{
  "id": "POL-181",
  "slug": "pol-181",
  "title": "The terms must describe every opt-in method actually used",
  "statement": "The SMS terms must describe every way people join the programme, consistently with the registered message flow.",
  "rationale": "Vonage asks for all of them rather than the primary one, because a subscriber who joined at a counter and reads terms describing only a web form cannot tell whether the document applies to them. Programmes accumulate entry points over time — a keyword added for an event, a tick box added at checkout — and the terms are written once.",
  "layer": "POLICY_PAGE",
  "layerSlug": "policy-page",
  "object": "SMS terms body vs campaign.message_flow",
  "severity": "HIGH",
  "detectability": [
    "AI_FORM"
  ],
  "failureClass": "TERMINAL_POLICY",
  "artifact": "sms_terms",
  "authorities": [
    "Twilio",
    "CTIA",
    "Vonage"
  ],
  "codes": [
    {
      "provider": "Twilio",
      "code": "30909",
      "remediable": true,
      "generation": "gen2"
    }
  ],
  "applicabilityText": "Applies to every 10DLC registration.",
  "universal": true,
  "remediation": "List every entry point in the terms — the checkout box, the keyword, the paper form, the phone call — and keep the list the same as the message flow. Done when the two documents name the same set.",
  "example": "You can join Acme Coffee Rewards by ticking the box at checkout on acmecoffee.com, or by texting JOIN to 55512.",
  "notes": "Three rules read the same fact from three sources and can disagree independently: POL-091 asks the privacy policy, this one asks the terms against the declared flow, and POL-232 asks the terms against the surfaces found by crawling the site.",
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/policy-page/pol-181/",
  "markdown": "https://ekas.io/rules/10dlc/policy-page/pol-181.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
