Snowplow
A self-hosted event pipeline that runs in your own cloud — full data ownership, but it collects exactly what you configure it to collect, which can be a lot.
verified 2026-07-11 · grade set per the published methodology
How the grade breaks down
How little it collects, and whether collection is purpose-bound.
Whether it respects GPC, consent state, and tracking-prevention signals.
Cookieless vs. persistent IDs, cross-site linkage, fingerprinting risk.
Where data lives and whether it is shared with third parties.
How verifiable and documented its real behavior is.
At a glance
Snowplow is an event-collection pipeline that runs in the operator’s own cloud account, so raw data never passes to a third party — the strongest possible ownership-and-residency posture. Everything else depends on configuration: the default web trackers set first-party cookies and collect granular event, session, and device context, and the pipeline will faithfully capture whatever schemas the operator defines, including personal data. Identifiers are first-party and feed no advertising graph, but they persist unless anonymous-tracking mode is enabled. Consent gating, GDPR contexts, and PII pseudonymization are available but must be deliberately implemented. The grade reflects the default documented behavior: a privacy-exemplary Snowplow deployment is entirely achievable — and entirely the operator’s responsibility.
Sources & basis for grade
Grades reflect documented behavior, vendor documentation, and ad.rip scans as of the date above. Each assessment is reproducible and vendors may request correction.
- Snowplow open-source repository (Community Edition)
- Snowplow tracker documentation (cookies, anonymous tracking mode)
- Snowplow consent / GDPR-context documentation