Compliance

Showing Customer Logos: Consent, Fair Use, and Opt-Outs Explained

Semir Jahic · · 8 min read

Every SaaS wants a logo wall; every general counsel has questions about it. This post lays out the consent question in plain language: when showing a customer’s logo is generally fine, when you should ask first, and why a no-friction way off the wall is the thing that keeps the whole practice honest.

This is not legal advice. It’s a plain-language orientation to how the practice generally works. Trademark law varies by jurisdiction and by facts — for your specific situation, talk to a lawyer.

Is it legal to show your customers’ logos?

Generally, truthfully identifying a real customer by name or logo is a common and widely accepted practice — the concept usually invoked is nominative use: using someone’s mark to refer to them, not to brand your own product. A logo wall that says “these companies use our product,” when they actually do, is a factual statement about your customer list.

The practice rests on staying inside a few lines:

  • It must be true. Ex-customers, trial signups that never converted, or companies whose employee once bought a single seat on a personal card are all shaky claims. The fastest way to get a logo wall wrong is to let it drift out of date.
  • No implied endorsement. A grid labeled “trusted by” states a relationship. Copy that suggests the customer endorses, certifies, or partners with you goes further than the facts.
  • Use the mark, don’t remix it. Show the logo as the company presents it — not recolored into your palette, stretched, or composited into your own branding.
  • Contracts beat defaults. If your agreement with a customer says you won’t publicize the relationship (NDAs, publicity clauses in enterprise deals), that promise controls, regardless of what trademark law would otherwise allow.

What is the actual test people are referring to?

In the US, the most-cited formulation comes from a 1992 Ninth Circuit case, New Kids on the Block v. News America Publishing, which set out three conditions for using someone else’s mark to refer to them:

  1. the product or service isn’t readily identifiable without using the mark;
  2. only as much of the mark is used as is reasonably necessary to identify it; and
  3. nothing about the use suggests sponsorship or endorsement by the mark holder.

The case and its context are laid out in Duke Law’s open trademark casebook. Notice how neatly a well-built logo wall maps onto those three: you can’t identify Acme without Acme’s mark, one normalized logo at a modest size is about as little of it as you can use, and a heading that says “companies that use our product” makes a relationship claim rather than an endorsement claim.

Two caveats that matter more than the test itself. First, US courts are not uniform on how nominative fair use should be analyzed — circuits differ, and the Supreme Court has declined to settle it — so treat these factors as a way of thinking, not a shield. Second, none of it travels automatically outside the US: nominative use is a US doctrine, and other jurisdictions reach broadly similar outcomes by different routes, with different edges.

It’s also worth knowing that practitioners genuinely disagree about how careful to be. Plenty of B2B marketing guides advise getting written approval from every client before their logo goes on your site — a stricter standard than trademark doctrine requires. Meanwhile the vendors that supply logos to software products publish their own usage rules: Logo.dev, for example, maintains public fair-use guidelines covering the display of company logos inside applications while prohibiting things like redistributing their data as a competing logo API. Three sets of rules can apply to you at once: trademark law governs the claim you’re making, your contracts govern what you promised, and your logo vendor’s terms govern how you obtained the file.

Do you need consent, and how do companies usually get it?

The pragmatic answer: consent is not always strictly required for a truthful nominative use, but getting it — or at least creating a clear path to object — is cheap insurance and better manners. Common approaches, roughly in order of formality:

  • A logo-rights clause in your terms of service — a limited, revocable license to display the customer’s name and logo to identify them as a customer, usually with an opt-out on request. This is the standard B2B SaaS pattern; customers who care negotiate it out.
  • Checkbox or onboarding consent — an explicit yes captured at signup. Strongest signal, lowest coverage: most customers never see the checkbox.
  • Ad-hoc permission — emailing the customer before featuring them. Standard for case studies and quotes; overkill for a logo grid, but common for marquee placements.

Whatever the approach, the through-line is revocability: the customer can always change their mind, and you honor it when they do.

Why does an opt-out path matter so much?

Because it converts a potential conflict into a routine request. A company that finds its logo somewhere it doesn’t want it has two paths: a friendly removal request, or a lawyer’s letter. Which one they pick depends almost entirely on how easy you made the first path.

A credible opt-out path is fast, reachable by the affected company itself, and unconditional: coming off the wall shouldn’t be a negotiation. It’s also simply honest — a wall that only ever grows is marketing; a wall someone can leave is a claim you stand behind. And it is your path to run: the company asks you, because it is your website.

Which is why the second half matters as much as the first. Saying yes takes a minute; the removal then waits on someone editing a file, opening a pull request, and shipping a deploy. The gap between “of course, we’ll take it down” and the logo actually being gone is where the goodwill you just bought evaporates. Removal should be a setting, not a release.

How does LogoSyncer handle consent and removals?

LogoSyncer generates logo walls from your live Stripe customer list, so the truthfulness problem — stale logos, ex-customers — largely solves itself: churned customers drop off the wall automatically. Around that core, three mechanisms:

  • A T&C column, populated passively. The dashboard tracks which customers were observed accepting your terms at checkout (Y / unknown) — a signal to inform your curation, not a claim we make on your behalf. Responsibility for what your wall asserts stays with you.
  • Exclusions you control, applied at serve time. Your wall is yours: exclusion lists and per-wall hide take any company off it immediately, without a deploy and without waiting for the next sync — so honoring a request is a tick box that’s live on your site straight away. Every wall also links a public page where a listed company can report a listing; those reports are forwarded to you, since the site is yours. Reports about LogoSyncer itself go to abuse@logosyncer.com; we review them, and we don’t advertise a turnaround time we can’t guarantee.
  • Domains, never emails. The sync reads only the email field of your Stripe customers, derives the company domain, and discards the address in-request. LogoSyncer stores acme.com, not jane@acme.com — your customers’ personal data is never written to disk. Details in the security docs and privacy policy.

Why those particular guarantees and not others is a design story: Why We Built LogoSyncer covers the decisions made in the first hour and the things we refused to build. If you’re setting up a wall, the step-by-step guide covers the mechanics, and the embed docs cover placement.

FAQ

Is it legal to put customer logos on my website?

Truthfully identifying a real customer by their logo is a common, generally accepted practice often described as nominative use. But it isn't unconditional — contracts, brand guidelines, and jurisdiction all matter, so check your agreements and talk to a lawyer for your specific situation.

What is the nominative fair use test?

The best-known formulation comes from the Ninth Circuit in New Kids on the Block v. News America Publishing: the thing must not be readily identifiable without the mark, only as much of the mark as reasonably necessary may be used, and nothing may suggest sponsorship or endorsement by the mark holder. US courts are not uniform on it, so treat it as a way of thinking rather than a guarantee.

What should a logo-rights clause in my terms say?

A typical clause grants you a limited, revocable right to display the customer's name and logo to identify them as a customer, and lets them opt out on request. Keeping it revocable and honoring opt-outs quickly is what makes the clause fair.

What happens if a customer asks me to remove their logo?

Remove it, promptly and without friction. On a LogoSyncer wall that is one tick in your exclusion list, applied at serve time with no deploy. The company can also report the listing at logosyncer.com/takedown — no account needed — and LogoSyncer forwards the report to you, since it's your site and your call.

Do practitioners agree on whether you need written permission?

No, and it's worth knowing that. Some B2B marketing guides advise getting written approval from every client before showing their logo; trademark doctrine is generally more permissive for truthful, non-endorsing use. The conservative path — ask when the relationship or contract is sensitive, always honor removals — satisfies both camps.

Does LogoSyncer store my customers' email addresses?

No. The sync reads the email field only to derive the company domain (jane@acme.com becomes acme.com) and discards the address in-request. What's stored is the domain — never end-customer emails or names.