

Privy
By Privy Operations, LLC
The typical implementation process for Privy software involves several key steps to ensure a smooth integration and optimization of its email, SMS, and list growth tools for e-commerce businesses. Here’s an overview of the process:
Configure integrations: Sync Privy with other tools you use, such as Shopify or other CRM systems.
Create email and SMS automation: Set up automated email flows like abandoned cart emails, purchase follow-ups, and welcome series. Similarly, configure SMS campaigns for timely customer engagement.
For businesses looking for more hands-on support, Privy offers its Accelerate Program, which is a 30-day onboarding process:
Custom checklist: A tailored 30-day checklist ensures all necessary features are implemented effectively.
Once the initial setup is complete, businesses can continue to optimize their campaigns by:
Leveraging additional resources like masterclasses or Privy's support team for further guidance.
The basic setup of Privy can be completed relatively quickly—often within a few hours or days depending on the size of your contact list and the complexity of your integrations. However, if you opt for the Accelerate Program or require more advanced customization, the process typically spans around 30 days. This period includes training sessions, strategy development, and ongoing optimization with the help of a dedicated expert.
Privy software can be customized to fit specific business needs, offering a range of customization options across its various tools and features. Here are several points highlighting the customization capabilities of Privy:
Privy allows businesses to customize the appearance of their marketing materials to align with their brand identity:
Display Customization: Pop-ups and other onsite displays (such as exit-intent displays or spin-to-win games) can be fully customized in terms of design, messaging, and targeting rules to match your business goals.
For more advanced users, Privy offers configurable APIs that allow businesses to create custom workflows:
Web3 Integrations: Privy supports integration with Web3 technologies, allowing businesses to customize how they manage authentication (e.g., using custom wallets or signing transactions). Developers can configure these features using the Privy SDK along with custom authentication providers like Auth0.
Privy provides flexible form-building tools that allow businesses to:
Multi-Step Displays: With multi-step display templates, businesses can gather more information from users in stages, such as collecting both email addresses and phone numbers for SMS marketing. These templates are fully customizable in terms of design and flow.
Privy enables businesses to create highly targeted marketing campaigns through segmentation:
Targeted Pop-ups: Pop-ups can be displayed based on specific user behaviors (e.g., exit intent or time spent on a page), allowing businesses to tailor their onsite marketing efforts more effectively.
For even more granular control over the appearance of Privy’s models and interfaces, users can apply CSS overrides:
Businesses can adjust specific elements like border-radius, background colors, and text colors using custom CSS variables. This is particularly useful for those who want their pop-ups or login modals to match their website's exact design system.
Privy supports integration with custom authentication providers:
Privy offers a range of pricing plans with no setup fees, activation fees, or annual contracts, making it relatively straightforward in terms of additional costs. However, there are some factors to consider regarding ongoing expenses:
Growth Plan: Starts at $45/month for up to 2,000 contacts and includes SMS marketing features. The cost also scales with the number of contacts and messages sent.
SMS scaling: Charges increase based on the number of textable contacts and the number of messages sent. If you exceed your plan's limit (e.g., sending more than 450 texts), you will be charged for additional sends.
Onboarding: Onboarding is free for Growth Plan users and includes one-on-one sessions to help set up the platform.
Privy emphasizes that there are no hidden costs such as activation or setup fees. However, businesses should be aware that as their contact list grows or they send more SMS messages, their monthly fees will increase accordingly.
Privy offers a variety of training and support options to help new users get the most out of the platform. These resources cater to different levels of experience and needs, from basic onboarding to more advanced, personalized coaching. Here’s an overview of the key training and support options:
Privy provides several self-service tools that help users learn at their own pace:
Tooltips: In-app tooltips provide additional context on powerful features while navigating the platform.
Privy offers multiple ways to get in touch with their support team:
Knowledge Base: The Privy Knowledge Base includes articles on various topics related to setup, troubleshooting, and best practices.
For businesses looking for more hands-on guidance, Privy offers the Accelerate Program, a 30-day onboarding process designed to help users implement the platform quickly and effectively:
Custom Checklist: A tailored 30-day checklist is provided to ensure that all necessary features are implemented based on the specific needs of the business.
Beyond initial setup and support, Privy offers ongoing educational resources:
Privy implements a comprehensive set of security measures to protect user data. These measures cover encryption, access control, data residency, and compliance with industry standards. Here are the key security practices in place:
HSTS Enforcement: Privy enforces HTTP Strict Transport Security (HSTS) across all subdomains, ensuring that browsers only communicate with Privy over secure HTTPS connections.
OAuth 2.0 and SIWE Authentication: For end-users, Privy supports secure authentication methods such as OAuth 2.0 for social logins (Google, Apple, etc.) and "Sign In With Ethereum" (SIWE) for wallet verification.
Salting and Hashing: All passwords are salted and hashed using one-way encryption before being stored, making it extremely difficult to reverse-engineer them even if the database is compromised.
Redundant Infrastructure: Customer data is stored on redundant infrastructure across multiple availability zones to eliminate single points of failure.
ISO Certifications: Privy’s data center security is managed by AWS, which holds certifications like ISO 27001 (Information Security Management) and ISO 27701 (Privacy Information Management).
Code Reviews and Testing: All code changes undergo extensive unit, integration, and static analysis testing before deployment. Additionally, human reviews help ensure that no vulnerabilities are introduced into production environments.
All customer data is stored within the continental United States, while static assets may be served globally through a content delivery network (CDN).
Physical security for Privy's datacenters is managed by Amazon Web Services (AWS), which has achieved top-tier certifications like ISO 27001 and SOC compliance. AWS employs strict physical access controls to protect server infrastructure.
Privy releases updates multiple times per week, reflecting an agile development process that ensures continuous improvement and rapid deployment of new features and bug fixes. These updates include both new functionalities and security patches.
Code Reviews: All application code changes undergo multiple forms of review, including both human and automated checks, before they are deployed. This ensures that only thoroughly tested and secure code is released.
Testing: Extensive unit, integration, and static analysis tests are conducted on all changes to ensure stability and functionality. This testing process helps catch potential issues before they impact users.
Deployment: Updates are rolled out regularly across separate production and development environments, which are kept on physically distinct networks. This separation minimizes the risk of disruptions in the live environment during updates.
Privy's policy on data ownership and portability is designed to ensure that customers retain control over their data while also providing mechanisms for data export and transfer. Here are the key points:
Privy’s Use of Data: While Privy processes and uses customer data to deliver its services, it does not claim ownership over this data. The company uses the data strictly in accordance with the customer’s instructions and applicable privacy laws. Privy also commits to not sharing user data with third parties beyond essential partners and service providers needed to deliver their services.
No Data Lock-In: Privy emphasizes that it will never lock user data into its systems, meaning businesses can always retrieve their data without restrictions or penalties. This aligns with best practices for ensuring customer flexibility and control over their information.
Privy’s terms for scaling up or down as organizational needs change are flexible and designed to automatically adjust based on the number of mailable or textable contacts in the account. Here are the key points:
Text Scaling: For SMS marketing, the Growth Plan includes a set number of textable contacts and message sends. If you exceed the number of texts allowed in your plan, you will be charged at a higher tier based on your total number of texts sent for that billing cycle.
The pricing scales as follows:
Growth Plan: Starts at $45/month for up to 2,000 mailable contacts and 75 textable contacts (with up to 450 sends). The cost increases similarly to the Starter Plan for email scaling and adjusts based on textable contacts and sends.
The scaling is automatic and does not require manual intervention from the user. Privy tracks the number of mailable and textable contacts during each billing cycle and adjusts the plan accordingly.
If your contact list decreases below a previous tier's threshold, Privy will automatically move you to a lower pricing tier in the next billing cycle. No notification is sent, but users can see changes reflected in their billing statements.
Privy’s terms and conditions for contract renewal and cancellation are designed to offer flexibility while ensuring transparency for users. Here are the key points regarding these processes:
Price Adjustments: If there are any changes in pricing, Privy will notify users at least 14 days in advance via email. If users continue to use the service after this notice period, they are deemed to have accepted the new pricing.
Annual Plan Refunds: For annual subscriptions, users can cancel within 30 days of the initial subscription date and request a pro-rated refund for the unused portion of the service period. After 30 days, no refunds are provided unless Privy terminates the account for reasons not related to user violations.
Privy meets several key compliance standards to ensure data security and privacy for its users. Here are the main compliance certifications and standards that Privy adheres to:
SOC 2: Privy is SOC 2 compliant, which means it adheres to strict security, availability, confidentiality, and privacy controls. SOC 2 compliance is particularly important for software companies that handle sensitive customer data, as it ensures that systems are designed to keep data secure.
ISO 27001: Privy is certified under ISO 27001, which is an international standard for Information Security Management Systems (ISMS). This certification demonstrates that Privy has a systematic approach to managing sensitive company information, ensuring it remains secure.
ISO 27701: Privy also complies with ISO 27701, which extends ISO 27001 to include Privacy Information Management Systems (PIMS). This standard focuses on managing personally identifiable information (PII) and ensuring privacy best practices are followed.
For payment-related data, Privy ensures compliance with the Payment Card Industry Data Security Standard (PCI DSS). Specifically, payment information is stored by a separate organization that is certified as a PCI Service Provider Level 1, the highest level of certification available for payment data security.
Privy supports compliance with FIPS (Federal Information Processing Standards) and WebTrust certifications, which are critical for cryptographic security and digital certificates. These certifications ensure that Privy's cryptographic operations meet stringent federal standards.
DPDP Act Compliance: In India, Privy aligns with the Digital Personal Data Protection (DPDP) Act, ensuring compliance with local privacy regulations.