Cookie Consent & Privacy Compliance When Using MailBack™
This article applies to all Postalytics customers who have activated the MailBack™ add-on.
MailBackTM identifies anonymous visitors to your website by setting a first-party cookie in their browser. That cookie is matched against an identity database to resolve the visitor's name, postal address, and other contact information, which is then used to trigger direct mail campaigns through Postalytics.
Because MailBackTM collects personal information from your website visitors, deploying it creates real privacy and compliance obligations for your business. These are your obligations as the website operator, not Postalytics'. This article explains what you need to have in place before or alongside your MailBackTM deployment.
|
Important: The information in this article is general guidance only and does not constitute legal advice. Privacy laws vary by jurisdiction and change frequently. Your specific obligations depend on where your business operates, where your customers are located, your industry, and how you use data collected through MailBackᵀᴹ. Postalytics strongly recommends consulting qualified legal counsel before deploying MailBackᵀᴹ on your website. |
There are four things every MailBackᵀᴹ customer should address before or at the time of deploying the pixel on their website.
1. A cookie consent bannerA cookie consent banner notifies your website visitors that cookies are being set and gives them a way to manage their preferences. For most US-based websites, this means an opt-out mechanism: visitors are informed of cookie use, and those who object can opt out. For visitors from Canada (particularly Quebec) or the EU and UK, opt-in consent is required, meaning cookies should not be set until the visitor actively accepts.
Your cookie consent banner needs to:
- Appear on the visitor's first arrival, before any non-essential cookies are set
- Clearly identify that tracking cookies are in use for marketing and retargeting purposes
- Provide a genuine way to decline or opt out of non-essential cookies
- MailBackTM must not fire for visitors who have declined or opted out — your consent tool needs to be configured to conditionally block the MailBackTM JavaScript snippet based on visitor consent status
- Your cookie consent functionality must honor Global Privacy Control (GPC)
|
Note: If your banner tells visitors they can opt out but the pixel fires anyway, your consent process is not working correctly. Verify pixel blocking behavior after installation. |
If your website is visited by California residents, the California Consumer Privacy Act (CCPA) requires you to provide a mechanism for visitors to opt out of the sale or sharing of their personal information. MailBackTM data, because it is used for targeted advertising, falls under the CCPA's definition of "sharing." This opt-out link is typically placed in the footer of your website and links to your cookie preference center or a dedicated opt-out page.
Several other US states have similar requirements. Your legal counsel can advise on which states apply to your business.
3. An updated Privacy PolicyYour existing Privacy Policy may not cover the type of data collection MailBackTM performs. Before deploying the pixel, your Privacy Policy should be updated to disclose:
- That your website uses a tracking pixel and first-party cookies to identify visitors
- The categories of personal information collected (name, postal address, email address, and any demographic data packages you have selected)
- The purpose for which that data is used, specifically that it is used to send direct mail via MailBackTM
- How long the data is retained
- How visitors can exercise their rights, including the right to opt out, request access to their data, request corrections to their data, or request deletion
- Jurisdiction-specific disclosures and rights for visitors from Canada or the EU and UK, if applicable
If your business is subject to Quebec's Law 25, you may also be required to designate a Privacy Officer and to conduct a privacy impact assessment before transferring personal data outside of Quebec. Your legal counsel can advise on whether these requirements apply to your situation.
4. A Cookie Policy page A dedicated Cookie Policy page lists every cookie your website sets, what each one does, how long it lasts, and which third parties are involved. Many cookie consent management platforms generate and maintain this page automatically, keeping it in sync as cookies on your site change over time. Keeping this separate from your Privacy Policy is considered best practice for any site deploying tracking cookies.
If your website visitors include Canadians or EU/UK residents
The US opt-out model is not sufficient for visitors from Canada or the European Union and United Kingdom. Those visitors require opt-in consent, meaning the MailBackᵀᴹ pixel and other non-essential cookies must not fire until the visitor has actively accepted.
Your cookie consent tool must be capable of detecting visitor location and serving different consent experiences by jurisdiction. A visitor from Quebec should see an opt-in consent banner. A visitor from California should see an opt-out banner. Verify that your chosen tool handles this correctly before going live.
|
Canada specifically: Quebec's Law 25 imposes opt-in consent requirements similar to GDPR. Because it is difficult to reliably distinguish Quebec visitors from other Canadian visitors at the banner level, the safest approach is to treat all Canadian visitors as requiring opt-in consent. |
MailBackTM is a JavaScript snippet that you install on your website, typically through your tag manager or by adding it directly to your site's header. Your cookie consent tool controls whether and when that snippet fires based on the visitor's consent status.
If you are using a tag manager (such as Google Tag Manager), configure the MailBackᵀᴹ tag to fire only when the visitor's consent state includes marketing or targeting cookies. Your cookie consent tool should push consent signals into your tag manager to enable this.
If you are embedding the pixel directly in your site's code rather than through a tag manager, ensure your consent tool wraps the script with conditional logic that prevents it from executing until consent is given. Most consent management platforms provide documentation on how to do this for custom scripts.
Staying compliant over timeInstalling a cookie consent banner is not a one-time task. As a MailBackᵀᴹ operator, you should:
- Re-scan your website for new cookies any time you add a new plugin, integration, or script
- Review your Privacy Policy and Cookie Policy at least annually, or whenever you make a significant change to how you collect or use visitor data
- Ensure your consent records are being logged so you have an audit trail if a regulator or enterprise prospect asks for evidence of compliant consent practices
- Monitor changes to US state privacy laws, as new states continue to pass legislation with opt-out and, in some cases, opt-in requirements
If you have questions about how the MailBackTM pixel works technically, including how to configure conditional firing through a tag manager or how to verify the pixel is respecting visitor consent choices, contact Postalytics Support. For questions about your specific legal compliance obligations, please consult qualified legal counsel.