All 915 10DLC rules

A2P 10DLC rule registry

10DLC policy pages rules

Policy checks catch inverse traps as often as omissions: a policy that contains the required sentence and, four paragraphs later, a clause that contradicts it. These rules cover both documents, their URLs, their sharing language, and the specific sentences carriers require to be present and absent.

157 rules· 41 blocking · 65 high · 38 medium · 13 low

POL-001A privacy policy URL is required on the campaigncampaign.privacyPolicyUrlBlockingBLOCKING

Every campaign registration must carry a non-empty privacy policy URL.

POL-002A terms and conditions URL is required on the campaigncampaign.termsOfServiceUrlBlockingBLOCKING

Every campaign registration must carry a non-empty terms and conditions URL.

POL-003An uploaded policy document must fit the provider file constraintscampaign policy document uploadBlockingBLOCKING

Where a policy is uploaded rather than linked, the file must be a PDF, PNG or JPEG within the tightest provider size cap.

POL-005The terms and conditions attestation must be setcampaign.termsAndConditions attestationBlockingBLOCKING

The campaign's terms-and-conditions attestation flag must be set to true, alongside supplying the URL.

POL-010Both policy URLs must resolve and return content anonymouslyprivacy policy URL + terms URL fetchBlockingBLOCKING

The privacy policy and terms URLs must resolve in DNS and return a successful response to an anonymous fetch — no session, no cookie, no member wall.

POL-015The policy host must serve a valid certificate of its ownprivacy policy + terms URL TLS chainBlockingBLOCKING

The host serving the policy pages must present a valid TLS chain, checked independently of the brand website host.

POL-016The privacy policy URL must open an actual privacy policyprivacy policy body (document classification)BlockingBLOCKING

The privacy policy URL must resolve to a real privacy policy — not the homepage, a stub, a placeholder, or a generic landing page.

POL-018Policy pages must be machine-crawlableprivacy policy URL + terms URLBlockingBLOCKING

The policy pages must be fetchable by an automated vetter — no robots.txt disallow, no noindex, no JS-only render, no geofence.

POL-022The policy must be the brand's own, not a platform'sprivacy policy body (authorship)BlockingBLOCKING

A reseller's, platform's, ISV's or generic vendor privacy policy must not be submitted in place of the brand's own.

POL-024The site hosting the policy must itself be live and realpolicy host siteBlockingBLOCKING

Where consent is collected offline, the site hosting the policy pages must still be a live, authentic site rather than a shell built to hold them.

POL-041Offline and keyword opt-in copy must carry the route to the policyverbal script, IVR prompt, keyword CTA or opt-in email bodyBlockingBLOCKING

Verbal, IVR, keyword and email opt-in copy must state where the privacy policy can be found, or carry the disclosures inline.

POL-043Print, QR and point-of-sale calls to action need a typeable policy URLprinted CTA artifact or POS screenBlockingBLOCKING

A printed, QR or point-of-sale call to action must show a spelled-out, typeable URL for the terms and the privacy policy.

POL-044The QR landing page must link a compliant policy and message-programme termsQR landing page link setBlockingBLOCKING

A QR opt-in landing page must link both a compliant privacy policy and compliant message-programme terms.

POL-045An offline opt-in does not relax the policy content requirementsprivacy policy body + terms bodyBlockingBLOCKING

The policy pages must satisfy the full content requirements even where opt-in never happens on the web.

POL-050Privacy policy must state mobile opt-in data is not shared or soldprivacy policy bodyBlockingBLOCKING

The privacy policy must explicitly state that mobile information and SMS consent are not shared or sold to third parties or affiliates for marketing.

POL-060No exception may permit sharing SMS opt-in dataprivacy policy body (whole document)BlockingBLOCKING

The privacy policy must contain no exception, carve-out or "except where" clause that permits SMS opt-in data to be shared.

POL-062A general permission to share data with other companies fails even where SMS is never namedprivacy policy body (whole document)BlockingBLOCKING

A policy permitting personal data to be shared with other companies is rejected whether or not it mentions SMS.

POL-063A policy that says mobile opt-in data is shared is refused outrightprivacy policy bodyBlockingBLOCKING

A privacy policy stating affirmatively that mobile opt-in data or consent is shared with third parties or affiliates is rejected.

POL-064No clause anywhere in the policy may permit sharing data for third-party marketingprivacy policy body (whole document)BlockingBLOCKING

The whole policy — not just the SMS section — must contain no clause permitting sale, rental, or sharing of personal data for third-party marketing.

POL-070No other document on the domain may contradict the SMS non-sharing clauseall policy-bearing pages on the brand domainBlockingBLOCKING

The terms of service, the cookie policy and any separate data-sharing page must not contradict the SMS non-sharing clause in the privacy policy.

POL-071No document may reserve the right to sell or share consent itselfprivacy policy and terms bodyBlockingBLOCKING

Neither the privacy policy nor the terms may reserve a right to sell, rent or share the consumer's consent.

POL-072Consent must not be described as transferable or assignableprivacy policy and SMS terms bodyBlockingBLOCKING

The policy and the SMS terms must not describe messaging consent as transferable or assignable between businesses.

POL-074An explicit SMS opt-in carve-out belongs in the policy either wayprivacy policy carve-out sentenceBlockingBLOCKING

The policy must carry an explicit sentence excluding SMS opt-in data and consent from any sharing, whether or not it discloses sharing elsewhere.

POL-078A political brand is held to the same data-sharing banprivacy policy bodyBlockingBLOCKING

The third-party data-sharing prohibition applies to a political brand's policy exactly as it does to a commercial one.

POL-079A charity policy must bar anyone but the charity from using subscriber dataprivacy policy bodyBlockingBLOCKING

A charity or donation programme's policy must state that no entity other than the charity itself may use the subscriber data.

POL-096The policy must state who the business isprivacy policy identity blockBlockingBLOCKING

The privacy policy must identify the business: legal name, any DBA, postal address, email address and phone number.

POL-109A cart-reminder programme must say how abandonment is detectedprivacy policy bodyBlockingBLOCKING

Where the programme sends shopping-cart reminders, the policy must state explicitly how cart abandonment is detected.

POL-114A child-directed service owes the full COPPA noticeprivacy policy children's sectionBlockingBLOCKING

Where the service is directed at children, the policy must carry the COPPA online-notice elements, including the categories of third parties that receive children's data and the purpose.

POL-117No document may designate an exclusive way to revoke consentprivacy policy + SMS terms bodyBlockingBLOCKING

No policy, terms or message copy may state that a single named method is the only way to opt out.

POL-150The SMS terms must exist as a document of their ownSMS terms documentBlockingBLOCKING

The SMS terms must be published as a distinct, directly accessible document rather than only as a clause inside the general website terms.

POL-170Terms must contain a dedicated SMS/messaging sectionterms bodyBlockingBLOCKING

The terms of service must contain a section covering the messaging programme, or a dedicated SMS terms page must exist.

POL-171The terms must describe the programmeSMS terms bodyBlockingBLOCKING

The SMS terms must carry a description of the programme — what the messages are about.

POL-175The terms must carry opt-out informationSMS terms bodyBlockingBLOCKING

The SMS terms must state how to stop the messages — "Reply STOP to cancel" or a clear equivalent.

POL-193The programme described in the terms must match the registered use caseSMS terms body vs campaign.usecaseBlockingBLOCKING

The programme description in the SMS terms must relate to the use case the campaign is registered under.

POL-194The terms must not say consumer data is sharedSMS terms and ToS bodyBlockingBLOCKING

The SMS terms must not indicate that consumer data or opt-in information is shared with third parties.

POL-195No affiliate-marketing or lead-generation language in the termsSMS terms and ToS bodyBlockingBLOCKING

The SMS terms must contain no affiliate-marketing or lead-generation language anywhere.

POL-196Opt-out information must appear in all three placesT&C body + call to action + opt-in confirmationBlockingBLOCKING

Opt-out information must appear in the call to action, in the terms and conditions, and in the opt-in confirmation message.

POL-197The programme name must appear on the call to action and in the termsT&C body + call-to-action textBlockingBLOCKING

The programme name or product description must appear both on the call to action and in the terms and conditions.

POL-225Legal entity name must be identical across policy, terms and brand recordprivacy policy + terms + brand.company_nameBlockingBLOCKING

The legal entity named in the privacy policy, in the terms, and on the TCR brand record must be the same name.

POL-242Never assert a fact about the business nobody has confirmedgenerated policy factual assertionsBlockingBLOCKING

A generated document must assert no fact about the business — retention periods, encryption, sub-processors, certifications, jurisdictions — that has not been sourced or confirmed by the user.

POL-021Policy URLs must not redirectprivacy policy URL + terms URLHighHIGH

A URL submitted for a policy page must resolve directly rather than returning a 30x redirect.

POL-023A social profile is not a policy pageprivacy policy URL + terms URL hostHighHIGH

A social-media profile or post must not be submitted as the privacy policy or terms URL where the brand has a website.

POL-025Exactly one privacy policy must be discoverableall discoverable privacy policies on the brand domainHighHIGH

The brand domain must present a single discoverable privacy policy, not several copies or versions.

POL-026The policy on the site and the policy attached to the registration must agreecrawled policy body vs uploaded policy documentHighHIGH

Where a policy document is uploaded with the registration and a policy also exists on the site, the two must not conflict.

POL-030Both documents must be linked from the site footer on every pagesite footer link setHighHIGH

The privacy policy and the terms must be linked from the footer of every page on the brand site.

POL-053The clause must say NOT SHARED, not merely "not sold"privacy policy bodyHighHIGH

The non-sharing statement must separately state that data is not shared — "we do not sell your data" alone is insufficient.

POL-061The non-sharing prohibition must hold even with consumer consentprivacy policy bodyHighHIGH

The prohibition must be unconditional — an "unless you consent" or "except where you have authorised" escape clause fails.

POL-065Boilerplate "trusted partners" language must be removed or narrowedprivacy policy bodyHighHIGH

Generic policy-generator output such as "we may share with trusted partners" must be removed or narrowed to service providers.

POL-066CCPA sold/shared disclosure must exclude phone numbers and SMS consentprivacy policy CCPA disclosureHighHIGH

Where the policy carries a CCPA "categories of personal information sold or shared" table, it must explicitly exclude phone numbers and SMS consent data.

POL-067A Do-Not-Sell link must not appear to reopen the SMS carve-outprivacy policy body + Do-Not-Sell linkHighHIGH

Where the brand publishes a "Do Not Sell or Share My Personal Information" link, the policy must make clear that the SMS exclusion applies regardless.

POL-068An override sentence should say the SMS clause prevailsprivacy policy SMS sectionHighHIGH

The policy should state explicitly that the SMS non-sharing clause prevails over any other sharing language in the document.

POL-069The general policy and the SMS clause must not contradict each otherprivacy policy body (intra-document consistency)HighHIGH

Where the policy contains both a general sharing disclosure and an SMS-specific non-sharing clause, the two must be reconciled rather than left to contradict.

POL-073The policy should say the brand does not use rented or purchased listsprivacy policy or SMS terms bodyHighHIGH

The policy or SMS terms should state affirmatively that the brand does not message rented, sold or shared opt-in lists.

POL-080A political donation programme must put its policy in front of donorsprivacy policy body + donor-facing disclosureHighHIGH

A political organisation soliciting donations by text must communicate its privacy policy to donors and enforce it.

POL-090The policy must say what messaging data is collectedprivacy policy bodyHighHIGH

The privacy policy must describe what data the messaging programme collects.

POL-091The policy must say how the number was obtainedprivacy policy bodyHighHIGH

The privacy policy must describe how phone numbers are obtained, consistently with the registered message flow.

POL-092The policy must say what the messages are forprivacy policy bodyHighHIGH

The privacy policy must describe the purpose of the texting, consistently with the registered use case.

POL-093A non-marketing programme's policy must not describe promotional textingprivacy policy body vs campaign.usecaseHighHIGH

Where the campaign is not registered for marketing, the policy must not describe promotional or marketing texting.

POL-094The policy must describe how information is collected, used and sharedprivacy policy bodyHighHIGH

The privacy policy must describe how the sender collects, uses and shares consumer information.

POL-095The policy must say how to contact the senderprivacy policy bodyHighHIGH

The privacy policy must describe how consumers can contact the sender about their information.

POL-097The policy must carry opt-out instructions of its ownprivacy policy bodyHighHIGH

The privacy policy must give opt-out instructions inside the policy itself.

POL-098The policy must disclose message frequencyprivacy policy bodyHighHIGH

The privacy policy must disclose how often the programme sends messages.

POL-099The policy must carry the message-and-data-rates disclosureprivacy policy bodyHighHIGH

The privacy policy must carry the "message and data rates may apply" disclosure.

POL-107The policy must be consistent with applicable privacy lawprivacy policy bodyHighHIGH

The privacy policy must be consistent with the privacy law that applies to the business.

POL-108The policy must describe what the business actually doesprivacy policy body vs observed site behaviourHighHIGH

The practices described in the policy must match what the site and the programme actually do.

POL-110A cart-reminder programme must be reflected in the termsSMS terms bodyHighHIGH

Where the programme sends shopping-cart reminders, the SMS terms must describe them.

POL-112Location-triggered messaging must be described in the policyprivacy policy bodyHighHIGH

The privacy policy must describe how location data is collected and why, where messaging is triggered by location.

POL-113The policy needs a children's-data sectionprivacy policy bodyHighHIGH

The privacy policy must carry a children's-data section with a parental-consent route and a deletion route.

POL-115Children's data needs a published retention policyprivacy policy bodyHighHIGH

The privacy policy must publish a written data-retention policy for children's data, with the purpose, the justification and the deletion timeframe.

POL-116A written internal do-not-call policy must existinternal do-not-call policy documentHighHIGH

The business must maintain a written internal do-not-call policy and make it available on demand.

POL-122The policy must list the categories of personal information collectedprivacy policy bodyHighHIGH

The privacy policy must list the categories of personal information collected, using the statutory category names.

POL-124The policy must state the purpose of each categoryprivacy policy bodyHighHIGH

The privacy policy must state the business or commercial purpose for each category of information, in terms a consumer can understand.

POL-125The policy must list who the information is disclosed toprivacy policy bodyHighHIGH

The privacy policy must list the categories of third parties personal information is disclosed, sold or shared to, and why.

POL-126The policy must say whether data was sold or shared in the last 12 monthsprivacy policy bodyHighHIGH

The privacy policy must state whether personal information was sold or shared in the preceding twelve months, or affirmatively that it was not.

POL-134The policy must enumerate the CCPA consumer rightsprivacy policy bodyHighHIGH

The privacy policy must enumerate the CCPA and CPRA consumer rights.

POL-135The policy must say how to exercise those rightsprivacy policy bodyHighHIGH

The privacy policy must give instructions for exercising consumer rights, including submission methods, verification and authorised agents.

POL-136A business that sells or shares must publish the Do-Not-Sell linksite-wide Do-Not-Sell linkHighHIGH

Where the business sells or shares personal information, the "Do Not Sell or Share My Personal Information" link must be published on the site.

POL-141The published documents must show when they were last updatedprivacy policy + terms date blockHighHIGH

The privacy policy and the terms must each display the date they were last updated.

POL-151The SMS terms must be about the messaging programmeSMS terms bodyHighHIGH

The SMS terms must cover the messaging programme specifically rather than restating general website terms.

POL-152The SMS terms must be findable rather than buriedSMS terms section position and anchorHighHIGH

The SMS terms must be near the top of the document or reachable by their own anchor, not buried inside terms about other services.

POL-156Published policy must not contain unreplaced template tokensprivacy policy body + terms bodyHighHIGH

The live privacy policy and terms must contain no {curly brace} or {{PLACEHOLDER}} tokens left from a template.

POL-157The documents must describe the programme as it runs todayprivacy policy + SMS terms bodyHighHIGH

The terms and the privacy policy must give up-to-date, accurate information about the programme's details and functionality.

POL-176SMS terms must state message frequency and that rates may applyterms bodyHighHIGH

The SMS terms section must disclose message frequency and that message and data rates may apply.

POL-177The terms must say one final message follows an opt-outSMS terms opt-out sectionHighHIGH

The SMS terms must state that a single confirmation message follows an opt-out and that nothing further is sent.

POL-180SMS terms must state consent is not a condition of purchaseterms bodyHighHIGH

The SMS terms must contain the statement that consent is not a condition of any purchase.

POL-181The terms must describe every opt-in method actually usedSMS terms body vs campaign.message_flowHighHIGH

The SMS terms must describe every way people join the programme, consistently with the registered message flow.

POL-184SMS terms must list the supported opt-out and help keywordsterms bodyHighHIGH

The SMS terms must name the keywords the programme honours for opting out and getting help.

POL-189The terms must distinguish transactional from promotional messagesSMS terms bodyHighHIGH

Where the programme sends both transactional and promotional messages, the terms must distinguish them and describe the separate consent.

POL-191The terms must say the opt-in applies to this programme onlySMS terms bodyHighHIGH

The SMS terms must state that the opt-in applies only to this brand's programme and is not transferable or assignable.

POL-192A sweepstakes campaign needs its sweepstakes terms in the T&CSMS terms bodyHighHIGH

A Sweepstakes campaign's terms must contain the sweepstakes terms, or a link to them.

POL-201The terms must name the contracting entity and its addressToS entity block vs brand.company_nameHighHIGH

The terms of service must identify the legal entity the consumer is contracting with, and its address.

POL-219The terms must carry a contact blockToS contact blockHighHIGH

The terms of service must carry a contact block naming the entity, its address, an email address and a phone number.

POL-226The brand name must be identical across samples, SMS terms and the opt-in disclosurecampaign.sample[] + terms body + consent disclosureHighHIGH

The brand or DBA used in the message samples must match the brand name in the SMS terms and the name shown in the opt-in disclosure.

POL-228The terms, the use case and the samples must promise the same messagesSMS terms message types + campaign.usecase + samplesHighHIGH

The message types described in the SMS terms, the registered use case and the sample messages must all agree.

POL-229The support contact in the terms must match the HELP replySMS terms contact block vs campaign.help_messageHighHIGH

The support email or phone number in the SMS terms must be one the HELP auto-reply also gives.

POL-230Keywords in the SMS terms must match the keywords declared on the campaignterms body + campaign.optout_keywordsHighHIGH

The opt-out keywords listed in the published SMS terms must be the same set declared on the campaign registration.

POL-232Every opt-in surface on the site must appear in the termscrawled opt-in surfaces vs SMS terms opt-in listHighHIGH

Every opt-in surface found by crawling the site must be represented in the list of opt-in methods in the SMS terms.

POL-241A generated document must carry brand-specific factsgenerated policy and terms bodyHighHIGH

A generated policy or terms document must contain facts specific to this brand — real product names, the actual opt-in surfaces, the actual vendors.

POL-243Mark every unverified variable and block export until it is resolveddraft policy placeholder tokensHighHIGH

Every unverified variable in a generated draft must be visibly marked, and export must be blocked until each is resolved.

POL-244Do not silently overwrite a policy the brand already publishesexisting published policy vs the generated draftHighHIGH

Where the brand already publishes a policy, a generated replacement must be diffed against it and the removed clauses surfaced for review.

POL-246Export must carry a visible not-legal-advice disclaimerdocument exportHighHIGH

A generated policy or terms document must be exported with a visible disclaimer that it is not legal advice and should be reviewed by counsel.

POL-247Do not claim a generated document makes the brand compliantproduct export copyHighHIGH

Neither the product nor its output may claim that a generated policy makes the brand compliant or approved.

POL-249A regulated vertical needs a warning that sector rules sit on topgenerated policy + product warningHighHIGH

Where the brand is in a regulated vertical, the generated documents must be accompanied by a warning that sector rules apply on top of them.

POL-252A sole proprietor still needs a published policybrand.entityType vs the policy generation gateHighHIGH

Policy pages must be produced for a sole-proprietor brand on the same terms as for any other entity type.

POL-020A non-English site needs an English policypolicy page languageMediumMEDIUM

Where the site is published in another language, an English version of the policy pages must exist.

POL-027The policy URLs must stay live after approvalregistered policy URLs after approvalMediumMEDIUM

The registered privacy policy and terms URLs must remain reachable after the campaign is approved.

POL-028Keep a dated copy of both documents as submittedprivacy policy + terms as submittedMediumMEDIUM

Both policy pages should be captured at submission so the exact version that was reviewed can be produced later.

POL-058A service-provider carve-back is required, not prohibitedprivacy policy bodyMediumMEDIUM

The policy should permit disclosure to the vendors that actually deliver the messages, while prohibiting everything else.

POL-076The privacy policy must describe data handling, not sell the programmeprivacy policy body (document purpose)MediumMEDIUM

The privacy policy must describe how data is handled rather than marketing the messaging programme.

POL-104The policy must say how message content is handledprivacy policy bodyMediumMEDIUM

The privacy policy must state how message content is stored, for how long, who can read it, and whether it is used for analytics or AI.

POL-105The policy must describe its security safeguards at a high levelprivacy policy bodyMediumMEDIUM

The privacy policy must describe the safeguards protecting the information, at least at a high level.

POL-106The policy must state retention and consumer rightsprivacy policy bodyMediumMEDIUM

The privacy policy must state how long data is kept and how consumers can access or delete it.

POL-111An incentivised opt-in needs a financial-incentive notice that agrees with the SMS clauseprivacy policy body + opt-in offer textMediumMEDIUM

Where joining the programme earns a discount or other reward, the policy must carry a CCPA Notice of Financial Incentive that does not contradict the messaging clause.

POL-123The policy must list where the information came fromprivacy policy bodyMediumMEDIUM

The privacy policy must list the sources of the personal information it collects.

POL-127The policy must state its position on minors under 16privacy policy bodyMediumMEDIUM

The privacy policy must state whether the business has actual knowledge that it sells or shares the personal information of consumers under 16.

POL-128The policy must state its position on sensitive personal informationprivacy policy bodyMediumMEDIUM

The privacy policy must state whether sensitive personal information is used beyond the permitted purposes.

POL-129The policy must name or categorise its processorsprivacy policy bodyMediumMEDIUM

The privacy policy must name or categorise the third-party processors that handle personal information.

POL-130The policy must disclose cookies, pixels and trackingprivacy policy bodyMediumMEDIUM

The privacy policy must disclose the cookies, pixels, SDKs and tracking it uses, and how to opt out of them.

POL-131The policy must describe how opt-out preference signals are handledprivacy policy bodyMediumMEDIUM

The privacy policy must describe how it honours browser opt-out preference signals such as Global Privacy Control.

POL-133A brand handling EU or UK data needs a GDPR addendumprivacy policy bodyMediumMEDIUM

The privacy policy must carry a GDPR addendum naming the controller, the legal bases, transfers, withdrawal of consent and the right to complain.

POL-140Both documents must say how changes are communicatedprivacy policy bodyMediumMEDIUM

The privacy policy must carry a section describing how changes to it are communicated.

POL-178The terms should say how to re-subscribeSMS terms opt-out sectionMediumMEDIUM

The SMS terms should describe how someone can rejoin the programme after opting out.

POL-182SMS terms must carry a carrier non-liability disclaimerterms bodyMediumMEDIUM

The SMS terms must state that wireless carriers are not liable for delayed or undelivered messages.

POL-185The terms should state a minimum ageSMS terms eligibility clauseMediumMEDIUM

The SMS terms should state the eligibility and minimum age for the programme, consistently with the privacy policy.

POL-186The terms should say the subscriber warrants the number is theirsSMS terms bodyMediumMEDIUM

The SMS terms should state that the subscriber warrants the number is their own and will tell the brand if it changes or is deactivated.

POL-187The terms should state the right to change or end the programmeSMS terms bodyMediumMEDIUM

The SMS terms should state that the brand may change or terminate the programme, and how notice will be given.

POL-188SMS terms and privacy policy must link to each otherterms body + privacy policy bodyMediumMEDIUM

The SMS terms must link to the privacy policy, and the privacy policy should link back to the SMS terms.

POL-190SMS terms must give a working support contactterms bodyMediumMEDIUM

The SMS terms must provide a support email or phone number a consumer can actually reach.

POL-200The terms need an acceptance clauseterms of service bodyMediumMEDIUM

The terms of service must include an acceptance clause saying that using the service constitutes agreement.

POL-202The terms should state a minimum ageterms of service bodyMediumMEDIUM

The terms of service must include an eligibility clause stating who may use the service and any minimum age.

POL-204The services in the terms must match the campaign descriptionToS services section vs campaign.descriptionMediumMEDIUM

The services or products described in the terms must be consistent with what the campaign description says the business does.

POL-205A retail brand's terms should cover orders and paymentterms of service bodyMediumMEDIUM

The terms of service must include a commerce section covering orders, pricing, payment, taxes, subscriptions and auto-renewal.

POL-207The terms should include an acceptable-use clauseterms of service bodyMediumMEDIUM

The terms of service must include an acceptable-use or prohibited-conduct clause.

POL-213The terms should allocate riskterms of service bodyMediumMEDIUM

The terms of service must include a disclaimer of warranties, a limitation of liability and an indemnity.

POL-214Arbitration and class-waiver language needs a lawyerToS arbitration and dispute-resolution clausesMediumMEDIUM

Arbitration, class-action-waiver and governing-law language must be reviewed by counsel rather than generated.

POL-215The terms should state governing law and venueterms of service bodyMediumMEDIUM

The terms of service must include a governing-law and venue clause.

POL-231The ages in the terms and the privacy policy must not conflictToS eligibility age vs privacy policy minors sectionMediumMEDIUM

The minimum age in the terms' eligibility clause must not conflict with the age threshold in the privacy policy's children's section.

POL-233The document dates must not predate the last change to the programmeprivacy policy + terms dates vs the last programme changeMediumMEDIUM

The last-updated dates on the privacy policy and the terms must be no older than the last material change to the messaging programme.

POL-234An opt-in incentive must be described in both documentsSMS terms + privacy policy incentive language vs the opt-in offerMediumMEDIUM

Where joining the programme earns a discount or reward, both the SMS terms and the privacy policy's financial-incentive notice must describe it.

POL-240Template policy and website content is a known reject causeprivacy policy + terms bodyMediumMEDIUM

Policy and terms text recognisable as generator boilerplate must be flagged, because reviewers reject it as evidence the business is not real.

POL-248Record who approved the document and whendocument approval recordMediumMEDIUM

The business should record who approved each published policy or terms document, and when.

POL-251Say that carriers, not CTIA, enforce the non-sharing languageproduct export disclosure copyMediumMEDIUM

The product should disclose that the SMS non-sharing language is a carrier and TCR requirement rather than a CTIA one.

POL-121The policy must say what it coversprivacy policy bodyLowLOW

The privacy policy must state its scope — which sites, apps and offline channels it applies to.

POL-137Other state-law addenda are needed where thresholds are metprivacy policy state addendaLowLOW

Where the business meets the applicability threshold of another US state privacy statute, the policy must carry that state's addendum.

POL-138The policy should offer an accessible alternative formatprivacy policy bodyLowLOW

The privacy policy must carry an accessibility statement or a route to an alternative format.

POL-139The policy should be printableprivacy policy page renderingLowLOW

The privacy policy should be available in a form a consumer can print or save.

POL-198STOP and HELP instructions must be legible — bold is not requiredSMS terms typography as renderedLowLOW

The STOP and HELP instructions must be legible in the rendered terms; bold typeface is no longer required.

POL-203The terms should cover accounts and credentialsterms of service bodyLowLOW

The terms of service must include a clause covering accounts, registration and credential security.

POL-206A retail brand's terms should cover shipping and returnsterms of service bodyLowLOW

The terms of service must include a section covering shipping, returns, refunds and cancellations, or links to those pages.

POL-208The terms should cover user-generated contentterms of service bodyLowLOW

The terms of service must include a user-content clause covering licence, takedown and a DMCA agent.

POL-209The terms should state intellectual-property ownershipterms of service bodyLowLOW

The terms of service must include a clause stating who owns the site content and the marks.

POL-210The terms should disclaim third-party links and servicesterms of service bodyLowLOW

The terms of service must include a third-party links and services disclaimer.

POL-212Email and other-channel marketing terms must be kept separate from SMS consentToS marketing-communications sectionLowLOW

Marketing terms for email and other channels must be kept separate from the SMS consent terms.

POL-216The terms should cover terminationterms of service bodyLowLOW

The terms of service must include a termination and suspension clause.

POL-217The terms should carry the standard boilerplateterms of service bodyLowLOW

The terms of service must include the standard boilerplate: severability, assignment, entire agreement, waiver, force majeure and notices.

The other 7 layers

Reading the rules is the easy part.

Ekas runs every rule that gates approval, 823 of these 915, against your registration before it reaches the carrier. It reads your site, your policy pages and your opt-in the way a reviewer would, and hands you the fix, not just the verdict.