MOD-ANL · Analytics & monitoring module See what customers do, and what breaks, before they tell you.
Funnels and retention in Mixpanel, Amplitude or Google Analytics, installs traced to the campaign that brought them, journeys that answer what customers do, and every crash caught with the release that caused it. Tracking starts only with the customer's consent, and every event follows a tracking plan your team approves.
- 17connectors
- +1your own, too
- 01 · The job
Measure the product, not the person.
Product teams see where customers drop out of onboarding and which features they use. Marketing sees which campaigns bring customers who open an account, not just installs. Engineers get every crash and error with the device, the app version and the release. The analytics tools see a random ID and the events on your tracking plan, never a name, an account number or a card number.
- Funnels, retention and feature use
- Installs traced to the campaign behind them
- Journeys triggered by what customers do
- Crash and error reports per release
- Consent per purpose, changeable in the app
- No card or account numbers in any event
- 02 · The connectors
Mixpanel, Amplitude, AppsFlyer, Braze, Sentry, and more.
Each job runs on the tool your teams prefer. The apps and the platform send events through one interface and one tracking plan, directly or through Segment, so an event means the same thing in every tool, and your screens stay the same whichever tools receive it.
- 03 · Your own
Your accounts, your tracking plan.
Accounts you already have with these tools connect as they are, and an in-house analytics stack or a self-hosted error tracker becomes one more connector.
In-house, or a provider you already use- Your existing accounts and projects
- Your event names and tracking plan
- Your consent texts and retention periods
How it works
How Analytics & monitoring works, from consent to deletion
- 01
The customer chooses
Before any analytics, attribution or engagement tool starts, the app asks, purpose by purpose. The choice is kept in the platform, and the customer changes it in the app's settings as easily as they gave it. On iPhones, Apple's tracking prompt comes before any tracking across other companies' apps and websites.
- 02
Events follow the tracking plan
Every event and property a tool may receive is on a tracking plan your team reviews, and the platform sends nothing else. Customers appear under a random platform ID; card numbers, account numbers, document images and passwords never go into an event, a recording or an error report.
- 03
Money events come from the server
Screens and taps come from the tools' SDKs in the apps. Events that involve money, such as an account opened, a card issued or a payment settled, are sent from the platform's server, so every tool counts what the ledger counts.
- 04
Crashes reach engineers, cleaned
Crash, error and performance tools receive each problem with its stack trace, device, app version and release. Personal data is stripped before a report leaves the device, and server-side scrubbing, where the tool offers it, checks again.
- 05
Choices are honoured later too
When a customer withdraws consent or asks to be forgotten, the platform stops sending their data and asks each tool that holds it to delete it, through the tool's own deletion route.
What Analytics & monitoring needs from outside the software
No licence of its own: only the tools' contracts, which we help you get, and your decisions on purposes and consent. Under the ePrivacy Directive, storing or reading information on a customer's phone needs their consent unless it is strictly necessary for a service they asked for (Article 5(3)), and the EDPB's guidelines confirm that this covers app SDKs and unique identifiers. No EU-level guidance exempts analytics or crash reporting, so the module can hold any tool back until the customer agrees. Under the GDPR, each tool works for you under a processor contract (Article 28), and data leaving the EU needs a basis such as the EU-US Data Privacy Framework or standard contractual clauses (Chapter V). On iPhones, Apple requires its tracking permission before any tracking, ad measurement included, though that answer does not replace consent under EU law. PCI DSS forbids keeping sensitive authentication data after authorisation and requires card numbers to be unreadable wherever they are stored, one more reason card data stays out of every tool. And for EU financial entities, each tool is an ICT service in the DORA register of information (Article 28(3)).
- EUR-Lex: Directive 2002/58/EC (ePrivacy), Article 5(3), consolidated text
- EDPB: Guidelines 2/2023 on the technical scope of Article 5(3) of the ePrivacy Directive
- EUR-Lex: GDPR, Regulation (EU) 2016/679
- EUR-Lex: Implementing Decision (EU) 2023/1795, the EU-US Data Privacy Framework
- Apple: User Privacy and Data Use
- PCI SSC: FAQ 1210, sensitive authentication data after authorisation
- PCI SSC: FAQ 1492, card numbers rendered unreadable where stored
- EUR-Lex: DORA, Regulation (EU) 2022/2554
Where it runs
In these platforms, and in yours.
Crypto exchangeSpot trading, order book and custody wallets. Your exchange, live in a month.
Stock exchangeEquities trading, portfolios and market data, under your brand.
SoftPOSNFC phones become card terminals, reading cards through certified software. No hardware.
Banking appAccounts, cards and transfers. A neobank under your brand.
Crypto card appA stablecoin wallet with its own cards. Top up in crypto, pay anywhere, send money to any bank.
Payment gatewayCheckout plus merchant dashboard, assembled for your flow.
Remittance appMoney abroad in seconds, with the rate and the fee shown before anyone pays.
Stablecoin checkoutMerchants accept USDT and USDC online and by QR, then keep them or get paid out to their bank.
B2B stablecoin paymentsDollars as stablecoins next to a euro IBAN, to pay suppliers abroad and get paid.
Crypto on-rampLet people buy and sell crypto inside wallets, games and marketplaces, by card, Apple Pay or bank transfer.
Business accountAn account with its own IBAN, a card for everyone on the team, and every receipt in the books.
Super appAccounts in several currencies, cards, crypto and shares, in one app under your brand.
Family banking appAccounts and cards for kids and teens, with the allowance, chores and spending rules set by parents.
Crypto OTC deskFirm quotes for large crypto trades, settled from custody, under your brand.
Gold savings appGold by the gram, saved every week or month and sold back to the bank any time.- Anything else you buildThe same modules assemble into the product you have in mind. Tell us what it is.
Questions
What buyers ask about the Analytics & monitoring module.
Do customers have to agree before these tools start?
As the module is set up, yes. EU law requires consent to store or read information on a customer's phone unless it is strictly necessary for a service they asked for, and the EDPB confirms that covers app SDKs and identifiers. Each analytics, attribution and engagement tool starts only after the customer agrees to its purpose. Crash and performance tools can wait for consent too: no EU-level guidance exempts them, and the final call is your data protection officer's. Customers change their choice in the app's settings, as easily as they gave it.
Can card numbers or personal details end up in these tools?
They are kept out by design. Every event follows a tracking plan your team approves, customers appear under a random platform ID, and card numbers, account numbers, document images and passwords never go into an event, a session recording or an error report. Where a tool offers session replay, text and inputs are masked and screens with card or identity details are masked or left out. Engagement tools receive only the contact details they need to reach customers who opted in. Keeping card data out matters for PCI DSS too, which forbids keeping sensitive authentication data after authorisation; your assessor decides what is in scope.
Where is our analytics data stored?
In the EU wherever the tool allows, which is most of them. Mixpanel, Amplitude, PostHog, Segment, Customer.io, Braze, CleverTap, Adjust, Sentry, Datadog and New Relic offer an EU region, chosen when the account is created and in most cases fixed after that, and AppsFlyer keeps every account's data in the EU. Google Analytics collects data from EU devices on servers in the EU. Branch, Singular and BugSnag's hosted service keep data in the United States, so with them we settle the options before launch, such as an EU hosting arrangement or BugSnag On-premise in your own infrastructure. Data that does leave the EU travels under the EU-US Data Privacy Framework, for providers certified under it, or under standard contractual clauses.
What happens when a customer asks to be forgotten?
The GDPR asks you to pass an erasure on to everyone who received the data (Article 19). The platform stops sending the customer's data, then asks each tool to delete it. Most offer an API for it, such as Mixpanel's GDPR API, Amplitude's User Privacy API, Braze's /users/delete, a suppression in Customer.io and the OpenDSR APIs of AppsFlyer and Singular; with a few, such as New Relic, the request goes to the provider. Crash and error reports carry no personal details by design, and they are removed when their retention period ends.
Do iPhone customers see Apple's tracking prompt?
Only where a tool tracks in Apple's sense: linking data from your app with other companies' apps or websites for advertising or ad measurement, which mobile attribution can do. The app then shows Apple's App Tracking Transparency prompt before the attribution SDK starts. Customers who decline still count in Apple's AdAttributionKit and SKAdNetwork results, which need no permission. Mixpanel and Amplitude do not track in Apple's sense by default. Apple's prompt does not replace consent under EU law, so the app asks for both.
Do these tools belong in our DORA register?
If you are an EU financial entity, yes. Each hosted tool provides ICT services, so it goes into your register of information on ICT third-party arrangements, which DORA has required since 17 January 2025 (Article 28(3)), in the templates of Implementing Regulation (EU) 2024/2956. We help you fill in each tool's entry: who provides it, what it does for you and where your data is processed.
- MOD-ADM
Admin backoffice
One console to run the platform: customers, money, risk, content and staff permissions.
+5 10 connectors - MOD-CMP
Compliance reporting
Transaction monitoring, the Travel Rule and regulatory reports, ready for your regulator.
+3 8 connectors - MOD-NTF
Notifications
Email, SMS, push and in-app messages in your brand, through the providers you choose.
+7 12 connectors
Start your project
Tell us the idea. We'll show you the platform.
One call is enough to map your product to the modules that already exist.
- Response in under one business day
- NDA on request
- No obligation