Guide

Privacy Policy & SMS Terms Requirements

A public privacy policy with the carrier-mandated 'we don't share or sell SMS opt-in data' clause is required to get a campaign approved. A missing or non-compliant policy is one of the top rejection causes — here's exactly what it must say.

guide Last verified mid-2026 3 min read

Your privacy policy is not a formality — campaign reviewers actually open the URL and read it. A missing, broken, or non-compliant privacy policy is one of the top 10DLC rejection causes, and the specific clause carriers look for is narrow and easy to get wrong.

It must be publicly accessible

The privacy policy URL has to resolve, for anyone, without a login. Reviewers will reject if it:

  • returns a 404, a blank page, or “under construction”;
  • is login-gated or behind a paywall;
  • is linked but doesn’t actually load.

It must be linked from both your website and the opt-in form where consent is captured. At minimum the policy must disclose: what data you collect and how, how SMS data is used, the opt-in method, the opt-out method (“Reply STOP”), security, retention, and a support contact.

The carrier-mandated SMS clause

This is the line carriers require, and its absence (or contradicting it elsewhere in the policy) is rejection cause #7. The policy must clearly state that SMS opt-in data and consent are never shared or sold:

No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. SMS opt-in data and consent are not shared with any third parties.

This clause must not be contradicted elsewhere
If the broader privacy policy says you may sell or share data with third parties or affiliates, it must carve out that this never includes SMS opt-in data or consent status. A general “we may share your data with partners” clause with no SMS carve-out will get the campaign rejected even if the dedicated SMS section looks fine.

The SMS provider carve-out

Sharing data with a subcontractor strictly to deliver the messages — your CSP / SMS provider — is permitted, and you should state it explicitly so it doesn’t read as a contradiction of the no-sharing clause:

We may share data with our SMS provider solely to deliver messages.

That carve-out covers Twilio, Telnyx, Bandwidth, and similar. It does not cover sharing for marketing, analytics resale, affiliates, or lead-gen — those remain prohibited.

What the SMS Terms of Service must include

Carriers also expect a Terms of Service (or SMS Terms section) covering the program. It must include:

  • Business name.
  • Message types the recipient will receive.
  • “To cancel, reply STOP”.
  • “For help, reply HELP” plus a support contact.
  • A carrier-liability disclaimer (carriers aren’t liable for delayed or undelivered messages).
  • “Message and data rates may apply; message frequency varies.”
  • A link to the privacy policy.
Deadline · 2026-09-15
Twilio: separate Privacy Policy and Terms URLs required — From this date, Twilio submissions must include separate Privacy Policy and Terms & Conditions URLs — a single combined URL is rejected with error 30493. Plan to host them at distinct links.

Generate the carrier-mandated SMS clause and a matching Terms block from your brand and provider details with the Privacy Clause Generator.

Next

Sources