Salesforce Pardot

Salesforce Pardot

Salesforce Pardot (now Marketing Cloud Account Engagement) is a B2B marketing automation platform. The Pardot tracking pixel and JavaScript identify website visitors by company, monitor page visits and form submissions, and sync lead activity data back to Salesforce CRM for lead scoring and sales follow-up.

Overview

Salesforce Pardot (now officially named Marketing Cloud Account Engagement) is a B2B marketing automation platform deeply integrated with Salesforce CRM. When its tracking code is present on a website, it identifies and monitors visitor behavior to score leads, trigger automated marketing workflows, and sync prospect activity data with Salesforce for sales follow-up. It is one of the most widely deployed B2B marketing automation tools, particularly on SaaS, technology, and professional services websites.

What This Script Does

Pardot deploys a first-party JavaScript tracker (pd.js or the newer pi.pardot.com tracking code) that fires on every page load. The script records visitor activity and transmits it to Pardot's servers, where it is associated with a prospect record.

Key cookies set:

  • visitor_id[accountID] — the primary Pardot visitor identification cookie, a first-party persistent cookie. Stores a unique visitor ID that ties browsing activity to a Pardot prospect record. 10-year expiry (one of the longest cookie durations in the marketing automation space).
  • visitor_id[accountID]-hash — a hash of the visitor ID used for validation. Same 10-year expiry.
  • pi_opt_in[accountID] — records whether the visitor has opted in to tracking (when Pardot's optional first-party tracking opt-in is enabled). 10-year expiry.
  • lpv[campaignID] — tracks the last page view within a specific Pardot campaign for landing page view deduplication. Session-scoped.

The tracker contacts Pardot's servers (typically pi.pardot.com or a custom tracking domain configured by the organization) to transmit page view events. Data collected includes: page URLs visited, referrer information, UTM parameters, form submission data (when Pardot forms or form handlers are used), IP address, and browser metadata.

When a visitor submits a Pardot form, clicks a Pardot-tracked email link, or is otherwise identified, the anonymous visitor cookie is linked to a known prospect record in Pardot. From that point, all historical and future browsing activity is attributed to the identified individual. This data feeds Pardot's lead scoring engine, which assigns point values to page views, form submissions, email interactions, and other engagement signals. High-scoring leads are flagged for sales follow-up in Salesforce CRM.

Pardot forms (form handlers or embedded Pardot forms) may also load on pages, adding form-specific tracking, progressive profiling, and validation scripts.

Consent & Compliance

Salesforce Pardot spans both marketing and analytics categories. It collects analytics-grade behavioral data, but its primary purpose is marketing automation — lead identification, scoring, nurturing, and sales enablement.

Under the GDPR, Pardot processes personal data extensively. The visitor_id cookie's 10-year expiry is particularly notable — it is among the longest-lived tracking cookies in common use. Once a visitor is identified (via form submission), their complete browsing history is linked to a named individual record. This creates a detailed personal data profile that requires explicit consent.

The ePrivacy Directive requires consent for the Pardot tracking cookies. A 10-year visitor identification cookie used for marketing automation is definitively outside the "strictly necessary" exemption. There is no technical justification for this duration that would survive regulatory scrutiny.

Under CCPA/CPRA, Pardot collects personal information and uses it for B2B marketing purposes. The linking of anonymous browsing history to identified individuals when they submit a form constitutes profiling. If Pardot data syncs to Salesforce CRM and is used for targeted outreach, the CPRA's profiling provisions may apply. The visitor's browsing history constitutes personal information regardless of whether the visitor has been identified yet.

Should You Block This Without Consent?

Yes. Pardot sets a 10-year visitor identification cookie, tracks detailed browsing behavior, and feeds this data into marketing automation and sales workflows. It is not essential for website functionality. Its exceptionally long cookie duration makes the consent requirement unambiguous under EU privacy regulations.

Visit website

Consent Categories

Marketing
Analytics

Also Known As

PardotMarketing Cloud Account EngagementPardot tracking pixelSalesforce B2B marketingPardot forms

Industries

Computers Electronics and TechnologyProgramming and Developer Software

Tracked Domains (1)

pi.pardot.comMarketing

Frequently Asked Questions

Is consent required for Salesforce Pardot on my website?

Yes. Pardot sets a 10-year visitor identification cookie, one of the longest in common use, and tracks browsing behavior for lead scoring and sales automation. Under GDPR and ePrivacy, this clearly requires explicit consent. It is classified as marketing and analytics and must be blocked until opt-in.

What cookies does Salesforce Pardot set?

Pardot sets visitor_id[accountID] (10-year expiry), visitor_id[accountID]-hash (10-year expiry), pi_opt_in[accountID] (10-year expiry), and lpv[campaignID] (session-scoped). The tracker contacts pi.pardot.com or a custom domain, collecting page URLs, referrer data, UTM parameters, form data, and browser metadata.

How does ConsentStack manage Salesforce Pardot consent?

ConsentStack detects Pardot by its pd.js or pi.pardot.com tracking scripts. It classifies Pardot as marketing and analytics, blocking all tracking scripts until the visitor explicitly consents. The exceptionally long 10-year cookie duration makes ConsentStack's blocking behavior especially important for GDPR compliance.

Related Vendors

Google Ads
Google Ads
Google Ads is Google's advertising platform for search, display, and remarketing campaigns. Conversion tracking scripts fire on advertiser landing pages to measure actions taken after ad clicks. The remarketing tag builds audience lists for retargeting users across Google's ad network.
Google
Google
Google is the dominant provider of web analytics, advertising, and infrastructure tools. Scripts like Google Analytics, Tag Manager, Ads, and reCAPTCHA collect behavioral data, manage tag firing, serve targeted ads, and detect bots. Sets persistent cookies to track users and correlate activity across sites.
Microsoft Dynamics 365
Microsoft Dynamics 365
Microsoft Dynamics 365 is a suite of CRM and ERP applications that integrates with websites through tracking scripts and embedded forms. Web tracking code captures visitor behavior, page views, and form submissions to build customer profiles and score leads. Sets cookies to identify returning visitors and attribute marketing touchpoints across sessions.
Microsoft
Microsoft
Runs Clarity (session recording and heatmaps), the Microsoft Advertising UET tag (conversion tracking), and Bing's remarketing pixel. Clarity injects a recording script that captures mouse movements, clicks, and rage clicks. The UET tag fires conversion events to tie ad clicks to on-site actions across Microsoft's ad network.
Microsoft Advertising UET Tag
Microsoft Advertising UET Tag
Microsoft Advertising UET Tag is the Universal Event Tracking pixel for Microsoft's ad platform, formerly Bing Ads. The JavaScript tag fires on advertiser websites to track page views, conversions, and custom events for campaign optimization. Sets cookies to identify visitors across sessions and attribute conversions to Microsoft Search and Audience Network ad clicks.
LinkedIn Ads
LinkedIn Ads
LinkedIn Ads is LinkedIn's advertising platform for B2B marketing and professional audience targeting. Conversion tracking scripts and pixels fire on advertiser websites to measure sign-ups, downloads, and purchases driven by LinkedIn ad campaigns. Sets cookies for audience matching, retargeting list building, and cross-device attribution reporting.

Manage consent for Salesforce Pardot

ConsentStack automatically detects and manages Salesforce Pardot trackers so your site stays compliant with global privacy regulations.