WayCool
WayCool
Docs
  • Docs
  • Changelog
  • Feature requests
  • Support portal
    • Inbox Overview
    • Inbox Settings
    • Texting Compliance Requirements
    • Purchasing Your Text Number
    • Getting Started in the Inbox
    • Sending Text Messages
    • When to Use a Regular Text vs. a Secured Message
    • Customizing the Secure Message Invite
    • Managing Conversations in Inbox
    • Conversation Types and Linked Records
    • Notes, Tags & Tasks in Inbox Conversations
    • Message Attachments
    • Understanding Text Message Delivery Warnings
    • Inbox Best Practices
    • Unresolved Texters
    • Merging & Cleaning Up Conversations
    • Texting More Than One Person
    • Inbox Domains: Client, Donor, and Volunteer
    • Sharing Information in the Client Portal
    • Website Chat Widget

Texting Compliance Requirements

What phone carriers and the national registry need before your organization can use the CoolFocus texting feature in Inbox — Privacy Policy, Terms & Conditions, Client Texting Consent Form, and first-pass approval tips.
Texting Compliance Requirements

Order of operations: Complete this Inbox Compliance checklist and wait for approval first. After WayCool connects your texting credentials, purchase your number under Settings → Inbox Settings → Numbers. See Purchasing Your Text Number.

Before CoolFocus can turn on text messaging for your organization, carriers require an approval process called A2P / 10DLC (Application-to-Person messaging on 10-digit long code numbers that businesses use to send SMS/MMS in the United States).

US mobile carriers (Verizon, AT&T, T-Mobile, and others) use this process to tell legitimate business texts apart from spam and to filter or throttle unregistered traffic. CoolFocus walks you through registration under Settings → Inbox Settings→ Compliance.

Goal of this article: help you submit a packet that The Campaign Registry (TCR) can approve on the first pass — especially your Privacy Policy, Terms and Conditions, and client texting consents.

CoolFocus does not provide legal advice or finished legal text. You will need to have leadership or counsel approve anything you publish. Regulators look for clear concepts, not one magic sentence for compliance. The requirements below follow Twilio guidance (our texting provider) and carrier best practices.

The three documents carriers always expect

When you apply for texting, Twilio and the carriers use these three items to confirm your organization is legitimate and that people are not being spammed:

  1. A public link on your website to your Privacy Policy

  2. A public link on your website to your Terms and Conditions

  3. Your Client Texting Consent Form (or equivalent public consent proof) showing clients gave permission to receive SMS (text messages)

If you do not already have these documents available, build them with leadership or legal counsel using the guidelines below, then enter the live URLs and consent proof in CoolFocus.

The six approval steps

Work through these in order. Each step in CoolFocus is clickable and opens the right page:

  1. Your names — name clients see (DBA, doing business as…), IRS legal name, tax ID, and primary contact person

  2. Legal pages — public website, Privacy Policy, Terms and Conditions, and SMS consent disclosures

  3. Messaging & consent proof — how contacts opt in, including STOP/HELP keywords and your client texting consent proof

  4. Message examples — two or more sample texts that match how you actually text

  5. Precheck — CoolFocus checks for common rejection causes before anything is submitted to the national registry

  6. Submit for WayCool review — WayCool reviews your packet and submits your brand and campaign registration into Twilio for TCR review

The Messaging Campaign details page also links back to the checklist:

  • If status is Not submitted yet or Changes requested, use Open approval in the banner at the top

  • After you publish the Stable Proof Link, use Back to approval checklist next to the publish date

Checklist: what to have ready

  • EIN / Tax ID that matches your IRS legal name

  • Website on your own domain (not a shared Google Doc, Dropbox, or Canva link for Privacy/Terms)

  • Privacy Policy URL that is public, live, and SMS-specific (see below)

  • Terms and Conditions URL that is public, live, and includes SMS + carrier delivery language (see below)

  • Client texting consent form / proof you can show reviewers (see below)

  • Organization-domain email for the primary contact (personal Gmail/Yahoo/Outlook is often rejected)

  • Sample messages that lead with the name that clients see (for identification) and include how to opt out (STOP)

Do not use CANCEL as an opt-out word. Clients who reply Cancel to an appointment reminder text can inadvertently opt out of future text messages from your organization. Use STOP for opt-out instead.

  • Opt-in keywords (CoolFocus recommends START) and automatic HELP/STOP replies

The name on your website is often not enough

Clients may know you as Pregnancy Choices, while the IRS lists you as Save a Life Inc. Carriers reject registrations when the public website name is submitted as the Legal Business Name.

In CoolFocus you will enter both:

  1. Name clients see — public or DBA name used in sample texts and proof pages

  2. Legal Business Name — exact name on your EIN letter or Form 990

CoolFocus only auto-fills Legal Business Name from your account’s IRS legal name field. It never copies your public/portal name into Legal Business Name. If both fields match, precheck will show a warning so that you can double-check that you did not enter the public name twice. If your organization truly has only one legal name, you can leave that warning in place after confirming federal records.

How to find your legal name

  • EIN letter, determination letter, or most recent Form 990

  • Board treasurer or accountant

  • IRS Tax Exempt Organization Search — use the Returned Organization Name for your EIN

Legal pages carriers review

Every registration needs both a Privacy Policy and Terms and Conditions. They must meet specific requirements that protect clients and keep you compliant. Both are required for approval.

Registration requires separate public URLs (web addresses) for:

  • Privacy Policy

  • Terms and Conditions (sometimes labeled Terms of Service)

Enter those URLs (website links) on the campaign / legal pages step. CoolFocus and The Campaign Registry reviewers will open the live pages. Pages must:

  • Load without a login

  • Stay on your organization’s real website (not a parked domain or someone else’s brand)

  • Use normal page text (not only a PDF, image, or script-only widget that precheck cannot read)

Host Privacy and Terms on your domain. Shared document hosts are a common first-pass failure.

Pro tip: Consider creating text messaging–specific Privacy Policy and Terms pages (or a clear SMS section) rather than only burying a line in long main documents. Dedicated messaging language is easier for reviewers to find and easier to update when carrier rules change.

Privacy Policy requirements (be specific)

The Campaign Registry and carriers treat the Privacy Policy as required campaign evidence. A generic “we care about privacy” page is not enough.

Your Privacy Policy is checked for language that communicates that messaging consent data is not being shared, sold, or bought.

What your Privacy Policy must do:

  1. Disclose what data you collect and how it is used
    Include mobile phone numbers and SMS/text messaging where that is how you contact people.

  2. State clearly that mobile information and opt-in consent are not shared for marketing purposes
    Carriers and The Campaign Registry expect to see language that mobile information and opt-in consent will not be shared with third parties or affiliates for marketing or promotional purposes (CTIA Messaging Principles and Best Practices).

    This exact wording, or very similar, is required in your Privacy Policy:

    • No mobile information will be shared with third parties or affiliates for marketing or promotional purposes.

    Other carrier–friendly examples:

    • Text messaging originator opt-in data and consent will not be shared with any third parties.

    • All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.

    • We do not share, sell, or rent SMS consent or mobile numbers to third parties for their marketing.

    The non-sharing wording must clearly apply to mobile numbers / SMS consent and third parties — not only to email or “personal data” in general.

  3. Cover how people control texts
    Best practice is to also state on the Privacy Policy (or link from it to Terms) that:

    • People can reply STOP to opt out

    • People can reply HELP for help

    • Message frequency varies (or your real cadence)

    • Message and data rates may apply

  4. Stay public and consistent
    The URL (web address) you enter in CoolFocus must match the live page. If you update the policy, republish, then run Precheck again.

Privacy Policy tips for first-pass approval

  • Put SMS language in its own short section titled something like Text messaging or SMS so that reviewers can find it quickly

  • Do not say that you sell, buy, or rent mobile numbers or messaging consent for third-party marketing

  • Avoid conflicting sentences nearby (for example “we may share your number with partners for their offers”)

CoolFocus precheck specifically looks on the Privacy Policy page for mobile/SMS consent non-sharing language tied to third parties.

Terms and Conditions (keep what you have; finish SMS details)

Your Terms page should cover SMS rules for people who opt in to receive text messages from your organization. You can keep your existing Terms structure, just add or tighten the SMS / text messaging section if it is thin.

Include on your Terms:

  • Organization or brand name that clients will see on texts to identify yourself as the sender

  • Short organization description (who you are)

  • How people opt in (intake form, website checkbox, keyword START, written consent, etc.)

  • What kinds of text messages they should expect to receive (appointment reminders, care follow-up, etc. — match your real use case)

  • Message frequency (for example “message frequency varies” or “up to X messages per week”) or a recurring-message disclosure

  • Message and data rates may apply

  • Complete opt-out instructions — reply STOP to opt out and HELP for help (display STOP and HELP in bold so they are easy to spot)

  • Customer support contact (email, phone, or web contact page)

  • Link or reference to your Privacy Policy

  • Carrier delivery disclaimer (CoolFocus scans Terms only for this):

    • Delivery is not always guaranteed (delays and failures can happen)

    • Wireless/mobile carriers are not liable for delayed or undelivered messages

    Exact carrier-friendly wording often used:

    • Carriers are not liable for any delayed or undelivered messages.

Client texting consents

Carriers approve the campaign based on how end users consent to receiving text messages from your organization. “We text clients” is not enough. You must show a verifiable opt-in process — typically a Client Texting Consent Form or equivalent public proof — and keep consent records in CoolFocus.

Messaging consent should be its own clear choice — not buried only inside long Terms, Privacy Policy, or unrelated agreements. A public Privacy Policy with the non-sharing language above is also expected as part of how you describe consent.

Your consent form / proof should include:

  • Explicit SMS messaging consent

  • Message frequency

  • Opt-in instructions (how they agree)

  • Opt-out instructions (STOP / HELP)

If possible, add a checkbox or clear acknowledgment line specifically for SMS, even on a paper or PDF form. That makes it much easier for reviewers to approve.

What “good” consent looks like

Reviewers want to see all of the following:

  1. Explicit opt-in
    The person takes a clear, intentional action: checks a box, signs a form, texts START, or completes a published consent page.
    You cannot use a first unsolicited text to ask them to opt in.

  2. Separate from other agreements
    SMS consent should not be only “by using this website you agree to everything.” A dedicated SMS checkbox or consent statement is preferred.

  3. Unchecked by default
    If you use a checkbox or toggle, it should default as blank/off. Pre-checked consent is a common rejection reason.

  4. Full disclosure next to the choice
    Near the checkbox or on the consent page, tell people:

    • Who is texting (your public organization name)

    • What kinds of messages they will get

    • Message frequency

    • Message and data rates may apply

    • Reply STOP to opt out; reply HELP for help

    • SMS consent / mobile numbers are not shared or sold to third parties for marketing

    • Link to Privacy Policy and Terms

    • Consent is not a condition of receiving services (recommended)

  5. Proof reviewers can open
    Provide a public consent proof URL: live web form, CoolFocus Stable Proof Link, publicly viewable screenshot/video of the intake flow, or a clear scan of your Client Texting Consent Form if that is how you collect permission. Login walls and private Google Docs often fail (Google Docs will need to be made PUBLIC in order to be acceptable).

  6. Matches what you type in CoolFocus
    Campaign fields must describe the same flow shown on the proof page:

    • Consent methods

    • Opt-in method

    • Opt-in description (how the person actually agrees — be specific, several sentences)

    • Checkbox / acknowledgement text (exact words on the form)

    • How users consent / disclosure text (frequency, rates, HELP/STOP, non-sharing)

    • Opt-in keywords and confirmation message if you support keyword opt-in

    • HELP and STOP keywords and auto-replies

Recommended path in CoolFocus

The clearest proof for most centers is:

  • SMS keyword + published consent proof (contact texts START and/or completes a published consent/proof page with full disclosure), or

  • Intake / web form checkbox with the disclosure text next to an unchecked box, plus a public proof link, or

  • Client Texting Consent Form (paper or digital) with a dedicated SMS checkbox/acknowledgment line, plus a public copy or Stable Proof Link reviewers can open

Verbal permission alone is usually not enough for campaign approval unless it is followed by a signed or link-based consent you can show reviewers.

People can always reply STOP to opt out and HELP for help. CoolFocus records those keywords automatically.

Client texting consent vs SMS Consent Log

These are different on purpose:

  • Messaging Campaign consent proof
    Public proof page and disclosure tied to your campaign registration. This is what carriers review for A2P approval.

  • SMS Consent Log
    Staff audit trail for individual opt-ins and opt-outs collected outside a keyword flow (phone call, paper form, web form, etc.). When logging by hand, choose how consent was collected (SMS keyword, verbal, written, web form).

Use the log for day-to-day records. Do not treat the log as a substitute for the campaign’s published consent proof.

Sample consent disclosure (edit with counsel)

You may adapt language like this next to your SMS checkbox, on your consent page, or on a signed form (examples only):

By checking this box, I agree to receive text messages from [Name clients see] about appointments, care follow-up, and related services. Message frequency varies. Message and data rates may apply. Reply STOP to opt out and HELP for help. Consent is not a condition of receiving services. Mobile information and SMS opt-in consent will not be shared with third parties or affiliates for marketing or promotional purposes. See our Privacy Policy and Terms.

Written / signed form variant:

By signing below, you agree to receive SMS messages from [Name clients see] regarding appointment reminders, cancellations, and care-related communications. Message frequency varies. Message and data rates may apply. Reply STOP to opt out or HELP for assistance. Consent is not a condition of receiving services. View our Privacy Policy for more information.

Message examples

Provide at least two sample messages that match your campaign description and real use case.

Each sample should:

  • Identify your organization (name clients see)

  • Sound like a real message you will send

  • Include opt-out language (for example “Reply STOP to opt out”)

  • Use brackets for variable pieces, such as [appointment date]

  • Use real website links only if the site is live

Weak one-word campaign descriptions (for example only “Marketing”) and sample texts that do not match the description are common rejection causes.

What CoolFocus precheck looks for on legal pages

When you run Precheck or Review website, CoolFocus checks that:

  • Privacy Policy and Terms URLs (live web addresses) are present, public, and not shared-document hosts

  • Privacy Policy includes SMS/mobile consent non-sharing language about third parties

  • Legal pages mention opt-in/consent, STOP/opt-out, HELP, message frequency, and message and data rates

  • Terms reference the Privacy Policy

  • Terms include carrier delivery not guaranteed / carriers not liable language

Fix warnings before Submit for WayCool review whenever you can. Clearing precheck does not guarantee approval, but it removes the most common first-pass failures.

What happens after you submit

  1. Complete the six steps and clear precheck blockers

  2. Submit for WayCool review

  3. Contact CoolFocus support team that your Inbox compliance information has been submitted.

  4. WayCool verifies details against federal records and submits brand and campaign into Twilio / The Campaign Registry

  5. After approval, WayCool connects texting credentials. Then purchase your number under Settings → Inbox Settings → Numbers, turn on SMS routing, and send texts only to consented contacts. See Purchasing Your Text Number

Timing varies. Brand review is often fast; campaign review can take multiple business days (sometimes about 10–15 days when volume is high). Twilio may ask for more information if something is unclear.

Questions while you prepare your packet? Contact WayCool Support (in-app chat or your usual support channel).

Common first-pass failures to avoid

  • Legal Business Name does not match IRS / EIN records

  • Privacy or Terms are on a Google Doc, PDF-only file, or login-only page

  • Privacy Policy missing mobile information / SMS opt-in not shared with third parties language

  • Terms document is missing brand name, support contact, STOP/HELP, rates, frequency, or carrier delivery disclaimer

  • Consent is only described in campaign fields with no public form or proof page

  • Pre-checked SMS checkbox or consent is buried only in the Terms document

  • Sample messages without your organization name or STOP

  • Personal email domain is used for the contact person’s email address

  • Campaign description or samples that do not match how you actually text

Related

  • Purchasing Your Text Number

  • Sending Text Messages

  • Understanding Text Message Delivery Warnings

PrevInbox Settings
NextPurchasing Your Text Number
Was this helpful?