Overview
Salesforce.com provides an enterprise CRM platform with a broad ecosystem of marketing and analytics tools including Marketing Cloud, Pardot (Account Engagement), Sales Cloud Web-to-Lead, Einstein Analytics, and Interaction Studio (Personalization). On-site scripts handle behavioral tracking, lead attribution, form capture, personalization delivery, and live chat. The specific consent implications depend heavily on which Salesforce products are deployed.
What This Script Does
Pardot / Account Engagement Tracking
Pardot's tracking code loads from pi.pardot.com (or a custom domain on advanced plans) and fires on every page of sites connected to a Pardot instance. It:
- Sets the
visitor_idcookie (first-party or third-party depending on domain configuration, 2 years) to identify visitors across sessions - Sets
pi_opt_in(first-party, 2 years) — consent flag for Pardot tracking - Records page views, form interactions, and file downloads against prospect records in the Pardot CRM
- Triggers lead scoring rule updates in real time based on page visit activity
- Fires marketing automation workflows when a known prospect visits key pages (e.g., pricing page, case study)
- Contacts
pi.pardot.comfor event logging andpd.pardot.comfor data synchronization
Salesforce Marketing Cloud (ExactTarget)
Marketing Cloud deploys tracking pixels and behavioral analytics through the Marketing Cloud Personalization (Interaction Studio) product. Scripts load from cdn.evgnet.com or {client}.evergage.com (legacy) and collect:
- Visitor identity resolution — matching anonymous web visitors to known CRM contacts via email hash or first-party cookie
- Behavioral segment membership — pages visited, products viewed, content consumed
- Real-time personalization decisions — which content blocks, banners, or recommendations to show
- A/B test assignments for campaign experiments
Web-to-Lead Forms
Standard Salesforce Web-to-Lead forms submit directly to webto.salesforce.com. These forms collect contact information (name, email, company, phone) and create Lead records in Salesforce CRM. No tracking cookies are set by the form submission itself, but the referrer and UTM parameters captured at submission time are recorded for attribution.
Einstein Analytics / Tableau CRM
JavaScript embeds for Einstein Analytics dashboards load from {instance}.salesforce.com or analytics.salesforce.com. These are typically internal business intelligence tools embedded in authenticated portals rather than public web pages.
Salesforce Live Agent / Chat
The Live Agent chat widget loads from {instance}.salesforceliveagent.com. It:
- Sets session cookies to persist the chat conversation across page navigations
- Collects visitor name and email when provided through the pre-chat form
- Sends chat transcripts and visitor data to the Salesforce Service Cloud instance
Cookies set:
visitor_id{account}(first-party, 2 years) — Pardot visitor identifierpi_opt_in(first-party, 2 years) — Pardot consent flag- Interaction Studio: first-party session and visitor cookies, duration varies by client configuration
- Live Agent:
liveagent_sid(session),liveagent_vc(session)
Domains contacted: pi.pardot.com, pd.pardot.com, cdn.evgnet.com, {client}.evergage.com, webto.salesforce.com, {instance}.salesforceliveagent.com
Consent & Compliance
GDPR/ePrivacy: Pardot's behavioral tracking and lead scoring constitute personal data processing for marketing automation purposes, requiring explicit opt-in consent under GDPR Article 7. The visitor_id cookie is non-essential and requires consent before placement under ePrivacy. Marketing Cloud Interaction Studio's visitor profiling and personalization require consent. Live Agent session cookies used to maintain an in-progress conversation requested by the user may qualify as functional. Web-to-Lead form submissions are based on the user's explicit action (consent by conduct).
CCPA/CPRA: Pardot behavioral tracking and Marketing Cloud personalization data collection constitute personal information collection. Salesforce acts as a service provider under CCPA when processing data under a data processing agreement. Sites must disclose Pardot and Marketing Cloud tracking in their privacy policy.
EU-US Data Transfers: Salesforce Inc. participates in the EU-US Data Privacy Framework (DPF) and offers Standard Contractual Clauses and Binding Corporate Rules.
IAB TCF: Pardot and Marketing Cloud marketing tools map to IAB TCF Purposes 1, 2, 3, 4, and 5.
Consent category: Marketing (Pardot, Marketing Cloud tracking), Analytics (behavioral analytics), Functional (Live Agent chat, Web-to-Lead forms).
Should You Block This Without Consent?
Conditional. Pardot tracking codes and Marketing Cloud personalization scripts must be blocked until marketing consent is granted. Einstein Analytics embeds in authenticated portals generally do not require public-facing consent. Live Agent chat widgets serving visitor support needs may load under a functional consent basis, provided the chat session data is not fed into marketing automation workflows. Web-to-Lead form submissions are user-initiated and do not require pre-consent.
Consent Categories
Also Known As
Industries
Tracked Domains (68)
krxd.netMarketingcquotient.comAnalyticssite.comEssentialigodigital.comMarketingpardot.comMarketingsalesforceliveagent.comFunctionalforce.comEssentialsaasler-impact.herokuapp.comEssentialcalc-backend-prod.herokuapp.comEssentialessential-apps-analytics.herokuapp.comEssentialdesign-packs.herokuapp.comEssentialgdpr-mm-geolocation.herokuapp.comEssentialdeliverytimer.herokuapp.comEssentialtnc-app.herokuapp.comEssentialobscure-escarpment-2240.herokuapp.comEssentialservicify-appointments.herokuapp.comEssentialxapps-geo-ca956fdeab0c.herokuapp.comEssentialpoboxblocker.herokuapp.comEssentialerror-reporter-163cf957cedf.herokuapp.comEssentialcstt-app.herokuapp.comEssentialgcb-app.herokuapp.comEssentialcart-discount.herokuapp.comEssentialsellup.herokuapp.comEssentialquantity-breaks-now.herokuapp.comEssentialdesign-packs-v2-f486db037e95.herokuapp.comEssentialsuperbump.herokuapp.comEssentialsession-recording-now.herokuapp.comEssentialpfp-app.herokuapp.comEssentialwholesale-pricing-now.herokuapp.comEssentiallive-visitor-counts.herokuapp.comEssentialconsent-insights-3c23a978f31a.herokuapp.comEssentialaccessibility-spark.herokuapp.comEssentialxgen-product-recommendations-c1d79539c721.herokuapp.comEssentialeedition-server.herokuapp.comEssentialfaqs-plus.herokuapp.comEssentialgow-media-server.herokuapp.comEssentialknock2-backend-2ba4792164c3.herokuapp.comEssentialshopify-gift-with-purchase-b91cd9320ca5.herokuapp.comEssentialreferralfetch.herokuapp.comEssentialvuhaus-api-production.herokuapp.comEssentialpixelflow-5f2c02572bf1.herokuapp.comEssentialpropel-appointments.herokuapp.comEssentialcms-plugin-bigcommerce-c556b84476d7.herokuapp.comEssentialjointcommerce.herokuapp.comEssentialpagespeed-audits-4857a7cea52b.herokuapp.comEssentialshopify-saasphoto-embed.herokuapp.comEssentialprod-clinic-search.herokuapp.comEssentialquinn-prod.herokuapp.comEssentialdelivery-estimator-production.herokuapp.comEssentialsellpy-parse-prod.herokuapp.comEssentialcockatoo-api8.herokuapp.comEssentialcalm-coast-69919.herokuapp.comEssentialtrx-carabiner.herokuapp.comEssentialtrx-unleash-794f030cd702.herokuapp.comEssentialw-gcb-app.herokuapp.comEssentialwheres-waldo-angel.herokuapp.comEssentialbigcommerce-hello-prod.herokuapp.comEssentialapp-stores.herokuapp.comEssentialmeateater-api.herokuapp.comEssentialccg-analytics-server-prod.herokuapp.comEssentialsize-charts-relentless.herokuapp.comEssentialcartdrawer-prod.herokuapp.comEssentialcors-anywhere.herokuapp.comEssentialuniversal-leaderboard.herokuapp.comEssentialf2f-server-prod-358733b59395.herokuapp.comEssentialblooming-shelf-2016.herokuapp.comEssentiallobster-staging.herokuapp.comEssentialsrgsnitch.herokuapp.comEssentialFrequently Asked Questions
Does Salesforce.com require cookie consent?
Conditionally. Pardot tracking and Marketing Cloud personalization scripts require marketing consent before loading. Live Agent chat cookies may qualify as functional when a visitor actively initiates a conversation. Essential CRM infrastructure and Web-to-Lead form submissions do not require separate pre-consent.
What cookies does Salesforce.com set?
Pardot sets visitor_id (first-party, 2 years) and pi_opt_in (2 years). Live Agent sets liveagent_sid and liveagent_vc session cookies. Interaction Studio sets first-party session and visitor cookies. Scripts contact pi.pardot.com, cdn.evgnet.com, webto.salesforce.com, and salesforceliveagent.com domains.
How does ConsentStack handle Salesforce.com?
ConsentStack evaluates Salesforce.com components separately by function. Marketing and analytics scripts such as Pardot tracking and Interaction Studio are blocked until consent is granted. ConsentStack may allow Live Agent session cookies under functional consent and does not block Web-to-Lead form submissions, which are user-initiated actions.
Related Vendors
Manage consent for Salesforce.com
ConsentStack automatically detects and manages Salesforce.com trackers so your site stays compliant with global privacy regulations.