
The typical implementation process for Matomo involves these steps:
Choose a Hosting Option: Decide whether to use Matomo Cloud (SaaS) or self-host the software.
Installation:
Matomo Cloud: Sign up for a Matomo Cloud account, and Matomo handles the installation and hosting.
Self-Hosting: Download the Matomo software and upload it to your web server. Then, run the installation script via your web browser. This involves setting up a database, configuring user accounts, and system settings.
Add Tracking Code: After installation, add the provided JavaScript tracking code to your website or mobile app. This code enables Matomo to collect data about visitor behavior.
Configure Settings: Configure Matomo settings, such as user roles, website goals, e-commerce tracking, and custom dimensions.
Start Collecting Data: Once the tracking code is implemented, Matomo will start collecting data, and reports will become available in real-time.
Matomo can be customized to fit specific business needs. Here's how:
Open-source platform: Matomo is an open-source platform, that allows users to modify the software to meet their specific requirements.
Data ownership and privacy: Matomo gives you 100% data ownership, which allows companies full ownership and control of all data they collect and store.
User-friendly interface: Matomo has a user-friendly interface to get the data you need, faster.
Matomo provides a range of training and support resources tailored to assist new users in effectively utilizing their web analytics platform.
Training Resources
Getting Started User Guide: This guide introduces key concepts, outlines how to use Matomo, and includes practical how-to guides, such as instructions for migrating from Google Analytics.
Web Analytics Training Videos: A series of concise and informative videos designed to educate users on the fundamentals of digital analytics and provide a step-by-step walkthrough of Matomo's features. The complete series comprises 18 videos with a total runtime of approximately 112 minutes.
Tag Manager Video Training: This training series focuses on Matomo's Tag Manager, offering insights into deploying tracking codes and managing various data collection tasks. The series includes 11 videos totaling about 66 minutes.
Support Resources
Help Centre: A centralized repository featuring user guides, video trainings, FAQs, and more, aimed at assisting users in navigating and troubleshooting the platform.
Community Forums: An interactive platform where users can engage with the Matomo community to seek advice, share experiences, and find solutions to common challenges.
Matomo implements an array of security measures to protect user data and ensure the integrity of its analytics platform. Key measures include:
1. Secure Infrastructure
Hosting Environment: Matomo's cloud service is hosted on Amazon Web Services (AWS), which complies with major security certifications. The infrastructure is designed to meet the requirements of security-sensitive and privacy-aware organizations.
Private Network Configuration: The infrastructure operates within a private network, ensuring that data and network traffic are inaccessible to unauthorized third parties.
2. Data Encryption
In-Transit Encryption: All sessions are encrypted using HTTPS (SSL/TLS), safeguarding data during transmission between users and Matomo servers.
At-Rest Encryption: Stored data, including user passwords and API tokens, are encrypted within the database. Disk encryption technologies are employed to ensure that data remains protected while at rest.
3. Access Controls
User Authentication: Matomo supports two-factor authentication (2FA), which can be enforced to add an extra layer of security to user accounts.
Role-Based Access: Access controls ensure that only authorized personnel can view reports and raw user data. Audit logs are provided to account for all activities performed by staff, users, and customers.
Employee Access Restrictions: Matomo staff do not access user data unless required to assist, maintaining strict internal data access policies.
4. Application Security
Development Practices: Matomo adheres to software development best practices, including systematic code reviews, automated testing, and internal security assessments, to maintain a secure codebase.
Bug Bounty Program: To encourage security research and enhance platform safety, Matomo operates a Security Bug Bounty Programme, offering rewards for valid critical security bug reports.
5. Data Privacy Compliance
GDPR Compliance: Matomo provides an advanced General Data Protection Regulation (GDPR) Manager, ensuring that websites can comply with GDPR requirements. Features include data anonymization, support for user data access and deletion requests, and respect for "Do Not Track" preferences.
IP Anonymization: By default, Matomo anonymizes IP addresses by masking the last components, protecting users with static IP addresses from being easily tracked across multiple sessions.
6. Recommendations for On-Premise Installations
For users hosting Matomo on their own servers, the following best practices are recommended:
Separate Database: Install Matomo in a dedicated MySQL or MariaDB database to isolate analytics data from other applications.
Unique Credentials: Use distinct MySQL usernames and passwords for the Matomo database to limit the potential impacts of SQL injection attacks.
SSL Usage: Ensure that Matomo is accessed over HTTPS to protect sensitive information such as login credentials and API tokens during transmission.
Regular Backups: Perform routine backups of the Matomo database and configuration files, and verify the integrity of these backups.
System Updates: Keep all components, including PHP, MySQL/MariaDB, web servers (Apache/Nginx), and the operating system, updated to benefit from the latest security patches.
Matomo is committed to ensuring that users have full control over their data, emphasizing both data ownership and portability.
Data Ownership: Matomo core philosophy centers on providing users with 100% ownership of their analytics data. This approach ensures that no external parties have access to or can utilize the data for their purposes. Unlike some other analytics platforms that may use collected data to support their advertising services, Matomo guarantees that your data remains exclusively under your control.
Matomo offers flexible options to accommodate organizations as their analytics needs evolve, allowing for seamless scaling both upward and downward.
Scaling Up: As your organization's data tracking requirements grow, Matomo provides several tiers to handle increased data volumes. For instance, the Business plan starts at €22 per month for up to 50,000 hits. For higher demands, such as tracking up to 1 million hits per month, the monthly cost adjusts accordingly. For organizations exceeding 10 million hits per month, Matomo offers customized pricing and allowances.
Matomo offers various services, each governed by specific terms regarding contract renewal and cancellation. Below is a summary of these terms for Matomo Cloud subscriptions, Premium Plugins, and Support Plans.
Matomo Cloud Subscriptions
Automatic Renewal: Matomo Cloud subscriptions automatically renew at the end of each billing cycle unless canceled by the user. Service fees are subject to change with 30 days' notice, and such changes will take effect in the subsequent billing cycle.
Cancellation by User: Users can terminate their subscription at any time by canceling their Customer Account through the account settings. The termination becomes effective at the end of the current billing cycle, and no further charges will be incurred.
Data Deletion: Upon termination, user data is no longer accessible and will be deleted 30 days after the effective termination date. Users must request any data exports before this period expires.
Termination by Matomo: Matomo reserves the right to suspend or terminate subscriptions immediately if users breach material obligations outlined in the Terms of Service.
Premium Plugins
Automatic Renewal: Premium Plugin subscriptions are set to renew automatically to prevent service interruption. Users authorize Matomo to charge the applicable annual fee to the payment method on record.
Cancellation by User: Users may cancel their Plugin Subscription at any time via the "My Account" section on shop.matomo.org. The subscription remains active until the end of the current paid period, with no refunds for early cancellation.
30-Day Refund Policy: Users can request a refund within 30 days of purchase. Upon refund, access to the Plugin is terminated. Subscription fees are non-refundable after these 30 days.
Termination by Matomo: Matomo may terminate or suspend accounts or subscriptions immediately if users breach the agreement terms.
Support Plans
Automatic Renewal: Support Plans are annual contracts that automatically renew unless canceled by the user.
Cancellation by User: Users can cancel Support Plan services at any time through the "My Account" section on shop.matomo.org or by submitting a cancellation request. The subscription remains active until the end of the current paid period.
Matomo is designed to help organizations comply with various global data protection and privacy regulations by offering features that support adherence to several compliance standards:
General Data Protection Regulation (GDPR): Matomo provides tools such as data anonymization, robust GDPR management, user opt-out capabilities, and IP anonymization to ensure compliance with GDPR requirements.
Health Insurance Portability and Accountability Act (HIPAA): For organizations handling protected health information (PHI), Matomo can be configured to meet HIPAA standards. This involves self-hosting Matomo on HIPAA-compliant infrastructure, implementing data encryption, and establishing processes for data management.