Skip to content
Independently verified · Quarterly re-audit
EU VETTED

Trackboxx

VERIFIED
Web analytics · Germany

German sole-proprietor cookieless analytics, B2B-only, with daily-rotating anonymisation and BunnyCDN script delivery.

Why this score?

German sole-proprietor analytics product (Christian Pust, Halberstadt) with cookieless tracking, daily-rotating anonymisation, and named sub-processors disclosed in the privacy policy — but the hosting provider for customer analytics data at rest is not publicly disclosed, the Imprint omits HRB/VAT details, no formal DPA artefact is published, and AWS Simple Email Service is used for newsletter email — together caps the score at 3/5.

SCORE
3.0/5
CLOUD ACT
OWNERSHIP
SUB-PROCS
0 none disclosed
JUMP TO
OVERVIEW

About Trackboxx

Trackboxx is a small German cookieless web analytics product operated by Christian Pust as a sole proprietorship (Humboldtstraße 9, 38820 Halberstadt; branch office at Dorfstr. 12, 22956 Grönwohld). The service is sold strictly business-to-business — the imprint explicitly states that "Unser Service richtet sich ausschließlich an Unternehmer" (our service is directed exclusively at commercial customers). Co-founders Christian and Ulrike split development, strategy, marketing, and social media duties. The product runs cookieless analytics with rotating daily encryption codes for visitor anonymisation, marketing itself as "100% DSGVO-konform" with the Bitmi (Bundesverband IT-Mittelstand) member badge. The privacy policy is unusually transparent for a small vendor: the named sub-processors are Paddle (UK, payments / merchant of record), Amazon Web Services (Amazon Simple Email Service for newsletter delivery — the only US-owned sub-processor), Userlike (DE, chat), BunnyCDN (SI, script delivery), and TradeTracker (NL, affiliate tracking). What it does not disclose is the underlying hosting provider or data-centre location for the customer analytics database itself, which is the main gap for procurement-grade buyers. Pricing was not captured at audit (the public /pricing and /preise paths returned 404) and a formal DPA artefact is not linked; the imprint also omits a Handelsregister number and USt-IdNr, which is consistent with a sole-proprietor (Einzelunternehmen) structure but unusual for a vendor courting business buyers. Best fit: small German-speaking SMBs and e-commerce shops that want a low-friction Google Analytics replacement, accept a sole-proprietor counter-party, and don't need a contract-grade DPA. Procurement-led buyers should choose Pirsch, Plausible, or Wide Angle Analytics in this category instead.
SUB-PROCESSORS

Sub-processor map · none disclosed

Source ↗
Vendor discloses zero sub-processors. All data processing happens in-house.
CERTIFICATIONS

Frameworks & certifications · none listed

We checked the vendor's website and standard certification body registries. No active certifications found at the time of last audit (2026-05-10).
FEATURES

Capability matrix

INTEGRATION & ACCESS
REST API No
SSO (SAML / OIDC) No
COMPLIANCE & GOVERNANCE
Audit log No
Self-host / on-prem option No
PRICING

Pricing & tiers

PAID
Custom pricing

Contact vendor for tier or volume pricing.

View pricing page ↗
PUBLIC DOCUMENTS

Public documents

Vendor does not publish a public DPA. Without a publicly accessible Data Processing Addendum, small EU customers cannot self-serve the processor agreement — this caps the compliance score (see How we score).
  • Data Processing Addendum (DPA)
    — missing
    missing
  • Sub-processors list
    www.trackboxx.com/datenschutz…
    Open ↗
  • Terms of Service
    www.trackboxx.com/agb…
    Open ↗
ALTERNATIVES

Alternatives in this category