Managed Matomo hosting

Workflow and dataOn-prem or sovereign site

Web analytics for your websites and apps, run in Switzerland, the EU or your own datacentre, with every visit stored in a database you own. Pilae runs it on your own servers, or in Zurich, Switzerland, and eleven other Pilae Cloud regions.

Talk to us about Matomo

Licence
GPL-3.0-or-later
Runs on
Your own hardware, or any of twelve Pilae regions — six of them in Switzerland and the EU
Upgrades
Pinned, tested against your configuration, applied in your window
Upstream
matomo.org

Running Matomo in production: what it takes

  1. Deploy on MariaDB

    A Matomo image pinned to a version we have run, on its own MariaDB database in utf8mb4. The installer is switched off once set-up is done, and the config file lives in your repository.

  2. Publish the tracker, keep the interface private

    The gate on port 443 publishes the tracking endpoint, the script and the opt-out on a hostname you choose. The interface and the reporting API answer only on the private network, behind sign-on.

  3. Archive by cron and watch it

    core:archive runs every hour with browser-triggered archiving off. A failed run alerts an engineer, because with browser archiving off a stopped cron means reports that quietly stop filling.

  4. Back up visits, config and plugins

    Every day the database, config.ini.php and any marketplace plugins leave for an offsite location, encrypted. The monthly drill restores them into a scratch instance and opens a report there.

  5. Upgrade without losing hits

    A release can migrate the database, and on a large visit table that can take hours, so the Pilae Agent times it on a copy first and waits for your approval. During the window, tracking requests are held in a queue and replayed afterwards. For a major release they are replayed from the access log instead, following the procedure upstream documents for large instances.

What Matomo is, and who runs it

Self-hosted Matomo for web analytics

Matomo is a web analytics platform: a JavaScript tracker on your sites and apps, a PHP application that receives the hits, and a MariaDB or MySQL database that keeps every visit. It covers the reports most teams open in Google Analytics, from traffic sources and pages to goals, events and ecommerce. What changes is where each hit lands: in a database you own, not in Google’s.

It gets a dedicated machine of its own, in your datacentre or in one of 12 Pilae Cloud regions, six of them in Switzerland and the EU, and the visit data and the reports built from it stay in that jurisdiction.

Matomo in production: archiving, the public endpoint and retention

Matomo does not build reports when a visit arrives. It aggregates raw visits into reports in a separate step called archiving, and by default a browser opening a report can start it. On real traffic that turns a dashboard into a long query against the busiest tables in the database, so we switch it off and run core:archive from cron every hour, with an alert when a run fails.

The tracker has to be reachable from every visitor’s browser, and the rest of Matomo does not. The gate publishes the tracking endpoint and script on a hostname you choose, and the interface stays on your private network, behind sign-on.

The raw visit tables are the part that grows. We agree a retention period with you, and raw visits older than that are deleted only once they have been archived. The reports built from them stay.

The database, config.ini.php and any marketplace plugins are backed up daily, encrypted, to an offsite location in your chosen country, and restored every month into a scratch instance. Probes check the tracker and the interface every 60 seconds and alert an engineer. Upgrades go through the Pilae Agent: timed on a copy, approved by you, applied in your window and recorded in the console.

Matomo licence and editions

Matomo has no fee per user or per page view. OpenID Connect for Keycloak or Entra ID is a free community plugin. The proposal names the premium plugins your requirements need, so none of them turns up later as a surprise. Pricing for our operation is on request. Talk to us about the sites you want to measure.

Matomo core, including the Tag Manager that ships with it, is GPL-3.0-or-later, and so are free plugins from the Matomo team such as LDAP sign-in and QueuedTracking. Premium plugins such as Heatmap & Session Recording, Funnels, Form Analytics, Custom Reports, A/B Testing and Login SAML are sold by InnoCraft, the company that makes Matomo, under its commercial EULA: one production instance per licence, installed on systems owned, leased or controlled by the licensee, and not open source. If you need them, the licences are held in your name. The Matomo name is a registered trademark that the GPL does not cover, and we run Matomo unmodified.

Matomo system requirements

Before anything is deployed, this is what has to exist. We size it with you in the first session, and we say so when your own hardware is already enough.

CPU and memory
4 vCPU · 8 GB · 250 GB SSDUpstream's figure for up to a million page views a month, with the database on the same machine. Above that, the database moves to a machine of its own.
Database
MariaDB 10.6+ or MySQL 8.0+PostgreSQL is not supported, and upstream says it is unlikely to be. The raw visit tables grow with traffic, which is why retention is agreed on the first day.
Archiving
core:archive, hourly cronReports are built ahead of time from the raw visits, not when someone opens them. A custom date range is the one report still computed on request.
Geolocation
DB-IP or MaxMind GeoIP2Without a GeoIP database Matomo guesses the country from the browser language and records no region or city. The free DB-IP database is refreshed monthly.
Public endpoint
/matomo.php, /matomo.jsBrowsers must reach the tracker, so these two paths and the opt-out are published through the Pilae gate on port 443.

Migrating from Google Analytics to Matomo

Google Analytics history comes across as reports, not as individual visits. Matomo's free Google Analytics Importer reads aggregated reports from a GA4 property through Google's API and writes them into a new site in Matomo. It cannot import into an existing site or be merged into one later, so the import starts before the tracker goes live and the tracker then reports into that same site. On imported months the visitor log, segments and custom reports do not work, weekly and monthly reports have no unique visitors, and GA4 goals arrive without names or revenue. Google's daily API quota spreads a large import over several days. The bigger job is elsewhere: replacing the Google tag on every site and app, rebuilding key events as Matomo goals, and agreeing with your data protection officer which consent setup applies.

  1. Start the history import first

    The Google Analytics Importer runs from the console against your GA4 property and creates the site Matomo then tracks into. Its end date is the day before Matomo starts tracking, so the two never overlap.

  2. Map key events to goals

    Each GA4 key event and custom dimension in use is listed with its owner and rebuilt as a Matomo goal, event or custom dimension. Anything nobody claims is left behind.

  3. Tag both, compare for a month

    The Matomo tracker goes on beside the Google tag, directly or through Matomo Tag Manager. The two tools define some metrics differently, so we agree which gaps are expected before anyone compares.

  4. Remove the Google tag

    Once owners accept the figures, the Google tag comes off every site and app and the privacy notice is updated. The GA4 property is kept or deleted under your own retention policy.

Matomo configured for cron archiving and a private interface

; config/config.ini.php (excerpt)
[database]
host = "db.acme.internal"
dbname = "matomo"
username = "matomo"
tables_prefix = "matomo_"
charset = "utf8mb4"

[General]
; the interface answers on the private hostname only
trusted_hosts[] = "matomo.acme.internal"
force_ssl = 1
assume_secure_protocol = 1
; the visitor's address, not the gate's
proxy_client_headers[] = HTTP_X_FORWARDED_FOR
; reports come from cron, never from a browser
enable_browser_archiving_triggering = 0
browser_archiving_disabled_enforce = 1
; archiving, retention and update settings stay in this file
enable_general_settings_admin = 0
enable_delete_old_data_settings_admin = 0
enable_auto_update = 0
enable_installer = 0

[Deletelogs]
; raw visits kept for 13 months, reports kept
delete_logs_enable = 1
delete_logs_older_than = 395

# /etc/cron.d/matomo-archive
5 * * * * www-data php /var/www/html/console core:archive --url=https://matomo.acme.internal/
An example excerpt. The interface answers only on a private hostname, reports come from the hourly cron, and raw visits older than thirteen months are deleted while the reports built from them stay. These settings live in your repository, and the admin screens that could override them are switched off.

What Pilae is responsible for

A pinned version

A version we have run, not whatever latest resolves to that day.

A runbook

What it depends on, how it fails, what to do about it. In your repository.

A restore drill

Backups restored on a schedule. A backup nobody has restored is a file.

A patch window

Security updates in a window you agreed, with a rollback ready.

Someone watching

Every endpoint probed on the minute. An alert reaches a person, not a dashboard nobody opens.

Where it runs
zur1, fra1, fal1, gra1, ams1, hel1, lon1, ash1, hil1, sin1, tok1, syd1, on-premZurich, Frankfurt, Falkenstein, Gravelines, Amsterdam, Helsinki, London, Ashburn, Hillsboro, Singapore, Tokyo, Sydney, Your own hardware
Who holds the credentials
You do. Ours are separate, named, logged and revocable with one command. We ask before anything changes outside an agreed window.
If you leave
The machine, the data, the compose files and the runbook are already yours. Nothing stops when our access does.

What drives the price of running Matomo

Pricing is on request: a fixed price for onboarding, then a monthly price for Matomo, quoted in writing within five business days. The plans set what every deployment includes; these are the inputs the quote is built from.

Instance size
The CPU, memory and, where a model runs, the GPUs the app needs for your users and your data.
High availability
One machine with tested restores, or a replicated setup that keeps serving when a node fails.
Storage and backups
How much data it holds, how long backups are kept, and point-in-time recovery for its database.
Plan and support
Essential, Business or Enterprise: support hours, response times in the contract and how often we review the service with you.
Region
Your own hardware, where the infrastructure is already yours, or a Pilae Cloud region, where it is passed through at cost plus a fixed margin.
Sign-on and integrations
Single sign-on, directory sync, mail relays and the other systems the app has to reach.

Matomo: common questions

Is Matomo open source?

Yes, the core is. Matomo, including Tag Manager, is GPL-3.0-or-later, and so are free plugins from the Matomo team such as LDAP sign-in and QueuedTracking, with no fee per user or per page view. Premium plugins such as Heatmap & Session Recording, Funnels, Custom Reports and Login SAML are sold by InnoCraft, the company that makes Matomo, under a commercial EULA. They are not open source.

Where does the visit data live?

In a MariaDB database on a dedicated machine, in Zurich if the data must stay in Switzerland, in an EU region such as Frankfurt or Helsinki, or on your own hardware. Browsers send hits to a tracking hostname you own, and no visit data goes to Google or to the makers of Matomo.

Can we run Matomo without a cookie banner?

It depends on the country, and the decision is your data protection officer's. Matomo documents a setup that meets the French CNIL's conditions for consent-exempt audience measurement, and can enforce it per site under Administration, Privacy, Compliance: IP addresses masked by two bytes, visitor log and profiles off, User ID off, retention capped. The opt-out still has to be placed on your site by hand. We configure what your DPO decides.

Does Matomo do everything GA4 does?

Not everything, and some of it costs extra. Standard reports, goals, events, ecommerce, segments and Tag Manager are in the free core. Funnels, heatmaps, session recordings, A/B tests and custom reports are paid plugins. Audiences built from site behaviour for Google Ads have no equivalent; a paid plugin can export Matomo conversions to Google Ads and Microsoft Advertising instead.

How do browsers reach Matomo if it sits on a private network?

Through one hostname the gate publishes. Matomo's own security guide lists the paths that must stay public: the tracking endpoint, the tracker script and the opt-out, plus the Tag Manager containers and the heatmap configuration if you use them. We publish those and nothing else. The interface and the reporting API answer only on the private network.

Also in workflow and data

Back to apps

Bring us your Matomo. We will tell you what it takes.

Thirty minutes on the deployment you already have, or the one you are about to start.