Security research has revealed that Klaviyo briefly exposed new customer sign-up details to third-party advertisers because of a website configuration issue. The problem affected the company's registration form and may have been active for an extended period before being corrected.
According to researcher Sam Jadali, the misconfigured form could send information entered by users to embedded tracking systems on the site. That data included email addresses, passwords, company names, website addresses, and phone numbers.
The trackers involved were tied to major digital platforms and marketing tools, including Facebook, Google, Microsoft, LinkedIn, X, and HubSpot. Klaviyo later confirmed that the issue came from an application configuration problem and said it had been fixed.
The company stated that fewer than 200 people were identified in its active logs as potentially affected, while also noting that it could not specify how long the issue had been present. Klaviyo said it notified the individuals it could verify.
The case highlights how website pixels and other tracking tools can unintentionally capture sensitive information when they are not carefully configured. As digital marketing platforms continue to expand, stronger privacy controls may become a defining standard for the next generation of online services.