Question

How does CIO comply with COPPA (Children’s Online Privacy Protection Act)?

  • 15 February 2023
  • 1 reply
  • 18 views

Are there any functionalities within the product to help us comply? Or is it up to us to set up the applicable rules and processes?


1 reply

Hi Alisha!

Wanted to address this one ourselves for you as it’s an important area to consider for any customer with COPPA questions or requirements. 

NOTE: Our customers are responsible for getting consent from parents or guardians for children under 13, not Customer.io.

Here are a few tips and tricks about how to leverage the Customer.io platform to send more engaging messages without compromising COPPA that your users trust you to safeguard.

  • You can opt to use coded segmentation or to use a CSV import and manual segments to send messages that are relevant to:
    • Customers of a particular age (13+)
    • Have permission or consent from a parent or from a guardian
  • You can opt to segment customers in your internal system, then upload those attributes to Customer.io via API or CSV import. That way, you can still send pertinent messages to people that comply with COPPA.
  • Don’t upload or import data into CIO that doesn’t comply with COPPA.
  • If you’re ever unsure of what you’re doing in Customer.io would violate your obligations under COPAA, then you you shouldn’t use Customer.io in that way.

I hope that gives you a good understanding of where responsibility lies and how we advise you to handle this type of case. 

Cheers!

Reply