Customer Consent and Privacy

Customer Consent and Privacy

Cockato tracks individual marketing consent for each customer across three channels, ensuring compliance with GDPR, CCPA, and other privacy regulations.

ChannelPermission CoversRequired For
Email MarketingPromotional emails, newslettersEmail campaigns
SMS MarketingText message campaignsSMS campaigns
Push MarketingWallet push notificationsPush campaigns

All marketing features respect these consent flags. A customer will never receive a campaign on a channel they have not opted into.

During Signup

When customers register through your signup form:

  1. Consent checkboxes are displayed for each channel.
  2. All checkboxes default to unchecked (opt-in model).
  3. Customers actively choose which channels to allow.
  4. Consent timestamps are recorded for audit purposes.

⚠️ Important: Consent defaults to opt-in (unchecked) to comply with GDPR and similar regulations. Pre-checked consent boxes are not permitted under most privacy laws.

Terms and Conditions

If your signup form includes terms acceptance:

Data RecordedPurpose
Acceptance timestampLegal proof of agreement
Terms versionWhich version was accepted
IP addressGeographic compliance verification

Customer Self-Management

Customers can update their consent preferences at any time through the Customer Portal:

  1. Customer visits the portal link.
  2. Verifies identity via email OTP code.
  3. Toggles their communication preferences on/off.
  4. Changes take effect immediately.
  5. A consent_updated_at timestamp is recorded.

💡 Tip: Include a link to the Customer Portal in your email footers so customers can easily manage their preferences.

Admin View

In Customer Management, each customer's consent status is visible:

InformationLocation
Email consent statusCustomer detail dialog
SMS consent statusCustomer detail dialog
Push consent statusCustomer detail dialog
Last consent updateCustomer detail dialog
Terms accepted dateCustomer detail dialog

⚠️ Important: Admins cannot override customer consent choices. Only customers themselves can change their marketing preferences through the portal. This is by design for regulatory compliance.

Impact on Campaigns

Consent is enforced automatically at every level:

StageHow Consent Is Applied
Segment creationConsent can be used as a filter criterion
Recipient estimationOnly consented customers are counted
Campaign sendingNon-consented customers are excluded
AnalyticsMetrics reflect only consented recipients

Example

If you send an email campaign to a segment of 500 customers, but only 350 have email consent:

  • Estimated recipients: 350
  • Emails sent: 350
  • The 150 without consent are silently excluded

Data Retention and Audit Trail

Cockato maintains a complete consent audit trail:

Data PointRetention
Current consent statusAlways current
Consent update timestampStored permanently
Terms acceptance timestampStored permanently
Signup date and methodStored permanently

This data is available for regulatory audits and customer data requests.

Compliance Features

GDPR (Europe)

  • Explicit opt-in consent model
  • Right to withdraw consent at any time
  • Data portability (customer data export)
  • Right to erasure (account deletion)

CCPA (California)

  • Do Not Sell compliance
  • Right to know what data is collected
  • Right to delete personal information

General Best Practices

  • Never pre-check consent boxes on signup forms
  • Provide easy opt-out via Customer Portal links in every communication
  • Honor requests promptly — consent changes take effect immediately
  • Document everything — timestamps provide your compliance evidence
  • Review regularly — audit consent rates to ensure healthy opt-in percentages

Ready to get started?

Try Cockato for free and see how it can help grow your business.

Get Started Free