Clickback
Clickback Inc. sells the thing most email platforms refuse to touch: bulk campaigns to cold and purchased business lists. Its copyright notice runs from 2000, it operates from St. Catharines in Ontario, and it reports more than a thousand customers including LexisNexis. Two products carry the business. Clickback MAIL, which the company brands Email Lead Generation, takes a list the customer bought or gathered without opt in, runs every contact through twenty to thirty hygiene and verification checks on import to strip bad addresses, spam traps, honeypots and moles, then sends the campaign from Clickback's own designated sending domains and internet addresses with an automated warmup process, so the customer's own domain reputation is never the thing at risk.
The stated goal is conversion rather than the sale itself: a cold contact who engages becomes an opted in lead, which the customer then pushes into whatever CRM or marketing automation platform they already run. Clickback WEB, branded Website Visitor Intelligence, picks up the contacts who visited the site after a campaign without converting, so they can be tracked and nurtured rather than dropped.
The compliance posture is enforced in the product rather than disclaimed in the terms: the platform detects and filters out Canadian and European addresses so campaigns stay clear of the consent regimes that would prohibit them, and the company states plainly that its software does not work for business to consumer lists. Pricing is published by monthly email volume across three tiers with an enterprise band on request, on a twelve month agreement.
Capability Axes
Capability grades
17 of 17 axes rated · 6 graded A or B
No artificial intelligence claim was located anywhere on the pages read: not in the product material, the pricing page, the feature matrix or the frequently asked questions. This is the second vendor in short order to make no claim at all, and as with the other one the band exists for exactly this case, since the lowest grade is reserved for a marketed claim that fails the removal test rather than for a competent product that never made one.
The engineering that is described is rule based rather than learned: twenty to thirty hygiene and verification checks applied to each imported contact, a spam checker examining a stated 287 or more variables, link validation, and an automated warmup routine. Those are deterministic filters. One phrase in the vendor's own blog describes an adaptive sending engine that reacts to mailbox behaviour, which is the only place anything resembling a model could sit, and it is not claimed as one. Recorded as observed rather than concluded.
Nothing here acts on its own initiative, and that is not what holds the grade down. What does is that the platform applies two consequential and non optional transformations to the customer's own campaign, and describes one of them in terms that contradict the other. Every link in a customer's message is automatically rewritten to point at a Clickback owned domain, and customers are prevented outright from spelling their own domain in the body text.
Separately, the platform detects and removes Canadian and European recipients from the send. Both are mandatory, neither is presented as configurable, and no log, preview or reconciliation is described that would let a customer see what was changed or who was dropped.
The contradiction sits in a single answer on the vendor's own page, which states that the company does not modify, edit or rewrite client email messages, three paragraphs before explaining that links are automatically rewritten when a message is sent. A buyer cannot govern what they cannot see, and here they are told two different things about it.
The axis barely bites, and the grade records that rather than penalising it. No model is disclosed because none is claimed, so there is no provider to name, no version to state, no inference location to publish and no prompt or output handling to describe. Nothing is being withheld.
The one loose end is a description in the vendor's own blog of an adaptive sending engine that reacts to mailbox behaviour, which is the only component that might rest on learned rather than fixed rules, and the vendor neither claims a model behind it nor states that it is deterministic.
Everything else that could plausibly be dressed as intelligence is instead described in mechanical terms, as a fixed number of checks and a fixed count of monitored variables, which is the more honest presentation. Recorded as observed rather than concluded.
Better attributed than most of this index. More than a thousand customers are claimed, named logos include LexisNexis, and eight testimonials carry a full name, a job title and a company rather than an initial and an industry, spanning consulting, financial public relations, publishing, a state accountancy association and a direct mail firm.
One outcome is quantified, attributed and linked to a case study: a named customer closing fourteen new accounts after four campaigns for an additional thirty thousand dollars in monthly recurring revenue. The vendor also publishes an average deliverability range of seventy to eighty percent, which is a real and unflattering number rather than a boast, and independent recognition exists in the form of a Canadian fastest growing company listing.
Off the top of the band on currency and method: that listing is from 2017, the testimonials are undated, neither the outcome figure nor the deliverability range carries a sample or a methodology, and the pages themselves record their last modification in August 2024, so the whole evidence surface appears frozen.
The only vendor in this index whose product refuses to send into a jurisdiction, and also the only one that tells its buyer they are above the law. The mechanism is real and it is enforced in software rather than disclaimed into the customer's terms: the platform detects Canadian and European addresses and filters them out of the send, on the reasoning that the consent regimes there would prohibit the campaign, and it refuses business to consumer lists outright.
Three regimes are named explicitly with linked explanatory material on each. Import hygiene strips spam traps, honeypots and moles before a message leaves. That architecture is stronger than a policy and it is why this sits in the band rather than below it. What keeps it off the top is the overclaim and the omissions.
Campaigns are marketed as one hundred percent compliant with all three regimes, which is not a property any platform can confer, since compliance turns on content, sender identification, honouring opt outs and the lawful basis of the underlying list, none of which the platform controls. Detection based filtering is also imperfect by construction, because a Canadian or European individual reachable at a generic corporate address is not detected.
And nothing published addresses unsubscribe mechanics, suppression retention, sender identification or the postal address requirement, which are the operative obligations rather than the jurisdictional ones.
A privacy policy is published and linked in the footer of every page, and it was not read this pass, so nothing here is a finding about its contents. What is visible from the surfaces that were read is the shape of the gap. This platform holds lists of named business people who never contracted with anyone, sourced from purchase rather than from a relationship, and it stores them without limit on every tier.
No notification route to those individuals is published, no self service lookup exists, no removal or objection path is named, and no controller and processor split, retention schedule, transfer mechanism, sub processor list or data protection contact appears anywhere on the read surfaces.
The jurisdictional filter is worth noting precisely here: it stops European addresses being sent to, and by definition those addresses must first be imported and processed in order to be detected, so the filter is a sending control rather than a collection one. Recorded as observed rather than concluded. Re verify by reading the published privacy policy directly.
The finding here is what the hygiene process does not check. Every imported contact passes twenty to thirty verifications, and each one tests deliverability: is the address real, is it a spam trap, is it a honeypot, is it malformed. Not one of them tests where the list came from or whether it was lawfully obtained. A list assembled from a breach would clear the whole gauntlet.
The vendor states it does not sell lists itself, which is creditable, and then operates on both sides of the market anyway: it runs a formal Become a Data Partner programme, and it offers to introduce buyers to what it describes as several reputable data providers trusted in the field. Not one of those partners is named publicly, so a buyer is asked to accept a referral to an undisclosed supplier for the most legally sensitive input in the entire workflow.
Published guidance on choosing a list exists and is about quality rather than provenance. Bottom of the band rather than below it because the vendor is transparent that the list is the customer's responsibility and does not pretend to have vetted it.
The exposure runs in the opposite direction from every social automation vendor in this index, and that is what earns the band. There is no scraping, no automated action against another platform's user surface and no credential custody.
The relevant terms are those of the mainstream email service providers and the receiving mailbox operators, and the vendor's answer is to take the risk onto itself: sending runs on Clickback's own designated domains and internet addresses, and the company states in writing that it assumes all of the risk so the customer's domain and addresses are never exposed.
Where a browser automation tool leaves the buyer holding the account that gets restricted, here the vendor holds the asset that gets blocklisted. The tension that keeps it off the top of the band belongs on the record plainly: the protection is achieved by concealment, since customer links are rewritten to vendor domains with the stated purpose of preventing anti spam appliances and filters from seeing them, and customers are forbidden from writing their own domain in the message body. No conformance position with bulk sender requirements is published anywhere.
The training question does not arise, because no model is claimed. The stewardship question does, and it is sharpened by a line on the price list: unlimited number of contacts stored, on every tier. That means a customer's accumulated cold contact database, together with its validation results, engagement history and the website visitor intelligence gathered on the people who did not convert, persists indefinitely with no published retention period, no deletion schedule and no stated limit on secondary use.
Nothing published says whether suppression, bounce or spam trap intelligence derived from one customer's list is applied to another's, which is a reasonable question for a platform whose core asset is knowing which addresses are dangerous to send to, and which would be a genuine cross customer boundary issue if it happens. Recorded as observed rather than concluded, and re verify in the published terms of use and privacy policy.
A new shape for this index, and it operates at the infrastructure layer rather than in the message. The recipient did not consent to contact, by design, and almost every technical signal they or their mail system could use to establish who is actually writing has been substituted. The message arrives from the vendor's domains and addresses rather than the sender's. Every link in it has been silently rewritten to point at a vendor owned domain.
The customer is forbidden from spelling their own domain in the body text. The reply address must be a separate domain from the sender's primary one. The vendor's stated reason for the link rewriting is to prevent anti spam appliances and filters from seeing the customer's domain. Held at the middle of the band rather than lower for three reasons that genuinely count.
Nothing impersonates a person: there is no agent, no synthetic voice, no invented human name and no manufactured research effort, and personalisation extends only to first name, company, phone and email. The commercial identity making the claim in the message is the customer's real one. And the campaign's stated purpose is to obtain consent rather than to substitute for it, which is a materially better objective than most cold outreach here.
Bottom of the band. The central workflow claim is that converted, opted in leads get pushed into whatever marketing automation or CRM platform the customer already runs, and that claim is repeated across the homepage, the product page and the frequently asked questions. Not one destination is ever named.
No connector list, no integration directory, no application programming interface, no developer documentation, no webhook description, no marketplace listing and no partner application catalogue was located on any surface read, and the only integration named anywhere in third party listings is a transactional mail relay.
The vendor positions itself explicitly as a complement that works alongside an existing email service provider and marketing automation stack rather than replacing it, which makes the absence of named integration points the most conspicuous gap in the whole record. Two partner programmes exist, for data providers and for agencies, and neither is a technical integration surface. Recorded as observed rather than concluded.
The service is described as cloud based and nothing further is published. No data centre location is named, no region is offered, no residency commitment is made, no sub processor list exists and no route for a customer with localisation obligations is described.
That matters more here than it would for most vendors, because the company is Canadian, its customers are predominantly sending into the United States, and the platform necessarily ingests and processes Canadian and European personal data in order to detect and filter those addresses out of a send. So personal data from at least three regimes crosses this system by design and its resting place is unstated.
Recorded as observed rather than concluded: this is a failure to locate documentation rather than a finding that none exists, and a terms of use document and a privacy policy are both published and unread. Re verify there.
No certification, trust centre, security page, audit report, penetration test, vulnerability disclosure policy or enumerated control set was located on any surface read. Recorded as observed rather than concluded: this is a failure to locate documentation rather than a finding that none exists, and the reading may well be a false negative, since the company has been trading for over two decades, counts a major legal information provider among its named customers, and enterprise buyers of that kind usually force attestations during procurement.
Two related observations from the pages that were read. The acceptable use policy is linked in the footer of every page and returns a not found error, which for a vendor whose entire product is bulk sending to non consenting recipients is the single document a buyer would most want to read. And no security or trust entry appears in the footer alongside the three legal links.
Three real published prices and, more valuable, a published consumption rule. The tiers run at three hundred, four hundred and six hundred United States dollars a month for twenty five, fifty and one hundred thousand emails, on a twelve month agreement billed monthly, with an enterprise band on request and a feature matrix showing what every plan includes.
The piece almost no metered vendor in this index supplies is the definition of the unit: total emails means the sum of emails cleaned in a month plus emails sent in that same month. That single sentence tells a buyer the most consequential thing about the bill, which is that importing and hygiene consume the same allowance as sending, so a large dirty list can burn a month's quota before a single message goes out. Held off the top of the band by three gaps.
The second product is entirely unpriced, with its cost described only as depending on site traffic and leads purchased. There is no figure anywhere between one hundred thousand emails and the five million where the enterprise band begins, which is most of the mid market.
And the page contradicts itself and its own search snippet, since the tiers are denominated in emails while the footnote asks about contacts and quotes two thresholds matching no tier boundary, and the meta description advertises a starting price of two hundred and eighty dollars against a page showing three hundred.
Nothing published states an export route, a post termination retention period, a deletion timeline, a deletion confirmation artefact or a data return mechanism, and no export feature appears in the published feature matrix. A terms of use document exists and was not read this pass and is the most likely place for any of it.
One architectural mitigation is real and worth naming: the customer supplied the list in the first place and therefore still holds the raw contacts, so unlike a vendor whose database is the product, leaving does not strip the buyer of their underlying asset.
What leaving does strip is everything the platform added, and that is the part with the value: validation and hygiene results, campaign engagement history, the record of which cold contacts converted to opted in leads, and the website visitor intelligence gathered on those who did not. Held at the middle of the band because the raw list survives and the enriched state is unaddressed. Re verify in the published terms.
The most complete sending architecture in the index, and it is included at the entry price rather than sold upward. The control set is enumerated rather than gestured at: designated sending domains and internet addresses per customer instead of a shared pool, an automated warmup process, list cleaning on import that removes bad addresses, spam traps, honeypots, moles and malformed records through twenty to thirty checks per contact, email verification and validation as a distinct step, a real time spam checker examining a stated 287 or more variables, link validation, and domain and address management.
Every one of those appears on the three hundred dollar entry tier. The vendor also publishes an outcome rather than a promise, stating an average deliverability of seventy to eighty percent, which is a modest figure honestly given, and it declines to predict a rate for any individual customer on the ground that content and list quality dominate.
Two structural points reinforce it: sending runs on the vendor's own infrastructure so it carries the reputation consequence of its own discipline, and it publishes guidance on separating the reply domain because that is the one element it cannot protect. Gaps that belong on the record: no bounce or complaint threshold is named, no blocklist monitoring, inbox placement testing or feedback loop handling is described, and unsubscribe and suppression mechanics are nowhere published.
The finding worth carrying out of this build is that the vendor with the most aggressive use case in the index has the most disciplined sending engineering in it, because the use case leaves it no choice.
A vendor that publishes who it will not serve, which is the shape that has earned the top of this band elsewhere, held one step below it by a size claim that covers everything. The refusals are explicit and in writing. Business to consumer lists are declined outright, with a stated reason about consumer mailbox providers and complaint rates.
Canadian and European recipients are filtered out of every send, which means the addressable list is functionally United States business contacts, a substantial narrowing that a buyer should understand before signing a twelve month agreement. Customer evidence is consistent with that positioning, spanning legal information, hardware, publishing, consulting, public relations and professional associations.
Off the top of the band because the market is claimed as running from startup to enterprise with no distribution published and no headcount, revenue or industry breakdown behind it, and because the geographic narrowing is presented as a compliance feature rather than as a definition of the market, so the buyer has to derive the addressable universe themselves from a paragraph about legislation.
Pricing
What this vendor charges, what it commits to in writing, and where the bill can move. Figures the vendor publishes itself are labeled Vendor Published. Figures labeled Estimated come from other sources and the vendor has not confirmed them.
- ›Nothing could be retrieved from this company at all. Every request to its website was refused, including the file that would normally explain why.
- ›That is different from a company that tells machines not to read its pricing. This one refuses everything and explains nothing, so no automated reader can reach any part of it regardless of the rules it follows.
- ›So there is no price here, and also no terms, no privacy policy and no compliance information. Nothing.
- ›That matters more than usual for this particular company, because it sells email marketing to cold and purchased business lists rather than to people who signed up. That is the kind of product where you most need to read the terms, and they cannot be read.
- ›If you evaluate this one, ask for the full document set in writing at the first conversation rather than at contract stage, and treat the fact that you cannot check any of it independently as part of your decision.
How the price works
What you are charged for, and what makes the bill go up.
Not retrievable. Every request to this vendor's domain returned a refusal: the pricing address in both trailing slash forms, the domain root, a subdomain variant, and the vendor's own exclusion file. Each returned an identical error document of approximately 75 kilobytes rather than any page content.
Because the exclusion file itself is refused, this cannot be characterized as a published crawler policy being honored. It is a request level block applied to all automated access without any accompanying statement, which means no compliant automated reader can reach any part of this vendor's site regardless of whether it respects exclusion directives.
Consequently nothing is established about tiers, rates, bands, metering basis, seat minimums, contract length, trial terms or free tiers. No structured data, metadata or page content of any kind was obtained.
No credible third party estimate is recorded. For a vendor whose own surfaces are wholly unreachable, no third party figure could be corroborated against vendor material, so recording one would present an unverifiable number as evidence.
This record should be attempted again from a different network position before its conclusions are relied upon.
What the contract says about your data
What the vendor commits to in writing once your data is in the product.
Not established, and nothing was retrievable from any surface. Every request to this vendor's domain returned a refusal, including the request for its own exclusion file, so no privacy policy, terms document, security page, processing agreement or sub processor listing could be reached.
This is the least established record in the index on the custody axis, and the limitation is total rather than partial.
What can be said comes from the product category alone and is worth stating because it is unusually pointed. This vendor sells email marketing to purchased and cold business lists rather than to opted in subscribers, which is a distinct and narrower proposition than general marketing automation. That model sits directly against the consent architecture of the European and United Kingdom regimes, and its viability in the United States rests on the specific carve outs of the CAN-SPAM Act rather than on consent.
A buyer evaluating this vendor therefore needs its data handling and compliance position more than they would for almost any other vendor on this roster, and it is the one vendor here from which nothing at all could be retrieved. That combination is the finding rather than an inconvenience.
A buyer should require, in writing and before any evaluation: the jurisdictions the vendor supports sending into, its position on European and United Kingdom recipients, its suppression and complaint handling process, and what liability it accepts for delivery to non consenting recipients.
Getting started
What it costs and what is included before the product is running.
Not established. Nothing was retrievable from any surface, so no fee, trial, minimum, contract term or onboarding arrangement could be reached.
This section records a limitation rather than a finding. Every request to the vendor's domain returned a refusal, including the root, the pricing address in both forms, a subdomain variant and the exclusion file itself.
For a buyer, the practical consequence is that this vendor cannot be evaluated remotely at all. Not merely that its prices are absent, but that its terms, its compliance position, its data handling and its support arrangements are equally unreachable. Every question must be put directly to the vendor and answered by them, with no published material against which to check the answers.
That is a materially weaker starting position than a quote only vendor, where a buyer can at least read the terms of service and the processing agreement before entering a sales conversation.
A buyer proceeding should require the full document set in writing at first contact rather than at contract stage, and should treat the inability to verify anything independently as a factor in the evaluation rather than as a technicality.
What to watch for
Where this pricing can surprise a buyer who has not read it closely.
The only vendor in this index from which nothing whatever could be retrieved, and the block is total rather than selective.
Every request returned a refusal: the pricing address in both forms, the domain root, the subdomain variant, and the vendor's own exclusion file. That last point is what makes this different from Aellysa, recorded earlier in this session, where the exclusion file was read and honored. Here the exclusion file itself is refused, which means this is not a crawler policy being respected but a request level block applied to everything, returning a substantial error document rather than a page.
That distinction matters for how the absence should be read. A vendor that publishes an exclusion file has made a choice about automated readers and expressed it in the conventional way. A vendor whose infrastructure refuses every request including the file that would explain the refusal has made no statement at all, and the effect is that nothing about this vendor is reachable by any compliant automated reader, whether or not it respects exclusion files.
For this index specifically that is the most complete form of invisibility recorded. Apollo's price was in structured data. HubSpot's needed a renderer. ActiveCampaign's needed a configurator input. Aellysa's was behind a stated exclusion. This vendor's site cannot be reached to determine whether a price exists at all.
No third party estimate is recorded either. Recording an estimate would require corroboration sufficient to stand as evidence, and for a vendor whose own surfaces are entirely unreachable, a third party figure could not be checked against anything.
The category context is worth one line because it bears on why a buyer would want this record. This vendor sells email marketing to cold and purchased business lists rather than to opted in subscribers, which is a compliance sensitive proposition. A buyer researching it has more than the usual need to read the vendor's own terms, and cannot.
No dollar figure is recorded in the numeric field, and no estimate is recorded in the display field. This record should be attempted again from a different network position before its conclusions are relied on.