Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
MailerLite Website Builder lets you host websites and landing pages and embed MailerLite forms, pop ups, and tracking. A JavaScript script sets first party cookies to manage form display logic and identify returning visitors. Core data is hosted in the European Union, although some sub processors operate in the United States. Because the cookies are not strictly necessary, prior consent is required under the GDPR and the ePrivacy Directive.
MailerLite Website Builder is the website and landing page hosting product within the MailerLite email marketing platform. It lets you build and publish sites, embed signup forms and pop ups, and connect them directly to your MailerLite subscriber lists. A JavaScript script runs on the published pages to display forms, apply targeting rules, and measure how visitors interact with the site and its campaigns.
The script sets first party cookies, including ml_ prefixed tracking cookies, a mailerlite cookie that controls form and pop up display logic, and a visitor identifier cookie that lasts about one year, alongside short lived session cookies. MailerLite also processes IP addresses, browser and device information, pages viewed, and any data entered into forms, such as names and email addresses, which constitute personal data under the GDPR.
Because the tracking and pop up cookies are read from and written to the visitor terminal for marketing purposes rather than for a strictly necessary function, Article 5(3) of the ePrivacy Directive requires prior consent. The processing of identifiable form data and behaviour also qualifies as personal data processing under the GDPR, so a lawful basis, a transparent privacy notice, and a record of processing activities are required, with MailerLite acting as a processor under a data processing agreement.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
The tracking script and its cookies must not load before the visitor has actively accepted the marketing category in your consent banner. Pre ticked boxes, implied consent from continued browsing, and cookie walls do not meet the GDPR standard. Form and newsletter sign ups must rely on a clear, affirmative opt in, and the consent you collect must be freely given, specific, informed, and as easy to withdraw as to give.
MailerLite hosts core data in the European Union, which is favourable, but some sub processors operate in the United States under Standard Contractual Clauses, so you should still document these transfers. In practice, sign the MailerLite data processing agreement, gate the tracking script behind your consent management platform, use affirmative opt in for forms, list the cookies and their durations in your cookie policy, and set retention so that visitor and subscriber data is not kept longer than necessary.
Websites using MailerLite Website Builder must obtain user consent under GDPR regulations.
DPIA considerations
MailerLite Website Builder sets a visitor identifier cookie for about one year plus form and pop up cookies, and processes form data and behaviour. Core data is hosted in the EU, but some sub processors are in the United States. A DPIA should assess the scale of visitor tracking, the linkage of behavioural and identifiable form data, the US sub processor transfers, and retention periods, together with mitigations such as consent gating, affirmative opt in, data minimisation, and shortened retention.
Sample consent text
We use MailerLite Website Builder to display our forms and pop ups, recognise returning visitors, and measure how our site is used. MailerLite places cookies on your device to manage form display and link your activity to our subscriber records. These cookies load only after you accept the marketing category, and core data is hosted in the European Union while some processing may occur in the United States. You can withdraw your consent at any time through our cookie settings.
Third-party domains contacted
static.mailerlite.comassets.mailerlite.comconnect.mailerlite.comgroot.mailerlite.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| ml_visitor | marketing | 1 year | Stores a MailerLite visitor identifier used to recognise returning visitors across sessions and to attribute activity to the right subscriber profile. |
| mailerlite | marketing | 1 year | Controls form and pop up display logic, for example remembering whether a visitor has already seen or dismissed a particular form so it is not shown again. |
| ml_session | marketing | Session | Short lived session cookie used by the MailerLite tracking script to manage the current browsing session and form interactions. |
| ml_webform_shown | marketing | 1 month | Records that a specific MailerLite web form or pop up has been shown to the visitor to control display frequency. |
MailerLite Website Builder collects user analytics data — you legally need a consent banner. Try FlowConsent free.
The script sets first party cookies including ml_ prefixed tracking cookies, a mailerlite cookie that controls form and pop up display logic, and a visitor identifier cookie that lasts about one year, alongside short lived session cookies. Together they recognise returning visitors and decide which forms or pop ups to show.
Yes. The tracking and pop up cookies are not strictly necessary, so under Article 5(3) of the ePrivacy Directive and the GDPR you must obtain prior, opt in consent before the script loads. Form and newsletter sign ups must also rely on a clear, affirmative opt in.
The storage and reading of cookies relies on consent under the ePrivacy Directive, and the processing of form data and behaviour relies on consent under Article 6(1)(a) of the GDPR. Legitimate interest is generally not available because consent is already required to place the cookies.
Core MailerLite data is hosted in the European Union, which is favourable, but some sub processors operate in the United States under Standard Contractual Clauses. You should still document these transfers in your privacy notice, although the EU residency of the core data lowers the overall risk.
A full DPIA is not always mandatory, but it is recommended because the product tracks visitor behaviour and links it to identifiable form data. Document the purposes, data categories, retention, the EU hosting, and the US sub processor transfers, and reassess if you enable advanced automation or profiling.
Load the tracking script only after the visitor accepts the marketing category in your consent management platform, and keep cookies blocked until then. Use affirmative opt in on forms, sign the MailerLite data processing agreement, set sensible retention, and document the cookies in your cookie policy.
Other EU friendly options include Brevo, MailPoet, and self hosted site builders combined with a privacy focused form tool. The right choice depends on whether you need MailerLite specific automation and EU hosting or prefer a different balance of features and data residency.
List each MailerLite cookie, its purpose, and its duration, name MailerLite as a recipient, and note that core data is hosted in the EU while some sub processors are in the United States. Keep the entries in sync with a regular cookie scan so that new or renamed cookies are reflected accurately.