# POL-090 — The policy must say what messaging data is collected

> The privacy policy must describe what data the messaging programme collects.

- **Rule ID:** POL-090
- **Layer:** Policy pages (`POLICY_PAGE`)
- **Checks:** `privacy policy body`
- **Severity:** HIGH — Rejected by at least one carrier or provider, and a common cause of failure at the rest.
- **When it bites:** Gates approval — get this wrong and registration is refused
- **How it is detected:** AI judgement over the submitted form
- **Fix type:** Fix the privacy policy or SMS terms
- **Required by:** Twilio, Bandwidth, TCR
- **Applies:** Applies to every 10DLC registration.
- **Canonical URL:** https://ekas.io/rules/10dlc/policy-page/pol-090/

## Why this rule exists

A consumer handing over a number is entitled to know that the consent timestamp, the source, the delivery status and in many programmes the message content are kept alongside it — none of which is obvious from typing a phone number into a box. Twilio asks directly for "what customer data you collect", and a policy that names only "contact information" answers a different question.

## How to fix it

Add a short list to the data-collection section naming the messaging fields specifically. Done when a reader can see that consent metadata is kept, not just the number.

## Example of a compliant value

```text
For the Acme Coffee text programme we collect your mobile number, the date and time you consented, the page or call it happened on, and the delivery status of each message we send.
```

## Provider rejection codes

| Provider | Code | Resubmission allowed |
| --- | --- | --- |
| Twilio (gen1) | `30908` | yes |
