Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Moosend is an email marketing and automation platform, now part of Sitecore, that uses an on site tracking script and email pixels to power behavioral campaigns.
Moosend, now part of Sitecore and offered as Sitecore Send, is an email marketing and automation platform with European origins. It lets brands send campaigns, build automations and personalise messages based on subscriber behavior.
Moosend provides a JavaScript tracking script, known as Mootrack, that you embed on your website. It follows page visits, product views, carts and purchase details and links them to subscriber records to trigger automated campaigns. Email messages also use tracking pixels to record opens and clicks. This behavioral data is stored within the platform and used to personalise marketing.
The website tracking script and its cookies are not strictly necessary, so Article 5(3) of the ePrivacy Directive and the GDPR require prior consent before they load. Building behavioral profiles for automation is a form of profiling, which raises the compliance bar and calls for clear information about purposes and recipients.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Collect freely given, specific and informed consent through a compliant consent banner before the tracking script runs, and rely on consent under Article 6(1)(a) for the behavioral processing. Marketing emails themselves typically rest on consent or, in narrow cases, the soft opt in for existing customers. Keep records of consent and provide an easy way to withdraw it.
Depending on the plan and Sitecore hosting, data may be processed in the European Union or in the United States. Where US processing occurs, transfers should rely on Standard Contractual Clauses or the EU US Data Privacy Framework, supported by a transfer impact assessment and supplementary measures.
Gate the Mootrack script behind consent, list Moosend cookies in your cookie policy, sign a data processing agreement with Sitecore, document transfer safeguards and honour withdrawal and erasure requests promptly.
Websites using Moosend must obtain user consent under GDPR regulations.
DPIA considerations
A DPIA is recommended where the Moosend website tracking script is enabled, because it follows visitors and product views to build behavioral profiles for automation. Assess the scale of profiling, the combination of on site behavior with email engagement, possible transfers to the United States and retention periods. Document the legal basis, consent capture and data subject rights handling.
Sample consent text
We use Moosend to send marketing emails and to track how you interact with our site and messages so we can personalise campaigns. This sets cookies and may transfer data to the United States. Do you consent?
Third-party domains contacted
moosend.comcdn.moosend.comapi.moosend.comtracking.moosend.comm.moosend.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| mootrack | Third-party | Persistent | Moosend website tracking cookie that identifies the visitor and links page visits, product views, carts and purchases to the subscriber profile for marketing automation. |
| mootrack_session | Third-party | Session | Maintains the visitor session for the Mootrack tracking script so on site activity is grouped correctly during a visit. |
| moo_id | Third-party | Persistent | Stores a Moosend visitor identifier used to recognise returning visitors and associate their behavior with automation workflows. |
| tracking_pixel | Third-party | None (pixel) | Email tracking pixel embedded in messages that records opens and engagement for campaign reporting; not a stored cookie but a tracking technology used by Moosend. |
Moosend places tracking cookies for advertising — comply with GDPR using FlowConsent.
When the Mootrack website tracking script is installed, Moosend sets cookies that identify visitors and record page visits, product views, carts and purchases. Email messages also use tracking pixels to record opens and clicks. These are not strictly necessary and require consent.
Yes for the on site tracking script and any non essential cookies, which require prior consent under the ePrivacy Directive and the GDPR. Sending marketing emails also generally requires consent, except where a soft opt in for existing customers applies.
The behavioral tracking and profiling rely on consent under Article 6(1)(a) of the GDPR. Strictly necessary platform operations may rest on legitimate interest under Article 6(1)(f), but the website tracking script always needs consent because it is not essential.
It can. Depending on the plan and Sitecore infrastructure, data may be processed in the European Union or the United States. US transfers should rely on Standard Contractual Clauses or the EU US Data Privacy Framework, backed by a transfer impact assessment.
A DPIA is recommended when the website tracking script is enabled, because it builds behavioral profiles across site activity and email engagement for automation. Assess the scale of profiling, possible US transfers and retention before launch.
Gate the Mootrack script behind a consent banner so it only loads after consent, list all Moosend cookies in your cookie policy, sign a data processing agreement with Sitecore, document transfer safeguards and offer easy withdrawal and erasure.
Alternatives include EU based email and automation platforms such as Brevo, Mailjet and CleverReach, as well as Mailchimp and ActiveCampaign. Compare data hosting location, transfer safeguards and whether on site tracking can be disabled to reduce risk.
List the Moosend tracking cookies with their names, purposes and durations, explain that they support marketing automation and behavioral tracking, note possible transfers to the United States and link to Sitecore privacy information. Keep the list updated as cookies change.