Simple Analytics
Netherlands · simpleanalytics.com · 37 vendors
Simple Analytics is a privacy-focused web analytics tool that provides website owners with insights into their website performance. It offers a simple dashboard to track visitors, referrers, and popular pages without collecting personal data or using cookies, ensuring compliance with privacy regulations like GDPR.
Resilience scores
- Digital Sovereignty: 27
- Digital Resilience: 7
- Financial Resilience: 7
Disruption prediction
Simple Analytics has an estimated 10% probability of disruption in the next 6 months.
20 of Simple Analytics's 37 vendors monitored for disruptions.
Technology vendors
- Box, Inc. — Technology — United States
- Netlify, Inc. — Technology — United States
- Stripe, Inc. — Financial Services — United States
- and 34 more
Services catalogue
1 service in catalogue across 1 category; runs on 37 sub-vendors.
- Analytics
Insights
Last updated 2026-08-15 · revision 11
37 direct vendors, 349 subvendors
Direct vendors by controlling owner country (sample)
- Sweden: 1
- UK: 1
- Australia: 1
Subvendors by controlling owner country (sample)
- Unknown: 1
- United States: 241
- Israel: 1
Migration Readiness: 5/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
Simple Analytics exhibits medium migration readiness, scoring 45. The most significant challenge to migration is the strict data residency requirement, mandating all data to be stored exclusively in the Netherlands (EU). This severely limits potential migration targets and necessitates complex architectural planning to maintain compliance. Their current reliance on bare-metal infrastructure hosting (Worldstream, Leaseweb, Hetzner) suggests a less cloud-native architecture, implying that a migration to a modern cloud environment would likely require substantial re-platforming or re-architecting efforts rather than a simple lift-and-shift. While the 'Vendor Relationships' section is contradictory, assuming the 'Internal Tech Stack' lists their actual vendors, there is moderate vendor diversity, but the nature of bare-metal hosting could introduce some vendor lock-in or at least significant effort to transition. On the positive side, Simple Analytics has consistent revenue growth, indicating financial stability to fund a migration project. Their existing robust GDPR compliance provides a strong foundation for data handling in a new environment. The presence of a REST API (Stats API & Export API) and data warehouse export capabilities (CloudQuery) suggests well-defined data interfaces that could facilitate integration with new systems. Their experience managing services across multiple infrastructure providers (Worldstream, Leaseweb, Hetzner) also indicates internal capabilities in handling diverse infrastructure environments, which could be an asset during a migration.
Compliance
6 in-scope frameworks identified; showing 3.
ePrivacy Directive — Compliant
Risk is Low because: (1) The ePrivacy Directive (2002/58/EC) and its national implementations (e.g., UK PECR) require consent for placing cookies or similar tracking technologies on user devices; (2) Simple Analytics explicitly uses no cookies, no localStorage, no sessionStorage, and no similar browser storage mechanisms; (3) This architectural choice means the cookie consent requirements of the ePrivacy Directive simply do not apply to Simple Analytics' tracking script; (4) The company explicitly markets compliance with ePrivacy/PECR as a core product feature; (5) The Dutch implementation (Telecommunicatiewet) is the primary applicable law, and the company's no-cookie architecture satisfies it by design.
Evidence: https://simpleanalytics.com, https://simpleanalytics.com/gdpr-compliance, https://simpleanalytics.com/analytics-without-consent
GDPR (source) — Compliant
Simple Analytics is a Dutch company (Simple Analytics B.V.) headquartered in Amsterdam, Netherlands, making GDPR universally applicable. However, risk is assessed as Low because: (1) The company's core product is architecturally designed to avoid collecting personal data entirely — no cookies, no IP addresses stored, no visitor IDs, no fingerprints, no cross-site tracking; (2) This 'privacy by design and by default' approach (Article 25 GDPR) dramatically reduces the scope of GDPR obligations; (3) The company explicitly states that standard controller-processor agreements are generally not required because no personal data is processed through the analytics service; (4) The Dutch Data Protection Authority (Autoriteit Persoonsgegevens) is the lead supervisory authority, and the company's architecture is specifically built to satisfy Dutch/EU regulatory expectations; (5) The company is self-funded and small (3 employees), reducing complexity but also meaning limited internal compliance resources — however, the minimal data architecture compensates for this; (6) Residual GDPR obligations still exist for employee data and customer account data (names, emails for billing), but these are standard and low-risk for a 3-person company.
Evidence: https://simpleanalytics.com/gdpr-compliance, https://simpleanalytics.com/security, https://simpleanalytics.com/about, https://simpleanalytics.com/data-processing-agreement, https://simpleanalytics.com/subprocessors, https://www.kvk.nl/bestellen/#/88269922000054145163
CPRA — Compliant
Risk is Low because: (1) Simple Analytics is a Dutch company not primarily subject to CCPA/CPRA, but its global customer base (31,000+ customers) likely includes California-based businesses; (2) As a service provider to California businesses, Simple Analytics could be classified as a 'service provider' under CCPA if it processes personal information on behalf of covered businesses; (3) However, the company's architecture collects no personal information as defined by CCPA (no names, emails, IPs, device identifiers, or other personal identifiers from website visitors); (4) This means CCPA obligations for the analytics data layer do not arise; (5) The company explicitly lists CCPA compliance on its homepage; (6) Residual risk exists for customer account data (emails, billing) of California-based customers, but this is standard and low-risk.
Evidence: https://simpleanalytics.com, https://simpleanalytics.com/gdpr-compliance, https://simpleanalytics.com/data-collection
Financials
Three-year financials
- 2024:
- 2023:
- 2022:
Financial Resilience Score: 7/10
Simple Analytics B.V. is a bootstrapped, self-funded Dutch SaaS company that the founders describe as independent and profitable. With no venture capital dilution, no debt-service obligations, and an extremely lean three-person team based in Amsterdam, the company has a structurally low fixed-cost base and minimal burn risk. Its recurring SaaS revenue model, typical high gross margins for privacy analytics vendors, and 31,300+ customer base provide a stable financial foundation. The company benefits from strong regulatory tailwinds, including EU cookie enforcement and DPA rulings against Google Analytics in Austria, France, Italy, and the Netherlands, which drive demand for GDPR-compliant, EU-hosted analytics. Marquee enterprise logos including Bloomberg, Bank of England, UK Government, Michelin, Hyundai, Havas, and the Scottish Government support pricing power and reduce reputational risk. SOC 2 compliance in progress further reduces enterprise sales friction. However, resilience is offset by significant risks. Key-person concentration is extreme with only three employees, creating operational continuity risk. The privacy analytics category is crowded and price-competitive with Plausible, Fathom, Matomo, Piwik PRO, Umami, and Cloudflare Web Analytics all targeting the same niche. The absence of external capital limits firepower to defend market share against better-funded rivals. Financial opacity, while normal for a small Dutch B.V., limits third-party scrutiny.
Key strengths: Bootstrapped and reportedly profitable with no VC dilution or debt, Low headcount and low fixed cost base (3 employees), Recurring SaaS revenue model with high gross margins, Marquee enterprise logos (Bloomberg, Bank of England, UK Government, Michelin, Hyundai), Regulatory tailwind from EU DPA rulings against Google Analytics, SOC 2 in progress, GDPR/ePrivacy/CCPA compliant by design, 31,300+ customer base providing revenue diversification
Risk factors: Extreme key-person concentration with only 3 employees, Crowded, price-competitive category with well-funded rivals (Plausible, Fathom, Matomo, Piwik PRO), Product-category risk if regulators soften consent rules or GA4 consent-mode improves, Likely enterprise revenue concentration in small number of accounts, No external capital limits ability to defend market share, Financial opacity as small Dutch B.V. limits scrutiny
Workforce by country
- Netherlands: 3
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.