Trust and privacy
Guest trust, built into your marketing
Record consent for every channel. Give guests control of what they receive. Keep their preferences, privacy requests and opt-outs connected across your marketing.
What happens when a guest asks to be erased?
Engage is built to erase the guest's personal data across every table, while your campaign statistics survive, so reports still add up. A test guards it: the build fails if someone adds a new table that erasure does not reach.
- Built to erase personal data across every table
- Campaign statistics kept after erasure
- The build fails if a new table escapes erasure
How long does Engage keep guest data?
As long as your retention policy says. You set the policy, and Engage anonymizes guests automatically when it runs out. Any guest activity resets the clock, so a guest who is still visiting or engaging is not anonymized because of an old sign-up date.
- Retention policies with automatic anonymization
- Any guest activity resets the clock
How does Engage record consent?
Channel by channel, with where it came from. Sign-up forms always use double opt-in and keep the version of the consent wording each guest saw. CSV imports record which channels the consent covers. Every guest has a subscription history for each channel, with its source and evidence.
- Forms with versioned consent wording, always double opt-in
- CSV import that records which channels consent covers
- Subscription history for each channel, with source and evidence
Can guests choose what they hear about?
Yes. Every guest gets a branded preference center. They can pick the topics they want, pause for 30 days, or leave. A pause is not an unsubscribe, so a guest who wants a break does not have to opt out to get one.
- Branded preference center with topics
- Pause for 30 days, or leave
How does Engage keep sends and figures honest?
Three connected safeguards. The suppression list survives re-import, so a guest who unsubscribed stays suppressed when you upload the same list again. Texts to US numbers are held outside each state's allowed hours. And Engage filters opens, so Apple Mail Privacy opens are not counted as a guest's.
- Suppression list that survives re-import
- US texts held outside each state's allowed hours
- Apple Mail Privacy opens excluded from open rates
Keep consent evidence connected
Record each decision, show which consent covered a message and connect privacy requests to your other systems.
- Consent receipts. A receipt for every consent decision: the wording shown, the lawful basis, the source, who recorded it and the venue.
- A "sent under" stamp on every message. Each message records the consent it was sent under.
- Subject access export. Export what Engage holds about a guest when they ask for it.
- contact.erased webhook. Tell your other systems when a guest is erased in Engage.
- Consent management platform webhook. Take consent changes from Ketch, Transcend, Didomi, Usercentrics and Syrenis.
Check preferences before you send
Consent checks, suppression and guest preferences follow each campaign, including work proposed by the agent.
- No AI proposals without consent. The AI agent can't propose a send that no guest consent covers.
- FCC revoke-all and free-text opt-outs. Free-text replies such as "stop texting me" opt a guest out, alongside STOP, and FCC revoke-all requests are handled.
- Consent re-checked before every send. Consent is checked again right before each message goes, not only when the send was scheduled.
- Hard bounces and spam complaints suppressed. Addresses that hard-bounce or complain stop receiving email.
- Regulator proof pack. Your consent evidence, gathered in one pack for a regulator's question.
Make privacy requests easier to manage
Give guests clear choices and give your team the evidence and controls to respond.
- Guest-chosen frequency. Guests choose how often they hear from you.
- Embeddable preference center. Put the preference center on your own website.
- Self-service privacy request page. Guests make their own privacy requests from a page you publish.
- Re-consent campaigns. Ask guests to confirm their consent again.
- Trust center. Request the DPA annex, subprocessor list, SLA and residency statement from the Purple team.
Questions
Is Purple Engage built for UK GDPR and PECR?
Yes, through specific mechanisms: double opt-in forms with versioned consent wording, consent recorded for each channel with its source, a suppression list that survives re-import, retention policies with automatic anonymization, and erasure built to erase across every table. Compliance also depends on how you collect consent and what you send, so no tool is compliant on its own.
What does Engage keep when a guest is erased?
Your campaign statistics remain in your reports when a guest's personal data is erased. The contact.erased webhook tells your connected systems so they can handle the same request.
If I re-import a list, do unsubscribed guests come back?
No. The suppression list survives re-import, so a guest who unsubscribed stays suppressed even if their address is in the file you upload.
Can a guest take a break without unsubscribing?
Yes. The preference center lets a guest pause for 30 days, choose their topics, or leave.
Record consent properly from the first sign-up
The free plan includes 500 Actions a month and unlimited contacts, with no card needed.