Constant Contact, a provider of email and digital marketing services, has detailed its practices regarding the collection, use, and sharing of customer contact data, underscoring its role as a service provider and its commitment to privacy compliance. The company assists small businesses and non-profits in managing contact lists, sending email newsletters, and tracking campaign results, acting solely at the direction and on behalf of its customers.
The company collects contact data primarily through customer uploads of email addresses, names, and other details into their Constant Contact accounts. Additionally, Constant Contact receives information directly from individuals who sign up for customer emails, register for events, or interact with marketing campaigns facilitated by its platform. This can include demographic data, shopping histories, and engagement details.
Email campaigns sent via the platform may incorporate web beacons and other tracking technologies to monitor email opens, clicks, delivery status, and geographic location, as well as to collect log data such as IP addresses and browser types. This information is shared with customers to help them optimize campaigns and understand engagement. Users can refuse web beacons by disabling HTML images or opt out of other tracking by not interacting with email content.
Constant Contact maintains that it never uses customer contact lists for its own marketing purposes. Information collected about user interaction is provided to customers and used to deliver and improve Constant Contact's products and services, and for security and compliance. Data may be shared with authorized service providers who integrate features with Constant Contact's products, with strict obligations to ensure data use aligns with applicable privacy laws.
The company offers features enabling customers to target contacts more effectively, sometimes partnering with third parties to provide additional demographic or shopping history information, particularly for contacts outside the European Union. Constant Contact requires both its customers and partners to comply with applicable laws and maintain transparent privacy policies regarding such enriched data.
Individuals wishing to stop receiving marketing emails can use the unsubscribe links found in all emails sent through the platform. Constant Contact clarifies its role as a “data processor” or “service provider,” meaning it processes data on behalf of its customers, who are the “data controllers.” Requests related to personal information, such as corrections or deletions, should be directed to the specific customer who sent the communication.
Constant Contact, including SharpSpring Technologies, Inc., participates in and has certified its compliance with the EU-U.S., UK Extension, and Swiss-U.S. Data Privacy Frameworks, subjecting it to the regulatory enforcement powers of the U.S. Federal Trade Commission. The company is committed to the Frameworks' principles for all personal data transfers and offers a third-party dispute resolution provider for unresolved privacy concerns, as detailed on the Data Privacy Framework website.