MOD-ANL · Analytics & monitoring module See what customers do, and what breaks, before they tell you.

Funnels and retention in Mixpanel, Amplitude or Google Analytics, installs traced to the campaign that brought them, journeys that answer what customers do, and every crash caught with the release that caused it. Tracking starts only with the customer's consent, and every event follows a tracking plan your team approves.

  • 17connectors
  • +1your own, too
  1. 01 · The job

    Measure the product, not the person.

    Product teams see where customers drop out of onboarding and which features they use. Marketing sees which campaigns bring customers who open an account, not just installs. Engineers get every crash and error with the device, the app version and the release. The analytics tools see a random ID and the events on your tracking plan, never a name, an account number or a card number.

    • Funnels, retention and feature use
    • Installs traced to the campaign behind them
    • Journeys triggered by what customers do
    • Crash and error reports per release
    • Consent per purpose, changeable in the app
    • No card or account numbers in any event
  2. 02 · The connectors

    Mixpanel, Amplitude, AppsFlyer, Braze, Sentry, and more.

    Each job runs on the tool your teams prefer. The apps and the platform send events through one interface and one tracking plan, directly or through Segment, so an event means the same thing in every tool, and your screens stay the same whichever tools receive it.

    Customer data platform

    Customer engagement

    Crash, error and performance monitoring

  3. 03 · Your own

    Your accounts, your tracking plan.

    Accounts you already have with these tools connect as they are, and an in-house analytics stack or a self-hosted error tracker becomes one more connector.

    In-house, or a provider you already use
    • Your existing accounts and projects
    • Your event names and tracking plan
    • Your consent texts and retention periods

How it works

How Analytics & monitoring works, from consent to deletion

  1. 01

    The customer chooses

    Before any analytics, attribution or engagement tool starts, the app asks, purpose by purpose. The choice is kept in the platform, and the customer changes it in the app's settings as easily as they gave it. On iPhones, Apple's tracking prompt comes before any tracking across other companies' apps and websites.

  2. 02

    Events follow the tracking plan

    Every event and property a tool may receive is on a tracking plan your team reviews, and the platform sends nothing else. Customers appear under a random platform ID; card numbers, account numbers, document images and passwords never go into an event, a recording or an error report.

  3. 03

    Money events come from the server

    Screens and taps come from the tools' SDKs in the apps. Events that involve money, such as an account opened, a card issued or a payment settled, are sent from the platform's server, so every tool counts what the ledger counts.

  4. 04

    Crashes reach engineers, cleaned

    Crash, error and performance tools receive each problem with its stack trace, device, app version and release. Personal data is stripped before a report leaves the device, and server-side scrubbing, where the tool offers it, checks again.

  5. 05

    Choices are honoured later too

    When a customer withdraws consent or asks to be forgotten, the platform stops sending their data and asks each tool that holds it to delete it, through the tool's own deletion route.

What Analytics & monitoring needs from outside the software

No licence of its own: only the tools' contracts, which we help you get, and your decisions on purposes and consent. Under the ePrivacy Directive, storing or reading information on a customer's phone needs their consent unless it is strictly necessary for a service they asked for (Article 5(3)), and the EDPB's guidelines confirm that this covers app SDKs and unique identifiers. No EU-level guidance exempts analytics or crash reporting, so the module can hold any tool back until the customer agrees. Under the GDPR, each tool works for you under a processor contract (Article 28), and data leaving the EU needs a basis such as the EU-US Data Privacy Framework or standard contractual clauses (Chapter V). On iPhones, Apple requires its tracking permission before any tracking, ad measurement included, though that answer does not replace consent under EU law. PCI DSS forbids keeping sensitive authentication data after authorisation and requires card numbers to be unreadable wherever they are stored, one more reason card data stays out of every tool. And for EU financial entities, each tool is an ICT service in the DORA register of information (Article 28(3)).

Where it runs

In these platforms, and in yours.

Questions

What buyers ask about the Analytics & monitoring module.

Do customers have to agree before these tools start?

As the module is set up, yes. EU law requires consent to store or read information on a customer's phone unless it is strictly necessary for a service they asked for, and the EDPB confirms that covers app SDKs and identifiers. Each analytics, attribution and engagement tool starts only after the customer agrees to its purpose. Crash and performance tools can wait for consent too: no EU-level guidance exempts them, and the final call is your data protection officer's. Customers change their choice in the app's settings, as easily as they gave it.

Can card numbers or personal details end up in these tools?

They are kept out by design. Every event follows a tracking plan your team approves, customers appear under a random platform ID, and card numbers, account numbers, document images and passwords never go into an event, a session recording or an error report. Where a tool offers session replay, text and inputs are masked and screens with card or identity details are masked or left out. Engagement tools receive only the contact details they need to reach customers who opted in. Keeping card data out matters for PCI DSS too, which forbids keeping sensitive authentication data after authorisation; your assessor decides what is in scope.

Where is our analytics data stored?

In the EU wherever the tool allows, which is most of them. Mixpanel, Amplitude, PostHog, Segment, Customer.io, Braze, CleverTap, Adjust, Sentry, Datadog and New Relic offer an EU region, chosen when the account is created and in most cases fixed after that, and AppsFlyer keeps every account's data in the EU. Google Analytics collects data from EU devices on servers in the EU. Branch, Singular and BugSnag's hosted service keep data in the United States, so with them we settle the options before launch, such as an EU hosting arrangement or BugSnag On-premise in your own infrastructure. Data that does leave the EU travels under the EU-US Data Privacy Framework, for providers certified under it, or under standard contractual clauses.

What happens when a customer asks to be forgotten?

The GDPR asks you to pass an erasure on to everyone who received the data (Article 19). The platform stops sending the customer's data, then asks each tool to delete it. Most offer an API for it, such as Mixpanel's GDPR API, Amplitude's User Privacy API, Braze's /users/delete, a suppression in Customer.io and the OpenDSR APIs of AppsFlyer and Singular; with a few, such as New Relic, the request goes to the provider. Crash and error reports carry no personal details by design, and they are removed when their retention period ends.

Do iPhone customers see Apple's tracking prompt?

Only where a tool tracks in Apple's sense: linking data from your app with other companies' apps or websites for advertising or ad measurement, which mobile attribution can do. The app then shows Apple's App Tracking Transparency prompt before the attribution SDK starts. Customers who decline still count in Apple's AdAttributionKit and SKAdNetwork results, which need no permission. Mixpanel and Amplitude do not track in Apple's sense by default. Apple's prompt does not replace consent under EU law, so the app asks for both.

Do these tools belong in our DORA register?

If you are an EU financial entity, yes. Each hosted tool provides ICT services, so it goes into your register of information on ICT third-party arrangements, which DORA has required since 17 January 2025 (Article 28(3)), in the templates of Implementing Regulation (EU) 2024/2956. We help you fill in each tool's entry: who provides it, what it does for you and where your data is processed.

Same family

The whole library

Start your project

Tell us the idea. We'll show you the platform.

One call is enough to map your product to the modules that already exist.

  • Response in under one business day
  • NDA on request
  • No obligation
What are you building?