Back to articles
Technology Insight

Self-Hosting a Privacy-First Web Analytics Solution: Deploying Shynet and PostgreSQL on a VPS for Cookie-Free Tracking

May 26, 2026

Introduction to Modern Web Analytics

In the contemporary digital business landscape, data-driven decision-making is paramount. However, the mechanism of gathering data has encountered a significant paradigm shift. For over a decade, platforms like Google Analytics dominated the market, relying heavily on tracking cookies to monitor user behavior across the web. Today, that model is breaking down. Tightening data privacy regulations such as the General Data Protection Regulation (GDPR) in Europe and the California Consumer Privacy Act (CCPA) in the United States, combined with aggressive cookie-blocking mechanisms in modern browsers like Safari and Firefox, have rendered traditional tracking methods both legally risky and technically inaccurate.

For enterprises and privacy-conscious developers, the solution lies in self-hosted, privacy-first web analytics. By shifting from a third-party hosted model to an infrastructure you completely own, you eliminate compliance headaches, bypass ad-blockers, and regain 100% data ownership. This comprehensive guide walks you through deploying Shynet, a powerful, lightweight, and completely cookie-free open-source analytics tool, paired with PostgreSQL on a Virtual Private Server (VPS).

Why Shynet and PostgreSQL?

Among the open-source analytics tools available today, Shynet stands out for its uncompromising stance on privacy and efficiency. Unlike other platforms that require complex cookie consent banners, Shynet identifies unique visitors using an ephemeral, cryptographic hash derived from the visitor's IP address, User-Agent, and a rotating daily salt. This ensures that you can gather deep insights without storing any personally identifiable information (PII) or leaving permanent tracking files on the client's machine.

When paired with PostgreSQL, Shynet transforms into an enterprise-grade tracking powerhouse. PostgreSQL offers unmatched reliability, advanced indexing capabilities, and excellent performance under heavy read/write loads. This stack provides several distinct advantages:

  • Zero Cookies: No consent banners required; completely frictionless user experience.
  • Absolute Data Ownership: Your data never leaves your VPS, keeping you insulated from third-party policy changes.
  • Ad-Blocker Resilience: Because the tracker runs from your own subdomain, it is vastly less likely to be blocked by standard browser extensions.
  • Lightweight Footprint: The tracking script is tiny, ensuring your website's performance and Core Web Vitals remain optimal.

Prerequisites and System Requirements

Before initiating the deployment process, ensure your infrastructure meets the following baseline requirements:

  1. A Linux VPS: Ubuntu 22.04 LTS or 24.04 LTS is highly recommended. A baseline instance with 2 vCPUs and 2GB to 4GB of RAM is sufficient for handling millions of monthly pageviews.
  2. A Fully Qualified Domain Name (FQDN): You will need access to your DNS provider to point a subdomain (e.g., analytics.yourdomain.com) to your VPS IP address.
  3. Docker and Docker Compose: Installed and configured on the host machine to streamline service orchestration.
Note on Security: Always ensure your VPS firewall (such as UFW) is active and configured to block all unauthorized ports, leaving only 80 (HTTP), 443 (HTTPS), and your custom SSH port open.

Step-by-Step Deployment Blueprint

Step 1: Network and DNS Configuration

Log into your DNS provider's dashboard and create an A Record pointing your chosen subdomain to the public IP address of your VPS. For example:

  • Type: A
  • Name: analytics
  • Value: [Your_VPS_IP_Address]
  • TTL: Automatic or 3600

Step 2: Preparing the Environment

Connect to your server via SSH and create a dedicated directory structure for your analytics stack. This isolates configuration files and ensures structured volume backups.

mkdir -p /opt/shynet-analytics && cd /opt/shynet-analytics

Inside this directory, we will manage our configuration files and environment definitions.

Step 3: Creating the Docker Compose Architecture

Shynet relies on a modern microservices architecture consisting of the core web service, an asynchronous celery worker for processing incoming hits without blocking the main thread, and the PostgreSQL database. Create a file named docker-compose.yml and insert the following production-ready configuration:version: '3.8' services: db: image: postgres:15-alpine container_name: shynet_db restart: always environment: POSTGRES_DB: shynet POSTGRES_USER: shynet_admin POSTGRES_PASSWORD: SecureDatabasePassword123! volumes: - pgdata:/var/lib/postgresql/data shynet: image: redowan/shynet:latest container_name: shynet_app restart: always ports: - "127.0.0.1:8080:8080" environment: - DB_ENGINE=django.db.backends.postgresql - DB_NAME=shynet - DB_USER=shynet_admin - DB_PASSWORD=SecureDatabasePassword123! - DB_HOST=db - DB_PORT=5432 - SECRET_KEY=YourSuperLongRandomSecretKeyHere - ALLOWED_HOSTS=analytics.yourdomain.com - SCRIPT_USE_HTTPS=True - TIME_ZONE=UTC depends_on: - db volumes: pgdata: driver: local

Step 4: Initializing the Database and Creating an Admin Account

Once your configuration file is saved, launch the services in detached mode:

docker-compose up -d

After the containers initialize, you must run the database migrations and create your initial administrative account to access the dashboard. Execute the following commands:

docker-compose exec shynet python manage.py migrate
docker-compose exec shynet python manage.py createsuperuser

Follow the interactive prompts to set your administrative email and password.

Step 5: Configuring Nginx as a Reverse Proxy with Let's Encrypt SSL

To securely expose Shynet to the internet over HTTPS, install Nginx and Certbot on your host system:

sudo apt update
sudo apt install nginx certbot python3-certbot-nginx -y

Create a new Nginx server block configuration for Shynet at /etc/nginx/sites-available/shynet:

server {
    listen 80;
    server_name analytics.yourdomain.com;

    location / {
        proxy_pass [http://127.0.0.1:8080](http://127.0.0.1:8080);
        proxy_set_header Host $$host;
        proxy_set_header X-Real-IP $$remote_addr;
        proxy_set_header X-Forwarded-For $$proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $$scheme;
    }
}

Enable the site configuration and request an SSL certificate from Let's Encrypt:

sudo ln -s /etc/nginx/sites-available/shynet /etc/nginx/sites-enabled/
sudo systemctl restart nginx
sudo certbot --nginx -d analytics.yourdomain.com

Certbot will automatically modify your Nginx file to handle secure SSL handshakes and force HTTP-to-HTTPS redirection.

Integrating the Cookie-Free Script into Your Web Properties

With the backend successfully running, navigate to [https://analytics.yourdomain.com](https://analytics.yourdomain.com) and authenticate using your superuser credentials. Create a new "Service" (website property) within the Shynet dashboard. The platform will automatically generate a localized, lightweight JavaScript tracking snippet.

Copy and paste this script tag directly into the element of your target websites. The tracking script will resemble the following structure:

Because the script loads asynchronously (defer), it will never block user-facing page elements, protecting your site's operational speed and conversion metrics.

Performance Optimization and Maintenance Strategy

Running self-hosted solutions requires regular administrative hygiene to ensure consistent performance over time. Consider implementing the following practices:

1. PostgreSQL Maintenance

As traffic grows, the database tables holding event logs will expand. Ensure PostgreSQL's autovacuum daemon is running correctly to optimize storage and index efficiency. Regularly check disk space utilizing the df -h command.

2. Automated Backups

Data ownership means you are also responsible for data resilience. Establish a daily cron job that executes a pg_dump to safely extract database states and upload them to an encrypted off-site cloud bucket or alternate backup server:

docker-compose exec db pg_dump -U shynet_admin shynet > /backups/shynet_$(date +%F).sql

Conclusion: Embracing Data Sovereignty

Transitioning to a self-hosted, cookie-free web analytics infrastructure using Shynet and PostgreSQL represents a massive operational advantage for forward-thinking enterprises. By building this system on your own VPS, you actively prioritize your user's privacy, eliminate compliance complications, and gain absolute, uncompromised control over your corporate data assets. This architecture proves that modern businesses can capture granular, actionable traffic metrics while honoring consumer trust and upholding global privacy standards.

Self-Hosting a Privacy-First Web Analytics Solution: Deploying Shynet and PostgreSQL on a VPS for Cookie-Free Tracking | DPTCloud