Back home

Legal

SMS Messaging Policy

Last updated

This SMS Messaging Policy sets out what you must do to send text messages to your own recipients through Unitpost. It is part of our Acceptable Use Policy, which is incorporated into the Terms of Service. Where this policy and the Terms differ, the Terms control.

It is not the same document as our SMS Terms, which describe the optional account alerts Unitpost sends to you. This page is about the messages you send.

We describe here what we require and what we enforce. We do not give legal advice. You are responsible for complying with the laws that apply to you and your recipients, and you should seek your own counsel.

01Scope and definitions

This policy applies to every SMS you send through Unitpost from any sending identity: a toll-free number, a 10-digit local (10DLC) number, a Canadian local number, or an alphanumeric Sender ID.

  • You are the sender of record. Unitpost is the conduit. The messages are yours, sent under your consent, your brand registration and your program. You are responsible for their content, their recipients and their lawfulness.
  • Transactional messages carry information about an action the recipient took or a relationship they already have with you: verification codes, receipts, order and delivery updates, appointment reminders, security alerts. They must not promote a product or service.
  • Marketing messages promote a brand, product or service or invite a purchase: sales, launches, restock alerts, newsletters, loyalty invitations. A discount code or call to action inside an otherwise informational text makes it marketing.
  • Recipient means the person whose phone number you message. Consent record means the evidence that a recipient agreed to receive messages from you.

03Message requirements

  • Identify yourself. Every message names the business the recipient agreed to hear from, except a reply inside a conversation the recipient started.
  • Say how to stop. The first marketing message from a number tells the recipient to reply STOP (or a standard equivalent). Ongoing programs repeat it regularly. A one-way Sender ID cannot receive replies, so every marketing message from a Sender ID must carry a working unsubscribe link. We do not check message bodies for these elements; including them is your responsibility.
  • Disclose frequency at opt-in. Your opt-in language and your confirmation message state how often you will text (or that frequency varies) and that message and data rates may apply.
  • Keep HELP working. Your registered help text names you and gives a way to reach you. On the phone numbers we provision, we answer HELP with the help text you registered.
  • Do not mislead. No false urgency, no invented deadlines, no impersonation of a carrier, bank, government agency, delivery service or any other party, no deceptive links, and no content that would fail truth in advertising rules where the recipient lives.
  • Match your registration. What you send must look like the sample messages and use case you registered for that number or Sender ID (see section 7).

04STOP, HELP and START

We handle the carrier keywords on every phone number we provision, in the language the carrier requires (for example ARRET on a Canadian number). You do not build keyword handling yourself, and you must not interfere with it.

  • STOP (and the standard equivalents: STOPALL, UNSUBSCRIBE, CANCEL, END, QUIT, OPTOUT, OPT-OUT, REMOVE, TD, and ARRET) opts the number out of your whole SMS channel, service messages included. We match the keyword as the whole message, ignoring case and trailing punctuation. On a local or Canadian number we recognize all of these and send one confirmation using your registered STOP text; nothing else follows. On a US toll-free number the carrier intercepts STOP and sends the confirmation itself, and we record STOP and STOPALL. The opt-out never touches the recipient's email subscription.
  • HELP (or INFO) returns your registered help text.
  • START or UNSTOP restores service messages only. Marketing needs a new express written consent.

You must honor an opt-out however it reaches you: a reply in plain words (we act only on the keywords above, so “please stop texting me” is yours to handle), an email, a phone call, a support ticket, a social message, or a request made to a partner. Record it in Unitpost (the contact page or the consent API) promptly and in any case within ten days, and never message that number again until the recipient opts back in. You must not word opt-out instructions, or spell keywords, in a way meant to defeat recognition.

Alphanumeric Sender IDs are one-way. Recipients cannot reply STOP to them, so opt-out for a Sender ID is the unsubscribe link in your message, and you record the result in Unitpost.

05Quiet hours

Marketing messages are delivered only between 8:00 and 21:00 in the recipient's local time, in every country we allow marketing to. Where a law or an operator code sets a narrower window, the narrower window applies: for example 8:00 to 21:00 under the US Telephone Consumer Protection Act rules, and 8:00 to 20:00 under the French operators' code. We hold a marketing message that falls outside the window and deliver it when the window opens. It is delayed, not dropped, and you are not charged twice.

Transactional messages are not held. A verification code or a delivery alert goes out when you send it.

We place a recipient on a clock from their phone number. When a country has several time zones and we cannot resolve the zone, we use the window that is inside 8:00 to 21:00 in every zone of that country. Some places have stricter day-of-week or holiday rules (for example Sunday and public-holiday limits) that we do not yet model; complying with them is your responsibility, and scheduling your campaign inside them is the way to do it.

06Prohibited content and use cases

You must not use Unitpost to send, link to, or run a program for any of the following, whether or not it is legal where you or the recipient are located. Carriers block these categories and a violation can cost you the number and the brand registration.

Never allowed

  • Sexual or adult content, adult services, escort or compensated companionship, adult dating.
  • Hate speech, harassment, threats, or content that incites violence or discrimination.
  • Firearms, ammunition, firearm parts and accessories, explosives, and other weapons including knives, tasers and stun guns.
  • Cannabis, CBD, THC, kratom and other psychoactive or controlled substances, prescription medicines that cannot legally be sold over the counter, and paraphernalia.
  • Anything illegal where the message is sent or received, including counterfeit goods and intellectual-property infringement.
  • Phishing, smishing, malware, credential harvesting, fake prizes, advance-fee scams, impersonation of any person, brand, carrier, bank, government body or delivery service, and simulated phishing or security-testing traffic.
  • High-risk financial offers: payday loans, short-term high-interest loans, third-party mortgage, auto or student loans, debt collection on behalf of a third party, debt consolidation, reduction or forgiveness, credit repair, cryptocurrency and forex promotion, stock tips and risky investment offers.
  • Multi-level marketing, pyramid and referral schemes, get-rich-quick, work-from-home, secret-shopper and similar offers.
  • Third-party lead generation, affiliate marketing where you have no direct relationship with the promoted product, list brokering, and the sale or sharing of recipient data or opt-ins.
  • Fireworks.
  • Snowshoeing (spreading similar content across several numbers to evade filtering), filter evasion, URL or number cycling, and sending from a number that is not yours or that you share with another business.
  • Public or shared URL shorteners (bit.ly, tinyurl.com, t.co and the like). Use a link on a domain you control. Our screen records the use of a public shortener; repeated use is a violation.
  • Person-to-person traffic relayed through the platform, and messages that offer emergency services.

Allowed only with an age-gated registration

Alcohol, tobacco and vaping, gambling, sweepstakes and lotteries may be promoted only over a number whose carrier registration declares the use case and an age gate, only where the carrier and local law permit it, and only to recipients you have verified are of legal age. We do not verify the age gate at send time; without that registration carriers are likely to filter the message and the violation is yours.

Allowed only when the registration says so

Political messaging, charitable or political donation asks, and anything else that carriers treat as a special use case may run only over a registration that declares it. A first-party payment reminder about a debt owed to you is allowed; collecting on behalf of someone else is not.

We screen the text of every message before it is sent: a single message when you send it through the API or the dashboard, and a campaign template when you schedule the campaign. Content our screen recognizes as sexual, hateful, weapons, cannabis or a controlled substance, or a phishing or scam pattern is refused. For the other categories on this page, and for public link shorteners, the send goes ahead: our screen records the match for our review and may trigger a model review of your recent messages, and the responsibility stays with you. Our screening is keyword-based and is not a permission: a message we did not catch, or let through, is still a violation.

07Registration truthfulness

Carriers and regulators approve a brand and a use case, not a number. What you tell them must be true and must stay true.

  • Your brand details (legal name, website, contact) and your use-case description and sample messages must describe the traffic you actually send. Do not register a notification use case and send promotions.
  • We refuse a marketing campaign over a number that is registered for a non-marketing use case, and a marketing message over a sender pool set up for transactional or verification traffic. Register a marketing use case, or make the campaign transactional. A single marketing message sent through the API is not checked against the registration; sending one over a non-marketing registration is still a violation.
  • One brand, one registration. Do not spread one program across several numbers, brands or workspaces to dilute complaint metrics or evade filtering, and do not re-register a brand or number that was rejected or suspended under a different name.
  • Keep your website and the pages your messages link to consistent with your registration: they must identify you and give contact details, and your opt-in flow must appear where you said it does.
  • A Sender ID must be your brand name or an unambiguous abbreviation of it. Impersonating another brand's name in a Sender ID is prohibited.

08Countries and local law

  • Each sending identity reaches specific countries. We route a message only over an identity that can deliver to the recipient's country, and never forward best-effort from a shared identity.
  • Marketing is delivered only to countries for which we have modeled a consent and quiet-hours rule. A marketing message to any other country is skipped, not attempted. Transactional messages are not gated by country rules.
  • Where a country's law sets stricter consent, identification, hours or registration requirements than this policy, the law prevails and you must follow it. Examples include the US TCPA and state rules, Canada's CASL, the UK PECR, the EU ePrivacy Directive as transposed nationally, Australia's Spam Act, and national Do-Not-Call or Do-Not-Disturb registers.
  • You are responsible for the consent law of every country you message. Our country rules are a floor, not legal clearance.

09Sensitive data and minors

  • Do not send, request or collect over SMS: government identifiers (social security, passport, driver's licence, tax numbers), full payment card or bank account numbers, passwords or one-time codes you did not issue, health information, or any special category of personal data (racial or ethnic origin, political or religious views, trade-union membership, sexual life or orientation, genetic or biometric data). A one-time code you issue for your own login is fine; asking someone to text you theirs is not.
  • Do not market to anyone under 13, or under the age of digital consent where the recipient lives if it is higher. Age-restricted categories require age verification as described in section 6.
  • Publish and follow a privacy policy that covers how you use the phone numbers you collect, and link it from your opt-in.

10How we enforce this policy

We enforce this policy to protect recipients, the numbers and registrations you rely on, and the platform for every customer. Depending on severity, action is automatic or follows review.

  • Screening. The text of every outbound message is checked against the refused categories in section 6 before it is sent, and a sample of unique content sent through the API or the dashboard may be reviewed by an automated model. We may also review a message after a complaint or a carrier notice.
  • Refusal. A message in a refused category, to a recipient without the required consent, outside your identity's reach, or a marketing campaign over a mismatched registration is refused before it reaches a carrier. You are not charged for a refused message.
  • Hold. Marketing outside quiet hours is held until the window opens.
  • Pause. We may pause a number, a Sender ID, a campaign or your SMS channel while we investigate a complaint, a carrier notice, a spike in opt-outs or failures, or a registration problem. A campaign is paused automatically when its sender loses carrier approval or when your workspace is suspended.
  • Suspension. Serious or repeated violations, or a confirmed abusive pattern, result in suspension or termination of your account under the Terms. Where our automated model and our content screen both identify abusive content, the workspace is suspended automatically and reviewed by us. Fees are not refunded on suspension for a policy violation.
  • Carrier fees. Carriers charge fees for policy violations (for example per-instance content violation and program evasion fees in the US). If a carrier or our upstream provider charges us a fee because of your traffic, we may pass it through to you, by invoice or as a debit from your wallet, under the Terms.
  • Reporting. Where a carrier, registry or regulator requires it, or the law compels it, we report the violation and the registration it occurred under, and we cooperate with their investigation.

When we act we tell you what we found, which message or registration it concerns, and what would resolve it, unless doing so is prohibited or would help an ongoing abuse. You can reply to the notice to dispute it.

11Your responsibilities and indemnity

You are responsible for complying with every law, regulation, carrier code and industry standard that applies to your messages and your recipients, including without limitation the US Telephone Consumer Protection Act (TCPA) and FCC rules, the Telemarketing Sales Rule, state telemarketing and privacy laws, Canada's Anti-Spam Legislation (CASL), the UK Privacy and Electronic Communications Regulations (PECR), the EU General Data Protection Regulation and ePrivacy Directive and their national transpositions, Australia's Spam Act 2003, the CTIA Messaging Principles and Best Practices, and the codes of conduct of the carriers that deliver your messages.

You are responsible for the acts of anyone who sends through your account, including your own customers if you build on Unitpost, and you must hold them to at least these rules.

Unitpost provides tooling and enforces the rules above, but we are not your counsel and our controls are not a legal clearance. Under the Terms of Service you indemnify Work Reactor Inc. against claims, damages, fines, penalties and costs arising from the messages you send and from your breach of this policy or applicable law.

12Reporting abuse

If you receive a text sent through Unitpost that you did not agree to, or that violates this policy, report it to legal@unitpost.com or, for general support, . Include the sending number or Sender ID, the date and time, and the message text. Replying STOP to a number always works and does not need a report.

On a report we investigate the sending workspace, take the actions in section 10 where warranted, and cooperate with the carrier or regulator involved. Where the recipient asks us to stop a sender's messages to their number, we see that the opt-out is recorded against that sender. Customers must report violations they become aware of in their own programs and cooperate with our investigation.

13Changes to this policy

Carrier rules and messaging laws change often. We update this page when they do and when our enforcement changes, and we note the date at the top. For material changes we give notice through the dashboard or by email before they take effect, unless a law or carrier requirement forces an immediate change. Continued sending after the effective date is acceptance. Questions: legal@unitpost.com.