Alibaba

Alibaba

Chinese e-commerce and technology conglomerate. Alibaba's advertising technology (Alimama) scripts fire tracking pixels on merchant sites that participate in Alibaba's affiliate and advertising networks, particularly for cross-border e-commerce.

Overview

Alibaba Group is the world's largest e-commerce and technology conglomerate, headquartered in Hangzhou, China. Its advertising technology arm — Alimama — operates a comprehensive digital advertising ecosystem serving merchants on Taobao, Tmall, AliExpress, and affiliated marketplaces. When Alibaba/Alimama scripts appear on third-party websites, they are typically affiliate tracking pixels, conversion measurement tools for Alibaba-affiliated advertising campaigns, or cross-border e-commerce attribution tags for merchants participating in Alibaba's global advertising networks. AliExpress in particular deploys tracking pixels on partner comparison sites and affiliate publishers to attribute cross-border traffic. In the EU and US, these scripts appear primarily on e-commerce affiliate and deal sites partnered with Alibaba's international commerce platforms.

What This Script Does

Script Files and Domains

Alimama and AliExpress tracking scripts load from g.alicdn.com (Alibaba's primary CDN for JavaScript assets), log.mmstat.com (Alibaba's behavioral tracking endpoint), and res.mmstat.com. AliExpress affiliate pixels fire to aax-eu.amazon-adsystem.com and click.aliexpress.com for click-based attribution. Some deployments use adfarm.mediaplex.com (ValueClick/Conversant heritage pixels). Alimama's performance network uses union.alimama.com for affiliate conversion reporting.

Cookies Set

  • cna — Alibaba's cross-network anonymous identifier. Persistent, 1-year expiry. Shared across Alibaba properties (Taobao, Tmall, AliExpress, Alimama). Set on Alibaba-owned domains. Used for user identification across Alibaba's ecosystem and for ad attribution.
  • munb — Member user number for authenticated Alibaba/Taobao users. Session-scoped.
  • tracknick — Tracks the affiliate referral source for commission attribution.
  • _m_h5_tk, _m_h5_tk_enc — CSRF protection tokens used in Alibaba's API calls, set on taobao.com and aliexpress.com domains.
  • uc1, uc3 — User credential cookies for Alibaba's unified login system.

Tracking Pixel Events

The Alimama affiliate pixel fires on: page view (with referral source and click ID), add-to-cart events (product ID, quantity, price), purchase completions (order ID, revenue, currency, item list), and custom conversion events. For AliExpress affiliate programs, the taoke tracking system records which affiliate publisher referred the converting customer, passing the affiliate ID and commission rate to Alimama's settlement system.

mmstat Behavioral Tracking

The log.mmstat.com endpoint receives behavioral telemetry from Alibaba properties and partner sites: scroll depth, click coordinates, time on page, navigation path, and search queries. This data feeds Alibaba's recommendation algorithm and cross-site behavioral targeting for Alimama DSP campaigns.

Data Jurisdiction — China PIPL

Alibaba is subject to China's Personal Information Protection Law (PIPL), which took effect November 2021. PIPL requires consent for cross-border data transfers. For European and US users whose data is collected by Alimama pixels and transmitted to Alibaba's servers in China, this creates a layered compliance obligation: GDPR applies on the collection side; PIPL governs Alibaba's handling on the processing side. Cross-border data transfers to China are not covered by the EU-US Data Privacy Framework, which only applies to US transfers.

Consent & Compliance

Category: Marketing

Under GDPR, Alibaba/Alimama tracking pixels require explicit prior consent. They set persistent cookies, build behavioral profiles, and transmit personal data to servers in China — a jurisdiction without an EU adequacy decision. Such transfers require supplementary safeguards (Standard Contractual Clauses) per GDPR Chapter V, in addition to consent.

The Hamburg DPA has flagged data transfers to China from EU websites without adequate transfer mechanisms as a priority enforcement area. Using Alimama pixels without proper SCCs and consent exposes site operators to dual risk: invalid consent and invalid transfer mechanisms.

Under CCPA, affiliate tracking and conversion data sharing with Alibaba's platform constitutes sharing personal information for advertising purposes.

Should You Block This Without Consent?

Yes. Alibaba/Alimama scripts perform conversion attribution and behavioral tracking for advertising, set persistent cookies, and transmit data to China without an EU adequacy decision. Both consent and valid data transfer mechanisms (SCCs) are required under GDPR before loading these pixels.

Visit website

Consent Categories

Marketing

Also Known As

AlimamaAlibaba pixelaffiliate tracking pixelAlibaba advertisingChinese ecommerce trackercross-border ad pixel

Industries

Computers Electronics and TechnologyProgramming and Developer Software

Tracked Domains (1)

alicdn.comEssential

Frequently Asked Questions

Do Alibaba tracking pixels require consent under GDPR?

Yes. Alimama and AliExpress pixels set persistent cookies and transmit behavioral data to Alibaba servers in China, a country without an EU adequacy decision. Both explicit consent and Standard Contractual Clauses are required under GDPR. The Hamburg DPA has flagged EU-to-China transfers without adequate mechanisms as an enforcement priority.

What cookies do Alibaba tracking scripts set?

The primary cross-network identifier is cna (1-year expiry, shared across Taobao, Tmall, and AliExpress). tracknick records affiliate referral source for commission attribution. munb is a session-scoped member number for authenticated users. The log.mmstat.com endpoint receives behavioral telemetry for ad targeting.

How does ConsentStack handle Alibaba and Alimama pixels?

ConsentStack blocks Alibaba and Alimama scripts until marketing consent is granted. Given the China data transfer risk, ConsentStack flags this vendor as requiring both consent and valid SCCs. Once consent is obtained and transfer mechanisms are confirmed, the pixel loads for conversion attribution and affiliate reporting.

Related Vendors

Google Ads
Google Ads
Google Ads is Google's advertising platform for search, display, and remarketing campaigns. Conversion tracking scripts fire on advertiser landing pages to measure actions taken after ad clicks. The remarketing tag builds audience lists for retargeting users across Google's ad network.
Google
Google
Google is the dominant provider of web analytics, advertising, and infrastructure tools. Scripts like Google Analytics, Tag Manager, Ads, and reCAPTCHA collect behavioral data, manage tag firing, serve targeted ads, and detect bots. Sets persistent cookies to track users and correlate activity across sites.
Microsoft Dynamics 365
Microsoft Dynamics 365
Microsoft Dynamics 365 is a suite of CRM and ERP applications that integrates with websites through tracking scripts and embedded forms. Web tracking code captures visitor behavior, page views, and form submissions to build customer profiles and score leads. Sets cookies to identify returning visitors and attribute marketing touchpoints across sessions.
Microsoft
Microsoft
Runs Clarity (session recording and heatmaps), the Microsoft Advertising UET tag (conversion tracking), and Bing's remarketing pixel. Clarity injects a recording script that captures mouse movements, clicks, and rage clicks. The UET tag fires conversion events to tie ad clicks to on-site actions across Microsoft's ad network.
Microsoft Advertising UET Tag
Microsoft Advertising UET Tag
Microsoft Advertising UET Tag is the Universal Event Tracking pixel for Microsoft's ad platform, formerly Bing Ads. The JavaScript tag fires on advertiser websites to track page views, conversions, and custom events for campaign optimization. Sets cookies to identify visitors across sessions and attribute conversions to Microsoft Search and Audience Network ad clicks.
LinkedIn Ads
LinkedIn Ads
LinkedIn Ads is LinkedIn's advertising platform for B2B marketing and professional audience targeting. Conversion tracking scripts and pixels fire on advertiser websites to measure sign-ups, downloads, and purchases driven by LinkedIn ad campaigns. Sets cookies for audience matching, retargeting list building, and cross-device attribution reporting.

Manage consent for Alibaba

ConsentStack automatically detects and manages Alibaba trackers so your site stays compliant with global privacy regulations.