FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. CMS
  4. Beehiiv

Beehiiv

OtherWebsite

Related services

@

@sulu/web

@sulu/web is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. @sulu/web supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, @sulu/web ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Other

1C-Bitrix

1C-Bitrix is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. 1C-Bitrix integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, 1C-Bitrix helps organizations maintain robust websites that meet user expectations and technical requirements.

Other
3

321 CMS

321 CMS is a powerful content management system (CMS) designed to help businesses and developers build, manage, and publish digital content with ease. It offers a flexible architecture that supports custom content types, templates, and workflows, making it ideal for websites of any scale. With 321 CMS, teams can streamline content creation, improve collaboration, and deliver engaging web experiences. Its extensible plugin ecosystem and API-first approach ensure seamless integration with existing tools and services.

Other
6

6Valley eCommerce CMS

6Valley eCommerce CMS is a powerful content management system (CMS) designed to help businesses and developers build, manage, and publish digital content with ease. It offers a flexible architecture that supports custom content types, templates, and workflows, making it ideal for websites of any scale. With 6Valley eCommerce CMS, teams can streamline content creation, improve collaboration, and deliver engaging web experiences. Its extensible plugin ecosystem and API-first approach ensure seamless.

Other

a-blog cms

a-blog cms provides a robust content management platform that enables organizations to create, organize, and distribute web content efficiently. Built with scalability and performance in mind, a-blog cms supports multi-site management, role-based access control, and advanced publishing workflows. Whether running a corporate website or a complex digital portal, a-blog cms delivers the flexibility and reliability needed to manage content at scale while maintaining optimal page load speeds and search engine.

Other

AboutMyClinic

AboutMyClinic is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. AboutMyClinic supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, AboutMyClinic ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Other
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does beehiiv do?

beehiiv is a US based newsletter platform founded in 2021 by former Morning Brew employees and headquartered in New York. It hosts newsletters, subscribe forms and publication websites, with built in monetisation and audience analytics. For European publishers, beehiiv involves transferring subscriber data to the United States and tracking email opens and link clicks, which require consent and a clear privacy notice.

What is beehiiv

beehiiv is a US based newsletter platform founded in 2021 by former Morning Brew operators and headquartered in New York. It bundles email delivery, hosted publication websites, subscribe forms, monetisation (Boost referral network and ad network), and audience analytics in a single SaaS product. beehiiv runs on AWS US East infrastructure, with Cloudflare in front and SendGrid as the email delivery sub processor.

Data and cookies collected

beehiiv collects subscriber email address, name, IP, opt in source, opens, clicks, browser, country and referral attribution. The embedded subscribe form and hosted publication pages set first party cookies (beehiiv_session, _beehiiv_referrer) for analytics and Boost attribution. Email opens are tracked via a 1x1 pixel and clicks via link wrapping through track.beehiiv.com.

GDPR and ePrivacy implications

beehiiv is a data processor for newsletter content and a controller for some platform functions (the Boost referral network, internal analytics). The embedded subscribe widget triggers Art. 5(3) ePrivacy because of the first party cookies it sets, so consent or appropriate UI deferral is needed. Subscribing itself is the user''s active opt in. The Boost referral network is a sharing of subscriber data with other publishers and needs an additional, distinct consent.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Consent requirements

Subscription itself relies on the user''s explicit action (entering email, clicking subscribe), so contract or consent applies depending on positioning. Open and click tracking should be disclosed. The Boost network requires explicit consent because it shares the subscriber address with other publishers. Subscribe widget cookies should ideally load only after a generic cookie consent or be configured to use no persistent identifiers.

Data transfers outside the EEA

beehiiv operates exclusively on US infrastructure with no announced EU data centre. Transfers rely on Standard Contractual Clauses, the EU US Data Privacy Framework if beehiiv is certified, and a documented Transfer Impact Assessment. Sub processors (AWS, Cloudflare, SendGrid) add their own data flows.

Practical compliance steps

Sign beehiiv''s Data Processing Agreement, complete a Transfer Impact Assessment, disable the Boost referral network or require explicit additional consent for it, configure the embedded subscribe widget to load after consent, disclose open and click tracking in the privacy notice and the subscribe confirmation, document sub processors (AWS, Cloudflare, SendGrid) and review beehiiv''s sub processor list at least annually.

GDPR consent category

Other

Websites using beehiiv must obtain user consent under GDPR regulations.

Legal basisConsent (Art. 6(1)(a) GDPR) for newsletter subscription, marketing emails to B2C and any non-essential cookies on the subscribe widget; Contract (Art. 6(1)(b) GDPR) for delivering the subscription the user explicitly asked for
Risk levelmedium
Applicable regulationsGDPR, ePrivacy Directive (Cookie Law), CAN-SPAM, CCPA, EU US Data Privacy Framework

DPIA considerations

beehiiv processes subscriber email, name, IP, opens, clicks and referral data on US infrastructure. Key DPIA considerations: (1) the embedded subscribe widget may set first party cookies before consent if loaded eagerly, beehiiv supports a lazy or post consent load; (2) open tracking pixels and link wrapping process personal data and require a lawful basis; (3) US transfers rely on SCCs and EU US Data Privacy Framework if certified; (4) sub processors include AWS, SendGrid and Cloudflare; (5) the beehiiv Boost referral network may share subscriber data with other publishers, this needs an explicit, granular consent; (6) automation and segmentation rules can produce profiling that should be documented.

Sample consent text

We use beehiiv to publish and send our newsletter. With your consent, beehiiv processes your email address, IP and engagement data (opens, clicks) to deliver the newsletter and measure interest. beehiiv is hosted in the United States, data is transferred under Standard Contractual Clauses and the EU US Data Privacy Framework. You can unsubscribe at any time from any email we send.

Technical details

Tracking methodEmail service provider: tracking pixels for opens, link wrapping for clicks, embedded subscribe forms on customer sites, hosted publication pages; first-party cookies on beehiiv.com and customer subdomains for analytics and referral tracking
Server locationUnited States (AWS US East 1 primarily); beehiiv, Inc. is headquartered in New York
Data transferred outside the EUbeehiiv, Inc. is a US company processing newsletter subscriber data on AWS US East infrastructure. Transfers from EU subscribers rely on Standard Contractual Clauses under Art. 46(2)(c) GDPR and the EU US Data Privacy Framework where beehiiv is certified. Sub processors include AWS, SendGrid and Cloudflare.

Third-party domains contacted

beehiiv.combeehiiv.nettrack.beehiiv.commedia.beehiiv.commail.beehiiv.com

Cookies placed

NameTypeDurationPurpose
beehiiv_sessionFunctionalSessionSession cookie used on beehiiv hosted publication pages and the embedded subscribe widget to keep state during a visit.
_beehiiv_referrerMarketing30 daysStores the referrer information used by beehiiv Boost and internal attribution analytics.
_beehiiv_subscribedFunctional1 yearStores a flag indicating that the visitor has already subscribed, to avoid showing the subscribe popup again.
__beehiiv_analyticsAnalytics13 monthsFirst party analytics cookie used to measure page views and engagement on beehiiv hosted publication pages.

This service may collect user data. Ensure GDPR compliance with FlowConsent.

Get started freeScan your site

Frequently asked questions

What cookies does beehiiv set on visitor browsers?

beehiiv sets first party cookies on its publication pages and on the embedded subscribe widget, including beehiiv_session (session), _beehiiv_referrer (referral attribution) and an analytics cookie for internal metrics. Email open tracking uses a pixel image, not cookies. Click tracking uses link wrapping through track.beehiiv.com without storing browser state.

Do I need consent to embed the beehiiv subscribe form?

The subscribe form is the user's explicit action, but if it loads first party cookies on page load, you need a cookie consent for those non essential identifiers. Configure the widget to load only after consent or use the lightweight variant without analytics cookies. Subscribing itself constitutes the lawful basis for the newsletter.

What is the legal basis for processing data via beehiiv?

Consent (Art. 6(1)(a) GDPR) for sending the newsletter to B2C subscribers and for any tracking pixels and cookies. Contract (Art. 6(1)(b) GDPR) for the delivery of the newsletter once the user has subscribed. Legitimate interest (Art. 6(1)(f) GDPR) may apply for very limited B2B promotional emails with a clear opt out.

Where does beehiiv process data, and are there transfers to the US?

beehiiv processes data on AWS US East infrastructure in the United States, with no announced EU data centre. EU subscriber data is transferred to the US under Standard Contractual Clauses and the EU US Data Privacy Framework where applicable. Sub processors include AWS, SendGrid for email delivery and Cloudflare for edge.

Is a DPIA required for beehiiv?

A DPIA is recommended if you operate a large list, monetise with beehiiv Boost or run highly personalised automations. The DPIA should cover open and click tracking, Boost data sharing with third party publishers, sub processor flows in the US and retention of subscriber engagement history.

How do I deploy beehiiv in a GDPR compliant way?

Sign the Data Processing Agreement, complete a Transfer Impact Assessment, disable Boost or require explicit additional consent, load the subscribe widget after consent or in a cookie free mode, disclose open and click tracking, document AWS, SendGrid and Cloudflare as sub processors and provide one click unsubscribe.

What are GDPR friendly alternatives to beehiiv?

EU based newsletter platforms include Brevo (France), Mailerlite (Lithuania), CleverReach (Germany), GetResponse (Poland), Newsletter2Go/Sendinblue group and Buttondown (US but minimalist) for technical writers. For full self hosting, Listmonk or Mailtrain remove the cross border transfer issue.

How should I update my privacy policy for beehiiv?

List beehiiv as a sub processor for newsletter sending, name SendGrid for email delivery and AWS/Cloudflare for infrastructure, describe open and click tracking with retention periods, disclose Boost as an optional data sharing requiring separate consent, mention US transfers under SCCs and the EU US Data Privacy Framework, and link beehiiv's privacy notice.