Overview
EmailOctopus is an email marketing platform that uses Amazon SES as its delivery infrastructure, positioning itself as a cost-effective alternative to Mailchimp and similar services. It serves small businesses, bloggers, and SaaS companies with list management, campaign sending, and basic automation. On publisher websites, EmailOctopus appears through embeddable subscription forms that capture email addresses and add subscribers to the operator's lists.
What This Script Does
EmailOctopus's client-side presence is limited to subscription form widgets loaded from emailoctopus.com scripts or embedded HTML form snippets.
Form rendering and submission:
- Scripts render styled subscription forms with name and email fields
- On submission, form data is sent via AJAX or standard POST to EmailOctopus API endpoints
- Success and error states are handled client-side (confirmation messages, validation feedback)
Tracking and cookies:
EmailOctopus may set a session cookie to prevent duplicate form submissions within a browser session. Persistent tracking cookies are not a standard part of the embeddable form widget. The form embed does not implement cross-site behavioral tracking or fingerprinting.
Email engagement tracking:
Open and click tracking for sent email campaigns is handled server-side through Amazon SES tracking pixels embedded in email content — this occurs in email clients, not in browser sessions on the publisher's website.
Network requests:
Form submissions are sent to emailoctopus.com API endpoints. The subscriber's email address and any additional fields collected (name, custom fields) are transmitted and stored on EmailOctopus servers.
Consent & Compliance
GDPR and ePrivacy Directive: The act of collecting an email address for marketing communications requires a lawful basis under GDPR. For email marketing, explicit consent is the standard required basis under the ePrivacy Directive and GDPR Article 6(1)(a). The subscription form itself must collect and record this consent — a checkbox with clear opt-in language is required for EU visitors. The cookie used for duplicate submission prevention is likely covered by the strictly necessary exemption.
CCPA/CPRA: Collecting email addresses through the form and transmitting them to EmailOctopus constitutes sharing personal information with a service provider. This is generally permissible under CCPA with appropriate data processing disclosures in the privacy policy.
Consent category: marketing — EmailOctopus forms are used to build marketing communication lists. Consent must be obtained at the point of subscription, not managed separately through a cookie banner.
Should You Block This Without Consent?
Yes.
The EmailOctopus form script transmits personal data (email addresses) to a third-party marketing platform. While the form's cookie footprint is minimal, the data collection purpose is marketing, and explicit consent for email marketing communications must be obtained at the point of form submission. The script should be blocked until marketing consent is granted, and the form itself must include clear opt-in language.
Is EmailOctopus GDPR compliant?
EmailOctopus typically loads marketing trackers, which are not strictly necessary for your site to work. Under the GDPR and the ePrivacy Directive, non-essential cookies and trackers must stay blocked until a visitor gives clear opt-in consent. So EmailOctopus can be fully GDPR compliant, but only if your site holds its scripts until consent is granted and lets visitors decline just as easily. Compliance depends on how your site loads EmailOctopus, not on EmailOctopus itself.
Consent Categories
Also Known As
Industries
Tracked Domains (1)
emailoctopus.comMarketingemailoctopus.com is a marketing domain operated by EmailOctopus, used to serve ads, build audiences, and measure ad conversions.
Frequently Asked Questions
Related Vendors

Manage consent for EmailOctopus
ConsentStack automatically detects and manages EmailOctopus trackers so your site stays compliant with global privacy regulations.