Privacy policy and terms
About a 2-3 minute read.
Every campaign needs two live documents: a privacy policy and terms for your messaging program. The campaign form has a URL field for each, and carriers read both during review. AgentMessage doesn't write these for you, they have to come from you or your counsel, but here's exactly what reviewers check for so yours pass.
You need both. A combined document confuses consumers and reviewers; keep them separate even if each is short.
The privacy policy
Off-the-shelf policies usually don't pass without changes, because the carriers want one specific clause most generic policies leave out.
It has to:
- Live at a working URL that resolves to the actual privacy policy, not your homepage, not a 404, not a page under construction. Check it in a private browser window before you submit.
- Describe how you collect, use, and share consumer data in general.
- Say how people can contact the business, email, phone, or address.
- Carry the SMS opt-in carve-out described below, the requirement that fails most often.
The SMS opt-in carve-out (the part that fails most)
The carriers require that SMS opt-in and consent data, phone numbers and the fact that someone opted in, is never shared with third parties for marketing, even with the consumer's consent. There are no permitted exceptions. A clause like "we may share your information with partners with your consent" disqualifies the policy for SMS purposes even if it's fine for other data.
Passing language carries this meaning unambiguously:
Information collected as part of SMS consent, including your phone number and the fact that you opted in to receive text messages from us, will never be shared, sold, or rented to any third party for marketing or promotional purposes. This applies regardless of any broader consent you may have given for sharing other types of personal information.
Reviewers look for: something that names SMS or mobile opt-in data specifically; "not shared / sold / rented"; "third party"; "marketing"; and some form of "even with consent."
What fails:
- "We may share your information with marketing partners with your consent." The "with your consent" clause is exactly what's prohibited.
- "Your information may be shared with affiliates and service providers." Too broad, carve SMS data out explicitly.
- "We do not sell your personal information." Closer, but "sell" isn't the only prohibited transfer, and it isn't specific to SMS opt-in.
Two things that get a privacy policy rejected outright
- Lead generation or affiliate marketing. If the policy describes selling consumer information to third parties as part of a lead-gen or affiliate model, the campaign is rejected. These are banned business models for registered messaging, and no consent language saves them. See Banned and restricted content.
- A use-case mismatch. If the campaign isn't a Marketing use case but the policy describes marketing, reviewers flag the inconsistency. Align the use case or rewrite the section.
The terms
Your terms, either a dedicated SMS terms page or a clearly labeled "SMS messaging" section inside your general terms, give people a permanent reference for the program rules. For the SMS portion, reviewers look for:
- Brand name, the business sending the messages.
- Program description, the types of messages people can expect, matching the campaign.
- Message frequency, "Msg frequency varies" or a specific cap.
- Message and data rates, "Message and data rates may apply."
- HELP, how to get help, typically the HELP instruction plus an email or phone.
- STOP, "Reply STOP to cancel," plus any other opt-out keywords you honor.
These overlap with what's on your opt-in screen and in your HELP and STOP replies,
see Opt-in, opt-out, and HELP. A dedicated page like
yourdomain.com/sms-terms tends to review faster than a section buried in a long
agreement; if you use a section, make it easy to find with a heading or a
table-of-contents entry.
Where the links go
Each URL goes in two places:
- Its field on the campaign form (privacy policy URL, terms URL).
- As an inline link on your opt-in screen, next to where someone consents.
Both URLs have to be live and reachable. Expired certificates, broken links, and pages that error out all fail review.
A note on legal liability
AgentMessage can tell you what the carriers require to pass review. We can't tell you what's legally compliant in your jurisdiction, privacy laws like GDPR, CCPA, and industry rules such as HIPAA are out of scope here. Talk to a lawyer who works in privacy law before you publish.
For how rejection feedback reaches you, see How rejections work.