Last updated: April 07, 2026
Statable is a privacy-first web analytics service operated by Key Arg B.V., a company registered in the Netherlands. We are fully committed to GDPR compliance, both as a data controller for our customer relationships and as a data processor for the analytics data we handle on behalf of our customers.
This page explains how Statable complies with the General Data Protection Regulation (GDPR) and why website owners using our service can confidently operate without intrusive cookie consent banners.
No. Statable does not use cookies, localStorage, sessionStorage, or any form of browser-side storage for analytics purposes. Our tracking script does not set any cookies on your visitors' devices.
Because we do not use cookies or similar tracking technologies, the ePrivacy Directive (often called the "Cookie Law") does not require a consent banner for Statable analytics. You can use Statable on your website without asking visitors for consent to track them.
Instead of cookies, we generate a daily rotating hash to count unique visitors. The hash is created from:
The raw IP address and User-Agent are never stored. Only the resulting one-way hash is used, and it cannot be reversed to identify the original visitor. Because the salt rotates daily, the same visitor generates a completely different hash each day, making cross-day tracking impossible.
Additionally, hashes are scoped to each individual website domain. This means visitors cannot be tracked across different websites that use Statable.
Our analytics script collects the minimum data necessary to provide useful website analytics:
We do not collect names, email addresses, or any form of personal contact information from website visitors. We do not engage in cross-site tracking, device fingerprinting, or behavioral profiling.
When you create a Statable account, we act as the data controller for your account information. This includes:
Our legal basis for processing this data is the performance of a contract (Article 6(1)(b) GDPR) and our legitimate interests in operating the service (Article 6(1)(f) GDPR).
When our analytics script runs on your website, we act as a data processor on your behalf. You, as the website owner, are the data controller for your visitors' data.
We process the minimum amount of data necessary to provide analytics insights. All data is anonymized through our hashing mechanism, and raw personal data (IP addresses) is never stored.
We offer a Data Processing Agreement (DPA) that governs our processing of visitor data on your behalf. The DPA is automatically included as part of our Terms of Service.
Key Arg B.V. is incorporated in the Netherlands, a member state of the European Union. All analytics data is processed and stored on servers located in the Netherlands.
We use Cloudflare as our CDN provider for network performance and security. Cloudflare may process network traffic data in accordance with their own privacy policy, but the analytics data itself is stored exclusively within the EU.
This means no analytics data leaves the European Economic Area, eliminating concerns about international data transfers under GDPR Chapter V.
Under the GDPR, individuals have specific rights regarding their personal data. Because Statable anonymizes visitor data through one-way hashing, we cannot identify or retrieve data relating to a specific individual visitor.
For Statable customers (account holders), we fully support:
To exercise any of these rights, please contact us at [email protected].
Because of our privacy-first design, Statable is also compliant with other major privacy regulations:
We use the following third-party services to operate Statable:
| Service | Purpose | Location |
|---|---|---|
| Server hosting | Analytics data storage | Netherlands (EU) |
| Cloudflare | CDN and network security | Global (EU data stays in EU) |
| Stripe | Payment processing | United States (PCI compliant) |
| OAuth authentication (optional) | United States |
If you have any questions about our GDPR compliance or data practices, please contact us: