Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy requires senders to hold documented proof of permission for every subscriber, either through direct opt-in or through a purchase made within the preceding 12 months where email consent was obtained at the point of sale.
This analysis describes what ConvertKit's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes a platform-level permission standard that requires documented proof of consent for each subscriber, and limits purchase-based consent to a 12-month window, creating an ongoing compliance obligation for list hygiene and consent record-keeping.
Interpretive note: The adequacy of the 12-month purchase-based consent window under GDPR and UK GDPR consent standards depends on jurisdiction and the specific manner in which consent was obtained at the point of purchase.
Under this clause, account holders are required to maintain verifiable records of subscriber consent for the entirety of their subscriber lists; subscribers added through purchase without documented consent at the time of purchase, or purchase-based consent older than 12 months, do not satisfy the policy's permission standard.
Cross-platform context
See how other platforms handle Subscriber Permission Requirement and similar clauses.
Compare across platforms →Monitoring
ConvertKit has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"Kit is a permission-based email marketing platform. We require that all Subscribers have given direct permission to receive marketing emails from the sender, or have purchased an item from the sender within the past 12 months and consented to receive emails at the time of purchase. Customers are required to have proof of permission for each Subscriber on their list.Excerpt from ConvertKit's Acceptable Use Policy
(1) REGULATORY LANDSCAPE: The permission standard stated in this provision engages the CAN-SPAM Act (explicitly referenced elsewhere in the policy), which governs commercial email practices in the United States. For EU and UK senders or subscribers, the consent requirement interacts with GDPR Article 6 lawful basis requirements and Article 7 consent conditions, as well as the UK PECR and EU ePrivacy Directive. The 12-month purchase-based consent window may require evaluation against GDPR's requirement that consent be freely given, specific, informed, and unambiguous; a blanket 12-month window may not satisfy GDPR consent standards depending on how it was obtained. The FTC and relevant data protection authorities (including the UK ICO and EU supervisory authorities) have enforcement jurisdiction. (2) GOVERNANCE EXPOSURE: High for organizations operating across jurisdictions. The platform-level permission standard adds an additional consent documentation layer on top of applicable legal requirements. Failure to maintain documented proof of permission could result in account termination, with the associated no-refund and discretionary data export consequences established elsewhere in the policy. (3) JURISDICTION FLAGS: EU and UK senders face heightened exposure, as the GDPR and UK GDPR impose specific consent record-keeping obligations that must be satisfied independently of this policy's requirements. California senders should assess whether their consent practices satisfy both Kit's platform standard and CCPA notification requirements. The double opt-in provision (applicable to Kit Forms and Landing Pages) may serve as sufficient proof of permission under Kit's standard but may require supplemental documentation under GDPR. (4) CONTRACT AND VENDOR IMPLICATIONS: Organizations migrating subscriber lists from other platforms to Kit should conduct a permission audit prior to import to ensure each subscriber satisfies the documented proof-of-permission standard. Purchase-based consent records must include timestamp and consent language to demonstrate compliance within the 12-month window. (5) COMPLIANCE CONSIDERATIONS: Compliance teams should implement or audit consent record-keeping systems to ensure documented proof of permission is maintained for each subscriber. Organizations should assess whether their current opt-in workflows generate auditable permission records, and whether purchased or rented lists (explicitly prohibited under this policy) have been fully removed from Kit accounts.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision establishes a platform-level permission standard that requires documented proof of consent for each subscriber, and limits purchase-based consent to a 12-month window, creating an ongoing compliance obligation for list hygiene and consent record-keeping.
Under this clause, account holders are required to maintain verifiable records of subscriber consent for the entirety of their subscriber lists; subscribers added through purchase without documented consent at the time of purchase, or purchase-based consent older than 12 months, do not satisfy the policy's permission standard.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by ConvertKit.