# Customer.io privacy rating

Messaging automation platform for email, push, SMS and in-app messages, with a transactional email API, US and EU regions and open and click tracking.

## Summary

Customer.io scores 40 out of 100 (grade D) on the email sending services criteria. It meets 3 of 12 criteria: tells users about requests, TLS configuration and EU data location. It partly meets no ads or data sales, independent audit, transparency report, message content deleted after delivery and open and click tracking off by default. It does not meet open source, no trackers or telemetry and security headers. Still needing evidence: encrypted delivery can be enforced. It is based in the United States: Five Eyes member; subject to the US CLOUD Act. Automated tests: SSL Labs grade A+ and Mozilla HTTP Observatory grade C+.

- Website: https://customer.io
- Jurisdiction: United States. Five Eyes member. Subject to the US CLOUD Act.
- Platforms: Web
- Home page trackers: Google Tag Manager
- Category: [Email sending services](https://privacyratings.com/email-sending/)
- Grade: D (40/100)

## Criteria

| Criterion | Answer | Note | Evidence |
| --- | --- | --- | --- |
| Open source | No | Closed source. |  |
| No trackers or telemetry | No | The privacy policy covers marketing cookies that help advertising partners show ads, and the website loads Google Tag Manager. | https://customer.io/legal/privacy-policy |
| No ads or data sales | Partial | Funded by paid plans and states customer data is not sold, but website cookies are used with advertising partners, and the policy offers an opt-out of sharing for behavioral advertising. | https://customer.io/legal/privacy-policy |
| Independent audit | Partial | SOC 2 Type II and ISO 27001 certified, but the audit reports are only available on request. | https://customer.io/security |
| Transparency report | Partial | The data processing addendum describes how government requests are handled, but no request counts are published. | https://customer.io/legal/dpa |
| Tells users about requests | Yes | The data processing addendum promises reasonable notice to customers of compelled disclosure unless legally prohibited. | https://customer.io/legal/dpa |
| TLS configuration | Yes | Grade A+ | https://www.ssllabs.com/ssltest/analyze.html?d=customer.io&hideResults=on |
| Security headers | No | Grade C+ (60/100+) | https://developer.mozilla.org/en-US/observatory/analyze?host=customer.io |
| Modern web standards | Not tested yet | Not tested yet. |  |
| Message content deleted after delivery | Partial | Message content is kept by default for an undocumented period. A Protect sensitive data setting stops the body of transactional messages from being stored. | https://docs.customer.io/messaging/send/transactional/api/ |
| Open and click tracking off by default | Partial | Link tracking is on by default for email in automations and API-triggered broadcasts, and can be turned off for each message. | https://docs.customer.io/messaging/channels/links/tracking/ |
| Encrypted delivery can be enforced | Unknown |  |  |
| EU data location | Yes | Accounts created in the EU region store all data about people in EU data centers in Belgium. | https://docs.customer.io/accounts/settings/data-centers/ |

Source: https://privacyratings.com/email-sending/customer-io/
Edit: https://github.com/privacyratings/privacyratings.com/edit/main/ratings/email-sending/customer-io.md
