Embedding implied consent to such tracking in a separate document (privacy policy) does not seem to be very transparent. What am I misunderstanding?
PS: It's usually better to have a look at the GDPR on the official website of EUR-Lex. https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL...
But, MailChimp allows open-tracking to be disabled. So, that wouldn’t seem to be a required element of their processing. Which means it’s for the controller to decide. I don’t understand how article 7 of the GDPR allows for email tracking to be immune from explicit consent.
Recital 48 is giving some explanation:
"The processing of personal data for direct marketing purposes may be regarded as carried out for a legitimate interest."
https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL...
IANAL, but I spent the past 2 years as CTO of an EU-based analytics company becoming compliant with GDPR, and consider myself quite informed on the topic. I would tread more carefully than what you are suggesting.