Monitored company
Customer.io
clause.watch tracks 2 legal documents published by Customer.io, re-reading each one every six hours. Below is what each document covers, in plain English.
Privacy Policy
Privacy Policy Overview — Customer.io
*This is a practical summary, not legal advice. The policy distinguishes between information Customer.io collects for its own purposes and information it processes for business customers using its marketing platform.*
1. Data Collection & Usage
Information collected
Customer.io may collect:
- Identifiers: name, email, address, phone number, IP address, device ID, advertising ID, online identifiers, and transaction identifiers.
- Customer and transaction information: products or services purchased, appointments, payment details, card information, and billing information.
- Technical and activity data: browsing history, search history, device and browser details, operating system, session information, referring pages, links clicked, and approximate location based on IP address.
- Message engagement data: whether recipients open emails or other communications, click links, and interact with customer messages.
- Communications and recordings: information submitted through forms, emails, support interactions, and potentially call recordings.
- Sensitive information: Customer.io says it does not collect sensitive information for its own purposes, but its business customers may upload sensitive information to the Services.
Uses
Information may be used to:
- Provide, operate, secure, troubleshoot, and improve the Site and Services.
- Send communications and marketing materials.
- Measure message engagement, segment recipients, and personalize content.
- Conduct analytics, research, and product development.
- Provide support, process payments, administer events or promotions, and communicate policy or service changes.
- Detect fraud, illegal activity, and security threats.
- Comply with legal obligations and protect Customer.io’s or others’ rights.
Cookies and similar technologies support analytics, functionality, advertising, social-media features, personalization, and cross-site targeted advertising.
Important distinction: For data processed through a customer’s use of Customer.io, Customer.io generally acts as a processor/service provider. The customer—not Customer.io—normally determines why the data is collected and is responsible for its own privacy notices and user-choice mechanisms.
2. User Rights
Depending on location and applicable exceptions, users may have rights to:
- Access or obtain a copy of personal information.
- Correct inaccurate or incomplete information.
- Delete information.
- Restrict or object to processing, including marketing.
- Port data to another provider.
- Opt out of the sale or sharing of personal information for behavioral advertising.
- Limit disclosure of sensitive personal information.
- Opt out of certain automated decision-making, where applicable.
- Receive equal treatment when exercising privacy rights.
EEA, UK, and Swiss users may contact legal@customer.io. However, requests concerning data processed for a Customer.io customer will generally be redirected to that customer.
U.S. requests may require identity or authority verification. Responses are generally due within 45 days, with a possible extension up to 90 days.
3. Third-Party Sharing
Customer.io may share information with:
- Its business customers, including end-recipient engagement data.
- Service providers.
- Messaging providers such as Twilio, email, SMS, and Apple-related platforms.
- Business applications such as Stripe and referral partners.
- Marketing and analytics providers such as Google Analytics, ZoomInfo, LinkedIn, and Zoom.
- Legal authorities, when required or considered necessary to enforce rights or prevent harm.
- Buyers or successors in a merger, acquisition, or business sale.
Some third parties—particularly messaging, business, and marketing applications—may use data for their own purposes, and their separate privacy policies apply. Data may be transferred to and stored in the United States and other countries.
4. AI/ML Training
The policy does not expressly state that personal information is used to train artificial-intelligence or machine-learning models. It does authorize internal research, development, analytics, product improvement, segmentation, and personalization. Those broad permissions could potentially include algorithmic development, but the policy does not clearly confirm or exclude AI training.
Users seeking certainty should request clarification or review the applicable customer agreement and Data Processing Addendum.
5. Key Obligations and Restrictions
- The policy does not knowingly permit collection from children under 16; inadvertently collected information will be deleted.
- Customers are discouraged from uploading sensitive personal information.
- Customers are responsible for providing legally required notices, choices, and opt-out mechanisms to their end users.
- Users who disable cookies may lose functionality.
- Users must provide sufficient information to verify privacy requests.
- Continued use after policy changes constitutes consent under the policy.
6. Liability & Disputes
Customer.io uses physical, technical, and administrative safeguards but does not guarantee security. The policy itself provides limited detail about damages, warranties, governing law, arbitration, or liability caps; those terms likely appear in the separate Terms of Service, Cloud Services Agreement, and Data Processing Addendum.
For qualifying EEA, UK, and Swiss Data Privacy Framework complaints, users may contact Customer.io, then JAMS for alternative dispute resolution at no cost. Binding arbitration may be available in limited circumstances.
7. Changes
Customer.io may change the policy by posting an updated version on its website. Changes become effective when posted, and continued use of the Site or Services—or continued interaction with Customer.io—constitutes consent. No separate notice is promised.
Terms and Conditions
Customer.io Terms: Practical Overview
*This summary highlights user-facing risks in the supplied Terms of Service. It is not a substitute for legal advice. The separate Privacy Policy, Data Processing Addendum (DPA), Acceptable Use Policy, and other incorporated terms may materially change the analysis.*
1. Data Collection and Usage
Data you provide
You retain ownership of:
- Campaign content, including text, audio, video, and images
- Recipient information, such as names, email addresses, telephone numbers, and phone numbers
- Other identifiers or information uploaded to or collected through the Services
- Registration and account information
The Terms do not provide a complete list of personal data Customer.io itself collects. That information is instead governed primarily by the separate Privacy Policy.
How Customer.io may use your Data
You grant Customer.io a broad, worldwide, royalty-free, transferable license to use, modify, reproduce, and display your Data to:
- Provide the Services
- Support and administer the Services
- Improve the Services
The Terms do not expressly limit these uses to aggregated, de-identified, or non-personal data. Customer.io may monitor Data, remove it, block campaigns, or suspend messaging if it believes the Data violates the Agreement, applicable law, or could affect service delivery.
You remain responsible for the accuracy, legality, quality, and security of your Data. Customer.io disclaims liability for the Data you provide.
Retention risk
After termination, your access to the Services and Data ends immediately. The Terms do not promise a post-termination export period or data-retrieval process. Free-trial Data may be permanently deleted when the trial ends unless you purchase a subscription.
2. User Rights Regarding Data
The Terms do not expressly grant individuals rights to:
- Access or receive a copy of their personal data
- Correct or delete personal data
- Restrict or object to processing
- Opt out of certain uses
- Port data to another provider
- Appeal an automated decision
Those rights, if applicable, must be determined under the Privacy Policy, DPA, and applicable law. If you are the customer providing recipient data, you are responsible for handling data-subject requests and complying with privacy laws.
Customers subject to European, U.S., or similar data-protection laws must execute Customer.io’s DPA. You must also maintain a privacy policy that discloses use of third-party providers like Customer.io and obtain all legally required notices, consents, and authorizations.
3. Third-Party Sharing and Integrations
Customer.io may disclose Data to employees, contractors, suppliers, affiliates, and representatives who need it to perform the Agreement, provided they are subject to confidentiality obligations.
The Services also use third-party messaging platforms and permit integrations with third-party software and tools. Customer.io states these providers are not its subcontractors or subprocessors and disclaims responsibility for how they access, transmit, store, process, secure, share, or use data. Their own terms may apply and may change without notice.
This creates a significant risk: data may move through third-party systems for which Customer.io accepts little or no responsibility. Review each integration’s privacy and security terms separately.
4. AI/ML Training
The Terms do not expressly state that customer Data is used to train artificial-intelligence or machine-learning models. They do, however, permit use of Data to “improve the Services,” which could be broad enough to warrant clarification.
Before uploading sensitive or regulated information, confirm through the Privacy Policy, DPA, or written agreement whether:
- Data is used for model training or product analytics
- Data is de-identified before secondary use
- customer Data is isolated from other customers
- prompts, outputs, or campaign data are retained
5. Key User Obligations and Restrictions
You must:
- Have the legal rights and consents necessary to use recipient data
- Comply with privacy, marketing, anti-spam, intellectual-property, consumer-protection, and other laws
- Keep registration information accurate
- Protect passwords and notify Customer.io of security breaches
- Ensure Authorized Users comply with the Terms
- Maintain a valid payment method
- Pay subscription fees, overages, taxes, and potentially interest of 1.5% per month on late payments
You may not send spam, phishing, unlawful or harmful messages, impersonate others, upload malicious code, misuse personal data, bypass security, reverse engineer the Services, develop a competing product, or use the platform for prohibited or unlawful products or activities.
You indemnify Customer.io for third-party claims arising from your use, breach, infringement, or Data.
6. Liability and Disputes
The Services are provided “as is,” with broad warranty disclaimers. Customer.io is generally not responsible for outages, delivery failures, loss or inability to retrieve Data, third-party services, or the legality and accuracy of your campaigns.
Except for specified carve-outs such as indemnification, Acceptable Use Policy violations, gross negligence, or intentional misconduct:
- Neither party is liable for indirect, punitive, incidental, or consequential damages
- Customer.io’s total liability is capped at the greater of fees paid in the preceding 12 months or $100
- You may remain liable for fees for the rest of a subscription term after termination for breach or early cancellation
Disputes must be brought in state or federal courts in Multnomah County, Oregon, under Oregon law.
7. Changes and Renewal
Customer.io may modify the Agreement by:
- Posting a notice on the Services
- Posting a revised agreement
- Sending email notice
You are responsible for reviewing changes. Continued use after notice constitutes acceptance. If you disagree, you must stop using and terminate the Services, but accrued fees and obligations remain due.
Paid subscriptions automatically renew unless you provide 30 days’ prior written notice. Fees may increase at renewal. Free features may be discontinued or made paid with at least 30 days’ notice.
Change history
2026-09-03 · Privacy Policy
2026-09-02 · Privacy Policy
2026-08-31 · Privacy Policy
2026-08-31 · Privacy Policy
2026-08-29 · Privacy Policy
2026-08-28 · Privacy Policy
2026-08-25 · Privacy Policy
2026-08-25 · Privacy Policy
2026-08-24 · Privacy Policy
2026-08-22 · Privacy Policy
2026-08-21 · Privacy Policy
2026-08-20 · Privacy Policy
2026-08-19 · Privacy Policy
2026-08-19 · Privacy Policy
2026-08-18 · Terms and Conditions
Summary
Information Provided
The diff states only:
> “Added approximately 444 words to the document”
It does not include the actual added language, deleted language, or replacement provisions.
Legal and AI-Training Analysis
Because the substantive contract text is missing, it is not possible to determine:
- Whether customer data may be used to train, fine-tune, or improve AI models;
- Whether such use is permitted by default or requires customer consent;
- Whether data is anonymized, aggregated, de-identified, or retained in identifiable form;
- Whether customer prompts, inputs, outputs, or usage metadata are included;
- Whether data may be shared with affiliates, vendors, or third-party model providers;
- Whether the customer can opt out of model training;
- Whether the provider must delete or return data;
- Whether confidentiality, security, intellectual-property, or regulatory obligations have changed;
- Whether the provider receives broader rights to use customer content; or
- Whether liability, indemnity, audit, or compliance protections have been added or weakened.
Risk Assessment
The statement that approximately 444 words were added is not enough to identify legal changes or risks. The additions could range from administrative language to a material expansion of the provider’s rights over customer data.
Any provision concerning “improvement,” “service enhancement,” “analytics,” “machine learning,” “artificial intelligence,” “model training,” “aggregated data,” or “de-identified data” should be reviewed carefully, particularly for:
1. Broad or perpetual rights to use customer content;
2. Permission to use data for general-purpose model training;
3. Lack of an opt-out or consent requirement;
4. Ambiguous definitions of customer data and usage data;
5. Continued retention after termination; and
6. Disclaimers or limitations on confidentiality and liability.
Next Step
Please provide the full redline or the actual 444 words added, including any deletions and replacements. Once provided, the changes can be analyzed clause by clause and summarized in a structured format.
Between 2023-04-02 and 2024-11-22 · Terms and Conditions
Summary of Important Changes
AI Model Training and Data Use
- No express change concerning AI training is visible in this diff. The amendments do not add language expressly permitting or prohibiting Customer.io from using Customer Data, Personal Data, or customer content to train, fine-tune, evaluate, or improve artificial-intelligence or machine-learning models.
- The existing data license remains important: Customer grants Customer.io a non-exclusive, worldwide, royalty-free, transferable license to use and modify “Data.” The full permitted-use language is not shown clearly enough to determine whether it could encompass AI development or model training.
- The Services definition now expressly includes analytics technology, applicable features, and content available through the Services. This may broaden the categories of information covered by the Agreement, but it is not itself an AI-training authorization.
- Action point: Review the complete Data license, Privacy Policy, Feature Terms, and Data Processing Addendum for separate AI-use provisions. Do not assume the absence of an AI reference means customer data cannot be used for training.
Agreement Structure and Document Priority
- The incorporated documents have been reorganized. The Agreement now includes the Terms of Service, applicable Exhibits and Service Orders, Privacy Policy, Acceptable Use Policy, Promotional Credit Terms, and applicable Feature Terms.
- A new conflict hierarchy gives priority to:
1. Applicable Service Order/Sales Order Form;
2. Terms of Service;
3. Applicable Feature Terms, but only for the relevant feature;
4. Data Processing Addendum, but only for Personal Data processing;
5. Other incorporated policies, unless the Service Order says otherwise.
- This hierarchy is helpful, but the ability of a Service Order to override incorporated policies creates a risk that negotiated or commercial documents may alter privacy, usage, or feature terms.
Third-Party Services and Data Transfers
- The revised terms distinguish third-party integrations selected by the customer from Customer.io’s subprocessors.
- By connecting or configuring a third-party service, the customer directs Customer.io to transmit, receive, disclose, and otherwise process Data with that service as needed to provide the Services.
- Customer is solely responsible for third-party terms, acceptable-use rules, registration requirements, carrier requirements, and other policies, which may change without notice.
- Customer.io broadly disclaims liability for third-party errors, outages, delivery failures, data corruption, loss, and similar issues. The customer also assumes broader indemnity exposure for violations involving third-party services or provider requirements.
Liability, Compliance, and Operational Risk
- The disclaimer is revised to cover third-party services, including communications providers, and states that Customer.io does not guarantee compliance, delivery, carrier approval, registration, routing, data residency, or suitability for regulated or sensitive data.
- Customer responsibility is expanded for determining whether the Services are suitable for health, financial, children’s, sensitive, regulated, or restricted data.
- Suspension rights are expanded to include disabling SMS and other communication channels, integrations, and location-based features.
- Payment language clarifies that third-party carrier and communications charges—including usage, overage, registration, compliance, and support fees—are the customer’s responsibility, while maintaining the requirement for a valid credit card.
Customer Representations
- The customer must confirm legal authority to bind its entity and legal permission to use the Services.
- Account-security obligations are clarified: Authorized Users must maintain separate accounts, and the customer is responsible for activity under those accounts and for promptly reporting security breaches.
Between 2023-12-06 and 2024-11-04 · Privacy Policy
No
Between 2022-01-17 and 2023-12-06 · Privacy Policy
Between 2021-10-18 and 2023-04-02 · Terms and Conditions
Between 2020-11-01 and 2022-01-17 · Privacy Policy
Between 2019-07-20 and 2020-09-15 · Terms and Conditions