Update your privacy policy for SMS

Updated August 17, 2026

As part of the registration and approval process for your SMS messaging, carriers require that your Privacy Policy and Terms of Service include specific language that outlines how you collect, use, and store customer information and how you manage consent for SMS messaging.

Your policies must be live when you request a phone number

Your privacy policy and terms and conditions must be published and available on public HTTPS URLs before you request a phone number—not drafted or staged. Reviewers check the actual links, so placeholder or staging URLs typically result in rejection.

Note

This section contains recommendations and examples, but it does not constitute legal advice. Contact your legal team to ensure that you’re compliant with all applicable laws and regulations before you make changes to your privacy policy or terms and conditions.

Update your privacy policy

Before you request a sender phone number, you need to update your privacy policy to include information about how you’ll message your audience and use their phone numbers. You must provide links to your privacy policy and terms and conditions on your public website when you submit a request for a sender number.

You’ll need to include information about:

  • Collection and use of phone numbers: State that you collect mobile phone numbers when users opt in, explain the types of messages you’ll send, and describe how often they can expect to receive them.
  • Data sharing disclosure Required : Explicitly state that you won’t share mobile opt-in data with third parties for marketing or promotional purposes. This is the most scrutinized requirement, and missing it is one of the most common reasons registrations are rejected.
  • Opt-out instructions Required : Describe how users can stop receiving messages, such as by replying STOP.
  • Data retention: State how long you retain mobile phone numbers and consent records, and what happens to that data when a user opts out.
  • Data security: Describe the measures you take to protect mobile data from unauthorized access or disclosure.
  • Support contact information: Provide a way for users to contact your organization with privacy-related questions.

Example language

Here is an example of compliant language for your privacy policy:

Privacy Policy Example

Text messaging

[Company Name] collects mobile phone numbers from customers who opt in to receive SMS messages. We use this information to send [describe: order updates / appointment reminders / promotional offers]. Message frequency varies. Or, if known: You may receive up to X messages per month.

We do not share mobile phone numbers or SMS opt-in consent with third parties or affiliates for marketing or promotional purposes. All other data-sharing disclosures in this policy exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.

We retain mobile phone numbers and consent records for as long as you are subscribed to our SMS program, and for a minimum of five years after you opt out, consistent with our legal record-keeping obligations. (Adjust this retention period to match your own record-keeping policy; five years is a common example, not a carrier mandate.) You may opt out at any time by replying STOP, after which your number will be removed from our active messaging list.

We implement reasonable technical and administrative safeguards to protect your mobile information from unauthorized access or disclosure.

For questions about how we handle your mobile information, contact [privacy@yourdomain.com]. See our SMS Terms and Conditions at [URL] for more on our messaging program.

Using 'All other categories' for data sharing

If your policy already lists other data-sharing disclosures—like sharing with service providers or for legal compliance—you can open the data sharing statement with “All the above categories exclude text messaging originator opt-in data and consent” instead.

Your policies must be publicly accessible

You’ll need to make sure that your privacy policy and terms and conditions are publicly accessible, preferably as links from your SMS opt-in form. If these pages aren’t publicly accessible, you might not be approved to send SMS messages.

Terms and conditions

Like your privacy policy, your terms and conditions (or terms of service—however you refer to them) must include the following items. Your terms and conditions must be publicly accessible, preferably as links from your SMS opt-in form.

  • Dedicated SMS section Required : Include a section in your terms that specifically covers your SMS messaging program and its rules. This section must stand alone—you can’t satisfy this requirement by bundling it into a general terms acceptance, such as “By accepting our Terms of Use, you also agree to receive text messages.”
  • Consent is not a condition of purchase Required : Explicitly state that consenting to receive SMS messages isn’t required to make a purchase or use your services.
  • Message frequency: State how often users can expect to receive messages, like “Message frequency varies” or “You may receive up to X messages per month”.
  • Opt-out instructions: Describe how to stop receiving messages—including by replying STOP or by contacting your support team directly. Users may opt out through any reasonable method, and you must honor all requests.
  • Help instructions: Explain how users can get assistance, such as by replying HELP or contacting your support team.
  • Carrier disclaimer: State that message and data rates may apply and that carriers aren’t liable for delayed or undelivered messages.
  • Privacy policy link: Reference and link to your privacy policy, so users can understand how you handle their mobile data.

Example language

Here is an example of compliant language for your terms and conditions:

Terms and Conditions Example

SMS terms and conditions

[Company Name] offers an SMS messaging program that sends [describe: order updates / appointment reminders / promotional offers] to customers who have opted in to receive text messages. Subscribers may receive text messages at the mobile number provided at enrollment, and participation in our SMS program is not a condition of purchase or use of our services.

Message frequency varies. Or, if known: You may receive up to X messages per month. Message and data rates may apply depending on your mobile carrier and plan.

You may opt out at any time by replying STOP, or by contacting us at [support@yourcompany.com]. We will also honor opt-out requests made by any other reasonable method. You will receive a single confirmation message confirming your opt-out, and no further messages will be sent. Reply HELP for assistance, or contact us at [support@yourcompany.com].

[Company Name] is not responsible for delayed or undelivered messages. Mobile carriers are not liable for any delays or failures in message delivery.

See our Privacy Policy at [URL] for information on how we handle your mobile information.

Keep your policies consistent with your registration

The message frequency and use case you describe in your privacy policy and terms must match what you submit during brand and campaign registration. Reviewers compare the two, and mismatches are a common cause of rejection.

Your policies must be publicly accessible

Your privacy policy and terms and conditions must be publicly accessible, preferably as links from your SMS opt-in form and entries in your sitemap.

If these pages aren’t publicly accessible, you might not be approved to send SMS messages.