FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. Marketing
  4. Customer.io
C

Customer.io

Marketing

Related services

6sense

6sense is a digital marketing technology that helps businesses reach, engage, and convert their target audience online. It provides advanced targeting, campaign management, and performance analytics capabilities. 6sense enables marketers to deliver personalized experiences across channels, optimize campaign ROI, and gain actionable insights into customer behavior. With automation features and data-driven optimization, 6sense empowers marketing teams to achieve measurable growth.

Marketing

ActiveCampaign

ActiveCampaign is a digital marketing technology that helps businesses reach, engage, and convert their target audience online. It provides advanced targeting, campaign management, and performance analytics capabilities. ActiveCampaign enables marketers to deliver personalized experiences across channels, optimize campaign ROI, and gain actionable insights into customer behavior. With automation features and data-driven optimization, ActiveCampaign empowers marketing teams to achieve measurable growth.

Marketing

AddEvent

AddEvent is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. AddEvent supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, AddEvent ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Marketing

Airform

Airform is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. Airform supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, Airform ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Marketing

Apollo

Apollo is a digital marketing technology that helps businesses reach, engage, and convert their target audience online. It provides advanced targeting, campaign management, and performance analytics capabilities. Apollo enables marketers to deliver personalized experiences across channels, optimize campaign ROI, and gain actionable insights into customer behavior. With automation features and data-driven optimization, Apollo empowers marketing teams to achieve measurable growth.

Marketing
A

Autopilot

Autopilot is a digital marketing technology that helps businesses reach, engage, and convert their target audience online. It provides advanced targeting, campaign management, and performance analytics capabilities. Autopilot enables marketers to deliver personalized experiences across channels, optimize campaign ROI, and gain actionable insights into customer behavior. With automation features and data-driven optimization, Autopilot empowers marketing teams to achieve measurable growth.

Marketing
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does Customer.io do?

Customer.io is a US based marketing automation platform built around event driven email, in app messaging, push notifications and SMS. It is popular with SaaS companies for lifecycle marketing thanks to its visual workflow editor, native webhooks and developer friendly API. The JavaScript tracker sets the first party cookie _cio (12 months) to recognise visitors.

What is Customer.io?

Customer.io is a marketing automation platform operated by Peaberry Software Inc., headquartered in Portland, Oregon, founded in 2012. It is built around event driven messaging: emails, in app messages, push notifications and SMS triggered by user actions in your product. Customer.io is particularly popular among SaaS companies for lifecycle marketing thanks to its visual workflow editor, native webhooks and developer friendly Track and Journeys APIs. The company offers an EU region (AWS Dublin) since 2021 for European customers seeking data residency.

Cookies and data collected

The Customer.io JavaScript tracker sets the first party cookie _cio (12 months) containing the visitor identifier, and _cio_id when an authenticated user is identified. The tracker forwards events to the Customer.io Track API: pageviews, custom events, identify calls, group memberships. Push notifications use the browser or mobile push tokens, and email deliveries are tracked via tracking pixels and open or click links. No cross site tracking takes place.

GDPR and ePrivacy compliance

The Customer.io tracker and the _cio cookie store behavioural data for marketing purposes and are not strictly necessary under Article 5(3) ePrivacy. Prior consent under Article 6(1)(a) GDPR is required for the cookie and for the email or push opt in. Transactional notifications tied to an existing service relationship (password reset, order confirmation) can rely on Article 6(1)(b) contract performance. Marketing emails and push notifications must follow the PECR and TDDDG opt in rules.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Data transfers

By default Customer.io runs on AWS US East. The EU region (AWS Dublin) keeps the production data inside the EEA but the US support and engineering teams may still access it under EU SCCs (2021/914) and the EU US Data Privacy Framework. The Customer.io DPA must be signed and the chosen region documented in the record of processing activities.

How to implement Customer.io correctly

Load the Customer.io tracker through a CMP that blocks the script until marketing consent is given. Prefer the EU region for European customers and document the choice. Use the server side Track API for transactional events that do not require cookies. Configure double opt in for newsletter subscriptions, an unsubscribe link in every campaign, IP anonymisation in the JavaScript and a retention policy aligned with your legitimate interest assessment.

GDPR consent category

Marketing

Websites using Customer.io must obtain user consent under GDPR regulations.

Legal basisConsent (Article 6(1)(a) GDPR) for marketing emails, push notifications and behavioural tracking under Article 5(3) ePrivacy. Contract performance (Article 6(1)(b)) for transactional messages tied to a service relationship.
Risk levelmedium
Applicable regulationsGDPR, ePrivacy Directive 2002/58/EC, CNIL guidelines, German TDDDG, Spanish LSSI, UK GDPR and PECR, CCPA

DPIA considerations

Customer.io is a medium risk processor: event level behavioural profiling and US transfer. A DPIA is recommended when the platform is used for sensitive segments or for sending automated messages with significant effect. Document the consent flow, the choice between US and EU regions, the Customer.io DPA and the retention period in the record of processing activities.

Sample consent text

We use Customer.io to send behavioural emails, in app messages and push notifications based on your activity. The _cio cookie (12 months) recognises you between visits and the Customer.io API receives your interactions only after you accept the marketing category. Data is processed by Peaberry Software Inc. (United States) under EU Standard Contractual Clauses.

Technical details

Tracking methodJavaScript tracker loaded from track.customer.io, first party cookie _cio (12 months) and _cio_id, in app messaging, push notifications, server side API and webhooks. Event based tracking with user, profile and device attributes for behavioural email and lifecycle marketing.
Server locationUnited States (AWS US East, primary) with optional EU region (AWS Dublin) for European customers. Customer.io is operated by Peaberry Software Inc., headquartered in Portland, Oregon.
Data transferred outside the EUDefault deployments are on AWS US East. An EU region (AWS Dublin) is available since 2021 for European customers, but Customer.io support and engineering teams operate from the United States. Standard Contractual Clauses (2021/914) and the EU US Data Privacy Framework are referenced in the Customer.io DPA.

Third-party domains contacted

track.customer.ioassets.customer.ioin-app.customer.io

Cookies placed

NameTypeDurationPurpose
_ciofirst_party12 monthsCustomer.io visitor identifier used to recognise the browser between visits and link anonymous activity to an identified user when identify is called.
_cio_idfirst_party12 monthsStores the persistent user identifier once the visitor has been authenticated and identified through the Track API.

Customer.io places tracking cookies for advertising — comply with GDPR using FlowConsent.

Get started freeScan your site

Frequently asked questions

Which cookies does Customer.io set?

The JavaScript tracker sets first party cookies _cio (12 months) for the anonymous visitor identifier and _cio_id (12 months) for the authenticated user identifier. No advertising or cross site cookies are set.

Do users have to consent to Customer.io?

Yes. The Customer.io tracker and the _cio cookie are not strictly necessary under Article 5(3) ePrivacy: they exist to track behaviour for marketing. Prior consent under Article 6(1)(a) GDPR is required. Transactional notifications tied to an existing service can rely on contract performance.

What is the legal basis for using Customer.io?

Consent for marketing emails, push and behavioural tracking (6(1)(a) GDPR). Contract performance for transactional notifications (6(1)(b)). Legitimate interest is generally not available for marketing under Article 5(3) ePrivacy.

Does Customer.io transfer data to the United States?

Yes by default. An EU region (AWS Dublin) is available since 2021. Standard Contractual Clauses (2021/914) and the EU US Data Privacy Framework cover the residual transfer when US support and engineering teams access data.

Is a DPIA required for Customer.io?

A DPIA is recommended for sensitive segments or automated messages with significant effect. Document the consent flow, region choice, Customer.io DPA, the retention policy and the lifecycle workflows in the record of processing activities.

How do I implement Customer.io correctly?

Block the tracker in a CMP, prefer the EU region for European customers, use the server side Track API for events that do not require cookies, configure double opt in for newsletters, include an unsubscribe link in every campaign and align the retention period with your legitimate interest assessment.

What are the alternatives to Customer.io?

EU based alternatives: Brevo (France), Plezi (France), Webmecanik (France, open source), Mautic (open source), Sarbacane (France), Iterable (US), Klaviyo (US, EU region available).

How do I keep my cookie policy up to date?

List Customer.io as a marketing automation processor (Peaberry Software Inc.), declare the _cio cookie duration, document the chosen region and the DPA and update the cookie list when Customer.io ships changes.