whats-best.ai

Marketing Automation

Customer.io

Provenance unknown Report an error

Panel rating · 6 judges · How to read the stars

Category median

Sovereignty: not determined

0–5 in half steps. 5 means the rubric's top anchor is met on the evidence.

by Customer.io, Inc. · customer.io

Report an error on this page Is this your product? →

Read this page as one judge. Each weighs the same scores by what they care about.

The Data Protection Officer

Weighted verdict

Sees a profiling system, not a mailing tool. Wants consent reproducible per person, tracking that can be switched off for someone who never agreed to it, deletion that removes derived scores as well as raw events, and scoring documented well enough to assess under Art. 22.

Same scores as the panel view — this lens weights them the way this judge cares.

Scored by The Data Protection Officer

Journeys & orchestration

How this is scored

Multi-step automation: triggers, branching, waits, and — the part that decides whether it survives contact with reality — what happens when journeys collide.

0 — Autoresponders on a single trigger; no branching, no waits, no conditions.

3 — Linear sequences with simple conditions, one entry trigger per journey, and no visibility into where a contact currently sits.

5 — A visual builder with branching on attributes and behaviour, waits and goals, entry and exit conditions, and per-contact journey state visible.

8 — Event-driven entry from external systems, frequency capping and suppression across journeys, priority when a contact qualifies for several, versioning of a live journey, and testing against real records.

10 — Orchestration is coherent across the whole programme: one decision layer deciding what a person receives next regardless of which journey wants to send it, holdout groups for measurement, and a journey a colleague can read months later without a diagram.

Report an error

The Data Protection Officer

A visual workflow builder is named and behavioural triggers are marketed for activation, onboarding, retention and cross-sell flows, which evidences multi-step automation exists. We found no public information on waits, entry and exit conditions, per-contact journey state, or what happens when journeys collide, so the parts that decide whether orchestration survives contact with reality are unevidenced. 1

Report an error

Lead scoring, routing & lifecycle

How this is scored

Scoring, qualification and handover to sales — including whether the customer can explain to a lead why the system decided what it decided.

0 — No scoring or lifecycle model; every contact is treated alike.

3 — A single additive score with fixed rules, no decay, no lifecycle stages and no routing.

5 — Configurable scoring on attributes and behaviour with decay, lifecycle stages, and routing to owners or teams with notification.

8 — Multiple scoring models per product or region, negative scoring, account-level scoring alongside contact-level, SLA on follow-up, and score history visible per contact.

10 — Scoring is explainable and accountable: the contribution of each signal visible per record, model changes versioned with their effect on the funnel, routing rules auditable, and predictive scoring — where offered — documented well enough for a DPO to assess it as automated decision-making.

Report an error

The Data Protection Officer

Retention messaging that responds to churn-risk signals implies engagement-based targeting, but we found no public information on scoring models, decay, lifecycle stages, or routing to owners and teams. Nothing here documents any decision about a lead, which is itself the finding for a scoring capability. 1

Report an error

Channels & personalisation

How this is scored

What the platform can actually send and personalise: email, SMS, push, on-site content, ads audiences — judged on what shares one profile and one suppression list.

0 — Email only.

3 — Email plus one further channel, managed separately with its own list and no shared suppression.

5 — Email, SMS or push and web forms driven from one contact profile, with dynamic content blocks and shared unsubscribe handling.

8 — The above plus on-site personalisation, ad-audience sync to the major networks, cross-channel frequency capping, and content personalised on behaviour rather than only on stored fields.

10 — Channel is a delivery detail: one profile and one consent state across every channel, next-best-channel selection, and personalisation that draws on the full behavioural record without the marketer assembling it by hand.

Report an error

The Data Protection Officer

Six channels are listed — email, mobile, in-app messages, push, SMS and WhatsApp — on a single platform that personalises cross-sell campaigns on product usage, which is behavioural rather than stored-field personalisation. We found no public information on shared suppression or unsubscribe handling across channels, ad-audience sync, or cross-channel frequency capping, so the one-profile claim rests on marketing copy alone. 1

Report an error

CRM integration & data model

How this is scored

The join that decides the implementation: how the platform and the CRM stay in agreement about who a person is, and what happens when they disagree.

0 — CSV import and export; no CRM integration and no identity resolution.

3 — One-way sync into a named CRM on a schedule, with duplicates resolved by hand and no conflict rules.

5 — Bidirectional sync with at least one major CRM, field mapping, deduplication rules, and a sync error log somebody can act on.

8 — Configurable conflict resolution per field, account and contact objects both modelled, custom objects supported, near-real-time sync with retry, and a documented API with rate limits.

10 — One record, two systems, no ambiguity: identity resolution across anonymous and known states, field-level ownership defined per system, replay of failed syncs, and a data model the customer can extend without vendor services.

Report an error

The Data Protection Officer

Custom objects, a data warehouse, data activation, anonymous messages and a published API reference are evidenced, which shows a real data model rather than CSV exchange. We found no public information on sync with any named CRM, field mapping, deduplication or conflict rules, or identity resolution between anonymous and known states — the join that decides the implementation is entirely unevidenced. 1

Report an error

European sovereignty

How this is scored

Where behavioural profiles of named EU residents are processed, who the contracting entity is, and which subprocessors see them. Independently sourced by the sovereignty pipeline; scored here as this buyer weighs it — which given the profiling is heavily.

0 — Non-EU vendor and contracting entity, hosting unstated or non-EU, subprocessors unnamed, behavioural data leaving the EU with no stated basis.

3 — EU data residency for storage while tracking, sending or support access remain non-EU, or the contracting entity sits outside the EU.

5 — EU hosting as standard and an EU contracting entity, but parts of the chain — tracking scripts, AI scoring, analytics — are non-EU without an explained safeguard.

8 — EU hosting on named infrastructure, EU contracting entity, complete subprocessor list published, and any non-EU processing named with its legal basis.

10 — Sovereign end to end and evidenced: every profile, event and derived score processed in the EU by European subprocessors, certification published, and no transfer requiring a Schrems II argument to survive.

Report an error

The Data Protection Officer

The only contracting entity on record is Peaberry Software, Inc., and no sovereignty attributes exist for this vendor — we found no public information on hosting location, an EU contracting entity, subprocessors, or the legal basis for any transfer. Certifications such as ISO 27001 and GDPR speak to a security and compliance posture, not to where behavioural profiles of EU residents are processed, and given the profiling that gap weighs heavily. 1

Report an error

Pricing transparency not rated — the vendor publishes no price

How this is scored

Whether a buyer can compute the real annual invoice for their contact base and send volume — including the tier where automation actually begins, overage, and mandatory onboarding — from public pages alone.

0 — No public prices at all; every tier is a sales conversation, and onboarding fees are never mentioned.

3 — A contact-tier headline exists, but the tier where journeys, scoring or CRM sync begin is unstated, as is any mandatory implementation fee.

5 — Contact-tier prices public with billing period and send limits stated, but at least one commonly needed capability sits in an unpriced enterprise tier.

8 — Every tier priced publicly with contact and volume limits, feature boundaries, overage rates, onboarding costs, minimum term and VAT treatment stated.

10 — Complete price computability: annual invoice derivable for a given contact count, send volume and feature set, including overage, additional users and any implementation fee stated outright.

Report an error

The Data Protection Officer

Only trial terms are public — fourteen days free, no credit card required — and we found no public information on tier prices, contact or send limits, feature boundaries, overage, or the cost of the hands-on implementation the page itself advertises. A buyer cannot compute any invoice for their contact base from these pages, and the tier where automation begins is unstated. 1

Report an error

European sovereignty — proven facts

0 of 4 dimensions proven

Built only from facts shown on the vendor's own pages. A dimension we could not prove is left open, not scored as zero.

Ownership Not determined — uncited Report an error
Data residency Not determined ⚠ unverified — uncited Report an error
Subprocessors Not determined ⚠ unverified — uncited Report an error

Where this could be wrong

What we left out

A claim that does not survive our checks costs us the claim, not the page. This is what was taken off this one.

Sources (12)

The pages every claim on this page was read from — each one checked, dated, and kept verifiable.

  1. 1 Vendor page customer.io Checked 29 Sep 2026 Details →
  2. 2 Security / trust page — found from the homepage customer.io Checked 30 Sep 2026 Details →
  3. 3 Journeys & orchestration — found from sitemap docs.customer.io Checked 1 Oct 2026 Details →
  4. 4 Journeys & orchestration — found from sitemap docs.customer.io Checked 1 Oct 2026 Details →
  5. 5 Lead scoring, routing & lifecycle — found from sitemap customer.io Checked 1 Oct 2026 Details →
  6. 6 Lead scoring, routing & lifecycle — found from sitemap customer.io Checked 1 Oct 2026 Details →
  7. 7 Channels & personalisation — found from sitemap docs.customer.io Checked 1 Oct 2026 Details →
  8. 8 Channels & personalisation — found from sitemap docs.customer.io Checked 1 Oct 2026 Details →
  9. 9 Consent, tracking & profiling — found from sitemap customer.io Checked 1 Oct 2026 Details →
  10. 10 Consent, tracking & profiling — found from sitemap docs.customer.io Checked 1 Oct 2026 Details →
  11. 11 CRM integration & data model — found from sitemap docs.customer.io Checked 1 Oct 2026 Details →
  12. 12 CRM integration & data model — found from sitemap docs.customer.io Checked 1 Oct 2026 Details →