Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Nepcha is a lightweight, cookieless web analytics tool designed to comply with GDPR and other privacy laws without a consent banner. It measures page views, sources, devices and campaigns using a small JavaScript snippet that sets no cookies and stores no persistent identifier, and it does not collect personal data. Because it stores nothing on the visitor device and processes only aggregated, non identifying data, it is built to run consent free and presents a low compliance risk.
Nepcha is a privacy first web analytics service aimed at site owners who want simple, GDPR friendly numbers without the weight and consent overhead of Google Analytics. A small script measures visits, traffic sources, top pages, devices and campaigns and presents them in a clean dashboard. The design goal is to deliver useful analytics while collecting no personal data and setting no cookies.
Nepcha is cookieless: it sets no cookies and stores no persistent identifier on the device. It records aggregated, non identifying signals such as the page viewed, the referrer, the campaign parameters, the device type and a coarse, anonymised location, and it does not try to follow the same person across visits. With no device storage and no personal data, there is nothing that can be traced back to an individual.
Article 5(3) of the ePrivacy Directive only requires consent when a service stores or reads information on the user device, which Nepcha does not do, so it falls outside the cookie consent requirement. As it processes no personal data, the GDPR obligations are minimal, and any residual, non identifying data can rest on legitimate interest under article 6(1)(f). This is what allows Nepcha to run without a consent banner.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Because Nepcha is cookieless and collects only aggregated, non identifying data, there is little or no personal data to transfer to a third country. For your records of processing, confirm the hosting region with the provider and note it; in the standard configuration there is no identifiable European data sent outside the European Economic Area.
Install the snippet, confirm with developer tools that no cookie or local storage entry is created, and describe Nepcha as a cookieless, consent free analytics tool in your privacy policy. Confirm and record the hosting region, keep the data aggregated, and if you ever combine Nepcha with cookie based tools, gate those behind consent so they do not undermine the consent free status.
Websites using Nepcha must obtain user consent under GDPR regulations.
DPIA considerations
Because Nepcha is cookieless and processes no personal data, a DPIA is generally not required. If you configure it to capture anything that could identify a person, reassess the legal basis and document the safeguards. Confirm and record the hosting region so your records of processing are complete.
Sample consent text
This website uses Nepcha, a cookieless analytics tool, to understand which pages and campaigns work best. Nepcha sets no cookies, stores no persistent identifier and collects no personal data, so it runs without requiring your consent. You can read more about how we measure our audience in our privacy policy.
Third-party domains contacted
nepcha.comcdn.nepcha.comNepcha collects user analytics data — you legally need a consent banner. Try FlowConsent free.
No. Nepcha is cookieless: it sets no cookies and stores no persistent identifier on the visitor device. It measures aggregated, non identifying data, which is why it does not need the cookie consent required by article 5(3) of the ePrivacy Directive.
Generally no. Because it stores nothing on the device and processes no personal data, Nepcha falls outside the ePrivacy consent requirement and can run without a cookie banner. Confirm with developer tools that no storage is created in your setup.
With no cookies and no personal data, there is little to justify; any residual, non identifying data can rest on legitimate interest under GDPR article 6(1)(f). No consent under article 6(1)(a) is needed for the standard configuration.
Because Nepcha is cookieless and collects only aggregated, non identifying data, there is little or no personal data to transfer. Confirm and record the hosting region with the provider so your records of processing are accurate.
Normally no. A cookieless tool that processes no personal data is low risk and does not trigger the DPIA requirement of GDPR article 35. Reassess only if you configure it to capture identifying data.
Install the snippet, confirm no cookie or local storage entry appears, describe Nepcha as cookieless and consent free in your privacy policy, and record the hosting region. Keep any cookie based tools behind consent so they do not undermine the consent free status.
Other cookieless, privacy friendly analytics include Plausible, Fathom, Simple Analytics, SealMetrics and Matomo in cookieless mode. Choose based on hosting location, features and pricing, and prefer EU hosting if you want to remove any transfer question entirely.
State that you use Nepcha, that it is cookieless and consent free, that it processes no personal data, and note the hosting region. Review the description if you change the configuration or combine Nepcha with other tools.