GDPR-Ready Web Analytics
Website Analytics Without The Cookie Banner
Statable is privacy-first web analytics, built for GDPR and for the ePrivacy Directive, PECR, and CCPA alongside it. No cookies, no consent pop-up, no banner. Your data is processed and stored in the EU.
No card required • 30 days trial • Based in Europe
Cookie-Free Setup
Skip The Cookie Banner Entirely
Cookie banners exist because of one rule.
The ePrivacy Directive, written into national law across the EU and into PECR in the UK, requires consent before a site stores or reads information on a visitor's device. Cookies and localStorage fall under that rule, so they trigger the banner.
Statable Does None Of That
- No cookies set.
- No localStorage used.
- Nothing saved on the visitor's device.
The storage rule that forces the banner has nothing to apply to.
So Statable adds no consent pop-up and no banner to maintain. Your pages stay clean, and every visit is counted, not just the ones who click “Accept.” Other tools you run, like ad pixels or chat widgets, may still need a banner of their own.
When A Visit Comes In, We Turn It Into A Daily, One-Way ID
- Resets every 24 hours — reports never link a visitor across days.
- Tied to your website's domain — reports never link a visitor to another site.
- We never store the visitor's IP address or full user-agent.
- We never build a profile.
Because the data is minimal and pseudonymous, and we don't use it to track or profile anyone, we rely on legitimate interest rather than consent. You get accurate numbers, and your visitors keep their privacy.
Privacy by Design
Analytics That Works Without Consent
Even without cookies, GDPR still applies — counting a visit means briefly handling an IP address. Statable does this under legitimate interest, with privacy built in from the start. You stay the controller, so the balancing test is yours to record; the DPA in our terms covers our side of it.
Analytics Without Surveillance.
The Privacy-First Difference
No Cookies
No first-party or third-party cookies.
No LocalStorage
We save nothing in your visitors' browsers.
No Fingerprinting
No canvas, audio, or font probing.
No Stored IP Addresses
We use the IP to count a visit, then drop it.
No Cross-Site Tracking
IDs are tied to your domain, so visitors are never followed from site to site.
No Profiles
We don't build behavioral profiles, and the daily ID resets every 24 hours.
EU Data Residency
Your Data Stays In The EU
Statable is a Dutch company. We process and store your analytics data in the EU (Netherlands), under EU law. There's no transatlantic transfer of your analytics data for you to document or defend.
We never store your visitors' IP addresses or full user-agents. What we keep is minimal and pseudonymous, so there's no profile sitting in a database waiting to be requested, leaked, or handed over.
One detail worth stating plainly: our script is delivered through Bunny, an EU company whose edge network spans the globe. A request from outside the EEA may pass through a nearby edge node before it reaches us. Nothing is stored there — your analytics data lives only in the Netherlands.
Our full list of sub-processors is on our security page. Our Data Processing Agreement is built into our terms, so there's nothing extra to sign. You can read it at our DPA.
Privacy Signals
We Honor Do Not Track And Global Privacy Control
Some visitors turn on a privacy signal in their browser, like Do Not Track or its newer version, Global Privacy Control. Statable respects both.
When the signal is on, our script collects nothing. It's handled right in the browser, so the visit never reaches us. There's nothing to delete because there was nothing to send.
This works for every visitor in the world, by default, with no setup on your side. We honor the signal even where no law requires it. Where the law does require it, like California's rules on opt-out preference signals, that part is handled before the request ever reaches us, though the rest of what your site does is still yours to answer for.
Compliance
Built To Meet GDPR, ePrivacy, PECR, And CCPA
GDPR (EU)
We process minimal, pseudonymous data under legitimate interest, as your data processor, with a DPA built into our terms.
ePrivacy Directive
We store nothing on your visitors' devices, so the consent rule behind cookie banners has nothing to apply to.
PECR (UK)
Same rule, same result: with no storage or access on the device, PECR's consent requirement isn't triggered.
CCPA / CPRA (California)
We don't sell or share personal data, and we honor Global Privacy Control by default.
The full details are in our Data Processing Agreement. This covers our side of the work: what you collect through custom events and how you tell your visitors about it stays with you, and none of this is legal advice.
Privacy Legislation
The Law Keeps Moving Our Way
Going privacy-first isn't a gamble. Around the world, the rules keep moving toward the way Statable already works.
United Kingdom
2026The Data (Use and Access) Act 2025 adds a PECR exemption for low-risk analytics: no consent needed, as long as the tool measures only your own site, doesn't follow people across the web, and gives visitors clear information and a way to object. Statable was built that way from day one.
California
2026California requires businesses to honor opt-out preference signals like Global Privacy Control. Statable honors them by default, for every visitor, everywhere.
European Union
2025The long-stalled ePrivacy Regulation proposal was withdrawn, so the existing ePrivacy Directive stays in force. The practical path forward is data minimization and privacy by design.
Choose analytics that gets stronger as the rules tighten, not weaker.
Use Cases
Who Statable Is For
If you want to understand your audience without tracking them, Statable fits.
Creators
See what your audience reads, without turning your site into a consent maze.
SaaS Marketing Teams
Measure campaigns and conversions with clean data and no banner in the signup flow.
Bloggers
Find your best posts without loading cookie scripts that slow your pages.
E-Commerce
Track traffic and campaigns with nothing standing between visitors and checkout.
Digital Agencies
Give every client GDPR-ready analytics and a built-in DPA, without the compliance overhead.
Educational Organizations
Understand your site while respecting students' and visitors' privacy.
Non-Profits
Learn what your supporters care about without collecting personal data.
Data Migration
Bring Your History With You
Switching analytics shouldn't mean starting from zero.
Connect your own Google account to import your historical GA4 data and link Google Search Console, so your dashboard is full from day one.
We pull only aggregated stats: no IP addresses, no individual rows, and we never send your visitors' data to Google.
FAQ
Frequently asked questions
Is Google Analytics GDPR-compliant?
It's complicated, and that's the problem. In 2022, data protection authorities in Austria, France, and Italy ruled that using Google Analytics broke GDPR, because it sent data to the United States. The 2023 EU-US Data Privacy Framework eased this, but it's under legal challenge and the uncertainty hasn't gone away. GA4 also relies on cookies, so it needs a consent banner. It can be configured toward compliance, but it isn't compliant by default, which is why people go looking for a GDPR-compliant alternative to Google Analytics in the first place.
How do you make Google Analytics GDPR-compliant?
Roughly: set data retention to the longest window you actually need rather than leaving it at the two-month default, turn off Google Signals, deploy Consent Mode v2 for EEA traffic, accept Google's data processing terms, and document the transfer mechanism you are relying on.
What none of that removes is the banner. GA4 writes cookies to the visitor's device, and device storage is what triggers the consent rule in the first place. You can get GA4 much closer to compliant. You cannot get it there without asking.
Do I need a cookie banner if I run Statable?
Not for Statable. The rule behind cookie banners — the ePrivacy Directive as implemented in national law, and PECR in the UK — applies when a site stores or reads information on a visitor's device. Statable does neither, so it doesn't trigger that rule. If your site uses other tools that set cookies, like ad pixels, you may still need a banner for those.
Is Statable GDPR-compliant out of the box?
As far as a tool can be, yes — that's what Statable is built for: GDPR-ready web analytics with nothing to configure. No cookies, no profiles, no stored IP addresses, pseudonymous data, processing in the EU, and a data processing agreement built in. Compliance is never a property of the tool alone, though. You're the controller, so don't put personal data into custom events or URLs, tell your visitors what you measure, and make sure you have a basis for anything extra you choose to collect.
Under what GDPR lawful basis does Statable process data?
Legitimate interest. You, the website owner, are the controller, and Statable acts as your processor. Because the data is minimal and pseudonymous and isn't used to build a profile, we rely on legitimate interest rather than consent. As the controller you should record that balancing test for your own site; our DPA covers our side. Visitors who turn on Do Not Track or Global Privacy Control aren't measured at all.
How does Statable handle the right to erasure (Article 17)?
For your visitors, we cannot act on an erasure request, because we cannot tell which rows belong to whom. We hold no names, no email addresses, no IP addresses, and no identifier that on its own points to a person; the daily ID resets every 24 hours and means nothing outside that day and that site. Article 11 covers exactly this: where a controller cannot identify someone from what it holds, it isn't required to collect more data just to service the request.
For your own account the answer is different. There we are the controller rather than your processor, and we do hold personal data: your email address and your sign-in history, which includes the IP address of each sign-in. Deleting your account removes both, along with your sites and access records.
Where do you process visitor data?
In the EU. Statable is a Dutch company, and your analytics data is processed and stored in the Netherlands, under EU law. Our script is delivered through Bunny, an EU company whose edge network spans the globe, so a request from outside the EEA may pass through a nearby edge node on its way to us — nothing is stored there. Our full list of sub-processors is on our security page.
What about the ePrivacy Directive and PECR?
Both require consent to store or read information on a visitor's device. Statable does neither, so there's nothing to consent to and no banner to show. The direction of the law backs this up: the UK's Data (Use and Access) Act 2025 exempts low-risk analytics from PECR consent once it meets conditions on scope and visitor information, and Statable goes further by using no device storage at all.

