To set up email analytics without invading privacy, you strip the invisible tracking pixel out of your sends, measure clicks and replies on your own domain instead, and report everything in aggregate with a short retention window. The configuration takes an afternoon. The maintenance is about an hour a quarter, and the setup review is a single page you can hand to a lawyer, an editor or a reporter who asks what you are doing with the list.
What you give up is the open rate. That is a real loss, because most teams have been reading it for years. It is also the one number nobody should have been reading at all, and I will come back to why a few steps in.
The rest of this guide follows the order I would actually work in: prerequisites first, then seven configuration steps, then the mistakes that quietly undo good setups. Menu names change constantly across email platforms, so I am describing which setting to look for rather than promising a click path that may be renamed next month. Always check the current documentation for the platform and version you run.
Table of Contents
- What You Need: Six Prerequisites Before You Change Any Settings
- Step-by-Step: How to Set Up Email Analytics Without Invading Privacy
- 1. Define the questions your analytics should answer
- 2. Choose privacy-safe metrics and data fields
- 3. Check consent, legal basis, and editorial purpose
- 4. Configure the platform with minimization settings
- 5. Set retention, access, and export controls
- 6. Test the setup with a small controlled send
- 7. Review results and improve the workflow
- Common Mistakes and How to Fix Them
- Frequently Asked Questions
What You Need: Six Prerequisites Before You Change Any Settings

You need six things in place, and five of them are decisions rather than software. Skipping the decisions is how teams end up with a “privacy-friendly” setup that still profiles every recipient.
- A written purpose. Two or three sentences saying what the measurement is for, such as deciding whether to keep a weekly send or testing two subject lines. If a metric cannot be traced back to that purpose, it does not belong in your setup.
- A documented lawful basis and consent position. Whether you rely on explicit consent, on a legitimate-interest argument for an existing subscriber relationship, or on a combination, and how that changes for readers in the EU, the UK and US states. Get this reviewed by whoever handles privacy on your team.
- An approved email platform and an approved analytics destination. Know who holds the subscriber data today, including any tracking or ad technology connected to your sending domain.
- A retention rule, written down. How long raw event data stays before it is aggregated or deleted, and who decides to shorten it.
- An access list. Named people, not a shared login. A small newsroom might be two editors and one audience reporter.
- A reviewer or point of contact. Someone outside the sending workflow who answers reader questions about tracking. Editors, a privacy contact, or a named person in the newsletter footer.
Write all six on one page and keep it next to your platform settings. It is the first thing an auditor, a reader, or your own successor will ask for, and it takes twenty minutes.
Step-by-Step: How to Set Up Email Analytics Without Invading Privacy
1. Define the questions your analytics should answer
Start by writing down the decisions the data has to support. For most newsrooms that is a short list: did the send reach inboxes, which links did readers act on, how many people left the list, and did anyone reply. Anything you cannot attach to one of those four is a candidate to drop before you collect it.
The default failure is collecting first and deciding later. Once a platform stores per-recipient events, the retention question moves from theoretical to urgent. Decide the questions first and the collection stays small.
2. Choose privacy-safe metrics and data fields
Pick aggregate delivery counts, click-through by link, reply volume, unsubscribe counts, and survey responses. Do not pick per-recipient read times, precise location, or the contents of anyone’s replies. Here is what the standard tracking pixel actually hands over, and what to use instead:
| Data point | What it reveals | Privacy-safe alternative |
|---|---|---|
| IP address | Where one specific person was when the image loaded, down to a city or block in some cases | Nothing, or a coarse region count with a minimum cohort size |
| User agent string | Mail client, device model and operating system version | Nothing, or device split with small cells suppressed |
| Timestamp | The exact second a person opened, which reveals time zone, work hours and bedtime | Hour buckets with no time zone attached |
| Recipient identifier | A token that links every event from one person into a single profile | Rotate the token per send and delete the map after the report |
| Message content | Which story, tool or recommendation that person received | Campaign-level totals only |
That table is the whole argument in five rows. Nothing on the right-hand side is hard to replace; most of it is just noise that looks like data.
3. Check consent, legal basis, and editorial purpose
Document the purpose and the basis in the same document you created in the prerequisites. Then check the things readers actually see: the sign-up language, the privacy policy, and the newsletter footer.
Three practical points. If you tell readers you track opens and you do not, that is a misleading disclosure, so keep the policy accurate to the configuration. If you rely on consent, the unsubscribe link and the consent record have to travel together, and you need one-click unsubscribe on commercial senders under the US CAN-SPAM rules. If a reader in the EU, the UK or a US state has sent a Global Privacy Control signal, your platform should honour it as a do-not-sell or do-not-track request for marketing, and you should be able to say what your system does with that signal.
I am not a lawyer and this is not legal advice. Rules differ by country and by state and they change, so have a qualified reviewer confirm the basis for your own audience before you switch anything on.
4. Configure the platform with minimization settings
This is the mechanical core of the job. Turn off campaign open tracking, turn off click tracking if you want the strictest setup, and then turn click tracking back on in its privacy-safe form, which is the next block. Most platforms bury these toggles in a campaign-creation screen or an account-level tracking section rather than a page named analytics, which is why teams leave them on for years.
Self-hosted tools are worth a look here. Keila, for example, treats campaign tracking as opt-in per campaign, so a newsletter can ship with no tracking pixels and no link redirects at all. ListMonk gives you aggregate campaign statistics on your own database. Plausible, Umami and Matomo cover the destination side if you want a first-party web analytics tool that does not build reader profiles across sites.
What to look for on any platform, whatever the label: a per-campaign open tracking toggle, a click tracking toggle, a short-menu or campaign-level reporting option, and a way to suppress small cohorts. Menu names differ between Mailchimp, MailerLite, Substack, Buttondown and Ghost, and the words used above are descriptive rather than quoted from each interface. Check the current documentation for your version, screenshot the setting once it is off, and record the date in your one-page document.
Click-only tracking, done in a way that does not rebuild the profile
You can keep real measurement without a pixel by wrapping links in a redirect on your own domain. When a reader clicks, your server logs the click and forwards them to the destination. That gives you a genuine engagement signal, because nobody accidentally loads an image they did not ask for.
Three settings keep it privacy-safe. Rotate the click token on every send, so the identifier is useless once the campaign report is written. Delete the token-to-address map as soon as the campaign closes, rather than keeping a joinable table. And disable IP logging, or truncate the address to a coarse region before storing, because the log is where the identity lives. Trim the redirect to a single hop, because every extra hop is another party learning which articles your readers want.
5. Set retention, access, and export controls
Set a retention window you can defend, then make the platform enforce it. Thirty days for raw event data and a year for aggregated campaign totals is a defensible default for a newsletter; the exact number matters less than the fact that one exists and is written down.
On access: named accounts, real authentication, and no shared logins. On changes: keep an administrative log of who turned tracking on, so the answer to an audit question is not guesswork. On export: exports go into the same access-controlled location as everything else, because a spreadsheet on someone’s laptop is the most common way a well-designed retention policy quietly fails.
For deletion requests, decide the route before you need it. If someone asks to be removed, the reply address, the sending platform and the click data all need to be reachable from one documented process.
6. Test the setup with a small controlled send
Send to a slice of the list rather than everybody, roughly ten to fifty addresses including your own, and check four things. Unsubscribe still works from every client. The confirmation or double opt-in flow still works for a new address. The report shows the aggregate numbers you expect and nothing more. And the raw data, when you look at it, contains no field you did not approve.
That last check is the one people skip. Open the raw event export in a text editor, read the column headers, and compare them to your one-page document. If a column appears that you cannot justify, find the setting that produced it before the next send.
Send the same test to a second, different provider if you can. Link security products in some organisations rewrite URLs before the message reaches the reader, and knowing whether your click redirect survives that is cheaper to learn now than to discover in a quarterly report.
7. Review results and improve the workflow
Read the first report as a campaign health check, not a performance review. Delivery and bounce rates tell you about list quality. Click-through by link tells you about the subject line and the structure. Replies and unsubscribes tell you about trust, and they are the two numbers privacy-safe setups measure best.
Put the review on a calendar, twice a year at minimum. Each time: delete platforms you stopped using, check whether the consent language still matches the configuration, re-read the retention rule, and write a one-paragraph summary for the rest of the newsroom so nobody has to ask what the numbers mean. Practitioners in r/email and r/adops describe the same fatigue from the other side, chasing vendors and pixels that keep changing behaviour without anyone noticing.
Common Mistakes and How to Fix Them
Leaving the open pixel on because the toggle is easy to miss. Open tracking is usually a per-campaign checkbox, so it survives every new campaign. Put the check on your send checklist and screenshot the setting.
Claiming you do not track readers while link redirects still build a profile. A rotating token, a deleted map and no IP logging change what the click data is. Without those, it is still a per-person record.
Reporting open rates as if they were real. Apple Mail Privacy Protection has pre-fetched images on delivery since iOS 15, and Gmail has proxied images through its own servers for well over a decade, so a large share of recorded opens are the mail client, not the reader. A thread in r/shopify showed a merchant reporting a 28% open rate on an email that included a discount code, so there was no reason to open it at all. Treat the number as a curiosity or delete it.
Trusting one dashboard for one metric. The same platform that gives you delivery health also gives you the profile. Ask which specific reports need to survive the test, and export those.
Setting retention in policy but not in the platform. If the software keeps raw events for two years because that is the default, your policy is fiction. Configure the deletion job and test it.
Disclosing tracking in a policy nobody reads. Put one plain sentence in the newsletter footer and link the full policy. It costs a line and it answers the reader question before it gets asked.
Footer wording that works: “We measure how many people click links in this newsletter, in aggregate. We do not track who opens it, we do not share data with advertisers, and every issue includes a one-click unsubscribe link.” Say only what your configuration actually does, and recheck it whenever a setting changes.
Three habits keep the setup safe over time. Review the inventory quarterly, because a new analytics tag often arrives with a new form or a new ad campaign nobody logged. Keep the minimum cohort size in front of you, and suppress any report cell below roughly ten recipients, since small cells are where re-identification happens. And when someone on the team asks for reader-level behaviour data, make them answer which decision it changes first.
Frequently Asked Questions
What data does an email tracking pixel actually collect?
An open-tracking pixel is a tiny remote image in the email HTML. When your mail client loads it, the request reveals the reader’s IP address, user agent and device, the exact timestamp, an approximate location, and a token that links every event from that one recipient. It is a per-person record created without the reader doing anything. That is why the privacy-safe alternative is a rotating click token with no IP logging.
Is email open tracking legal under GDPR?
It is contested rather than clearly banned. Open tracking involves personal data processing, so a lawful basis and a transparent notice are generally expected, and several European regulators have treated undisclosed email tracking as a problem. Rules differ by country and change, and this is not legal advice. The practical answer for most small teams: turn the pixel off, keep click and reply measurement, and document why.
Can I track clicks without a tracking pixel?
Yes, and that is the recommended default. Wrap links in a redirect on your own domain, log the click server-side, and forward the reader to the destination. No image is loaded, so no false opens appear. Keep it privacy-safe by rotating the token each send, deleting the token-to-address map after the campaign closes, and disabling or truncating IP logging.
What can I use instead of open rate to measure engagement?
Use click-through rate by link, reply volume, unsubscribe rate, forward and share counts where your platform offers them, and a short periodic reader survey. Each measures something a reader chose to do rather than something a mail client did automatically. Together they describe engagement better than a single inflated open rate, and each one is far less privacy-invasive.
How do I filter bot opens from my email analytics?
If you have turned open tracking off, filtering is no longer needed. If you keep opens for internal delivery diagnostics, apply simple rules: discard opens within a few seconds of delivery, discard events from known security scanners, cap opens per recipient per campaign, and set a rate threshold above which a campaign is flagged for review. Engineering write-ups commonly use a ten-second rule for this reason.
How do I tell if my emails are being monitored?
Send yourself a test message and view the raw HTML source. A tracking pixel appears as a one-pixel image tag pointing at a tracking domain, usually with a unique identifier in the URL. Security products in some organisations also rewrite links, so check whether your redirects resolve to a vendor domain. As a recipient, blocking remote images in your mail client stops most open tracking at once.
Start with one change today: open the next campaign’s settings and turn off open tracking, then note the date in your one-page document. Everything after that is measurement you can rebuild without a per-reader record, and a privacy policy that finally matches what the software actually does.


