The ICO has issued the following guidance on cookie use in emails and landing pages, based on compliance with PECR and GDPR. https://ico.org.uk/for-organisations/guide-to-pecr/guidance-on-the-use-of-cookies-and-similar-technologies/
How can Vuture assist your journey towards compliance?
As email is already a permission-based marketing channel so getting consent for open and link tracking is relatively straightforward. Just add this to the permission being requested and given at time of email opt-in.
For example, you could add to your Consent section a new line such as: "I consent to having the way I interact with these emails tracked and recorded. I understand you will track if I open any emails you send to me, and/or click on any links in those emails."
It is possible, using Vuture, to switch off tracking by container. This means you could send emails from that container to clients who have not consented to having their actions tracked. There is a Help Desk article here which discusses switching off tracking by container: https://support.vutu.re/hc/en-us/articles/360020700178-Restricting-Web-Tracking-Cookies-to-Individual-Containers
The ICO wants to see openness and transparency. That is don't bury this information deep in a policy privacy policy in language that can never be understood.
To be safe we suggest that tracking is signposted on all opt in forms and preference forms.
- Signpost at time of signup that tracking technology is used. Use simple clear language that can be understood by clients.
- Signpost on preference forms that tracking technology is used.
- Change your privacy policy so that opting to email permission is also opting in email tracking. Don't bury this information in the privacy policy or difficult to understand. Include information about tracking that is not part of the regulation too.
- Provide a link to the privacy policy during signup/preferences and to the separate Cookie policy.
- Include a block of information in your Welcome campaign email about privacy and tracking.
We are not lawyers so you should get your own legal advice on compliance.
The following sample policy explains how we track email and landing page activity which you are free to use or tailor to your own requirements:
EMAIL TRACKING
Where you receive a marketing email, event invitation or other direct mailing from us, we may collect information about you in the following ways:
-
Opening emails - if you open the email either by downloading images in the email or clicking in a link we log such activity in our database:
- A tracking image (1 pixel GIF) is included at the bottom of each email. The link to this image includes a tracking code that identifies you and if images are downloaded then an email open activity is logged against your contact record in our database.
- All links in the email include a tracking code that identify you and if you click on a link for the first time and have not downloaded images then an email open activity is logged against your contact record in our database.
- If you do not download images in the email or click on any links then no email open activity is logged against your contact record.
-
Unsubscribe:
- If you click Unsubscribe, we automatically log this information on our database. If you unsubscribe from any email invitation or alert, we will continue to store your personal data on a "marketing suppression list" so as to record your preference.
-
Event RSVP buttons:
- In our event invitations and confirmations we provide buttons to allow you to accept, decline, cancel and register (if you are not the original recipient of the email) for that event. Clicking on these buttons will pass a tracking code so we can record your choice in our database to help us manage the event