Comments (1)
Thank you for bringing this to our attention. Our technical and policy review determined that klaviyo.com meets our definition of tracking and that this domain is properly classified.
Our technical review revealed Request URLs from Klaviyo subdomains are present on thousands of 3P sites. Although the Bugzilla report says “. . . all tracking and analytics code is under static-tracking.klaviyo.com, all other subdomains serve experiences to brand's websites and should be allowed . . .”; we are also seeing that static.klaviyo.com points to the same IP as static-tracking.klaviyo.com and we are also seeing what appear to be tracking requests from sub-domain a.klaviyo.com, including but not limited to the following:
⁃ https://www.pierreherme.com/ Request URL https://a.klaviyo.com/onsite/track-analytics?company_id=Yaq7Ec
⁃ https://www.evike.com/ Request URL https://a.klaviyo.com/onsite/track-analytics?company_id=LZBAWh
In addition, several portions of the Klaviyo policy and website marketing seem to support the current classification, including but not limited to the following:
Website marketing:
⁃ “Send hyper-personalized, targeted messages with Klaviyo’s intelligent marketing automation platform. With your data in one place, you can efficiently automate your workflow across marketing channels.” https://www.klaviyo.com/marketing-automation
⁃ “Real-time data makes it possible, increasing customer engagement with personalized, relevant messages.” https://www.klaviyo.com/features/segmentation
⁃ “Maximize your sales with omnichannel campaigns” https://www.klaviyo.com/features/campaigns
⁃ “Using Klaviyo’s built-in CDP and its CRM functionality, you can gain a comprehensive understanding of your customers’ behavior and preferences. Easily view their purchase history, email engagement, and website activity all in one place.” https://www.klaviyo.com/features/customer-profiles
Privacy policy https://www.klaviyo.com/legal/privacy/privacy-notice talks about data collection:
⁃ “Klaviyo as a Data Processor: In providing our Service, our customers may collect data in our products and services, or we may collect data on their behalf, which may include personal information or data about our customers’ end users (“Customer Data”). In such instances, Klaviyo acts as a “data processor” (or similar term under applicable laws), and we have contractually committed ourselves to process Customer Data on behalf and under the instruction of the respective customer, who is the data controller. This Privacy Notice does not apply to the processing of Customer Data and we recommend you read the privacy notice of the respective customer if their processing concerns your personal information.”
⁃ “Log Data: Including your internet protocol (IP) address, operating system, browser details such as type, ID, and configuration, unique identifiers, local and language settings; session logging, heatmaps and scrolls; screen resolution, ISP, device type and version, the referring URL, date/time of your visit, the time you spent on our services and any errors that may occur during your visit to our Services.”
⁃ “Analytics Data: Including the electronic path you take to our services, through our services and when exiting our services, UTM source, as well as your usage and activity on our services, such as the time zone, activity information (first and last active date and time), usage history (flows created, campaigns scheduled, emails opened, total log-ins) as well as the pages, links, objects, products and benefits you view, click or otherwise interact with. We may also analyze the interaction between you and your customer using our Services.”
⁃ “Digital Behavioral Data: Web page interactions (clicks, hovers, focus, mouse movements, browsing, zooms and other interactions), referring web page/source through which you accessed the Sites, and statistics associated with the interaction between device or browser and the Sites.”
⁃ Regarding the use of data “Opportunity tracking, conversion and lead generation”
⁃ “Advertising Partners: We may share certain personal information (including information collected through cookies) with our advertising service providers and vendors in order to advertise our Services to you.”
⁃ “We or the online advertising networks use this information to make the advertisements you see online more relevant to your interests. We may also display targeted advertising to you through social media platforms, such as LinkedIn, Facebook, Twitter, Google, and others.”
Although we understand Klaviyo is offering a service, our review has determined that Klaviyo also is collecting and retaining data about particular devices/users on websites that Klaviyo does not own, and this activity fits our definition of tracking: https://disconnect.me/trackerprotection.
Based on this analysis we believe this domain is properly classified but please feel free to provide additional information and we’ll be sure to consider.
from disconnect-tracking-protection.
Related Issues (20)
- Don't block the entire wp.com domain, block only its tracking subdomains
- Block OneTrust Privacy Annoyances HOT 1
- `app.datadoghq.eu` fails to load due to `datadoghq.com` rule HOT 2
- Japottatweet
- Consider reclassifying inmobi.com from tracker to content tracker HOT 1
- x.com is missing from twitter's property HOT 2
- Tinypass breaks logins and accounts HOT 1
- Don't block Discord CDN, only root domain HOT 3
- Consider reclassifying `consent.cookiebot.com` from Advertising to Content HOT 2
- OneTrust Privacyportal HOT 6
- ondemand.com unclear why on the list HOT 1
- Regarding a.js entries HOT 1
- `banner-rotation.com` seems to be a outdated asset for Awin HOT 1
- Only block analytics subdomain for Coveo to prevent search pages loading issues HOT 7
- Please remove our domains from the trackers list HOT 5
- Remove wistia from trackers list HOT 2
- Remove our domains from the trackers list to avoid disrupting the search functionality. HOT 3
- sardine.ai tracking and fingerprinting HOT 2
- nocodelytics.com tracking HOT 2
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from disconnect-tracking-protection.