Privacy Ratings

Email sending services

Mailchimp Transactional privacy rating

Transactional email API and SMTP relay from Mailchimp, formerly Mandrill, sold as an add-on to Mailchimp plans.

Summary

Mailchimp Transactional scores 33 out of 100 (grade F) on the email sending services criteria. It meets 1 of 12 criteria: TLS configuration. It partly meets no ads or data sales, independent audit, transparency report, tells users about requests, message content deleted after delivery and open and click tracking off by default. It does not meet open source, no trackers or telemetry, security headers and EU data location. Still needing evidence: encrypted delivery can be enforced. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade C+.

Score 33 out of 100. How scoring works

Criteria

  • No

    Open source Weight 3 of 3

    Is all the source code needed to run the product public?

    Closed source.

  • No

    No trackers or telemetry Weight 3 of 3

    Are the website and apps free of third-party trackers, with any analytics anonymous and any telemetry off by default?

    The Intuit privacy statement covers advertising cookies, pixels and session-replay tools, and the website loads Google Tag Manager.

    intuit.com

  • Partial

    No ads or data sales Weight 2 of 3

    Is the product funded without advertising, ad targeting or selling user data?

    Funded by subscriptions and states data is not sold, but personal information is shared with advertising networks for targeted ads unless users opt out.

    intuit.com

  • Partial

    Independent audit Weight 2 of 3

    Has an independent security or privacy audit been published within the last three years?

    SOC 2 and ISO 27001 audits are done, but the reports are only available through the Intuit compliance portal.

    mailchimp.com

  • Partial

    Transparency report Weight 2 of 3

    Does the provider regularly publish how many government and legal requests it receives and how it responds?

    Publishes how it accepts legal process from governments, but no request counts.

    mailchimp.com

  • Partial

    Tells users about requests Weight 1 of 3

    Does the provider promise to tell users about requests for their data, unless a court forbids it?

    Mailchimp reserves the right to notify customers of legal process, and some customer agreements require notice unless prohibited.

    mailchimp.com

  • Partial

    Message content deleted after delivery Weight 3 of 3

    Is the content of sent mail deleted once it has been delivered?

    A copy of the HTML and text parts of each sent email is kept for 30 days.

    mailchimp.com

  • Partial

    Open and click tracking off by default Weight 2 of 3

    Are open tracking pixels and click tracking links off unless the sender turns them on?

    Click tracking is on by default for HTML and text email. Open and click tracking can be turned off in account settings or for each message.

    mailchimp.com

  • Unknown

    Encrypted delivery can be enforced Weight 2 of 3

    Can outbound mail be kept from being delivered without TLS?

    Needs evidence. Add it

  • No

    EU data location Weight 1 of 3

    Can message content and delivery logs be processed and stored only in the European Union?

    Servers are located in the United States. No EU storage option is offered.

    mailchimp.com

Automated tests

  • Yes

    TLS configuration Weight 2 of 3

    Does the website pass the Qualys SSL Labs test with a grade of A or better?

    Grade A+

    ssllabs.com

  • No

    Security headers Weight 1 of 3

    Does the website pass the Mozilla HTTP Observatory test with a grade of A or better?

    Grade C+ (60/100+)

    developer.mozilla.org

  • Not tested yet

    Modern web standards Weight 1 of 3

    Does the website score 90% or higher on the Internet.nl website test?

    Not tested yet.

Other email sending services

All 17 email sending services