8 Total
1 High severity
6 Medium severity
1 Low severity
Summary

This privacy statement establishes Mixpanel's data collection, processing, and sharing practices for individuals who access Mixpanel's website, use its analytics platform, or whose data is processed through Mixpanel's tools by third-party operators. Mixpanel collects IP addresses, device identifiers, browsing behavior, event data, and email addresses, and discloses this data to third-party vendors including advertising, analytics, infrastructure, and professional services providers. For end users of applications or websites that integrate Mixpanel's analytics tools, the statement designates Mixpanel as a data processor operating under the terms established by the app or website operator, with limited direct obligations to those individuals.

Technical / Legal Breakdown

This document is Mixpanel's Privacy Policy, governing the collection, use, storage, and disclosure of personal data by Mixpanel, Inc. in its capacity as both a data controller (for data collected about visitors to its own website and marketing contacts) and a data processor (for personal data that Mixpanel's business customers send to Mixpanel's analytics platform on behalf of their own end users). The policy states that Mixpanel collects identifiers, device information, IP addresses, usage and behavioral event data, and customer-provided profile data; authorizes use of this data for product analytics, service delivery, marketing communications, and security purposes; and discloses sharing with infrastructure, analytics, advertising, and professional services vendors as well as in corporate transaction contexts. The policy's dual-role structure (controller and processor) is operationally significant: as a processor, Mixpanel's obligations to end users of its customers' applications are governed by those customers' own privacy practices rather than this policy, which may limit end users' direct recourse against Mixpanel. The policy states compliance with GDPR and engages the EU-U.S. Data Privacy Framework, UK GDPR, and the California Consumer Privacy Act (CCPA); it provides data subject rights mechanisms including deletion, correction, portability, and opt-out of sale or sharing of personal information. Material compliance considerations include the adequacy of Mixpanel's processing agreements with its business customers, the lawfulness of cross-border data transfers, and the scope of Mixpanel's data deletion obligations where it acts as a processor on behalf of enterprise clients.

Institutional Analysis

Institutional analysis available with Compliance

Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Compliance.

Start Compliance free trial

1 important change detected

2 versions captured · Last updated: June 2026

What changed Mixpanel added a reference to 'Mixpanel AI - Trust, Safety, and Compliance' in the navigation menu of their Privacy Statement on June 2, 2026. This new menu item appears three times throughout the document's navigation structure. The change is a documentation and disclosure addition rather than a substantive revision to existing privacy practices or obligations.
Why this matters The updated Privacy Statement now includes a navigation link to 'Mixpanel AI - Trust, Safety, and Compliance' resources. This is a disclosure and navigation addition rather than a substantive change to privacy practices or data handling. The change makes AI governance documentation more discoverable but does not alter data collection, retention, or processing obligations.
View full change record →

Recent Provision Changes Jun 2, 2026

8 provisions unchanged.

View full change record →
High — 1 provision
Medium — 6 provisions
Low — 1 provision

Monitoring

Mixpanel has updated this document before.

Monitor includes same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Start Monitor free trial Or create a free account →

Compliance Governance Intelligence

Need provision-level monitoring and regulatory mapping?

Compliance includes governance timelines, compliance memos, audit-ready analysis, and full provision tracking.

Start Compliance free trial

Cross-platform context

See how other platforms handle Controller and Processor Dual-Role Structure and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

CCPA/CPRA
California, USA
View official text ↗
Connecticut Data Privacy Act Amendments
US-CT
View official text ↗
CAN-SPAM
United States Federal
View official text ↗
DMA
European Union
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
GDPR
European Union
View official text ↗
Indiana Consumer Data Protection Act
US-IN
View official text ↗
Kentucky Consumer Data Protection Act
US-KY
View official text ↗
Universal Opt-Out Mechanism Expansion 2026
US
View official text ↗
VPPA
United States Federal
View official text ↗
Archival ProvenanceSource & Archival Record
Last Captured June 2, 2026 21:14 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000704
Version ID CA-V-003359
SHA-256 2bcb11dee9567aec1e9bcab8282833836bab779cdc687c86cbcbe7d1f0318fab
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 318+ platforms.

Create free account Compare plans