Email sending services
Customer.io privacy rating
Messaging automation platform for email, push, SMS and in-app messages, with a transactional email API, US and EU regions and open and click tracking.
Summary
Customer.io scores 40 out of 100 (grade D) on the email sending services criteria. It meets 3 of 12 criteria: tells users about requests, TLS configuration and EU data location. It partly meets no ads or data sales, independent audit, transparency report, message content deleted after delivery and open and click tracking off by default. It does not meet open source, no trackers or telemetry and security headers. Still needing evidence: encrypted delivery can be enforced. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade C+.
Score 40 out of 100. How scoring works
Criteria
- No
-
No
No trackers or telemetry Weight 3 of 3
Are the website and apps free of third-party trackers, with any analytics anonymous and any telemetry off by default?
The privacy policy covers marketing cookies that help advertising partners show ads, and the website loads Google Tag Manager.
-
Partial
No ads or data sales Weight 2 of 3
Is the product funded without advertising, ad targeting or selling user data?
Funded by paid plans and states customer data is not sold, but website cookies are used with advertising partners, and the policy offers an opt-out of sharing for behavioral advertising.
-
Partial
Independent audit Weight 2 of 3
Has an independent security or privacy audit been published within the last three years?
SOC 2 Type II and ISO 27001 certified, but the audit reports are only available on request.
-
Partial
Transparency report Weight 2 of 3
Does the provider regularly publish how many government and legal requests it receives and how it responds?
The data processing addendum describes how government requests are handled, but no request counts are published.
-
Yes
Tells users about requests Weight 1 of 3
Does the provider promise to tell users about requests for their data, unless a court forbids it?
The data processing addendum promises reasonable notice to customers of compelled disclosure unless legally prohibited.
-
Partial
Message content deleted after delivery Weight 3 of 3
Is the content of sent mail deleted once it has been delivered?
Message content is kept by default for an undocumented period. A Protect sensitive data setting stops the body of transactional messages from being stored.
-
Partial
Open and click tracking off by default Weight 2 of 3
Are open tracking pixels and click tracking links off unless the sender turns them on?
Link tracking is on by default for email in automations and API-triggered broadcasts, and can be turned off for each message.
-
Unknown
Encrypted delivery can be enforced Weight 2 of 3
Can outbound mail be kept from being delivered without TLS?
Needs evidence. Add it
-
Yes
EU data location Weight 1 of 3
Can message content and delivery logs be processed and stored only in the European Union?
Accounts created in the EU region store all data about people in EU data centers in Belgium.
Automated tests
-
Yes
TLS configuration Weight 2 of 3
Does the website pass the Qualys SSL Labs test with a grade of A or better?
Grade A+
-
No
Security headers Weight 1 of 3
Does the website pass the Mozilla HTTP Observatory test with a grade of A or better?
Grade C+ (60/100+)
-
Not tested yet
Modern web standards Weight 1 of 3
Does the website score 90% or higher on the Internet.nl website test?
Not tested yet.