However, you can send a custom event on close to update the session duration. The session won't be counted as bounced in our system then and the time is updated. https://docs.pirsch.io/advanced/events https://docs.pirsch.io/advanced/events
- euph0ria 2y agoDoes it require cookie and/or gdpr consent from the user to use these privacy analytics tools?
- marvinblum 2y agoNo. You can learn more about it here: https://docs.pirsch.io/privacy https://docs.pirsch.io/privacy
- tonyhart7 2y agothese are good list however very few of them offer for Apps like mobile,dekstop etc
- marvinblum 2y agoFor Pirsch, we have a PWA you can install right from your mobile browser :)
- tonyhart7 2y agoYeah but its PWA, that's the problem
- willsmith72 2y agoWhat's wrong with a PWA?
- satvikpendem 2y agoThey simply don't work as well as non-web apps. People continue to insist that they do, but from my experience, they just don't have the same smoothness as a native app to show that it's not a web app.
- bryanhogan 2y agoDo you have examples of such apps? Generally curious since I would assume that there might be other factors at play that make such apps "not smooth".
- satvikpendem 2y agoTry something simple like Instagram via the browser versus as an app, it's simply smoother on the app. I would have to dig up more examples but IG immediately comes to mind as a recent experience.
- 2y ago
- TZubiri 2y agoI'll have a basic "how is this different than the thing they are copying" please.
- deleted 2y ago[deleted]
- marvinblum 2y agoI guess you have to sign up to a few, test them on your site, and decide which one to use. In the end, they are all slightly different. If you would like to self-host or have other specific requirements, you can quickly reduce the list to a couple of options of course.
- andiareso 2y agoIs Pirsch a fork of Plausible? It looks nearly identical.
- marvinblum 2y agoNo, they are comparable, but it's an independent tool. When we started, Plausible wasn't as big as it now is. We also had a focus on deeper integrations via API from the get go, a nicer dashboard, and a few other minor details. I basically started this for my personal use as a library for Go, which it still is: https://marvinblum.de/blog/server-side-tracking-without-cookies-in-go-OxdzmGZ1Bl https://marvinblum.de/blog/server-side-tracking-without-cook...
- vladkens 2y agoPricing page looks completely same with Plausible. But prices is less which is good
- marvinblum 2y agoFunny enough, they seem to have "copied" our structure. I remember when it basically was just a slider, without tiers.
- ksec 2y agoYes because I remember I suggested to them their pricing structure were not simple. Although I am not sure who started the slider pricing UX.