Visitors
Closed-source SaaS SaaS only From $9/mo
← All tools

Visitors Review (2026)

Real-time globe + RUM Web Vitals + revenue attribution, GPC + DNT honored — only directory tool checking GPC. US Delaware LLC, EU-hosted Hetzner

🇺🇸 United States Since 2025 Closed-source SaaS

Visitors.now is the only tool in this directory that honors Global Privacy Control (GPC) — and the second to honor DNT (alongside Fathom). GPC is the newer browser standard (since 2021), legally enforced under California SB-260 — making Visitors the cleanest privacy-signal-respecting option for California compliance.

— Mark Sutton, editor
Visitors.now product UI — live visitor curve, 28 people in last 30m, Experience Score 100 Perfect, Revenue A$750, Sales 100% CR
Dashboard captured via puppeteer
Editor score 3.5/5
From $9/mo Cloud only
Hosting SaaS only EU hosted
Privacy passport

Visitors compliance at a glance

GDPR posture, sub-processors under DPA, per-jurisdiction stance, and encryption — everything a procurement team checks.

GDPR Compliant EU General Data Protection Regulation EU's omnibus privacy law requiring a lawful basis for processing personal data (consent, legitimate interest, etc.). Applies to anyone handling EU-resident data. Visitors's posture: Legitimate interest.
CA
CCPA Compliant California Consumer Privacy Act California Consumer Privacy Act — rights for California residents (access, deletion, opt-out of sales). Triggered at $25M revenue or 50k+ CA-consumer records.
UK PECR Compliant UK Privacy and Electronic Communications Regulations UK Privacy and Electronic Communications Regulations sit on top of GDPR specifically for cookies and electronic marketing. PECR Reg 6 governs analytics-cookie consent.
SOC 2 · II Not held SOC 2 Type II SOC 2 Type II — independent audit verifying security/availability controls operate effectively over 6+ months. Standard B2B procurement requirement.
ISO27001
ISO 27001 Not held ISO/IEC 27001 information-security ISO/IEC 27001 — international information-security management standard, certified by accredited bodies on a 3-year renewal cycle.
HIPAA Not held US HIPAA (with BAA) US health-data law requiring a Business Associate Agreement (BAA) for any tool touching protected health information. Without BAA the tool cannot legally process PHI.

Per-jurisdiction posture

🇫🇷
France CNIL No banner Cookieless + EU-hosted + GPC/DNT honored aligns with CNIL guidance.
France · CNIL Cookieless + EU-hosted + GPC/DNT honored aligns with CNIL guidance.
🇬🇧
United Kingdom UK ICO / PECR No banner PECR Reg 6 cookies/storage trigger avoided.
United Kingdom · UK ICO / PECR PECR Reg 6 cookies/storage trigger avoided.
🇩🇪
Germany TTDSG No banner TTDSG §25 trigger avoided.
Germany · TTDSG TTDSG §25 trigger avoided.
🇮🇹
Italy Garante No banner GPC + DNT honoring strengthens position even with strict Italian Garante.
Italy · Garante GPC + DNT honoring strengthens position even with strict Italian Garante.

Sub-processors (5)

GDPR Art. 28 disclosure — third parties under DPA that may receive data.

Hetzner Primary infrastructure (EU) Germany
Cloudflare CDN + security United States
Stripe Payment processing United States
Mapbox Real-time globe city-level mapping United States

Collected

  • URLs visited and page titles
  • HTTP referrer + UTM parameters
  • Browser, OS, device type
  • City-level geolocation (via Mapbox; IP discarded after lookup)
  • Real-user Web Vitals (LCP, CLS, INP, FCP, TTFB)
  • Custom events with structured properties
  • Stripe/Dodo Payments/RevenueCat revenue events

Explicitly NOT collected

  • IP addresses (immediately discarded after city lookup)
  • Cookies on visitor devices (default mode)
  • Cross-site tracking identifiers
  • (Persist mode opt-in adds localStorage-based persistent identifier)
Data retention

Per-tier retention not publicly disclosed beyond 'unlimited' marketing copy.

Encryption
  • In transit: HTTPS
  • At rest: Encryption in transit + at rest (vendor self-attest)
DPA Yes · click through
AI & Modern Capabilities

How Visitors works with AI agents

Tier 3 — no AI yet — vendor focuses on classic privacy-first analytics; no AI/MCP features advertised.

AI Chat Not yet

Conversational natural-language interface

Not advertised by vendor

MCP Server Not yet

Model Context Protocol — Claude / Cursor / Codex

Not advertised by vendor

Agent API Not yet

Programmatic AI-agent endpoints

Not advertised by vendor

AI Insights Not yet

Anomaly detection / hypothesis / summaries

Not advertised by vendor

Export for AI Not yet

Structured export formatted for LLM ingestion

Not advertised by vendor

Strengths & weaknesses

What makes Visitors worth a look — and where it falls short.

Strengths 8

  • Only directory tool honoring GPC (Global Privacy Control)
  • Honors both DNT + GPC (verified in source)
  • RUM Web Vitals + Experience Score grade
  • Revenue attribution (Stripe + Dodo Payments + RevenueCat)
  • Funnels INCLUDED from $9 entry — no upsell wall
  • 3D real-time visitor globe (Mapbox-powered)
  • EU-only Hetzner hosting
  • ALL features unlocked at every tier

Weaknesses 6

  • Tracker ~7 KB gzipped (vendor advertises "Under 1KB" — misleading)
  • Newest tool in directory (launched Dec 2025, ~6mo operational)
  • Closed-source SaaS, no self-host option
  • No third-party security certs
  • No permanent free Cloud tier — 14-day trial only
  • No US data residency option (EU-only Hetzner)

Feature matrix

All 38 verified checks across 4 categories. Hover any row for the editor's note.

Tracking & Reporting 15

  • Pageviews & visitors Yes
  • Live visitor count Yes
  • Top pages report Yes
  • Top referrers Yes
  • UTM campaign tracking Yes
  • Country & city breakdown Yes
  • Device, browser, OS Yes
  • Bounce / engagement Yes
  • Time on site Yes
  • Custom events Yes
  • Goals / conversions Yes
  • Funnels Yes
  • Outbound link tracking ~Partial
  • File download tracking ~Partial
  • 404 / error tracking No

Privacy & Compliance 9

  • Cookieless by default Yes
  • No personal data collected Yes
  • GDPR-compliant out of the box Yes
  • Data hosted in EU Yes
  • Data hosted in US No
  • Self-hostable No
  • Open source No
  • Data retention period ·
  • Bot & spam filtering Yes

Setup & Integrations 10

  • Script weight (KB) 7
  • Single-snippet install Yes
  • WordPress plugin ~Partial
  • Proxy / first-party domain No
  • Public API Yes
  • Data export (CSV/JSON) Yes
  • Google Search Console connector No
  • Email digests No
  • Slack / webhook alerts No
  • Public shareable dashboard Yes

Pricing & Plans 4

  • Free tier exists No
  • Entry price ($/mo) $9/mo
  • Price at 100k pageviews $19/mo
  • Unlimited sites on entry plan Yes

Visitors vs alternatives

How it compares to the closest 3 rivals on key buyer-decision fields.

Fathom Analytics

Fathom Analytics

Cookieless privacy analytics with EU Isolation by default, founder-led since 2018

  • From$15/mo
  • HostingSaaS only
  • EU-hostedYes
  • CookielessYes
Pirsch

Pirsch

Cookieless EU-hosted analytics built in Germany, with open-source AGPLv3 core

  • From$6/mo
  • HostingSaaS only
  • EU-hostedYes
  • CookielessYes
DataFast

DataFast

Multi-processor revenue attribution for indie founders — Stripe + LemonSqueezy + Polar + Paddle + Shopify + Dodo + Woo + custom API. Singapore JustShipIt Pte Ltd. $9 entry

  • From$9/mo
  • HostingSaaS only
  • EU-hosted
  • Cookieless

Pricing tiers

Real plans, real numbers — pulled from visitors.now (verified May 2026).

Trial

Trial/14 days

Full access

  • ✓ No card required
10K

$9/mo

10K events

  • ✓ ALL features unlocked
  • ✓ Unlimited sites + team
100K

$19/mo

100K events

  • ✓ ALL features
500K

$49/mo

500K events

  • ✓ ALL features
1M

$79/mo

1M events

  • ✓ ALL features
25M

$889/mo

25M events

  • ✓ ALL features

Tech specs

Stack, repo health, deployment options — for engineers evaluating self-host.

Stack

  • Written inTypeScript (TanStack Start)
  • HostingHetzner EU
  • CDNCloudflare
  • PaymentsStripe + Dodo + RevenueCat
  • MapsMapbox
  • EmailResend
  • LicenseClosed-source SaaS
  • Min specsN/A — SaaS only

Deploy

  • · Cloud SaaS only
Mark Sutton

Editor review

Independently reviewed by Mark Sutton, cross-checked against vendor documentation. Click any panel to expand.

+ What it does well

Visitors.now is the only tool in this directory that honors Global Privacy Control (GPC) — and the second to honor DNT (alongside Fathom). GPC is the newer browser standard (since 2021), legally enforced under California SB-260 — making Visitors the cleanest privacy-signal-respecting option for California compliance.

Real-User Monitoring Web Vitals + Experience Score grade. Live LCP/CLS/INP/FCP/TTFB collection with per-page/country/device breakdowns. The "Experience Score" 0-49 / 50-89 / 90+ rating mirrors Lighthouse — among directory peers, only Swetrix bundles Web Vitals (and that's lab-data, not RUM).

Revenue attribution across 3 payment processors (Stripe + Dodo Payments + RevenueCat) — typical SaaS stack covered. Datafast has 8 processors but Datafast is US-hosted with cookies on by default; Visitors stays EU-only and cookieless.

Funnels included from $9 entry — no upsell wall. Plausible gates funnels behind $39 Business; Fathom has no funnels at any price.

3D real-time visitor globe + visitor profiles with full session history — visual flair plus genuinely useful for SaaS demos and Stripe purchase moment-capture. Mapbox-powered city-level.

Weaknesses & gotchas

Tracker is NOT 'Under 1KB' as advertised. Verified actual size: 20.1 KB raw / ~7 KB gzipped (curl-measured from cdn.visitors.now/v.js). Vendor homepage's "Under 1KB" claim is materially misleading — actual size is ~7× the advertised. Plausible 1 KB / Pirsch 1.5 KB / GoatCounter 1 KB / TelemetryDeck 0.7 KB are genuinely sub-2 KB; Visitors is closer to Swetrix's 5 KB tier.

Newest tool in directory. Public launch December 2025 — ~6 months operational at time of writing. No track record under load. Compare to Plausible (founded 2018, profitable since 2020) or Pirsch (founded 2019).

Closed-source SaaS only. No GitHub repo, no self-host option. For data sovereignty, look at AGPL alternatives (Plausible/Rybbit/Swetrix/OpenPanel/Databuddy).

No third-party security certifications. GDPR/CCPA/PECR self-attested only. Among directory peers, only Matomo Cloud (ISO 27001), Piwik PRO (full enterprise), Countly (ISO+SOC2) hold third-party certs.

No permanent free Cloud tier — only 14-day trial. Among directory peers with free SaaS: Umami Hobby, GoatCounter Cloud, Aptabase 20K, Databuddy 10K, TelemetryDeck 100K signals, Seline 3K events.

No US data residency option. Hetzner EU-only — for US-only-data customers, look at Fathom (AWS multi-region with US East option).

Best for

Best for: indie SaaS founders running on Stripe + Dodo Payments + RevenueCat who want one privacy-first tool for analytics + funnels + Web Vitals + revenue attribution. California-compliance-conscious operators who need GPC honoring (legally enforced under SB-260). Teams that want unlimited websites + team members on every tier.

Real value at $9 entry: all features unlocked — funnels, revenue, Web Vitals, custom events, public dashboards, real-time globe, visitor profiles, custom events. At $19 (100K events): sweet-spot for SaaS at PMF stage. At $79 (1M events): mid-traffic SaaS with revenue tracking enabled.

Not for: sites with strict JS-budget constraints (use Plausible 1KB or TelemetryDeck 0.7KB); enterprises requiring SOC 2 / ISO 27001 (use Piwik PRO or Countly); teams needing US data residency (use Fathom AWS multi-region); teams that prefer self-host or AGPL audit-ability (use Plausible CE / Rybbit / Swetrix / OpenPanel / Databuddy); high-traffic publishers (Visitors $889/25M is premium pricing — Plausible scales flatter).

Setup walkthrough

1. Sign up at visitors.now — 14-day trial, no card.
2. Drop the script in :
`html

`
~7 KB gzipped — note vendor's homepage "<1KB" claim is misleading. 3. Connect Stripe via OAuth in dashboard for revenue attribution. Add Dodo Payments + RevenueCat similarly if used. 4. (Optional) Enable persist mode via data-persist HTML attribute for cross-session visitor identity (requires consent if your jurisdiction triggers ePrivacy).
5. Use Visitors.identify({user_id, email}) for known/logged-in users; Visitors.event('signup', {plan: 'pro'}) for custom events.
6. View 3D real-time globe + visitor profiles + Web Vitals + revenue dashboards. Public read-only sharing available.
7. Use REST API for programmatic access (launched March 2026 — Account API + Project API with 30+ endpoints).

SDK frameworks supported: Next.js, React, Vue.js, Nuxt.js, SvelteKit, Astro, Angular per /docs.

Migrating from GA4

From GA4 + Stripe Dashboard reports. Visitors replaces both with a single dashboard.

1. Export GA4 historical data first (BigQuery or CSV) — Visitors imports nothing from GA4, history starts at install.
2. Install Visitors alongside GA4 for 2-4 weeks. Bot filtering will make Visitors counts ~10-20% lower than GA4 — expected.
3. Map GA4 conversions → Visitors goals via Visitors.event() API.
4. Connect Stripe via OAuth. Existing payments backfill automatically (no metadata pass-through required, unlike Datafast).
5. Drop GA4 + cookie banner — Visitors is cookieless by default with GPC + DNT honoring, so most EU sites can drop the consent banner entirely.
6. Set up Web Vitals dashboard (auto-collected from RUM data) — replaces PageSpeed Insights field-data exports.
7. Funnels can be defined in dashboard from existing custom events.

Caveats: if you depend on GA4's Looker Studio integration, Visitors REST API is read-only at the moment. If you need US data residency, Visitors is EU-only — look at Fathom AWS multi-region.

Help & FAQ

Where to get help with Visitors and the questions buyers email us about.

Support

HoursAsyncUS (Delaware) / AU founder origin
ChannelsEmail
LanguagesEnglish
Response SLA~48h

FAQ (7)

Does Visitors really honor Do Not Track and GPC?

Yes — verified in tracker source code. Both navigator.globalPrivacyControl (GPC) and navigator.doNotTrack (DNT) are checked, and when either is on, no events are sent. Among directory peers, only Fathom honors DNT — Visitors is the FIRST directory tool to also honor GPC (legally enforced under California SB-260).

Is the tracker really 'Under 1KB' as advertised?

No — vendor's homepage claim is misleading. Verified actual size: 20.1 KB raw / ~7 KB gzipped (curl-measured from cdn.visitors.now/v.js). Still small but ~7× the advertised 1KB. For honest size comparisons, Plausible 1 KB / Pirsch 1.5 KB / GoatCounter 1 KB / TelemetryDeck 0.7 KB are genuinely sub-2 KB; Visitors is closer to Swetrix's 5 KB tier.

What does Visitors.now actually do that Pirsch/Plausible don't?

Three things: (1) Real-User Monitoring (RUM) Web Vitals — live LCP/CLS/INP/FCP/TTFB with per-page/country/device breakdowns + 'Experience Score' grade; (2) revenue attribution across 3 processors (Stripe + Dodo Payments + RevenueCat); (3) GPC honoring (in addition to DNT). Plus a 3D real-time visitor globe (Mapbox-powered) which is more visual flair but useful for SaaS demos.

What's the actual price ladder?

$9 (10K events) → $19 (100K) → $29 (300K) → $49 (500K) → $79 (1M) → $129 (2.5M) → $229 (5M) → $399 (10M) → $549 (15M) → $699 (20M) → $889 (25M). 14-day trial no card. Annual = 20% off. ALL features unlocked at $9 entry — no upsell wall for funnels/revenue/Web Vitals.

Where is data stored?

Hetzner EU only (per DPA verbatim). US-incorporated Delaware LLC but analytics data plane is EU-only. Cloudflare CDN + Stripe + Resend + Mapbox are US-resident sub-processors for ancillary services.

Is there a free tier?

No permanent free Cloud tier — only 14-day trial without credit card. Among directory peers with free tiers: Umami Hobby (free SaaS), GoatCounter Cloud (free), Counter.dev (PWYW), Aptabase (20K free), Databuddy (10K free), TelemetryDeck (100K signals free), Seline (3K events free).

Are there third-party security certifications?

No. GDPR/CCPA/PECR self-attested only. Among directory peers, only Matomo Cloud (ISO 27001), Piwik PRO (full enterprise stack), and Countly (ISO+SOC2) hold third-party certs.