Measurement and observability
GDPR Plausible
In an indie stack, Plausible is used for Audience measurement without cookies. Entity cited: Plausible Insights OÜ. The sections repeat what the vendor publishes, without filling a gap. Last update of the facts: October 4, 2026. Verified on October 4, 2026.
Translation of the French sheet. The facts do not change. The date is the date the official pages were read.
DPA Plausible
Yes. Public DPA.
Stated role
For visitor data of the customer's site, the customer is controller and Plausible is processor. For customer account data, Plausible is controller.
Personal data
Page URL, source and campaign parameters, browser, system, and device type derived from the User-Agent, country, region, and city derived from the IP address, engagement metrics, page views, events, properties, and optional revenue. The raw IP address and the User-Agent are used for a daily salted hash and are not stored. Account: email, billing, support exchanges.
Sub-processors of Plausible
Sub-processors that touch visitor data: Hetzner (Germany), Bunny (Slovenia), UpCloud (Finland).
Transfers outside the EU
Hosting / location
Visitor data is processed and stored in the EU. The site is stored at Hetzner in Falkenstein (Germany), UpCloud (Finland) for the database and exports, Bunny (Slovenia) as CDN. Plausible states that visitor data does not leave the EU.
EU–United States Data Privacy Framework
Official search for “Plausible”, “Plausible Insights”, and “Plausible Analytics”: no participant. Not registered.
Cookies
Plausible uses neither cookies, nor browser cache, nor local storage for visitor measurement. A persistent first-party cookie is used only to maintain the signed-in customer's session.
Typical use, written by StackLégal and not by the vendor: Audience measurement without cookies.
History
Last update: October 4, 2026.
First publication. The facts come from the official pages cited in the sources. Anything not stated there remains "not disclosed".
Clause to paste
Place it in the sub-processor section of your privacy policy. Review it: a “not disclosed” field must be completed before publication.
Sub-processor clause
Sources
Verified on October 4, 2026.
Frequently asked questions
Is Plausible a processor within the meaning of the GDPR?
For visitor data of the customer's site, the customer is controller and Plausible is processor. For customer account data, Plausible is controller.
What DPA does Plausible publish?
Yes. Public DPA. https://plausible.io/dpa
Which further sub-processors does Plausible publish?
Sub-processors that touch visitor data: Hetzner (Germany), Bunny (Slovenia), UpCloud (Finland). https://plausible.io/privacy#subprocessors
Where does Plausible state that it processes data, including outside the EU?
Visitor data is processed and stored in the EU. The site is stored at Hetzner in Falkenstein (Germany), UpCloud (Finland) for the database and exports, Bunny (Slovenia) as CDN. Plausible states that visitor data does not leave the EU.
Is Plausible registered under the EU–United States Data Privacy Framework?
Official search for “Plausible”, “Plausible Insights”, and “Plausible Analytics”: no participant. Not registered.
Which personal data does Plausible mention?
Page URL, source and campaign parameters, browser, system, and device type derived from the User-Agent, country, region, and city derived from the IP address, engagement metrics, page views, events, properties, and optional revenue. The raw IP address and the User-Agent are used for a daily salted hash and are not stored. Account: email, billing, support exchanges.
Often in the same stack
These sheets come up in searches for a Next.js SaaS. Next.js itself is not a processor: GDPR Next.js.
Related tools
Full pack, from 39 € incl. VAT
The clause above covers only one tool. StackLégal generates the legal notices, terms of use, terms of sale, privacy policy, Article 28 DPA, and the public list, naming only the boxes that are checked. One-time payment via Gumroad. This is not legal advice.