Conversion Optimization
OptiMonk
Provenance unknown Report an errorPanel rating · 6 judges · How to read the stars
Category median
Sovereignty: 2 of 4 dimensions proven
0–5 in half steps. 5 means the rubric's top anchor is met on the evidence.
by OptiMonk Kft. · optimonk.com
Report an error on this page Is this your product? →
Read this page as one judge. Each weighs the same scores by what they care about.
The panel's verdict
OptiMonk, an AI-driven popup builder for ecommerce businesses, is scored here as a client-side A/B testing tool for popups, product pages and campaigns. It is strongest on data and integrations, where scores cluster at 4 — an OpenAPI 3.1 REST API, an MCP server with 26 tools and a GA4 integration documented to the data-layer event — and on sovereignty, 4 to 6, reflecting a Hungarian controller with entered form data stored in Frankfurt, Germany. It is weakest on performance impact, where scores cluster at 0: we found no public information on the snippet's size, loading behaviour or any measured effect on Core Web Vitals. The genuine split is statistical rigour, 0 to 3: the score of 0 rests on a Confidence figure computed once a variant reaches 50 impressions, with no method named and challengers deactivated in one click, while scores of 2 and 3 credit the same documentation, one noting a captured article that titles the vendor's approach Bayesian. Elsewhere, experimentation scope runs 3 to 4, consent and tracking 2 to 4, pricing transparency 3.
Speaks for it
- Client-side A/B testing of popup campaigns with unlimited variants, a drag-and-drop editor and an A/B Test Center.
- GA4 measurement via Google Tag Manager documented end to end, with a data-layer event, custom definitions and an importable GTM container.
- A documented developer surface: an OpenAPI 3.1 REST API and an MCP server with 26 tools, scopes, rate-limit headers and idempotency.
- A published list of the seven cookies the script writes with their purposes, and a stated retention of up to 14 days for IP addresses.
- A Hungarian controller — OptiMonk International Zrt., a Debrecen principal office, the NAIH as supervisory authority — with entered form data stored on servers in Frankfurt, Germany, and a published subprocessor list.
Held against it
- A Champion is named above 90% Confidence once a variant reaches 50 impressions, and an option automatically deactivates the challengers, with no documented method, assumptions or sample-size guidance.
- We found no public information on server-side or SDK delivery, feature flags, multivariate tests, holdouts or personalisation that can itself be tested against a control.
- We found no public information on the snippet's size, loading behaviour, flicker handling or any measured effect on Core Web Vitals.
- We found no public information on what the script does before consent is given, on consent-management-platform integration or on a cookieless mode, while the unique visitor identifier cookie lasts one year and is described as created on a visitor's first visit.
- The published subprocessor chain includes US-headquartered processors such as Braintree, Mailchimp, HubSpot, Zendesk, Intercom and Mixpanel, the EU hosting note appears as a parenthetical on the host's line rather than a product-wide commitment, and we found no public information on safeguards for those transfers.
Best for
- You want no-developer A/B testing of popup campaigns — unlimited variants, a drag-and-drop editor and a documented free plan to pilot on.
- You want to verify variant performance in your own analytics, through the documented GA4 and Google Tag Manager integration.
- You build with scripts or AI agents and need a documented API for creating and publishing campaigns — an OpenAPI 3.1 REST surface and an MCP server with 26 tools.
- You need a Hungarian controller with entered form data stored on servers in Frankfurt, Germany, and a published subprocessor list.
Avoid if
- You need server-side or SDK experimentation, feature flags, multivariate tests or holdouts — what the pages document is client-side testing of popups, product pages and campaigns.
- You make revenue calls on test winners — the documented rule can name a Champion above 90% Confidence once a variant reaches 50 impressions and automatically deactivate the challengers.
- You must read results back through the API or export visitor-level data — the vendor's own documentation states the API is not the analytics or subscriber API and has no tool for reports, leads or submits.
- Your consent review requires documented script behaviour before consent is answered — we found no public information on a consent-pending mode or consent-platform integration, and the unique visitor identifier cookie runs a year and is described as created on a visitor's first visit.
The scores
Experiment types & delivery
Show reasoningHide reasoning
How this is scored
What can be tested and where: client-side changes through an editor, server-side and feature experiments through SDKs, multivariate and multi-page tests, and personalisation — judged on what the documentation shows rather than on the feature grid.
0 — Simple A/B split of one page element through a visual editor; no server-side option, no targeting beyond URL.
3 — Client-side A/B and split-URL tests with basic audience targeting, and no SDK or server-side delivery.
5 — Client-side and server-side experiments through documented SDKs for common languages, multivariate and multi-page tests, audience targeting on behaviour and attributes, and rule-based personalisation.
8 — Feature-flag-based experiments sharing one audience and metric model with web tests, mutually exclusive experiment groups, holdouts, edge or CDN delivery, and personalisation that can itself be tested against a control.
10 — One experimentation programme across every surface: web, app, server and edge from the same platform, experiment interactions managed, a documented experiment lifecycle from hypothesis to archived result, and a library of past results a team can search.
The Growth Lead
The drag-and-drop editor with unlimited variants and an A/B Test Center is exactly the no-developer workflow my team needs, and cookie-based targeting with AND/OR groups and rich operators goes beyond URL rules. But we found no public information on server-side or SDK delivery, multivariate or split-URL tests, holdouts or mutually exclusive experiments, so the programme stays confined to popup and campaign content. 3 4 6 7
The E-Commerce Manager
What's documented is client-side A/B testing of popup campaigns with unlimited variants, a drag-and-drop editor, and cookie-based audience targeting with AND/OR groups and number and text operators — and we found no public information on server-side delivery, SDKs, feature flags, holdouts, or personalisation that can be tested against a control. A multi-campaign test cookie suggests testing across campaigns, but as a popup tool this stops well short of a full-page experimentation programme. 3 4 6 7
The Product Engineer
Testing is popup-centric: unlimited variants through a drag-and-drop editor, A/B tests on popups, product pages and campaigns, with cookie-based targeting that supports AND/OR groups and typed operators — all client-side. We found no public information on server-side SDKs, feature flags, edge delivery, multivariate or multi-page tests, so nothing here reaches a server-side programme. 3 4 6
The CRO Consultant
The pages show client-side A/B testing of popup and campaign variants with unlimited variants, a drag-and-drop editor, automatic winner handling, cookie-based targeting with AND/OR groups, and multi-campaign tests, plus advertised A/B tests on product pages. We found no public information on server-side or SDK delivery, feature flags, multivariate or multi-page tests, or personalisation that can be tested against a control, so a server-side programme has nothing documented to run on. 3 4 7
The Data Protection Officer
The captured documentation shows client-side A/B testing of popup campaigns with unlimited variants, a dedicated A/B Test Center, automatic winner handling, and cookie-based audience targeting with AND/OR logic. We found no public information on server-side delivery, SDKs, feature flags, mutually exclusive experiments, holdouts or personalisation that can itself be tested, so what is evidenced is client-side split testing with basic targeting. 3 4 6 7
The Skeptic
The documentation shows client-side A/B testing of popup campaigns — unlimited variants, a drag-and-drop editor, an A/B Test Center — with cookie-based targeting rules combined by AND and OR, aimed at popups, product pages and campaigns. We found no public information on server-side or SDK delivery, feature flags, multivariate tests, holdouts, or personalisation that can itself be tested against a control. 3 4 6
Statistical method & guardrails
panel disagrees
Show reasoningHide reasoning
How this is scored
Which statistics decide the winner and what protects the customer from misreading them. Scored on what the vendor documents: the method by name, how peeking and multiple comparisons are handled, and whether sample ratio mismatch is detected.
0 — A "winner" or "probability to beat" figure with no documented method, no stated sample-size guidance and no warning against stopping early.
3 — The method is named (frequentist or Bayesian) but its assumptions are not documented, and nothing prevents a test from being called while it is still underpowered.
5 — Documented method with confidence or credible intervals, a sample-size or test-duration calculator, and stated guidance on when a result may be read.
8 — Sequential testing or an equivalent documented protection against peeking, correction for multiple metrics or variants, sample ratio mismatch detection, variance reduction such as CUPED, and guardrail metrics that can stop a harmful test.
10 — The statistics are auditable: methodology published in enough detail to reproduce a result, the choice of method explained per use case, raw per-visitor data available for independent re-analysis, and the interface refuses to present an underpowered result as a conclusion.
The Growth Lead
The winner logic that is documented rests on an un-named significance calculation the app labels "Confidence", with a champion named above 90% confidence and significance computed from as few as 50 impressions — a level at which a popup test is underpowered and I could not defend it to finance. The vendor's site carries a guide on Bayesian testing, but we found no public information on sample-size guidance, the handling of peeking or multiple comparisons, or sample ratio mismatch detection. 4 5
The E-Commerce Manager
The only documented statistics are a Confidence figure computed once a variant reaches 50 impressions, with a bar of above 90% for naming a Champion that then automatically deactivates the challengers; we found no public information naming the method behind that figure, and nothing on sample-size guidance, peeking, multiple comparisons, or guardrail metrics. Fifty impressions is far too thin a base for a revenue call on my shop, and the captured pages give me no way to check it. 4 5
The Product Engineer
Significance is branded "Confidence" and computed after 50 impressions, a Champion is named above 90%, and an auto-winner deactivates challengers — a stopping rule with no visible guard against peeking. We found no public information on the method's assumptions, sample-size guidance, multiple-comparison handling, or sample ratio mismatch detection. 4 5
The CRO Consultant
Significance is calculated once a variant reaches 50 impressions in the described settings, a Champion is named above 90% Confidence, and an option automatically deactivates challengers; a captured article titles the vendor's approach Bayesian. The pages we have do not document the method's assumptions, intervals, sample-size guidance or any protection against reading a test early, and the automatic winner means a very small test can still be called. 4 5
The Data Protection Officer
The only documented statistics are a "Confidence" figure calculated once a variant reaches 50 impressions, a Champion named above 90% confidence, and an option that automatically deactivates challengers. We found no public information naming the method or its assumptions, no sample-size or duration guidance, and no handling of peeking, multiple comparisons or sample ratio mismatch — and a 50-impression trigger invites reading a test far too early. 4
The Skeptic
What the pages show is a "Confidence" figure that names a Champion at 90 percent once a variant reaches 50 impressions — no method named, no assumptions documented, and fifty impressions is precisely where noise is loudest. The "keep only the winner" option even automates deactivating challengers, which builds early stopping into the product as a one-click feature; we found no public information on sample-size guidance, protection against peeking, multiple-comparison handling, or sample ratio mismatch detection. 4 5
Consent & visitor tracking
Show reasoningHide reasoning
How this is scored
Whether the test script respects §25 TDDDG and the ePrivacy rules as evidenced on the vendor's own pages: when the script runs relative to consent, what it stores on the device, whether a cookieless or consent-free mode exists, and how visitor identifiers are handled.
0 — Nothing on the vendor's pages says what the script stores on the device or whether it runs before consent; consent is described as the customer's problem.
3 — Cookies or local storage are listed, and a consent integration is mentioned, but the documentation does not say what the script does before consent is given.
5 — Documented behaviour before and after consent, integration with common consent management platforms, a published list of cookies and storage keys with their lifetime, and IP anonymisation described.
8 — A documented consent-pending mode that holds tracking until consent while variants can still be served, a cookieless or first-party-only option, retention of visitor data stated, and guidance on the legal basis for testing in the EU.
10 — Built for §25 TDDDG: the default configuration stores nothing on the device without consent, a server-side or cookieless mode documented end to end, per-visitor data deletable on request, and the vendor states in writing how each mode maps to consent requirements.
The Growth Lead
The published cookie list is genuinely useful: seven cookies with purposes and lifetimes, including a unique visitor identifier lasting a year, and IP addresses kept only 14 days. But we found no public information on what the script does before consent is given, on any consent management platform integration, or on a cookieless mode — the first question my legal team will ask before a campaign ships in Germany. 2 6 7
The E-Commerce Manager
The vendor publishes the seven cookies its script writes, with purposes and lifetimes of up to one year for the unique visitor identifier, caps IP storage at 14 days, and ties retention in its policy to withdrawal of consent — but we found no public information on what the script does before consent is given, on consent-management-platform integration, or on IP anonymisation. The unique visitor cookie is described as created during a visitor's first visit, and nothing documented says it waits for consent. 2 6 7
The Product Engineer
A published cookie inventory with lifetimes (visitor identifier for one year, session cookie) and a 14-day cap on IP retention is real disclosure. But we found no public information on what the script does before consent is given, on consent-management-platform integration, or on IP anonymisation, and the unique visitor identifier cookie runs a year. 7 2
The CRO Consultant
The vendor publishes the seven cookies its script writes, with purposes and lifetimes — including a one-year unique visitor identifier created on a visitor's first visit — and states IP addresses are kept up to 14 days. We found no public information on what the script does before consent is given, consent-management-platform integration, or a cookieless mode, which is the first thing a client's DPO will ask for. 7 2
The Data Protection Officer
I can credit a published list of the seven cookies the script writes, with purposes and lifetimes — including a unique visitor identifier kept one year — and a stated 14-day retention for IP addresses. What I cannot find is any answer to whether the script may run before the consent banner is answered: we found no public information on behaviour before consent, a consent-pending mode, consent-platform integration or IP anonymisation, and several cookies carry no stated lifetime. 6 7
The Skeptic
Seven cookies the script writes are published with purposes and lifetimes — the unique visitor identifier lasts a year — and the vendor states IP addresses are kept at most 14 days with form data stored in Frankfurt. We found no public information on what the script does before consent is given, a consent-pending mode that serves variants while holding tracking, cookieless delivery, or integration with consent management platforms. 7 2
Snippet performance & flicker
Show reasoningHide reasoning
How this is scored
The cost the client-side snippet imposes on the page it tests: blocking load, flicker of original content, script weight and the effect on Core Web Vitals — scored on what the vendor measures and publishes, not on "lightning fast".
0 — A synchronous snippet with no stated size, no flicker handling and no mention of performance.
3 — An anti-flicker snippet that hides the page until the test loads, with a timeout, and no published figures for script size or load cost.
5 — Script size and loading behaviour documented, asynchronous loading option, flicker handling explained with its trade-off, and CDN delivery of the snippet.
8 — Published performance figures including impact on Core Web Vitals, a self-hosting or first-party-domain option for the script, per-project bundles containing only active experiments, and a server-side or edge alternative for flicker-sensitive tests.
10 — Performance is a stated commitment: measured overhead published and maintained, flicker eliminated by edge or server-side rendering as a documented path, and tooling that shows the customer what their own configuration costs the page.
The Growth Lead
The only documented fact about the script is the cookies it writes on the customer's site; we found no public information on its size, loading behaviour, flicker handling or any effect on Core Web Vitals. With nothing measured and nothing published, there is nothing to weigh against the cost every visitor pays. 7
The E-Commerce Manager
The captured cookie page proves a script runs on my site, but we found no public information on its size, how it loads, how flicker of original content is handled, or any measured effect on Core Web Vitals. For a shop where a tenth of a second shows in conversion, published silence on the snippet's cost is the worst possible answer. 7
The Product Engineer
The only captured description of the script is the cookie documentation; we found no public information on snippet size, loading behaviour, flicker handling, Core Web Vitals impact, or a self-hosting option. Nothing is measured or published here at all. 1 7
The CRO Consultant
The only fact touching the snippet is that an OptiMonk script runs on the customer's site. We found no public information on script size, loading behaviour, flicker handling, self-hosting, or any measured effect on Core Web Vitals. 7
The Data Protection Officer
The script that writes these cookies demonstrably loads on the customer's site, but we found no public information on its size, loading behaviour, flicker handling, effect on Core Web Vitals, a self-hosting option, or any measured overhead. 7
Analytics, data export & integrations
Show reasoningHide reasoning
How this is scored
Getting results and raw data out: integration with analytics and tag management, export of visitor-level results, warehouse-native analysis, and an API — because an experiment result that cannot be checked in the customer's own data is a claim, not a finding.
0 — Results visible in the vendor's dashboard only; no export, no analytics integration, no API.
3 — CSV export of aggregated results and one analytics integration, with no visitor-level data and no documented API.
5 — Integrations with common analytics and tag managers, export of results, and a documented API for managing experiments and reading results.
8 — Visitor-level raw data export or streaming to a data warehouse, warehouse-native analysis on the customer's own metrics, CDP integration for audiences, and an API with stated limits.
10 — The platform treats the customer's warehouse as the source of truth: metrics defined once and computed there, full historical experiment data exportable in open formats, and a versioned API a team can build its own programme tooling on.
The Growth Lead
The GA4 and Google Tag Manager integration is documented down to the data-layer event and variant names, so variant performance can be checked in our own analytics, and the OpenAPI 3.1 surface with scopes, rate limits and idempotency is serious engineering. But the documentation itself states the API surface is build and campaign management with no tool for reports or leads, and we found no public information on visitor-level export or data warehouse delivery. 8 9
The E-Commerce Manager
There is a genuinely documented API surface — an OpenAPI 3.1 REST service plus an MCP server with 26 tools, scopes, rate limits and revocable keys — but the vendor's own documentation states it is not the analytics API and offers no tool for reports, leads or submits. The GA4 integration via GTM is documented in detail with data-layer events, yet we found no public information on exporting the vendor's own results, on visitor-level export, or on warehouse streaming, so a winner stays a claim I cannot re-check in my data. 8 9
The Product Engineer
The API surface is genuinely well-built — OpenAPI 3.1, typed errors, rate-limit headers, idempotency keys, OAuth connected apps, scoped credentials — but it drives campaign creation and publishing and is stated not to be the analytics or subscriber API, so results cannot be read back programmatically. GA4 via GTM is the only evidenced results path, and we found no public information on visitor-level export or warehouse delivery. 8 9
The CRO Consultant
The documented API is genuinely well built — OpenAPI 3.1, scopes, OAuth connected apps, idempotency keys, rate-limit headers — but the vendor states it is not the analytics or subscriber API and has no tool for reports, leads or submits. The GA4 integration pushes impression and conversion events into the data layer via GTM, giving measurement in the customer's own analytics; we found no public information on visitor-level export or warehouse connectivity. 8 9
The Data Protection Officer
GA4 measurement through Google Tag Manager is documented end to end with event names, properties and audiences, and there is a documented developer surface with an OpenAPI description, scopes, rate limits and idempotency. That surface is for building popups and managing campaigns — the vendor writes plainly that there is no tool for reports, leads or submits — and we found no public information on exporting aggregated or visitor-level results. 8 9
The Skeptic
The Google Analytics 4 integration is documented in real depth — a data-layer event, custom definitions, an importable GTM container — and the API surface is genuinely documented with an OpenAPI 3.1 description, rate-limit headers and idempotency. But the vendor's own documentation states the API "is not the analytics or subscriber API" and "There is no tool for reports, leads or submits", and we found no public information on export of results or visitor-level data. 8 9
European sovereignty
panel opinion
Show reasoningHide reasoning
How this is scored
Where visitor data is processed and stored and who the contracting entity is. Independently sourced by the sovereignty pipeline; weighted higher here than in categories that hold only the customer's own data, because the script runs on every visitor to the customer's site and their behaviour is what the platform records.
0 — Non-EU vendor and contracting entity, hosting unstated, subprocessors unnamed, and visitor data leaving the EU without a stated safeguard.
3 — EU data residency offered as an option or an enterprise add-on while the contracting entity is non-EU, or the subprocessor list is absent.
5 — EU processing of visitor data as standard and an EU contracting entity, but parts of the chain — CDN, support access, analytics — are non-EU without an explained safeguard.
8 — EU hosting on named infrastructure including the delivery of the snippet, EU contracting entity, subprocessor list published, and a DPA covering the visitor data the script collects.
10 — Sovereign end to end and evidenced: vendor, entity, hosting, snippet delivery and every subprocessor European, certification published, and no visitor data reaching a non-EU party at any point.
The Growth Lead
The contracting entity is Hungarian with a Hungarian VAT number and the NAIH named as supervisory authority, form data sits on named infrastructure in Frankfurt, and the processor list is published with addresses and tasks. But the chain includes US-headquartered processors such as Braintree, Mailchimp, HubSpot, Zendesk, Intercom and Mixpanel, and we found no public information on where the script itself is delivered from or a published data processing agreement covering the visitor data the script collects. 2 7
The E-Commerce Manager
The contracting entity is Hungarian with a Debrecen address and the NAIH as supervisory authority, entered form data is stored on servers in Frankfurt on named infrastructure, and the processor list is published — but that list names many US-headquartered companies such as Mailchimp, HubSpot, Zendesk, Intercom, Mixpanel and Braintree without stated safeguards, and the EU hosting note reads as a parenthetical on the host's line rather than a product-wide commitment. We also found no public information on where the test snippet itself is delivered from. 2 7
The Product Engineer
The controller is a Hungarian company — Debrecen address, Hungarian VAT number, NAIH named as supervisory authority — and campaign data sits on DigitalOcean's Frankfurt data centers, so EU entity and EU processing are evidenced. But the published subprocessor chain includes US-headquartered processors (Braintree for card payments, plus Mailchimp, HubSpot, Intercom among others), the host itself is US-based, and we found no public information on where the snippet itself is delivered. 2 7
The CRO Consultant
The controller is a Hungarian company with a Debrecen principal office under the NAIH, entered data is stored on servers in Frankfurt, and a subprocessor list is published — but much of that chain (Mailchimp, HubSpot, Zendesk, Intercom, Mixpanel, Braintree, and US-headquartered DigitalOcean even for its Frankfurt data centers) is non-EU, with the EU location appearing as a parenthetical on the hosting line rather than a product-wide commitment. We found no public information on where the test snippet itself is delivered from. 2 7
The Data Protection Officer
The controller is a Hungarian company answerable to the Hungarian supervisory authority, entered form data is stored in Frankfurt on the host's EU data centers, and the subprocessor list is published — that earns the middle ground. But the EU location appears only as a parenthetical on the hosting line rather than a product-wide commitment, several processors are US-headquartered with no stated safeguard, and we found no public information identifying who delivers the test script to European visitors or on a data processing agreement covering visitor data. 2 7
The Skeptic
The controller is a Hungarian company — a Debrecen address, a Hungarian VAT number, the NAIH named as supervisory authority — form data is stated to be stored on Frankfurt servers, and a subprocessor list is published. But that list runs through US-headquartered processors such as Braintree, Mailchimp, HubSpot, Zendesk, Intercom and Mixpanel, and we found no public information on safeguards for those transfers, on where the test script is delivered from, or on a data processing agreement covering the visitor data the script collects. 2 7
Pricing transparency
not rated — the vendor publishes no price
Show reasoningHide reasoning
How this is scored
A category priced by traffic — monthly tracked users, visitors or impressions — where the tier a site lands in depends on numbers the buyer has to estimate. Whether a buyer can compute the real annual cost including traffic limits, overage, server-side or personalisation modules and seats — from public pages alone.
0 — No public prices at all; every tier is a sales conversation.
3 — A starting price or a free tier exists, but the traffic metric, the limits and what happens above them are unstated — the invoice is unknowable.
5 — Tier prices public with the traffic metric and its limits defined, but at least one commonly needed piece (server-side SDKs, personalisation, overage) is unpriced or "contact sales".
8 — Every tier priced publicly with the traffic metric defined, limits, overage rates, module prices, minimum term and VAT treatment stated.
10 — Complete price computability: annual invoice derivable for a given traffic volume, set of modules and team size, with overage and every add-on published.
The Growth Lead
A free plan and a free account are published, which lets my team pilot at no cost. But we found no public information on the traffic metric, tier prices, limits, overage or seat pricing, so the real annual invoice is unknowable from the vendor's pages alone. 2 4
The E-Commerce Manager
A free plan exists and card payments run through Braintree, but we found no public information on tier prices, the traffic metric, what the limits are, overage rates, modules or minimum terms — so the annual invoice for my December traffic cannot be computed from public pages. For a category priced by traffic, that silence is the deciding fact. 2 4
The Product Engineer
A free plan exists and Braintree is the card payment processor, but we found no public information on paid tier prices, the traffic metric, its limits, or what happens above them. A buyer cannot compute the annual cost from these pages. 2 4
The CRO Consultant
Registration for the "FREE plan" is the only priced item in the captures; we found no public information on paid tiers, the traffic metric a contract would be priced on, traffic limits or overage. Without a published visitor or impression metric, I cannot estimate a client's annual invoice before they sign. 2 4
The Data Protection Officer
A free plan is published and card payments run through Braintree, but we found no public information on tier prices, the traffic metric, plan limits, overage, seats or minimum term — the invoice is unknowable from public pages. 2 4
European sovereignty — proven facts
2 of 4 dimensions provenBuilt only from facts shown on the vendor's own pages. A dimension we could not prove is left open, not scored as zero.
| Legal entity | Not determined | — | uncited Report an error |
|---|---|---|---|
| Ownership | Not determined | — | uncited Report an error |
| Data residency | EU only ⚠ unverified | 3/3 pts | 2 Report an error |
| Subprocessors | US CLOUD Act reach ⚠ unverified | 0/2 pts | 2 Report an error |
Where this could be wrong
- Evidence ages. The oldest capture behind this page is from 29 Sep 2026. Vendors change pricing and policies without notice; every fact reflects its source as of the capture date shown in the registry.
- Weak sourcing — Data residency. The EU location appears only as a parenthetical on the hosting subprocessor's line in the processor list rather than as an explicit product-wide data residency commitment, and the host DigitalOcean is itself US-headquartered.
- Weak sourcing — Subprocessors. The Rocket Science Group (Mailchimp), HubSpot, Zendesk, Intercom, Mixpanel, Outreach and Zoho are US-headquartered and DigitalOcean is US-based even though only its Frankfurt data centers are used; Mailchimp's MOSS number is an EU VAT registration rather than an EU entity, and Unbounce is Canadian.
- AI can misread a source. Extraction and judgement are automated; a citation guarantees traceability, not infallibility. If something here is wrong, say so — no account needed, every report is decided within 5 business days, and accepted corrections are published.
What we left out
A claim that does not survive our checks costs us the claim, not the page. This is what was taken off this one.
- 22 product facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 2 integrations facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 1 compliance fact could not be confirmed on the vendor’s page as captured and was left out of this page and of the panel’s material. Know more? Tell us
- 1 pricing fact could not be confirmed on the vendor’s page as captured and was left out of this page and of the panel’s material. Know more? Tell us
- 1 subprocessors fact could not be confirmed on the vendor’s page as captured and was left out of this page and of the panel’s material. Know more? Tell us
Sources (9)
The pages every claim on this page was read from — each one checked, dated, and kept verifiable.
- 1 Vendor page optimonk.com Checked 29 Sep 2026 Details →
- 2 Privacy policy — found from the homepage www.optimonk.com Checked 30 Sep 2026 Details →
- 3 Experiment types & delivery — found from sitemap www.optimonk.com Checked 1 Oct 2026 Details →
- 4 Experiment types & delivery — found from sitemap www.optimonk.com Checked 1 Oct 2026 Details →
- 5 Statistical method & guardrails — found from sitemap www.optimonk.com Checked 1 Oct 2026 Details →
- 6 Consent & visitor tracking — found from sitemap support.optimonk.com Checked 1 Oct 2026 Details →
- 7 Consent & visitor tracking — found from sitemap support.optimonk.com Checked 1 Oct 2026 Details →
- 8 Analytics, data export & integrations — found from sitemap support.optimonk.com Checked 1 Oct 2026 Details →
- 9 Analytics, data export & integrations — found from sitemap support.optimonk.com Checked 1 Oct 2026 Details →