Now in private beta

Shed more
light on your
traffic.

Lumastat reads the full story of every visit — where traffic came from, how deeply each page was explored, where sessions hesitated, and exactly why they dropped off. Plain-language insights. No cookies, no consent banner, GDPR compliance built in by design.

You're on the list.
No cookies EEA-hosted No tracking across days
Who it's for

For pages that sell,
explain, and convince.

Lumastat is not a web app analytics tool. It answers one question: did the people landing on your pages find what they came for — and if not, exactly why not?

Product pages Sales landing pages Small & medium e‑commerce Blogs & content sites Marketing websites

Not designed for SaaS dashboards or complex web application interfaces.

Do they find what they came for?

Scroll depth, navigation paths, and in-page search patterns reveal exactly how easily traffic reaches the information it came for — and the precise moment sessions drop off.

What repels — and what draws them in?

Heatmaps, frustration signals, and active-time metrics pinpoint which elements create hesitation and which earn attention — so you know what to fix and what to amplify.

Behaviour profiles. Zero personal data.

Lumastat classifies traffic by page behaviour — not by who anyone is. Rich segmentation and engagement categorisation with full GDPR compliance, no personal data ever stored.

See what works on the page.
Fix what doesn't.

Behaviour analytics built for content pages — every metric tied to a page, never to a person.

Heatmaps

Click and movement coordinates aggregated over a server-side screenshot — see exactly where attention lands and where it disappears.

Engagement

Scroll depth and active time on every view — what holds attention versus what gets skipped.

Session funnels

Flow across pages within a 24-hour window, surfacing exactly where people drop off.

Frustration signals

Dead clicks and rage clicks detected automatically — pinpointing where the UI creates friction.

Attribution

UTM parameters parsed from every URL — tie each visit back to the exact campaign that drove it, so you stop guessing which channel actually converts.

AI & bot analysis

Server-side module isolating bots, scrapers and AI agents from human traffic.

What you actually get

Numbers tell you what.
Lumastat tells you why.

Skip the dashboard archaeology. Lumastat reads your aggregated data for you and writes it back in plain language — what it noticed, the likely reason traffic drops off, and a clear recommendation you can act on. No charts to decode.

Lumastat Insights
Weekly digest · yourstore.com
Plain language
Why traffic drops

Most shoppers abandon at the cart — shipping cost only appears at the very last step, so they feel ambushed and bail.

Recommendation Surface shipping cost on the product page, before checkout.
−43% Cart→Pay
Price is the blocker

The Pro plan is revisited 3× per session before drop-off — price is being weighed, not the features.

Recommendation Try an annual discount or a visible money-back guarantee.
Pro · +4s dwell
They can't find it

People arrive searching for your “returns policy”, but no page answers it — they bounce within eight seconds.

Recommendation Link a clear returns FAQ from the checkout and footer.
Search intent

More sales, same spend

See exactly where buyers drop off and fix it — lift conversion without raising the ad budget.

Stop burning ad budget

UTM tags plus on-page engagement reveal which campaigns bring people who actually read your offer.

A ready-made fix list

Rage and dead clicks hand your developers the exact interface bugs to fix after every release.

Drop the cookie banner

Cookieless by design: no consent banner, no GDPR fines, a cleaner first impression for privacy-aware users.

Privacy by Design

Privacy by design,
not by policy.

Lumastat can't profile a person because it never holds the data to do so. Compliance with GDPR and ePrivacy is structural, not a checkbox.

  • No cookies, no local storage
    The tracking script never reads or writes anything in the browser — it sidesteps ePrivacy consent entirely.
  • Daily salted hashing
    IP and user-agent are one-way hashed with a salt that resets at midnight, so no one is trackable across days.
  • Full aggregation
    Events attach to pages and UI elements, never to an individual. No profiles are ever built.
  • Respects DNT & GPC
    Do Not Track and Global Privacy Control headers are honoured automatically — that traffic is ignored.
  • Raw IPs never stored
    Raw data lives in server RAM for the milliseconds it takes to hash, then it is gone. Hosting is EEA-only.

Two kinds of traffic.
Measured separately.

Most tools blur people and machines into one number. Lumastat keeps them apart — and tells you what the machines are costing you.

Humans

Behaviour worth optimising

See where real traffic lands, scrolls, hesitates and rage-clicks — so you can fix friction and lift conversion.

Heatmaps Scroll & active time Session funnels Rage & dead clicks
Machines

Costs worth cutting

A dedicated server-side module isolates bots, scrapers and AI agents from organic traffic — and counts the resources they burn.

Bot isolation AI-agent detection Scraper costs

Why not just
Google Analytics?

Privacy-first scripts are blocked less often by ad-blockers and browsers like Brave and Safari ITP — so your numbers are simply more accurate.

Lumastat Google Analytics
Cookie consent banner needed No Yes
GDPR compliant by design Yes No
Resistant to ad-blockers Yes No
Separates humans from bots & AI Yes No
Data hosted in the EEA Yes No
FAQ

Questions we get
asked a lot.

Do I need a cookie consent banner with Lumastat?

No. Lumastat sets no cookies and collects no personally identifiable information, so there is no legal trigger for a GDPR or ePrivacy consent banner. You get full behavioural analytics on your pages with zero consent overhead.

Is Lumastat GDPR compliant?

Yes — by structural design, not by configuration. Lumastat never stores personal data. IP addresses are hashed daily and cannot be reversed. Sessions are not linked across days, devices, or pages in any way that constitutes personal data processing under GDPR Article 4. Infrastructure runs inside the EEA. No Data Processing Agreement is required.

What data does Lumastat actually collect?

Lumastat collects page-level behavioural signals: scroll depth, click coordinates, active time on page, navigation path within a session, UTM parameters from the URL, and device category (desktop / mobile / tablet). It does not collect names, email addresses, raw IP addresses, device fingerprints, or any data that could identify a specific person.

How does cookieless analytics actually work?

Instead of setting a cookie to follow a user across visits, Lumastat analyses each page visit independently. Behavioural signals — scroll depth, click positions, active engagement time — are aggregated server-side and attached to the page URL rather than to any individual. Every metric is page-scoped, not person-scoped.

How accurate is cookieless analytics compared to cookie-based tools?

For page-level insights — heatmaps, scroll depth, exit patterns, funnel drop-offs — cookieless analytics is highly accurate and often more complete than cookie-based tools, because it is not skewed by visitors who declined the consent banner. The trade-off is that individual user journeys across multiple sessions cannot be traced. For landing pages and content sites this is rarely a limitation.

What are frustration signals and rage clicks?

Frustration signals are behavioural patterns that indicate a visitor encountered something broken, confusing, or misleading. Rage clicks are rapid repeated clicks on an element that does not respond. Dead clicks are clicks on non-interactive elements that visually imply they are clickable. Both are automatically detected by Lumastat and highlight UI problems that raw visitor counts would never surface.

What is scroll depth tracking and why does it matter?

Scroll depth measures how far down a page a visitor scrolled before leaving, expressed as a percentage of total page height. When correlated with exit rate, it tells you whether visitors leave because they never found the information they were looking for (low scroll depth) or because nothing on the page convinced them after reading it (high scroll depth, high exit). The two causes require completely different fixes.

What is a heatmap and how does it help my website?

A heatmap overlays a screenshot of your page with colour-coded zones showing where visitors clicked, moved, or tapped — warmer colours indicate higher activity. Heatmaps make it immediately visible which sections attract attention, which calls-to-action receive clicks, and which content is completely ignored. Lumastat generates heatmaps from aggregated click coordinates, without cookies and without a consent banner.

What are session funnels?

Session funnels show the sequence of pages visited within a single browsing window and reveal where visitors exit the site. For multi-step flows — product page → cart → checkout — funnels pinpoint the exact step causing the most drop-off, so you know where to focus optimisation effort instead of guessing.

How does UTM attribution work in Lumastat?

UTM parameters are tags appended to URLs in marketing campaigns (e.g. ?utm_source=newsletter&utm_medium=email). Lumastat reads these from the URL on arrival and associates the session's behavioural data — scroll depth, clicks, engagement time, exit point — with that specific campaign source. You can see which channels send visitors who genuinely engage versus those who bounce within seconds.

Can Lumastat detect bots, scrapers, and AI crawlers?

Yes. A server-side module analyses request patterns, timing, and behavioural signals to separate human visits from automated traffic — search engine crawlers, scraper bots, AI training agents, and uptime monitors. Bot visits are excluded from all analytics metrics by default, so heatmaps and engagement numbers reflect genuine human behaviour only.

Does Lumastat work when visitors have ad blockers installed?

Lumastat is designed to be adblocker-resistant because all data collection happens server-side. There is no third-party tracking script loaded from an external domain that ad blockers routinely intercept. The result is a more complete picture of visitor behaviour than tools that depend on client-side JavaScript which can be silently blocked.

What is the difference between Lumastat and Google Analytics?

Google Analytics (GA4) tracks individuals across sessions using cookies and device IDs, requires a GDPR consent banner, routes data through Google's US-based advertising infrastructure, and is designed for audience segmentation and attribution modelling. Lumastat tracks behaviour per page without cookies, stores no personal data, keeps data inside the EEA, and is focused on answering why visitors leave a specific page rather than who they are.

How does Lumastat compare to Hotjar?

Hotjar collects session recordings and heatmaps using cookies and requires user consent under GDPR and ePrivacy. It is a powerful UX research tool aimed at product and design teams. Lumastat covers similar visual analytics — heatmaps, scroll depth, click patterns — without cookies or a consent banner, and adds UTM attribution, bot filtering, and frustration signals. It is oriented towards marketers and website owners who need conversion insight without a compliance layer.

What type of website is Lumastat designed for?

Lumastat is built for pages where a single visit determines whether a visitor converts: product pages, sales landing pages, blog posts, e-commerce category and product detail pages, and marketing microsites. It is not designed for tracking authenticated user workflows inside SaaS dashboards or complex web applications, where a different class of analytics tool is more appropriate.

Where is visitor data stored and is it safe?

All data is processed and stored on infrastructure hosted within the European Economic Area (EEA). Data never leaves EU jurisdiction, which means Lumastat's data handling complies with GDPR Chapter V requirements on international transfers by default — without needing Standard Contractual Clauses or other transfer mechanisms.

Get analytics you
don't have to apologise for.

Join the private beta. We're onboarding sites in batches and you'll get your DPA and privacy-policy snippet ready on day one.

You're on the list — talk soon.