What is the _mcid cookie?
_mcid is an HTTP cookie set by Mailchimp, the email marketing and automation platform owned by Intuit. It typically appears on websites that use Mailchimp signup forms, landing pages built with Mailchimp, or integrations that send visitor behavior data to the site owner's Mailchimp account.
The cookie is placed either directly by the Mailchimp script loaded on the page or by an embedded Mailchimp form. It is not an essential technical cookie; it is part of Mailchimp's tracking ecosystem used to recognize returning visitors.
What data it stores
_mcid stores a unique identifier associated with the visitor, generated by Mailchimp so it can recognize the same visitor on repeat visits to the site or within the same Mailchimp account. The exact format of the value is not publicly documented in detail and may vary; it generally does not contain directly readable personal data, but the identifier can later be linked to subscriber data in Mailchimp (e.g. an email address, if the visitor submits a form).
Data collected through this identifier is sent to Mailchimp/Intuit servers for processing within the platform's marketing services.
What it is used for
For Mailchimp, _mcid helps connect an anonymous visitor's on-site behavior (page visits, form interactions) with their later activity as a subscriber or campaign recipient, supporting attribution and segmentation features.
For the website owner, the cookie helps measure signup form performance, build audiences for email remarketing, and correlate site visits with engagement from Mailchimp email campaigns.
Does it require consent?
In CookieFix's classification, _mcid falls under the marketing category. Since it is used for visitor tracking and advertising/attribution purposes, it requires prior user consent under the GDPR (Regulation 2016/679) and the ePrivacy Directive, transposed in Romania through Law 506/2004.
- The site owner must disclose this cookie in the cookie policy, including provider, category, and duration.
- The cookie must not be set before the visitor gives explicit consent for the marketing category.
- Withdrawing consent must be as easy as giving it.
How to block or delete _mcid
A visitor can manually delete or block _mcid via browser settings (Chrome, Firefox, Safari, Edge), through per-site cookie management, or by using tracker-blocking browser extensions.
At the site level, the owner needs a consent management platform (CMP) that automatically blocks Mailchimp scripts before consent is given. CookieFix, for example, can block the script that sets _mcid until the visitor opts into the marketing category, preventing the cookie from being placed without prior consent.
Frequently asked questions
It is a marketing/tracking cookie, not strictly necessary, since it identifies visitors for attribution purposes and Mailchimp campaigns.
Its typical duration is about 1 year, after which it expires automatically unless renewed by a new visit.
Yes, as a marketing cookie it must only be set after the visitor gives consent under GDPR and Law 506/2004.
It can be removed from the browser's privacy/cookie settings, under the section for the relevant domain or Mailchimp.