Overview
Alibaba Group is the world's largest e-commerce and technology conglomerate, headquartered in Hangzhou, China. Its advertising technology arm — Alimama — operates a comprehensive digital advertising ecosystem serving merchants on Taobao, Tmall, AliExpress, and affiliated marketplaces. When Alibaba/Alimama scripts appear on third-party websites, they are typically affiliate tracking pixels, conversion measurement tools for Alibaba-affiliated advertising campaigns, or cross-border e-commerce attribution tags for merchants participating in Alibaba's global advertising networks. AliExpress in particular deploys tracking pixels on partner comparison sites and affiliate publishers to attribute cross-border traffic. In the EU and US, these scripts appear primarily on e-commerce affiliate and deal sites partnered with Alibaba's international commerce platforms.
What This Script Does
Script Files and Domains
Alimama and AliExpress tracking scripts load from g.alicdn.com (Alibaba's primary CDN for JavaScript assets), log.mmstat.com (Alibaba's behavioral tracking endpoint), and res.mmstat.com. AliExpress affiliate pixels fire to aax-eu.amazon-adsystem.com and click.aliexpress.com for click-based attribution. Some deployments use adfarm.mediaplex.com (ValueClick/Conversant heritage pixels). Alimama's performance network uses union.alimama.com for affiliate conversion reporting.
Cookies Set
cna— Alibaba's cross-network anonymous identifier. Persistent, 1-year expiry. Shared across Alibaba properties (Taobao, Tmall, AliExpress, Alimama). Set on Alibaba-owned domains. Used for user identification across Alibaba's ecosystem and for ad attribution.munb— Member user number for authenticated Alibaba/Taobao users. Session-scoped.tracknick— Tracks the affiliate referral source for commission attribution._m_h5_tk,_m_h5_tk_enc— CSRF protection tokens used in Alibaba's API calls, set ontaobao.comandaliexpress.comdomains.uc1,uc3— User credential cookies for Alibaba's unified login system.
Tracking Pixel Events
The Alimama affiliate pixel fires on: page view (with referral source and click ID), add-to-cart events (product ID, quantity, price), purchase completions (order ID, revenue, currency, item list), and custom conversion events. For AliExpress affiliate programs, the taoke tracking system records which affiliate publisher referred the converting customer, passing the affiliate ID and commission rate to Alimama's settlement system.
mmstat Behavioral Tracking
The log.mmstat.com endpoint receives behavioral telemetry from Alibaba properties and partner sites: scroll depth, click coordinates, time on page, navigation path, and search queries. This data feeds Alibaba's recommendation algorithm and cross-site behavioral targeting for Alimama DSP campaigns.
Data Jurisdiction — China PIPL
Alibaba is subject to China's Personal Information Protection Law (PIPL), which took effect November 2021. PIPL requires consent for cross-border data transfers. For European and US users whose data is collected by Alimama pixels and transmitted to Alibaba's servers in China, this creates a layered compliance obligation: GDPR applies on the collection side; PIPL governs Alibaba's handling on the processing side. Cross-border data transfers to China are not covered by the EU-US Data Privacy Framework, which only applies to US transfers.
Consent & Compliance
Category: Marketing
Under GDPR, Alibaba/Alimama tracking pixels require explicit prior consent. They set persistent cookies, build behavioral profiles, and transmit personal data to servers in China — a jurisdiction without an EU adequacy decision. Such transfers require supplementary safeguards (Standard Contractual Clauses) per GDPR Chapter V, in addition to consent.
The Hamburg DPA has flagged data transfers to China from EU websites without adequate transfer mechanisms as a priority enforcement area. Using Alimama pixels without proper SCCs and consent exposes site operators to dual risk: invalid consent and invalid transfer mechanisms.
Under CCPA, affiliate tracking and conversion data sharing with Alibaba's platform constitutes sharing personal information for advertising purposes.
Should You Block This Without Consent?
Yes. Alibaba/Alimama scripts perform conversion attribution and behavioral tracking for advertising, set persistent cookies, and transmit data to China without an EU adequacy decision. Both consent and valid data transfer mechanisms (SCCs) are required under GDPR before loading these pixels.
Consent Categories
Also Known As
Industries
Tracked Domains (1)
alicdn.comEssentialFrequently Asked Questions
Do Alibaba tracking pixels require consent under GDPR?
Yes. Alimama and AliExpress pixels set persistent cookies and transmit behavioral data to Alibaba servers in China, a country without an EU adequacy decision. Both explicit consent and Standard Contractual Clauses are required under GDPR. The Hamburg DPA has flagged EU-to-China transfers without adequate mechanisms as an enforcement priority.
What cookies do Alibaba tracking scripts set?
The primary cross-network identifier is cna (1-year expiry, shared across Taobao, Tmall, and AliExpress). tracknick records affiliate referral source for commission attribution. munb is a session-scoped member number for authenticated users. The log.mmstat.com endpoint receives behavioral telemetry for ad targeting.
How does ConsentStack handle Alibaba and Alimama pixels?
ConsentStack blocks Alibaba and Alimama scripts until marketing consent is granted. Given the China data transfer risk, ConsentStack flags this vendor as requiring both consent and valid SCCs. Once consent is obtained and transfer mechanisms are confirmed, the pixel loads for conversion attribution and affiliate reporting.
Related Vendors
Manage consent for Alibaba
ConsentStack automatically detects and manages Alibaba trackers so your site stays compliant with global privacy regulations.