Compliance frameworks, security audits, and quality certifications this company maintains.
Klaviyo maintains SOC 2 Type II certification covering its email and SMS marketing platform, ensuring the security, availability, and confidentiality controls protecting 143,000+ customers' marketing data and subscriber lists are independently audited annually.
Klaviyo's platform supports GDPR compliance for European e-commerce brands, providing consent management, data subject request tools, and Data Processing Agreements to enable lawful processing of EU subscriber email and SMS data.
Klaviyo's platform enables California Consumer Privacy Act compliance for its US e-commerce customers, offering opt-out mechanisms, consent tracking, and data deletion workflows for California resident subscriber data managed through Klaviyo.
Klaviyo enforces CAN-SPAM Act compliance across all email campaigns sent through its platform, automatically including unsubscribe links, honoring opt-out requests within 10 business days, and monitoring sender reputation to protect customer deliverability.
Klaviyo's SMS platform is designed for Telephone Consumer Protection Act compliance, requiring explicit prior written consent for marketing texts, providing double opt-in flows, and maintaining STOP keyword opt-out processing for all Klaviyo SMS customers.
Klaviyo holds ISO 27001 certification for its information security management system, demonstrating that its controls for protecting customer data — including email subscriber lists, behavioral data, and purchase history — meet international security standards.
Klaviyo maintains PCI DSS compliance for its integrations with Shopify and other e-commerce platforms, ensuring that payment card data referenced in purchase event triggers is handled securely and never stored in Klaviyo's marketing data layer.
Klaviyo supports Canadian Anti-Spam Legislation compliance for its Canadian e-commerce customers, enabling express and implied consent tracking, managing unsubscribe obligations, and providing CASL-required sender identification fields in all marketing emails.
Klaviyo adheres to ISO 27018, ensuring that personally identifiable information processed in its cloud-based email and SMS marketing platform is handled with strict privacy controls protecting sender and subscriber data.
Klaviyo's marketing platform and customer-facing dashboards conform to WCAG 2.1 AA accessibility guidelines, ensuring that marketers of all abilities can build, analyze, and optimize campaigns without barriers.