Overview
Mailchimp is an email marketing and automation platform used by over 11 million businesses worldwide. On websites, Mailchimp appears through embedded signup forms, landing pages, and tracking pixels that attribute web visits to email campaign clicks.
What This Script Does
Mailchimp scripts serve several functions depending on integration type:
- Embedded signup forms: JavaScript loads and renders email subscription forms on the page. When a user submits their email, it is sent directly to Mailchimp's API and added to the site owner's mailing list. The form script itself is relatively lightweight and does not set tracking cookies.
- Tracking pixel (mc.js): When enabled, the Mailchimp site tracking script (
mc.js) sets a persistent cookie to identify visitors and track their page views. It links this browsing data to known Mailchimp contacts, attributing web visits to specific email campaigns. This builds behavioral profiles used for audience segmentation and automated email triggers. - Landing pages: Full Mailchimp-hosted pages with forms, which operate within Mailchimp's domain and set their own cookies.
- E-commerce tracking: For connected stores, Mailchimp tracks product views, cart activity, and purchases to power abandoned cart emails and product recommendation campaigns.
The tracking pixel makes requests to Mailchimp's servers on each page load, transmitting the page URL, referrer, and a visitor identifier cookie. This data is used to build contact activity timelines in the Mailchimp dashboard.
Consent & Compliance
Mailchimp spans the marketing consent category. Embedded signup forms alone are relatively low-risk — the user explicitly provides their email. However, the mc.js tracking pixel and e-commerce tracking components collect behavioral data and build user profiles for marketing automation, which requires consent.
Under GDPR/ePrivacy:
- Signup forms (without tracking): Can arguably load without consent as the user initiates the data submission. However, the form script itself may set cookies.
- mc.js tracking pixel: Requires explicit opt-in consent. It sets persistent cookies and tracks browsing behavior for marketing purposes.
- E-commerce tracking: Requires consent as it monitors purchasing behavior for automated marketing campaigns.
Under CCPA, Mailchimp's behavioral tracking and profile building must be disclosed, and the data sharing with Mailchimp (as a service provider) should be covered in the privacy policy.
Should You Block This Without Consent?
Yes. Mailchimp scripts serve email marketing and audience tracking purposes. Block the Mailchimp tracking script and any marketing-related components until the user grants marketing consent. The tracking pixel, e-commerce tracking, and behavioral data collection all constitute marketing data processing that requires explicit opt-in consent.
Consent Categories
Also Known As
Industries
Tracked Domains (2)
chimpstatic.comMarketinglist-manage.comMarketingFrequently Asked Questions
Is Mailchimp consent-required on my website?
Yes, for the mc.js tracking pixel and e-commerce tracking. These set persistent cookies and build behavioral profiles linking browsing activity to email campaign engagement — clear marketing data processing requiring opt-in consent under GDPR and ePrivacy. Embedded signup forms alone carry lower risk but may still set cookies.
What does the Mailchimp tracking script actually collect?
The mc.js pixel sets a persistent cookie on each page load, transmits the page URL and referrer to Mailchimp servers, and links the browser to known Mailchimp contacts. E-commerce tracking captures product views, cart additions, and purchases. This behavioral data powers abandoned cart emails and audience segmentation.
How does ConsentStack handle Mailchimp?
ConsentStack places Mailchimp in the marketing consent category. The tracking pixel and e-commerce scripts are blocked until the visitor grants marketing consent. ConsentStack can load a basic signup form embed separately if configured without attribution cookies, allowing list growth without gating the form behind consent.
Related Vendors
Manage consent for Mailchimp
ConsentStack automatically detects and manages Mailchimp trackers so your site stays compliant with global privacy regulations.