Email Marketing & Newsletter
Brevo
EU-Made Report an errorPanel rating · 6 judges · How to read the stars
Category median
Sovereignty: 2 of 4 dimensions proven
0–5 in half steps. 5 means the rubric's top anchor is met on the evidence.
by Sendinblue SAS · www.brevo.com
Compare with Mailchimp → Report an error on this page Is this your product? →
Read this page as one judge. Each weighs the same scores by what they care about.
The panel's verdict
Brevo, an email marketing and newsletter platform from Sendinblue SAS, tops out on integrations at a uniform 8: a REST API with published rate limits, seven official SDKs, real-time webhooks, and a Shopify integration syncing purchase and abandoned-cart data. Campaign and automation and deliverability sit at 6 to 7, resting on SPF, DKIM and DMARC setup and a Deliverability Center with six months of history. The weakest is consent and proof at 4 to 6, with no public information on what stored consent records contain, unsubscribe mechanics, or switching open and click tracking off. Pricing transparency spans 5 to 7: tier prices are public — Starter from €7, Standard from €15, Professional from €499, Enterprise custom — but credit, overage, dedicated-IP and SMS rates are not, and the captured pages give different figures for the free plan's limits. Sovereignty at 6 to 7 rests on EU hosting with named providers, while the terms name transfers to the USA and India and the transmission of AI input and output including customer content to third-party AI providers. The flagged splits flagged none.
Speaks for it
- Integrations scored a uniform 8 on a documented REST API, official SDKs in seven languages, published rate limits and real-time webhooks
- Abandoned-cart, welcome and birthday automations run off web-tracking segmentation and Shopify purchase events
- Automatic SPF, DKIM and DMARC configuration and a Deliverability Center with six months of history are documented
- Double opt-in is the documented default, backed by consent groups and a self-serve preference centre for topic-level control
- Hosting sits on named EU providers — OVH in France and Germany, Google Cloud in Belgium — with downloadable ISO 27001:2022 certification and a TÜV Rheinland audit
Held against it
- Consent and proof drew the lowest scores, 4 to 6, with no public information on what stored consent records contain, on unsubscribe mechanics, or on switching open and click tracking off
- Exit is tight — customer content is deleted immediately and irrevocably on termination unless requested within 24 hours, and accounts inactive for six months can be deleted
- No public information appears on email-credit, overage, dedicated-IP or SMS rates, and the captured pages give different figures for the free plan's contact and send limits
- The terms state AI input and output including customer content is transmitted to third-party AI providers such as OpenAI, and we found no public confirmation of a complete subprocessor list
- We found no public information on exporting engagement history, campaigns or templates
Best for
- You run a shop on Shopify, WooCommerce or PrestaShop and want purchase and abandoned-cart events driving recovery automations
- Your team builds in-house tooling and wants a documented API with official SDKs, published rate limits and an API playground
- You want EU hosting on named providers with a downloadable ISO 27001:2022 certificate and a GDPR Article 28 data processing agreement inside the terms
- You want automation workflows included on the free plan before committing to a paid tier
Avoid if
- You must be able to switch open, click or web tracking off — tracking is advertised as an included feature and we found no public information on limiting it
- Your exit plan counts on exporting campaigns, templates or engagement history — customer content is downloadable during the subscription and for 24 hours after termination, and we found no public information on exporting these
- You need to compute the full invoice up front — ask the vendor: the public pages we read do not show it
- You must keep customer content away from third-party AI providers — the terms name the transmission of AI input and output including customer content to them
The scores
Campaigns & automation
Show reasoningHide reasoning
How this is scored
Building the mail and the journey around it: editor, templates, segmentation, triggered sequences, A/B testing.
0 — One-off broadcasts from a fixed template; no segmentation and no automation of any kind.
3 — A drag-and-drop editor and simple list segmentation, but automation is a single welcome mail and there is no testing.
5 — Reusable templates, attribute and behaviour segmentation, multi-step automations on common triggers, and subject-line A/B testing.
8 — A visual journey builder with branching on behaviour and data, dynamic content per segment, send-time optimisation, and testing that reports significance rather than raw counts.
10 — Journeys treat the whole lifecycle: event-driven entry from other systems, branching on any attribute or event, holdout groups for measurement, and automations a marketer can read months later without a diagram.
The CRM Manager
Automation is genuinely multi-step: a workflow editor with smart triggers, website events usable as automation and engagement conditions, Shopify purchase and abandoned-cart data driving recovery, and ready welcome and anniversary journeys. Segmentation can run on web tracking, unengaged subscribers can be excluded automatically, and there is an AI send-time feature plus subject-line A/B testing. We found no public information on branching, dynamic content per segment, holdout groups, or testing that reports significance rather than raw counts, so it stops short of the top of the scale. 8 9 16 17 1
The Deliverability Engineer
A workflow editor with smart triggers across the platform, Shopify purchase and abandoned-cart events driving recovery flows, behaviour segmentation from website tracking, AI best-time sending and subject-line A/B testing on top of ready-made workflows and templates. I found no public information on branching journeys, per-segment dynamic content, or tests reporting statistical significance. 8 9 16 17
The Data Protection Officer
A drag-and-drop editor, ready-made and custom automations triggered on website events, segmentation that includes web tracking, and subject-line A/B testing are all publicly documented, with automation workflows already in the free plan. We found no public information on journey branching, per-segment dynamic content, or testing that reports statistical significance rather than raw counts, so this stops short of the top of the range. 8 9 17 1
The Shop Owner
The workflow editor with smart triggers covers exactly what my shop runs — abandoned-cart recovery, welcome sequences, birthday and anniversary mails — on top of a drag-and-drop editor, behaviour segmentation via web tracking and website events, subject-line A/B testing and AI send-time selection. We found no public information on branching journeys, dynamic content per segment, significance reporting on tests, or revenue attributed per campaign, so I stop short of the top band. 8 9 17 1
The Integrator
Templates, segmentation that includes web tracking, ready-made and custom automation workflows with welcome, birthday and abandoned-cart triggers, subject-line A/B testing and AI send-time selection are all documented. We found no public information on journey branching on behaviour and data, dynamic content per segment, or tests that report statistical significance, so I stop below the full journey-builder mark. 8 9 17 1
The Skeptic
A drag-and-drop editor, ready-made and custom workflow builders, welcome, birthday and abandoned-cart automations, segmentation that includes website tracking, AI send-time selection, and subject-line or content A/B testing are all documented — comfortably past the middle level. We found no public information on branching journeys on behaviour and data, dynamic content per segment, holdout groups, or testing that reports significance. 8 1 9 17 2
Deliverability infrastructure
Show reasoningHide reasoning
How this is scored
Whether the mail arrives — authentication, sending reputation, bounce and complaint handling — judged on what the vendor documents rather than the inbox rate it advertises.
0 — No documentation of authentication or bounce handling; deliverability appears only as a marketing number.
3 — SPF and DKIM setup documented, but no DMARC guidance, no stated bounce policy and shared sending only.
5 — SPF, DKIM and DMARC documented with a custom sending domain, automatic hard-bounce suppression, and complaint-loop handling stated.
8 — The above plus dedicated-IP options with a documented warm-up, seed or inbox-placement testing, engagement-based sunsetting, and published guidance on list hygiene.
10 — Deliverability is operated as a service: reputation monitoring surfaced to the customer, per-domain and per-ISP diagnostics, enforced authentication before first send, and postmaster or blocklist handling the vendor documents doing on the customer's behalf.
The CRM Manager
SPF, DKIM and DMARC configuration is documented with step-by-step DNS setup, domain authentication has a documented API, dedicated IPs are offered on Professional and Enterprise plans, and a Deliverability Center surfaces a score with open-rate and bounce drivers over six months of history. Automatic exclusion of unengaged subscribers is stated. We found no public information on dedicated-IP warm-up, seed or inbox-placement testing as a tool, a stated hard-bounce suppression policy, or list-hygiene guidance; the up-to-99% figures appear as marketing copy rather than evidence. 17 10 11 9
The Deliverability Engineer
Automatic SPF, DKIM and DMARC configuration is documented alongside a domain-authentication flow, shared IPs on all plans and a dedicated IP option on Professional and Enterprise, with automatic exclusion of unengaged subscribers and a Deliverability Center surfacing a score plus open and bounce drivers over six months of history. I found no public information on automatic hard-bounce suppression, dedicated-IP warm-up, or seed and inbox-placement testing — and the advertised 99% inbox-placement figures count for nothing with me. 9 10 11 17
The Data Protection Officer
SPF, DKIM and DMARC configuration is documented with custom domain authentication and three verification paths, dedicated IP addresses are offered on higher plans, unengaged subscribers can be excluded automatically, and a Deliverability Center surfaces a score, bounce drivers and six months of history to the customer. We found no public information on IP warm-up guidance, seed or inbox-placement testing, or a stated bounce-suppression and complaint-loop policy; the 99% inbox placement figure appears as marketing copy. 17 10 11 9
The Shop Owner
Automatic SPF, DKIM and DMARC configuration is documented with three domain-verification routes and public API endpoints, dedicated IPs sit on the Professional and Enterprise plans, transactional and marketing streams can be split on separate IPs for free, unengaged subscribers can be auto-excluded, and a Deliverability Center surfaces a score, bounce and open drivers, and six months of history. We found no public information on warm-up guidance, seed or inbox-placement testing, or published list-hygiene practice, and the 99% inbox-placement figure appears only as a marketing claim. 17 10 11 9
The Integrator
SPF, DKIM and DMARC with a custom sending domain are documented down to API endpoints for validation and authentication, shared IPs ship on all plans with dedicated IPs from Professional, and a Deliverability Center surfaces a score with six months of history while unengaged subscribers can be auto-excluded. We found no public information on dedicated-IP warm-up, seed or inbox-placement testing, automatic hard-bounce suppression, or blocklist handling done on the customer's behalf, and the 99% inbox figure appears only as marketing copy. 17 10 11 9
The Skeptic
Automatic SPF, DKIM and DMARC configuration with a custom sending domain is documented, dedicated IPs sit on Professional and Enterprise, a Deliverability Center surfaces a score with open-rate and bounce drivers over six months of history, and unengaged subscribers can be excluded automatically. We found no public information on dedicated-IP warm-up, seed or inbox-placement testing, or an explicit automatic hard-bounce suppression policy, and the 99% inbox-placement figure appears only as a marketing number. 17 10 11 9
Consent, proof & tracking limits
Show reasoningHide reasoning
How this is scored
How subscribers arrive and what the sender can prove afterwards: double opt-in, logged consent, unsubscribe handling, and whether open and click tracking can be limited or switched off.
0 — Single opt-in with no consent record; tracking is always on and cannot be disabled.
3 — Double opt-in available but not the default, and the consent record is a timestamp without the source, IP or the wording consented to.
5 — Double opt-in as the documented default with a stored consent record including source and timestamp, one-click unsubscribe, and tracking that can be turned off per campaign.
8 — Consent is reproducible as evidence: the confirmation mail and form wording versioned and retrievable per subscriber, unsubscribe honoured across lists, tracking off-by-default available, and retention rules for inactive subscribers.
10 — Built for the burden of proof: a per-subscriber consent history an authority would accept, documented handling of Art. 15 access and Art. 17 erasure requests, pixel-free and link-tracking-free sending as a supported mode, and preference-centre granularity rather than all-or-nothing.
The CRM Manager
Double opt-in is the documented default, consent groups with a self-serve preference centre give contacts topic-level granularity rather than all-or-nothing, and the GDPR pages document erasure within 30 days, access and portability rights, and forwarding of requests sent directly to the vendor. The proof layer is where the captures go quiet: we found no public information on a stored consent record with source and wording, on unsubscribe handling across lists, or on any way to limit or switch off open and click tracking. 9 13 12 4
The Deliverability Engineer
Double opt-in is documented as the default with opt-in-only language, consent groups give contacts a self-serve preference centre with topic-level granularity, and access, erasure within 30 days and forwarded data-subject requests are all documented. I found no public information on what the stored consent record contains, on one-click unsubscribe mechanics, or on limiting or switching off open and click tracking. 9 12 13
The Data Protection Officer
Double opt-in is documented as the default and the consent groups plus preference centre give each contact self-serve, topic-level control — with documented handling of access and erasure requests including removal across Brevo accounts — which is real progress. But the proof a complaint demands is only half-built: we found no public information on what the stored consent record contains beyond timestamps, and no public information on switching open, click or web tracking off, while tracking is advertised as an included feature. 9 13 12 17
The Shop Owner
Double opt-in is the documented default, and the newer consent groups with a self-serve preference centre give contacts topic-level granularity rather than all-or-nothing — good for a shop mailing buyers on several lines. Erasure and subject-request handling is documented with a 30-day window, but we found no public information on what the stored consent record contains, on unsubscribe mechanics, or on whether open, click and web tracking can be limited or switched off. 9 13 12
The Integrator
Double opt-in is the documented default, consent groups with a self-serve preference centre give topic-level granularity, and erasure handling is written down to removal across accounts when a contact writes to Brevo directly. We found no public information on what a stored consent record contains, on unsubscribe mechanics, or on switching open and click tracking off — tracking is listed as an included feature. 9 13 12 4
The Skeptic
Double opt-in is documented as the default, opt-in-only collection with pre-checked boxes prohibited, a preference centre with consent groups gives per-topic granularity, and handling of access, erasure and portability requests with 30-day erasure is written down. We found no public information on what the stored consent record contains beyond the opt-in itself, on one-click unsubscribe mechanics, or on whether open and click tracking can be limited or switched off. 9 12 13 4
List ownership, import & exit
Show reasoningHide reasoning
How this is scored
Whether the list and its history remain the sender's: import with attributes intact, full export including engagement history, deletion that executes, and no metering that prices leaving out of reach.
0 — Export is addresses only; engagement history, segments and automations cannot leave.
3 — CSV import and export of subscriber fields, but engagement history and unsubscribe state are not exportable.
5 — Full subscriber export including custom attributes, subscription status and unsubscribe state, plus API access sufficient to sync elsewhere.
8 — Everything exportable in open formats — subscribers, engagement history, campaigns and templates — with documented deletion of a subscriber across all records, and no export throttling.
10 — Exit is a documented feature: full-fidelity export of the whole account, contractual data return, deletion that is evidenced rather than asserted, and migration tooling in both directions.
The CRM Manager
Import and export are first-class API operations — asynchronous import with a callback URL and consent groups, export to CSV with selectable attributes, list memberships, timestamps, and email and SMS subscription status — and deletion of a contact erasing all their personal data is documented. We found no public information on exporting engagement history, campaigns or templates. The captured terms also make exit tight: customer content is deleted immediately and irrevocably on termination unless requested within 24 hours, recovery for the last monthly subscription amount is possible, and accounts inactive for six months can be deleted. 14 15 12 3
The Deliverability Engineer
Import and export run through documented endpoints with selectable attributes, email and SMS subscription status, timestamps and csv output, the GDPR page pledges export for transfer to a third party or competitor, and customer content is downloadable in an interoperable format for as long as the subscription runs. The captured terms give only a 24-hour window after termination before immediate and irrevocable deletion, and I found no public information on exporting engagement history, campaigns or templates. 3 12 14 15
The Data Protection Officer
Contacts import and export are documented API operations with selectable attributes, added and modified timestamps, list membership and email and SMS subscription status, and deletion of a subscriber across all records — including across Brevo accounts — is written down. The exit door is narrow: content is downloadable in an interoperable format only during the subscription and within twenty-four hours after termination, an account unused for six months is deleted, and we found no public information on exporting engagement history, campaigns or templates. 15 14 12 3
The Shop Owner
Import and export are real API operations — attributes selectable, subscription and SMS status exportable, list IDs and timestamps included, blacklist options on import — and portability to a competitor is promised with contact deletion documented. We found no public information on exporting engagement history, campaigns or templates, and the terms make customer content available for only 24 hours after termination before irrevocable deletion, which makes exit something to plan rather than a relaxed feature. 14 15 12 3
The Integrator
Import and export are documented endpoints — CSV or JSON in with a completion callback, export with selectable attributes, metadata and email and SMS subscription status — and the GDPR pages commit to exporting data for transfer to a competitor. We found no public information on exporting engagement history, campaigns or templates, the export endpoint lists a too-many-requests error, and exit is tight: termination deletes content immediately and irrevocably unless requested within 24 hours, with the last monthly subscription amount named as a possible recovery fee. 14 15 12 3
The Skeptic
Import and export run through a documented API with selectable attributes including marketing subscription status and contact metadata, and the terms grant download of customer content in an interoperable format during the subscription, with deletion on request. We found no public information on exporting engagement history, campaigns or templates; the captured terms delete all content immediately and irrevocably on termination unless it is requested within twenty-four hours, and inactive accounts are deleted after six months — the exit door exists, but it is narrow and time-boxed. 14 15 3 12
Integrations & API
Show reasoningHide reasoning
How this is scored
The connection surface a newsletter lives on: shop and CRM systems, events in and out, webhooks, and an API somebody can build against without a partner agreement.
0 — No API and no named integrations; the list is maintained by CSV upload.
3 — A handful of native integrations and a read-mostly API, with no webhooks and no documented rate limits.
5 — Named integrations for common shop and CRM systems, a documented REST API with keys, and webhooks for the core subscriber events.
8 — Maintained bidirectional integrations with named systems including at least one major shop platform, event webhooks with retries, documented rate limits, and a sandbox.
10 — The tool is a component rather than a destination: transactional and marketing sending on one API, events flowing both directions, versioned API with a deprecation policy, and integrations the vendor maintains rather than lists.
The CRM Manager
A real developer surface: a documented v3 REST API with key authentication, official maintained SDKs in seven languages, inbound and outbound webhooks covering delivered, opened, clicked, bounced and spam, inbound parsing, idempotency, published rate limits, and an API playground for live test calls. The marketplace names the systems a lifecycle programme lives on — Shopify syncing purchase and abandoned-cart data, WooCommerce, Salesforce, HubSpot, Zapier, Segment — and transactional and marketing sending sit on the same API on all plans. We found no public information on webhook retry policy or an API versioning and deprecation policy. 17 16 9 14 2
The Deliverability Engineer
Official, maintained SDKs in seven languages, documented rate limits of 1,000 requests per second on all plans, real-time webhooks for delivered, opened, clicked, bounced and spam events, inbound parsing, an API playground for live endpoint tests, transactional sending on every plan, and a marketplace with named Shopify, WooCommerce and WordPress integrations — Shopify syncing purchase data and abandoned carts. I found no public information on webhook retry behaviour or a versioning and deprecation policy for the API. 2 9 16 17
The Data Protection Officer
More than 150 named integrations include Shopify with purchase and abandoned-cart sync, official SDKs cover seven languages, real-time webhooks report delivery, opens, clicks, bounces and spam complaints, rate limits are published per plan, and an API playground lets developers test live before writing code, with transactional and marketing sending on the same API. We found no public information on webhook retry behaviour or a versioned deprecation policy, which is what separates this from the very top. 8 16 17 9 2
The Shop Owner
The Shopify integration syncs purchase data and abandoned cart details to trigger recovery, one-click connections cover WordPress, Shopify and PrestaShop, and the marketplace lists WooCommerce, BigCommerce, Stripe and Klarna — that is my shop wired end to end. Real-time webhooks for delivered, opened, clicked, bounced and spam events, documented rate limits per plan, seven official SDKs and an API playground to test endpoints round it out; we found no public information on webhook retries or an API deprecation policy. 16 9 17 14
The Integrator
This is one I can build against: a documented REST API with key authentication, official SDKs in seven languages, published rate limits per plan (1,000 requests per second on all plans, 2,000 on Professional and Enterprise, 6,000 Enterprise-only), real-time webhooks for delivered, opened, clicked, bounced and spam plus inbound parsing, idempotency keys, an API playground for live endpoint testing, transactional and marketing sending on one API, and a Shopify integration syncing purchase and abandoned-cart data. We found no public information on webhook retry behaviour or a deprecation policy, and the marketplace's Developed-by filter alongside a technology-partner contact form suggests not every listing is vendor-maintained — that caps it at the connection-surface mark for me. 17 16 9 2 14
The Skeptic
A marketplace naming Shopify, WooCommerce, Salesforce, HubSpot and dozens more, one-click WordPress, Shopify and PrestaShop connections, a documented REST v3 with api-key authentication, published rate limits rising from 1,000 to 2,000 requests per second by plan, real-time webhooks for delivered, opened, clicked, bounced and spam events, inbound parsing, official SDKs in seven languages, an API playground, and transactional and marketing sending on one API. We found no public information on webhook retry behaviour or an API versioning and deprecation policy. 16 17 8 9 14
European sovereignty
panel opinion
Show reasoningHide reasoning
How this is scored
Where subscriber data and behavioural tracking live, who the contracting entity is, and which subprocessors touch the send. Independently sourced by the sovereignty pipeline; scored here as this buyer weighs it — which in this category is heavily.
0 — US vendor and contracting entity, US hosting, subprocessors unnamed; subscriber behaviour leaves the EU with no stated basis.
3 — EU hosting offered as an option or for storage only, while sending, tracking or support access remains non-EU, or the subprocessor list is absent.
5 — EU hosting as standard and an EU contracting entity, but parts of the chain — sending infrastructure, analytics, support tooling — are non-EU without an explained safeguard.
8 — EU or DACH hosting with a named data-centre provider, EU contracting entity, complete subprocessor list published, and any non-EU processing named with its legal basis.
10 — Sovereign end to end and evidenced: vendor, entity, hosting, sending and every subprocessor in the EU, certification published, and no transfer that needs a Schrems II argument to survive.
The CRM Manager
Contracting is with the French parent Sendinblue SAS, hosting is stated as EU-only on named providers — OVH in France and Germany, Google Cloud in Belgium, the latter a US-headquartered company — and ISO 27001:2022 certification is downloadable with a TÜV Rheinland audit of the technical and organisational measures. Non-EU transfers to the USA and India are named with their basis in adequacy decisions or standard contractual clauses. Subprocessors are partly named — OpenAI and Chatbase for chatbots, Karumi, the payment providers — and the privacy policy states all subprocessors are listed in the DPA, but we found no published complete list on the captured pages, and the EU-only hosting statement sits in homepage marketing copy while AI input and output including customer content is transmitted to third-party AI providers. 3 4 1 7 5
The Deliverability Engineer
EU hosting is standard on named infrastructure — OVH in France and Germany plus Google Cloud in Belgium — under a French contracting entity, with a downloadable ISO 27001:2022 certificate and transfers to the USA and India named with their Data Privacy Framework or standard-contractual-clause basis, while the privacy policy names OpenAI, Chatbase, Karumi and the payment providers. It stops short of the top rung: the complete subprocessor list could not be confirmed on the vendor's own pages, Google Cloud is a US-headquartered host, and customer content including AI input and output is passed to third-party AI providers. 1 3 4 7
The Data Protection Officer
Hosting is EU-standard with named providers — OVH in France and Germany, Google Cloud in Belgium — under a French contracting entity, with ISO 27001 published and a TÜV Rheinland report on the technical measures. My standing question still needs a Schrems II argument to answer: the privacy policy documents transfers to the USA and India on the basis of the Data Privacy Framework or standard contractual clauses, the named third parties include US companies such as OpenAI and PayPal, and a complete subprocessor list on the vendor's own captured pages was not confirmed. 1 3 4 7 5
The Shop Owner
Hosting is EU as standard with named providers — OVH in France and Germany, Google Cloud in Belgium — under a French contracting entity with a German subsidiary, transfers to the USA and India are named with their legal basis under adequacy decisions or standard clauses, and the ISO 27001:2022 certificate is downloadable. What keeps me below full marks: we found no confirmation of a complete subprocessor list published on the vendor's own pages, and the terms state AI input and output including customer content is transmitted to third-party AI providers such as OpenAI. 1 3 4 6
The Integrator
Hosting is EU with named providers — OVH in France and Germany, Google Cloud in Belgium — under an EU entity, with downloadable ISO 27001:2022 certification, a TÜV Rheinland audit of the technical measures, an Article 28 GDPR data processing agreement inside the terms, and transfers to the USA and India named with adequacy decisions or standard clauses as the basis. The captured pages name different entities for contracting and control — Sendinblue SAS in Paris in the terms, Brevo GmbH in Berlin as controller — the full subprocessor list is referenced to the data processing agreement rather than shown, and AI input and output including customer contents are transmitted to third-party AI providers, so I hold this just under the fully evidenced mark. 1 4 3 7 6
The Skeptic
Hosting on named EU providers (OVH in France and Germany, Google Cloud in Belgium) and an EU contracting entity — the French parent Sendinblue SAS — are documented, third-country transfers to the USA and India are named with adequacy or standard-clause bases, and ISO 27001:2022 has a downloadable certificate. The complete subprocessor list is stated to sit in the data processing agreement but we found no public confirmation of it, the named processors include US providers such as OpenAI receiving AI input and output that can include customer content, and the EU-hosting statement sits in homepage marketing copy — we found no public information on where the sending infrastructure itself is located. 1 3 4 7 6
Pricing transparency
Show reasoningHide reasoning
How this is scored
Whether a sender can compute the real invoice for their list size and send volume — including overage, extra domains and automation limits — from public pages alone.
0 — No public prices at all; every tier is a sales conversation.
3 — A headline price per contact tier exists, but send limits, overage rates or the tier where automation begins are not stated.
5 — Contact-tier prices public with the billing period stated and send limits given, but at least one commonly needed capability sits in an unpriced tier or add-on.
8 — Every tier priced publicly with contact and volume limits, overage rates, feature boundaries and VAT treatment stated; only genuinely custom volume lacks a number.
10 — Complete price computability: a calculator producing the annual invoice for a given list size and send frequency, including overage, additional domains and dedicated IPs.
The CRM Manager
The tiers are public with volumes and periods stated — Starter from €7, Standard from €15, Professional from €499 per month "From 150,000 emails per month", Enterprise at custom price from 1 million emails per month, and a free plan at 300 emails a day — and the terms state prices exclude VAT and additional fees, with the currency depending on region, which matches the different figures in euros and dollars across the captured pages. We found no public information on overage rates when the monthly email volume is exceeded, on the price of a dedicated IP, or on SMS beyond "volume- and destination-dependent", and there is no calculator producing an annual invoice. 17 3 2 9
The Deliverability Engineer
Public tier prices with volume limits and the billing period are stated — Starter from €7 per month at 5,000 emails, Professional from €499 per month from 150,000 emails, a yearly toggle at minus 10% — and the terms state that prices are exclusive of VAT with a 30-day price-change notice. I found no public information on how email-credit pricing scales, on the cost of a dedicated IP address, or on contact limits above the free plan's 2,000. 2 3 9 17
The Data Protection Officer
Every named tier carries a public price with billing period and monthly send volume — Starter from €7 a month at 5,000 emails, Professional €499 a month at 150,000 — and the terms state prices exclude VAT and follow the currency of the buyer's region. The invoice still cannot be computed end to end: we found no public information on overage or per-email credit rates, dedicated IP pricing, or SMS rates beyond a price that depends on volume and destination, and contact allowances for the middle tiers are not stated. 17 2 3 9
The Shop Owner
Tier prices are public with monthly volumes and the yearly discount — Starter at €7, Standard at €15, Professional at €499 — VAT treatment is explicitly stated as exclusive, the free tier's 2,000 contacts and 300 mails per day are stated, and add-ons like removing the logo at 8,10 € per month carry numbers. But the email-credit model is described only as priced by email number with no rate stated, contact limits per paid tier are unclear across the captured pages, and SMS campaigns are described as volume- and destination-dependent without figures, so I cannot fully compute my invoice. 17 2 3 9
The Integrator
Volume tiers are public with the billing period and VAT treatment stated — Starter from 5,000 emails per month at €7, Standard at €15, Professional from 150,000 at €499, Enterprise custom — alongside priced add-ons such as removing the logo at 8,10 € per month. We found no public information on overage rates, dedicated-IP or SMS pricing, and the credit model's price depends on the number of emails without a visible rate table; the captured pages also give different figures for the free plan's contact and send limits, so the real invoice is not fully computable from public pages. 17 2 3 9
The Skeptic
Public tier prices carry monthly and annual billing and per-tier email volumes — Starter from €7 at 5,000 emails per month, Standard from €15, Professional from €499 at 150,000, Enterprise custom from one million — VAT exclusion is stated, and add-ons such as branding removal at €8.10 per month carry prices. We found no public information on contact limits for the paid tiers, on email-credit or overage rates, or on the price of a dedicated IP, and the captured pages give different figures for the free plan's contacts and daily sends. 17 2 9 3
European sovereignty — proven facts
2 of 4 dimensions provenBuilt only from facts shown on the vendor's own pages. A dimension we could not prove is left open, not scored as zero.
| Legal entity | Incorporated in DE ⚠ unverified | 3/3 pts | 6 Report an error |
|---|---|---|---|
| Ownership | Not determined | — | uncited Report an error |
| Data residency | EU only ⚠ unverified | 3/3 pts | 1 Report an error |
| Subprocessors | Not determined ⚠ unverified | — | uncited Report an error |
Where this could be wrong
- Evidence ages. The oldest capture behind this page is from 15 Sep 2026. Vendors change pricing and policies without notice; every fact reflects its source as of the capture date shown in the registry.
- Weak sourcing — Legal entity. The terms of use name the French parent Sendinblue SAS (Paris, France) as the contracting party for the service, of which Brevo GmbH is a subsidiary.
- Weak sourcing — Data residency. The statement sits in homepage marketing copy rather than the excerpted contractual terms, and one of the named hosts, Google Cloud, is a US-headquartered company (Belgian region).
- Weak sourcing — Subprocessors. Not confirmed on the vendor’s own pages as captured.
- AI can misread a source. Extraction and judgement are automated; a citation guarantees traceability, not infallibility. If something here is wrong, say so — no account needed, every report is decided within 5 business days, and accepted corrections are published.
What we left out
A claim that does not survive our checks costs us the claim, not the page. This is what was taken off this one.
- 53 product facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 10 integrations facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 5 data facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 4 support facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 2 compliance facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 2 pricing facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 1 sovereignty dimension could not be confirmed on the vendor’s own pages and is shown as unknown. Know more? Tell us
Sources (17)
The pages every claim on this page was read from — each one checked, dated, and kept verifiable.
- 1 Vendor homepage www.brevo.com Checked 15 Sep 2026 Details →
- 2 Pricing www.brevo.com Checked 15 Sep 2026 Details →
- 3 Terms www.brevo.com Checked 15 Sep 2026 Details →
- 4 Privacy policy www.brevo.com Checked 15 Sep 2026 Details →
- 5 Privacy policy www.brevo.com Checked 30 Sep 2026 Details →
- 6 Imprint www.brevo.com Checked 30 Sep 2026 Details →
- 7 Security / trust page — found from the homepage www.brevo.com Checked 30 Sep 2026 Details →
- 8 Campaigns & automation — found from sitemap www.brevo.com Checked 30 Sep 2026 Details →
- 9 Campaigns & automation — found from sitemap www.brevo.com Checked 30 Sep 2026 Details →
- 10 Deliverability infrastructure — found from sitemap developers.brevo.com Checked 30 Sep 2026 Details →
- 11 Deliverability infrastructure — found from sitemap www.brevo.com Checked 30 Sep 2026 Details →
- 12 Consent, proof & tracking limits — found from sitemap www.brevo.com Checked 30 Sep 2026 Details →
- 13 Consent, proof & tracking limits — found from sitemap www.brevo.com Checked 30 Sep 2026 Details →
- 14 List ownership, import & exit — found from sitemap developers.brevo.com Checked 30 Sep 2026 Details →
- 15 List ownership, import & exit — found from sitemap developers.brevo.com Checked 30 Sep 2026 Details →
- 16 Integrations & API — found from sitemap www.brevo.com Checked 30 Sep 2026 Details →
- 17 Integrations & API — found from sitemap www.brevo.com Checked 30 Sep 2026 Details →