Part of Inbox texting approval. This page is only about your Privacy Policy. For the full checklist (names, Terms, consent form, samples, submit), see Signing Up for Inbox: Texting Compliance Requirements.
Before CoolFocus can turn on text messaging for your organization, carriers require an approval process called A2P / 10DLC (Application-to-Person messaging on 10-digit long code numbers that businesses use to send text messages in the United States).
U.S. mobile carriers (Verizon, AT&T, T-Mobile, and others) use this process to differentiate legitimate business texts from spam and to filter or throttle unregistered traffic. You provide this as part of the Set up texting wizard, in the guided texting setup, from Settings → Phoneting → setup is up temporarextily paused while we move to a new phone provider — if you cannot find it, nothing i wrong with your account. Yontact WayCool Support if you need a nuur organicy rezady tion.
Registration requires three documents. This article covers only #1:
1. Privacy Policy (this page)
2. Terms and Conditions Requirements for Texting — SMS rules + carrier delivery language
3. Client Texting Consent Form Requirements — how clients opt in
All message senders must have an acceptable Privacy Policy when registering 10DLC (10-Digit Long Code) campaigns. The most important aspect of the Privacy Policy mandates that your organization clearly describes how consumer data will be used and shared (if applicable), and how consumers can contact the message sender. A compliant Privacy Policy for 10DLC messaging should include the points below to help ensure that campaign registration and vetting are successful.
Consent
When a campaign is being vetted, the language presented in a sender's Privacy Policy is heavily scrutinized to ensure the message sender doesn't improperly claim to have the consumer's consent to share end-user data with third parties for marketing purposes. While it's permissible for a business to share end-user data when it is essential for business operations, the fundamental practice of sharing data to for the purpose of selling consumer information (leads) to third parties is a prohibited campaign type and will be rejected.
Privacy Policies are reviewed during vetting to ensure consumer data isn't transferred among various organizations. To successfully address these requirements, we recommend adopting and including a process in the Privacy Policy that demonstrates that senders will refrain from sharing consumer data.
Example: "Mobile information will not be shared with third parties/affiliates for marketing/promotional purposes. All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties."
Basically, your Privacy Policy is checked for language that shows messaging consent data is not being shared, sold, or bought.
Disclose what data you collect and how it is used — Include mobile phone numbers and that SMS / text messaging is how you contact people.
State clearly that mobile information and opt-in consent are not shared with third parties or affiliates for marketing or promotional purposes.
This exact wording, or very similar, is required in your Privacy Policy:
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes.
Other carrier-friendly examples:
• Text messaging originator opt-in data and consent will not be shared with any third parties.
• All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
• We do not share, sell, or rent SMS consent or mobile numbers to third parties for their marketing.
The non-sharing wording must clearly apply to mobile numbers / SMS consent and third parties — not only to email or "personal data" in general.
How people control texts (best practice)
Best practice is to also state on the Privacy Policy (or link from it to the Terms & Conditions) that:
• People can reply STOP to opt out
• People can reply HELP for help
• Message frequency varies (or your real cadence)
• Message and data rates may apply
Stay public and consistent. The URL you enter in CoolFocus must match the live page. If you update the policy, republish it, then revisit the Review step of the setup wizard to confirm the link still passes.
Your Privacy Policy must:
Load without a login
Live on your organization's real website domain (not a parked domain or someone else's site). Shared document hosts (Google Doc, Dropbox, Canva) are a common first-pass failure for Privacy and Terms & Conditions. The Privacy Policy must be a direct link from your website.
Use normal page text (not a PDF, image, or script-only widget that CoolFocus cannot read)
Pro tip: Consider a text messaging–specific Privacy section (or short dedicated page) titled something like Text messaging or SMS, rather than burying one line in a long general policy. Dedicated messaging language is easier for reviewers to find.
• Put SMS/text language in its own short section titled Text messaging or SMS
• Do not say that you sell, buy, or rent mobile numbers or messaging consent for third-party marketing
• Avoid conflicting sentences nearby (for example "we may share your number with partners for their offers")
The setup wizard's review screen looks on your Privacy Policy link for mobile/SMS consent non-sharing language tied to third parties, and flags anything worth a second look before you send it for approval.
• Privacy is only on a Google Doc, PDF-only file, or login-only page
• Missing mobile information / SMS opt-in not shared with third parties language
• Non-sharing language talks only about email or general "personal data," not specifically mobile/SMS messaging
• Conflicting language that allows selling or sharing numbers for partner marketing
• Signing Up for Inbox: Texting Compliance Requirements
• Terms and Conditions Requirements for Texting
• Client Texting Consent Form Requirements
• Purchasing Your Text Number