Docs
Double opt-in and suppression
New public form-endpoint captures that proceed record the configured consent wording and policy version. Form captures remain pending until email confirmation; unsubscribe, bounce, and complaint handling create durable suppressions.
What is double opt-in?
Double opt-in means a new signup stays pending until the person confirms by email. Gather Sprout enforces that for new public form-endpoint captures.
An unconfirmed form address stays pending. Sends target subscribed contacts only.
Is double opt-in required in Gather Sprout?
Yes for new form and API captures on the public form endpoint. Those contacts cannot become subscribed until they confirm. CSV import and management paths can set subscribed when a consent basis is supplied.
Consent snapshots
Forms carry a consent notice and policy version. When a new capture proceeds, Gather Sprout stores that snapshot as a consent event against the contact, so you can show what wording was accepted and when. Duplicate responses and captures blocked by a bounce, complaint, honeypot, or other non-mutating path do not create a new snapshot. The workspace export and a single contact's privacy export both carry those events; the contacts CSV is a list of addresses and does not.
Suppressions
Unsubscribe, bounce, and complaint paths create suppressions so future imports cannot silently re-add the address. A bounce or complaint also blocks a new signup outright. An unsubscribe does not: the person can sign up again and confirm by email, which is the one route back, and it clears their own suppression. Related privacy controls live in the workspace console.
Duplicates
Already-subscribed addresses are accepted without creating a second contact row or attaching new provenance. See Provenance.
This page is operational documentation, not legal advice. Review Privacy for data categories.