# POL-058 — A service-provider carve-back is required, not prohibited

> The policy should permit disclosure to the vendors that actually deliver the messages, while prohibiting everything else.

- **Rule ID:** POL-058
- **Layer:** Policy pages (`POLICY_PAGE`)
- **Checks:** `privacy policy body`
- **Severity:** MEDIUM — Usually survives review, but lowers your trust score or invites manual review.
- **When it bites:** Gates approval — get this wrong and registration is refused
- **How it is detected:** AI judgement over the crawled website or policy page
- **Fix type:** Fix the privacy policy or SMS terms
- **Required by:** TCR, Twilio
- **Applies:** Applies to every 10DLC registration.
- **Canonical URL:** https://ekas.io/rules/10dlc/policy-page/pol-058/

## Why this rule exists

An absolute "we never disclose your number to anyone" is factually false — your platform, aggregator and the carriers all handle it — and a reviewer who spots the impossibility distrusts the rest of the policy. The correct shape is a narrow carve-back for message delivery.

## How to fix it

Add a narrow carve-back naming the delivery chain, immediately after the non-sharing sentence.

## Example of a compliant value

```text
We share your mobile number only with the service providers who deliver our messages (our messaging platform, aggregators, and wireless carriers), and for no other purpose.
```
