Email sending services
Mailchimp Transactional privacy rating
Transactional email API and SMTP relay from Mailchimp, formerly Mandrill, sold as an add-on to Mailchimp plans.
Summary
Mailchimp Transactional scores 33 out of 100 (grade F) on the email sending services criteria. It meets 1 of 12 criteria: TLS configuration. It partly meets no ads or data sales, independent audit, transparency report, tells users about requests, message content deleted after delivery and open and click tracking off by default. It does not meet open source, no trackers or telemetry, security headers and EU data location. Still needing evidence: encrypted delivery can be enforced. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade C+.
Score 33 out of 100. How scoring works
Criteria
- No
-
No
No trackers or telemetry Weight 3 of 3
Are the website and apps free of third-party trackers, with any analytics anonymous and any telemetry off by default?
The Intuit privacy statement covers advertising cookies, pixels and session-replay tools, and the website loads Google Tag Manager.
-
Partial
No ads or data sales Weight 2 of 3
Is the product funded without advertising, ad targeting or selling user data?
Funded by subscriptions and states data is not sold, but personal information is shared with advertising networks for targeted ads unless users opt out.
-
Partial
Independent audit Weight 2 of 3
Has an independent security or privacy audit been published within the last three years?
SOC 2 and ISO 27001 audits are done, but the reports are only available through the Intuit compliance portal.
-
Partial
Transparency report Weight 2 of 3
Does the provider regularly publish how many government and legal requests it receives and how it responds?
Publishes how it accepts legal process from governments, but no request counts.
-
Partial
Tells users about requests Weight 1 of 3
Does the provider promise to tell users about requests for their data, unless a court forbids it?
Mailchimp reserves the right to notify customers of legal process, and some customer agreements require notice unless prohibited.
-
Partial
Message content deleted after delivery Weight 3 of 3
Is the content of sent mail deleted once it has been delivered?
A copy of the HTML and text parts of each sent email is kept for 30 days.
-
Partial
Open and click tracking off by default Weight 2 of 3
Are open tracking pixels and click tracking links off unless the sender turns them on?
Click tracking is on by default for HTML and text email. Open and click tracking can be turned off in account settings or for each message.
-
Unknown
Encrypted delivery can be enforced Weight 2 of 3
Can outbound mail be kept from being delivered without TLS?
Needs evidence. Add it
-
No
EU data location Weight 1 of 3
Can message content and delivery logs be processed and stored only in the European Union?
Servers are located in the United States. No EU storage option is offered.
Automated tests
-
Yes
TLS configuration Weight 2 of 3
Does the website pass the Qualys SSL Labs test with a grade of A or better?
Grade A+
-
No
Security headers Weight 1 of 3
Does the website pass the Mozilla HTTP Observatory test with a grade of A or better?
Grade C+ (60/100+)
-
Not tested yet
Modern web standards Weight 1 of 3
Does the website score 90% or higher on the Internet.nl website test?
Not tested yet.