All Vendors
marketing_automation
Beehiiv

Beehiiv

Beehiiv fires 55% of its vendors pre-consent across 38 detected third-party scripts, while its privacy policy leaves 15 vendors — including ZoomInfo identity resolution — completely undisclosed.

163 IOCs3 detections2 sites
80
Vendor Risk Score

How This Briefing Works

This report opens with key findings, then maps the gaps between what Beehiiv discloses and what BLACKOUT observed at runtime. From there: what it means for your organization, what to do about it, and the detection data and evidence underneath.

Key Findings

Key Findings

3 detections across 2 sites1 critical disclosure gap
CRITICAL

Consent Violation

55% of vendors (21/38) fire before user consent is obtained

GDPR Art 6GDPR Art 7CCPA 1798.100
HIGH

Disclosure Gap

15 vendors detected at runtime not disclosed in privacy policy

GDPR Art 13GDPR Art 14CCPA 1798.110
HIGH

Identity Resolution

ZoomInfo detected loading pre-consent for visitor identification

GDPR Art 6(1)(a)CCPA 1798.140(o)
HIGH

Undisclosed Party

Not in privacy policy

HIGH

Undisclosed Sharing

Hidden data recipients

Disclosure Gaps

Claims vs. Observed Behavior

4 gaps
1 CRIT2 HIGH1 MED
Classified:BTI-X01BTI-X02BTI-X05

Disclosure Gap

GDPR Art 13 · GDPR Art 14 · CCPA 1798.110HIGH
They Claim

Privacy policy lists data processors

Observed Behavior

15 vendors detected at runtime not disclosed in privacy policy

ZoomInfo, CHEQ, TrenDemon, Salesloft, Dreamdata, Pubrio, VWO, Human Security, PerimeterX, NeverBounce, Loom, Typeform, Bitly, Ada, Ahrefs found in runtime but absent from policy

Identity Resolution

GDPR Art 6(1)(a) · CCPA 1798.140(o)HIGH
They Claim

No identity resolution disclosure

Observed Behavior

ZoomInfo detected loading pre-consent for visitor identification

ZoomInfo vendor slug detected in runtime scan with pre_consent=true

Fingerprinting Disclosure

ePrivacy Directive Art 5(3)MEDIUM
They Claim

Cookie policy mentions browser fingerprinting

Observed Behavior

Browser fingerprinting acknowledged but creates consent complexity - fingerprints cannot be deleted like cookies

Cookie policy states: Browser Fingerprinting creates an identifier based on a device unique combination of characteristics

Customer Impact

What This Means For You

YOUR newsletter audience data hosted on Beehiiv flows through a platform with 15 undisclosed vendor relationships. YOUR subscribers' reading behavior, engagement patterns, and email interactions may be enriched by ZoomInfo's identity resolution without YOUR knowledge or disclosure. If YOUR newsletter runs on Beehiiv, YOUR readers are exposed to CHEQ, Human Security, and PerimeterX fraud detection tools that profile visitor behavior — none of which appear in Beehiiv's privacy policy. YOUR compliance posture is undermined: claiming GDPR/CCPA compliance while 55% of vendors fire pre-consent creates material regulatory exposure for YOUR publication.
Recommended Actions

What To Do About It

Role-specific actions based on observed behavior

If You Use Beehiiv

  • Audit your own privacy policy — you may inherit Beehiiv vendor relationships without knowing it
  • Verify consent flows on Beehiiv-hosted pages match your stated compliance posture
  • Request Beehiiv's complete subprocessor list and compare to the 38 vendors detected at runtime
  • Implement additional consent controls for your subscribers beyond what Beehiiv provides by default

If You're Evaluating Beehiiv

  • Request Beehiiv's subprocessor list and compare against 38 detected vendors before committing
  • Verify whether ZoomInfo identity resolution applies to your subscribers' data
  • Compare with Substack, ConvertKit, and Ghost on vendor transparency and pre-consent behavior
  • Require contractual guarantees on audience data isolation and restrictions on identity resolution

Negotiation Leverage

  • 55% pre-consent rate: More than half of Beehiiv's vendors fire before consent — use this to negotiate consent architecture improvements or require server-side consent enforcement for your newsletter
  • ZoomInfo integration undisclosed: Identity resolution on beehiiv.com means subscriber data may be enriched and resold — require contractual restrictions on identity resolution for your audience data
  • 15 undisclosed vendors: Including fraud detection tools CHEQ, Human Security, and PerimeterX — require complete vendor disclosure and DPA coverage for all detected vendors
  • Publisher inheritance risk: Your newsletter subscribers inherit Beehiiv's vendor relationships — use this to negotiate data isolation for your publication audience
Runtime Detections

Runtime Detections

5 BTI-C CODES

BLACKOUT observed this vendor's JavaScript executing in a live browser and classified each hostile behavior using our BTI-C (Behavioral Threat Intelligence — Capability) taxonomy. These are not theoretical risks — each code below was triggered by something we watched this vendor's code actually do.

BTI-C01Defeat Device

Evasion infrastructure, auditor bypass

BTI-C06Behavioral Biometrics

Keystroke/mouse tracking

BTI-C08Cross-Domain Sync

Identity stitching

BTI-C10Fingerprinting

Device identification

BTI-C13Persistence Mechanisms

Long-lived identifiers

IOC Manifest

IOC Manifest

163 INDICATORS

Indicators of compromise across 5 categories. Use for detection rules, CSP policies, or Pi-hole blocklists.

TRACK
*www.beehiiv.com/_next/static/chunks/*.js*
Tracking script
TRACK
*www.beehiiv.com/_next/static/chunks/turbopack-*.js*
Tracking script
TRACK
*www.beehiiv.com/_next/static/HeGc6CSw5rMMOvnpD5rDs/_ssgManifest.js*
Tracking script
TRACK
*www.beehiiv.com/_next/static/HeGc6CSw5rMMOvnpD5rDs/_buildManifest.js*
Tracking script
TRACK
*embeds.beehiiv.com/static/js/main.*.chunk.js*
Tracking script
TRACK
*embeds.beehiiv.com/static/js/2.*.chunk.js*
Tracking script
TRACK
*embeds.beehiiv.com/variables.js*
Tracking script
TRACK
*www.beehiiv.com/cdn-cgi/challenge-platform/scripts/jsd/main.js*
Tracking script
TRACK
*www.beehiiv.com/_next/static/HeGc6CSw5rMMOvnpD5rDs/_clientMiddlewareManifest.json*
Tracking script
TRACK
*www.beehiiv.com/cdn-cgi/challenge-platform/h/b/scripts/jsd/*/main.js*
Tracking script
TRACK
*embeds.beehiiv.com/cdn-cgi/challenge-platform/scripts/jsd/main.js*
Tracking script
TRACK
*www.beehiiv.com/_vercel/insights/script.js*
Tracking script
TRACK
*www.beehiiv.com/attributor-min.js*
Tracking script
TRACK
*www.beehiiv.com/static/lottieFiles/homepage-*/Section-3.json*
Tracking script
TRACK
*embeds.beehiiv.com/cdn-cgi/challenge-platform/h/b/scripts/jsd/*/main.js*
Tracking script
TRACK
*www.beehiiv.com/static/lottieFiles/homepage-*/Section-1-2.json*
Tracking script
TRACK
*www.beehiiv.com/static/lottieFiles/homepage-*/Section-2.json*
Tracking script
TRACK
www.beehiiv.com/_next/static/chunks/afe9917a82737dff.js
Auto-extracted from scan
TRACK
www.beehiiv.com/_next/static/chunks/1944df3fe3957e14.js
Auto-extracted from scan
TRACK
www.beehiiv.com/_next/static/chunks/44af5f9a448163fa.js
Auto-extracted from scan
TRACK
www.beehiiv.com/_next/static/chunks/ae6383810ea627ce.js
Auto-extracted from scan
TRACK
www.beehiiv.com/_next/static/chunks/347a2f5a7a3ada64.js
Auto-extracted from scan
TRACK
www.beehiiv.com/_next/static/chunks/70f80e8e3d757a83.js
Auto-extracted from scan
TRACK
www.beehiiv.com/_next/static/chunks/2318aca0a15c86d9.js
Auto-extracted from scan
TRACK
www.beehiiv.com/_next/static/chunks/2bf8743e68809dbc.js
Auto-extracted from scan
TRACK
www.beehiiv.com/_next/static/chunks/0b076c8dc816843d.js
Auto-extracted from scan
TRACK
www.beehiiv.com/_next/static/chunks/b26aa574f78e9bdb.js
Auto-extracted from scan
TRACK
www.beehiiv.com/_next/static/chunks/f4f9fc9770e73e8f.js
Auto-extracted from scan
TRACK
www.beehiiv.com/_next/static/chunks/0e1ad8fd1bcd55f9.js
Auto-extracted from scan
TRACK
www.beehiiv.com/_next/static/chunks/988b0326079286f5.js
Auto-extracted from scan
TRACK
www.beehiiv.com/_next/static/chunks/a5e8df11a09d3180.js
Auto-extracted from scan
TRACK
www.beehiiv.com/_next/static/chunks/49ef547df8b24471.js
Auto-extracted from scan
TRACK
www.beehiiv.com/_next/static/chunks/d6bc8e62b761649b.js
Auto-extracted from scan
TRACK
www.beehiiv.com/_next/static/chunks/e6211ae6ece9b7a8.js
Auto-extracted from scan
TRACK
www.beehiiv.com/_next/static/chunks/14df49a3aa3b0871.js
Auto-extracted from scan
TRACK
www.beehiiv.com/_next/static/chunks/turbopack-2023c2e1d1ecde54.js
Auto-extracted from scan
TRACK
www.beehiiv.com/_next/static/chunks/37cff80e17930668.js
Auto-extracted from scan
TRACK
www.beehiiv.com/_next/static/chunks/d82704e45e998abc.js
Auto-extracted from scan
TRACK
www.beehiiv.com/_next/static/chunks/2cbc1d24e71c8ed0.js
Auto-extracted from scan
TRACK
www.beehiiv.com/_next/static/chunks/6d7a7ec29d25dcd3.js
Auto-extracted from scan
TRACK
www.beehiiv.com/_next/static/chunks/turbopack-a7aa123c5a48a3d2.js
Auto-extracted from scan
TRACK
www.beehiiv.com/_next/static/HeGc6CSw5rMMOvnpD5rDs/_ssgManifest.js
Auto-extracted from scan
TRACK
www.beehiiv.com/_next/static/HeGc6CSw5rMMOvnpD5rDs/_buildManifest.js
Auto-extracted from scan
TRACK
embeds.beehiiv.com/variables.js
Auto-extracted from scan
TRACK
embeds.beehiiv.com/static/js/2.a4e584bc.chunk.js
Auto-extracted from scan
TRACK
embeds.beehiiv.com/static/js/main.839e97df.chunk.js
Auto-extracted from scan
TRACK
www.beehiiv.com/cdn-cgi/challenge-platform/scripts/jsd/main.js
Auto-extracted from scan
TRACK
www.beehiiv.com/cdn-cgi/challenge-platform/h/b/scripts/jsd/d251aa49a8a3/main.js
Auto-extracted from scan
TRACK
embeds.beehiiv.com/cdn-cgi/challenge-platform/scripts/jsd/main.js
Auto-extracted from scan
TRACK
www.beehiiv.com/attributor-min.js
Auto-extracted from scan
TRACK
www.beehiiv.com/_vercel/insights/script.js
Auto-extracted from scan
TRACK
embeds.beehiiv.com/cdn-cgi/challenge-platform/h/b/scripts/jsd/d251aa49a8a3/main.js
Auto-extracted from scan
TRACK
www.beehiiv.com/_next/static/chunks/079bb93860221283.js
Auto-extracted from scan
Ecosystem

Ecosystem & Supply Chain

Beehiiv sits at a critical junction in the newsletter ecosystem: they host 19,000+ publishers and their subscriber data. The platform loads a heavy martech stack including identity resolution (ZoomInfo), attribution (TrenDemon, Dreamdata), fraud detection (CHEQ, Human Security, PerimeterX), and standard ad pixels (Meta, Google, LinkedIn, TikTok). Publishers who embed beehiiv widgets or use beehiiv-hosted pages inherit this entire vendor stack and its consent obligations. Beehiiv is loaded by newsletter publishers; beehiiv itself loads 38+ vendors. This creates a multiplier effect where beehiivs disclosure gaps propagate to every publisher on the platform.
Evidence

Evidence Artifacts

Artifacts collected during analysis, available with evidence-tier access.

HAR Capture

Complete network capture with all requests and responses

IOC Manifest

163 detection signatures across scripts, domains, cookies, and network endpoints

Vendor Details