plausible.io is hosted on AWS - an american company
snowplowanalytics.com seems to be hosted in digitalocean as well
as I understand they are equally illegal now.
[Self-hosting and maintaining is not an option for the vast majority of mom-and-pop shops]
That means Posthog self-hosted on an AWS server in Frankfurt wouldn't avoid this issue.
What're the best options for non-US owned cloud providers? AFAICT Canada or many other countries with privacy laws would be fine, it's really the US specifically that's problematic.
International companies must comply to the local laws and regulations. EU is so large market that they will implement anything EU requires. For example, AWS can host and collect EU data and fully comply with EU regulations, never moving data to the US. With AWS customers can determine where their customer data will be stored, including the type of storage and geographic region of that storage.
For me, it makes no sense when companies like plausible say they have EU based hosting when they pay for hosting from a US-only company (DigitalOcean)
https://plausible.io/privacy-focused-web-analytics
All of the data that we do track and collect is kept fully secured, encrypted and hosted on renewable energy powered server in Germany. This ensures that all of the website data is being covered by the European Union’s strict laws on data privacy.
Plausible seems to use Netlify/AWS for analytics. Both US companies.
In fact, I don't think I will ever use or recommend Fathom to anyone after seeing you act so childish.
What's childish about me not wanting people to potentially get fined?
At what point exactly are they going to get fined? I don't understand so I would love to know, so as long as you actually manage to answer with somewhat of a technical depth.
Maybe you should do one of those "Fathom vs Plausible" pages on your website, then point out that Plausible is using a testing environment and because of that they will be fined.
I've put together the details here in an image, so it's easy to follow (https://imgur.com/a/9wEanqD). Hope that explains what I'm talking about.
Sending data from the EU to US-controlled cloud infrastructure is illegal. Please read the noyb article again, read the Schrems II ruling and read the EDPB's advice.
This is unique to Plausible itself and not the services they provide for their customers.
Why do you insinuate misbehavior from a competitive company when you don't have actual proof?
You have the URL of a CDN network that is hosted in the US. What you don't have is the proof of this data being stored in the US. Because it is not. Their FAQ pages clearly state that none of the data is ever stored outside of EU.
Last but not least, you entirely missed my point. Plausible is an extremely successful business, do you really believe they would risk their reputation / livelihood without understanding Schrems II or otherwise?
I honestly have nothing else to say mate. But good luck with Fathom. I am sure it will be a great success.
CDN is processing of Personal Data in the clear. Please read Use Case 6 of the EDPB's recommendations, specifically what they say about US cloud providers (https://edpb.europa.eu/sites/default/files/consultation/edpb...).
And I'm not interested in commenting on what I think Plausible would or wouldn't risk, as it's not relevant.
And also, you're completely wrong.
As a Plausible customer, your data is never processed in the US, or sent to the "cloud" outside of EU.
I wonder what Paul thinks of your attempts to fear monger people into thinking your crappy product is superior to an open-source alternative.
But hey man, good luck with Fathom. It will be a great success.
Using EU servers that are owned by a US company (e.g. AWS deployed in the EU, DigitalOcean deployed in the EU) is a violation of the Schrems II ruling. The way you check this is by looking at the IP addresses the analytics software are using, seeing where they're located and who they're owned by. You can then run that IP in ipinfo.io to get information about who controls that IP. If it's a US cloud provider, regardless of server location, it's a GDPR violation.
The English translation of the ruling can be found here. They go into detail within the rulings about the transfer of Personal Data (IP & User Agent) to servers that cannot be protected from US surveillance laws: https://noyb.eu/sites/default/files/2022-01/E-DSB%20-%20Goog...
"This is a very detailed and sound decision. The bottom line is: Companies can't use US cloud services in Europe anymore. It has now been 1.5 years since the Court of Justice confirmed this a second time, so it is more than time that the law is also enforced." - Max Schrems
For our self-hosted version, you can install it with any cloud provider and in any country you wish. Even in the USA. That's the testing one we had on our site as we're testing the latest release of our self-hosted version on our own website. This has nothing to do with what our customers place on their sites.
You were using Netlify previously, which is a US provider and backed by AWS, and then Cloudflare for the testing.
But yesterday I can see you moved to Bunny (an EU cloud provider), which is great news for your customers, party time!
Provided you’re using Hetzner behind Bunny, that looks like solid Schrems II compliance to me.
For our self-hosted version, you can install it with any cloud provider and in any country you wish. Even in the USA.