XLens/Blog
← All articles
Jul 8, 2026

Do You Need Permission to Use Customer Testimonials?

Editorial illustration of a signed note being pinned beside a quote card on a calm wall.

You asked a happy customer how things were going, they replied with a sentence so good you want it on your homepage tomorrow. Before you paste it in, one question is worth answering: are you actually allowed to publish it? A private message, a support ticket, or a survey reply was written for you, not for the public. Using it as a testimonial is a small republishing act, and the safe default is to get permission first.

The short answer: yes, get explicit permission

Treat every testimonial as something you publish with the person’s knowledge, not something you lift from a conversation. A customer praising you in a DM has not agreed to appear on your pricing page next to a photo. Asking is polite, and it also protects you. If a customer later feels surprised to find their words on your site, you have a trust problem with the exact person whose trust you were showcasing. Explicit permission turns a nice quote into an asset you can use without second-guessing.

The good news is that asking is rarely awkward. Most customers who said something kind are glad to see it used. A short note works: “That comment really captured it. Would you be okay with us featuring it on our site, with your name and role?” You are giving them a heads-up and a chance to shape how they appear, which most people appreciate.

What counts as real permission

Permission is strongest when it is written, specific, and easy to walk back. Written means you have a record, an email reply or a ticked box, not a vague memory of a hallway comment. Specific means the person knows what they are agreeing to: the quote itself, where it will appear, and what identifying details go with it. “Sure, use it” is thinner than “Yes, you can use that quote on your website with my first name and company.” And revocable means you accept that someone can change their mind later and ask you to take it down.

The detail that trips makers up is scope. Consent to be quoted in a case study is not automatic consent to run the same quote in a paid ad, or to keep it live forever. When in doubt, ask for the broader use up front rather than assuming it. If you are still working out how to make that ask without friction, this guide on how to ask SaaS customers for testimonials covers the tone that gets a yes.

Names, faces, and logos raise the bar

The more identifying the material, the more explicit the permission should be. An anonymous quote is low-risk. Add a full name and a company, and you are now attributing a public statement to a real person, so they should have signed off on the exact wording. Add a photo, and you need their okay to use their likeness. Add a company logo, and you are touching someone else’s brand, which often has its own usage rules, so a customer’s personal yes may not cover their employer’s mark.

None of this should scare you off using names and faces, because concrete, attributed proof is far more persuasive than anonymous praise. It just means the person featured should have seen and approved the final version. That is also good practice when you turn a customer review into a case study, where the quote sits inside a longer story about their results.

The cleanest way to avoid chasing permission later is to collect testimonials through a channel where people knowingly write feedback for publication, rather than repurposing a private message that was never meant to go public. This is where a dedicated tool helps. When someone leaves a review through XLens Review, they are deliberately submitting it as a public review, and if they include an email they verify it with a single-use token before it counts. So the words on your site came from a real person who chose to share them, which is far firmer ground than a screenshot of a chat.

XLens Review also keeps a separate, explicit opt-in for whether the reviewer wants to hear from you by email, off by default and never assumed, with a record of when they opted in and which version of the wording they agreed to. Publishing a review someone wrote for you and adding them to a marketing list are two different permissions, and keeping them apart respects the customer and keeps your records clean.

When someone changes their mind

Permission is a relationship, not a signature you file and forget. Occasionally a customer will move on, rebrand, or simply prefer their quote comes down, and honoring that quickly is part of keeping the whole wall trustworthy. This is easier when you control what is live. With XLens Review, nothing publishes until you approve it, and each approval and rejection is kept in an audit trail, so pulling a testimonial or swapping an attribution is a deliberate action you can make on request rather than a scramble through scattered screenshots.

Handled this way, permission stops being a legal worry and becomes a habit. You ask, you record the yes, you keep control of what shows, and you take things down when asked. Do that, and every testimonial on your site is one you can stand behind, which is the entire reason to display them.