Constant Contact, a provider of email and digital marketing services, has issued a notice detailing its practices regarding the collection, use, and sharing of customer contact data. The company emphasizes its role as a service provider to small businesses and non-profits, processing contact information solely at the direction and on behalf of its customers. Constant Contact maintains that it does not have a direct relationship with the recipients of its customers' emails and requires customers to use its platform only for permission-based marketing.
Contact data, including email addresses, names, and demographic information, is primarily uploaded by Constant Contact's customers into their accounts. The company also collects data directly from individuals who sign up for customer emails, register for events, or interact with Constant Contact products used by its customers. This includes information gathered through web beacons and other tracking technologies embedded in email campaigns, which can determine email opens, clicks, geographic location, and subscription preferences.
The collected data is shared with customers to help them optimize campaigns, customize offerings, and understand user engagement. Constant Contact explicitly said it will never email customer contact lists for its own purposes. Information may be shared with authorized service providers who integrate features with Constant Contact's products, with obligations to ensure data use aligns with applicable privacy laws. The company is located in and processes information in the United States, adhering to applicable privacy laws for international data transfers.
Constant Contact offers features allowing customers to target contacts more effectively, sometimes partnering with third parties for additional demographic or shopping history information, particularly for users outside the European Union. Customers must opt into these features and are required to comply with applicable laws and maintain compliant privacy policies. Individuals can opt out of marketing emails via unsubscribe links provided in every communication.
As a "data processor" or "service provider," Constant Contact does not own customer contact lists. It supports its customers, who are the "data controllers," in fulfilling data subject rights requests, such as correcting or deleting personal information. Constant Contact participates in and has certified its compliance with the EU-U.S., UK Extension, and Swiss-U.S. Data Privacy Frameworks, subjecting it to the regulatory enforcement powers of the U.S. Federal Trade Commission. Unresolved privacy concerns can be directed to a U.S.-based third-party dispute resolution provider, and under certain conditions, binding arbitration may be invoked.