Zum Inhalt springen
Unabhängig verifiziert · Quartalsweises Re-Audit
EU VETTED

GoatCounter

VERIFIZIERT
Web-Analyse · Ireland
Founded 2019 · goatcounter.com ↗

Solo-developer open-source web analytics on Hetzner DE/FI; no IP storage, no trackers, free for personal use, MIT-style source on GitHub.

Warum diese Bewertung?

Solo-developer open-source web analytics (Martin Tournoij, Ireland-based) running on Hetzner servers in Germany and Finland with no third-party sharing, no IP storage, no User-Agent storage, no trackers, and no US sub-processors anywhere on the customer-data path; score capped at 4/5 because the project does not publish a formal DPA artefact or unified named sub-processors annex — adequate for indie/SMB buyers but not for procurement-grade buyers requiring contract-level transparency.

SCORE
4.0/5
CLOUD ACT
OWNERSHIP
SUB-PROCS
0 none disclosed
JUMP TO
OVERVIEW

About GoatCounter

GoatCounter is a minimalist open-source web analytics tool developed and operated by solo developer Martin Tournoij (GitHub: arp242). The hosted service goatcounter.com runs on Hetzner Online GmbH servers in Finland and Germany; the operator is currently based in Ireland. The project is fully open source on GitHub and self-hostable, making it a credible "no SaaS lock-in, no CLOUD Act exposure" answer for indie publishers, NGO sites, and small EU teams. The privacy posture is exceptionally clean: GoatCounter does not store IP addresses, does not store the full User-Agent header, does not use cookies for visitor tracking, and stores only aggregate-table data per hour rather than individual pageviews (with the option to opt into pageview-level data collection if the customer enables it). Site owners are advised that a GDPR consent banner is generally not required because no personally identifiable data is collected and the service rests on legitimate interest analogous to in-store foot-traffic counting. Account login uses cookies for session persistence; no third-party sharing of account data; backups retained up to 30 days after account deletion. Pricing is freemium and pragmatic: the hosted service is free for personal and non-commercial use, with paid tiers for commercial and high-traffic use; specific tier prices were not captured at audit and are listed in /help/billing. Best fit: indie devs, bloggers, small e-commerce shops, and EU NGOs who want a no-cookie analytics stack on Hetzner with the option to self-host the open-source build. Procurement-grade enterprise buyers who require a formal DPA, named sub-processors annex, and a corporate legal entity should look at Plausible (also Hetzner DE) or Pirsch (also Hetzner DE) instead — GoatCounter is structurally a one-person shop and does not produce those artefacts today.
SUB-PROCESSORS

Unterauftragsverarbeiter-Karte · none disclosed

Source ↗
Vendor discloses zero sub-processors. All data processing happens in-house.
CERTIFICATIONS

Rahmenwerke & Zertifizierungen · none listed

We checked the vendor's website and standard certification body registries. No active certifications found at the time of last audit (2026-05-10).
FEATURES

Funktionsmatrix

INTEGRATION & ACCESS
REST API Yes
SSO (SAML / OIDC) No
COMPLIANCE & GOVERNANCE
Audit log No
Self-host / on-prem option Yes
PRICING

Preise & Tarife

FREEMIUM
Individuelle Preise

Kontaktieren Sie den Anbieter für Staffel- oder Mengenpreise.

Preisseite ansehen ↗
PUBLIC DOCUMENTS

Öffentliche Dokumente

DPA accessibility is not scored for this listing. Self-hosted or local software, vendors that are not data processors, and products carrying a SecNumCloud, EUCS or BSI C5 certification are not assessed on DPA accessibility — see How we score.
  • Data Processing Addendum (DPA)
    — not assessed
    n/a
  • Sub-processors list
    www.goatcounter.com/help…
    Open ↗
  • Terms of Service
    www.goatcounter.com/help…
    Open ↗
ALTERNATIVES

Alternativen in dieser Kategorie