- What is Klaviyo ActiveOnSite and does it need to be disclosed?
- ActiveOnSite is a Klaviyo feature that identifies known email subscribers who visit your website without being logged in, using the __kla_id cookie set when they previously clicked an email link. When identified, Klaviyo tracks their browsing behavior and can trigger automated flows like browse abandonment emails. This is a distinct processing activity that combines email identity with behavioral tracking and must be described in the privacy policy. Visitors who receive browse abandonment emails should understand why and how their behavior was tracked.
- Does Klaviyo email marketing require GDPR consent?
- Yes, for promotional and marketing emails. GDPR requires a lawful basis for each processing activity. For marketing email, the standard basis is freely given, specific, informed, and unambiguous consent. Klaviyo website behavioral tracking via Klaviyo.js additionally requires prior consent under the ePrivacy Directive, separate from the email marketing consent. A subscriber who has not consented to cookie-based tracking should not be subject to Klaviyo.js behavioral collection when they visit the website.
- What are the TCPA requirements for Klaviyo SMS marketing?
- The Telephone Consumer Protection Act (TCPA) requires prior express written consent before sending marketing text messages to US phone numbers. For Klaviyo SMS, this means obtaining consent through a clearly disclosed opt-in mechanism, retaining evidence of consent, and providing clear opt-out instructions in every message. Klaviyo provides compliance features for SMS opt-in and opt-out flows, but legal review is required to confirm that the consent language and mechanism meet TCPA requirements for the specific program.