Overview
Mailchimp is an email marketing and automation platform used by over 11 million businesses worldwide. On websites, Mailchimp appears through embedded signup forms, landing pages, and tracking pixels that attribute web visits to email campaign clicks.
What This Script Does
Mailchimp scripts serve several functions depending on integration type:
- Embedded signup forms: JavaScript loads and renders email subscription forms on the page. When a user submits their email, it is sent directly to Mailchimp's API and added to the site owner's mailing list. The form script itself is relatively lightweight and does not set tracking cookies.
- Tracking pixel (mc.js): When enabled, the Mailchimp site tracking script (
mc.js) sets a persistent cookie to identify visitors and track their page views. It links this browsing data to known Mailchimp contacts, attributing web visits to specific email campaigns. This builds behavioral profiles used for audience segmentation and automated email triggers. - Landing pages: Full Mailchimp-hosted pages with forms, which operate within Mailchimp's domain and set their own cookies.
- E-commerce tracking: For connected stores, Mailchimp tracks product views, cart activity, and purchases to power abandoned cart emails and product recommendation campaigns.
The tracking pixel makes requests to Mailchimp's servers on each page load, transmitting the page URL, referrer, and a visitor identifier cookie. This data is used to build contact activity timelines in the Mailchimp dashboard.
Consent & Compliance
Mailchimp spans the marketing consent category. Embedded signup forms alone are relatively low-risk — the user explicitly provides their email. However, the mc.js tracking pixel and e-commerce tracking components collect behavioral data and build user profiles for marketing automation, which requires consent.
Under GDPR/ePrivacy:
- Signup forms (without tracking): Can arguably load without consent as the user initiates the data submission. However, the form script itself may set cookies.
- mc.js tracking pixel: Requires explicit opt-in consent. It sets persistent cookies and tracks browsing behavior for marketing purposes.
- E-commerce tracking: Requires consent as it monitors purchasing behavior for automated marketing campaigns.
Under CCPA, Mailchimp's behavioral tracking and profile building must be disclosed, and the data sharing with Mailchimp (as a service provider) should be covered in the privacy policy.
Should You Block This Without Consent?
Yes. Mailchimp scripts serve email marketing and audience tracking purposes. Block the Mailchimp tracking script and any marketing-related components until the user grants marketing consent. The tracking pixel, e-commerce tracking, and behavioral data collection all constitute marketing data processing that requires explicit opt-in consent.
Is Mailchimp GDPR compliant?
Mailchimp typically loads marketing trackers, which are not strictly necessary for your site to work. Under the GDPR and the ePrivacy Directive, non-essential cookies and trackers must stay blocked until a visitor gives clear opt-in consent. So Mailchimp can be fully GDPR compliant, but only if your site holds its scripts until consent is granted and lets visitors decline just as easily. Compliance depends on how your site loads Mailchimp, not on Mailchimp itself.
Consent Categories
Also Known As
Industries
Tracked Domains (2)
chimpstatic.comMarketingchimpstatic.com is a marketing domain operated by Mailchimp, used to serve ads, build audiences, and measure ad conversions.
list-manage.comMarketinglist-manage.com is a marketing domain operated by Mailchimp, used to serve ads, build audiences, and measure ad conversions.
Cookies Mailchimp Sets (2)
_mcidMailchimp visitor identifier set on the customer apex when a Mailchimp signup form or popup loads.
_mcvidMailchimp visitor identifier persisting across visits for email-campaign attribution.
Frequently Asked Questions
Related Vendors
Manage consent for Mailchimp
ConsentStack automatically detects and manages Mailchimp trackers so your site stays compliant with global privacy regulations.