Skip to main content

SMS compliance: privacy policy & terms

Sample Terms and Condition & Privacy Policy when using SMS

Written by John | BriteApp
Updated over 2 weeks ago

Before you can send SMS messages to customers, US carriers require your account to be registered under the A2P 10DLC programme. Part of that registration involves providing links to publicly hosted compliance documents. Download the template below and follow these steps.


What you need to do

1. Download and customise the template Replace every [BRACKETED PLACEHOLDER] in the document with your actual business name, website, contact email, and address. Also fill in your sample messages in the Terms & Conditions (Section 2) and your message frequency (Section 7).

2. Publish both policies at public URLs Host the Privacy Policy and the Terms & Conditions as separate pages on your website β€” for example /sms-privacy and /sms-terms. They must be accessible without a login. Carriers will not accept Google Docs, Notion pages, or file downloads as valid URLs.

3. Let us know the URLs of these two web pages. These are submitted when we register your 10DLC campaign.


What's in the template

The download contains two documents:

SMS Privacy Policy β€” covers what data is collected, a declaration that opt-in data is never sold or shared with third parties (required by carriers), Twilio as a sub-processor, data retention, and your customers' rights to opt out, access, and delete their data.

SMS Terms & Conditions β€” covers opt-in consent, STOP and HELP instructions, message frequency, carrier charge disclaimers, US-only eligibility (18+), and governing law.


Before publishing

This is a boilerplate template, not legal advice. Have your legal counsel review the final documents before publishing, particularly if your industry has specific regulatory requirements (e.g. healthcare, finance).


Common questions

Can I use my existing privacy policy?

You can, but only if it explicitly states that SMS opt-in data is never sold or shared with third parties. Carriers reject policies that omit this language. A dedicated SMS policy is the safest approach.

Do the URLs need to be on my own domain?

Yes. They must be publicly accessible web pages. Carriers do not accept Google Docs, Notion pages, or file downloads as valid policy URLs.

What if my campaign is rejected?

The most common rejection reason is a missing or non-compliant privacy policy. Check that your published page contains the explicit no-sharing declaration, then resubmit.

Did this answer your question?