Early access — pilot stage · sample data / no live messaging yet · pilot enquiry form not yet connected to intake — nothing is sent

Guide · Consent

The opt-in and consent checklist.

You may message a person on WhatsApp only when they have opted in to receive messages from your business — that is Meta’s Business Messaging Policy, and it is also good business. This guide shows what a valid opt-in looks like, how ConvoTide records and enforces consent per contact and channel, and a ten-point checklist to run before your first campaign.

What a valid opt-in contains

Meta’s policy (WhatsApp Business Messaging Policy and the developer “getting opt-in” guidance, both accessed 15 August 2026 — always re-read the live versions before relying on them) requires three things regardless of how you collect consent:

  • The person must take an action that clearly signals they are opting in to receive messages from you.
  • Your business must be named. The opt-in must state which business will be messaging them — a generic “our partners may contact you” does not cover you.
  • Local law is layered on top. In India, the DPDP Act’s consent regime applies to how you collect and honour that permission; consent and its withdrawal should be as easy as each other.

The capture method itself is free-form: a web form, an in-chat reply, paper, IVR or SMS are all acceptable — what matters is that you can produce the evidence if Meta asks. And Meta does ask, typically when block rates or complaints rise.

How the platform enforces consent

ConvoTide treats consent as data with teeth, not as a paragraph in your onboarding deck:

  • Consent is stored per contact, per channel, per purpose — with the evidence attached, so “they opted in somewhere once” is never the answer.
  • Campaign recipients are consent-gated. Adding a contact who has not opted in on the campaign’s channel is refused outright — the platform answers with a consent-required error rather than enqueueing the message.
  • Journeys check consent at the gate. Automated journey sends are opted-in-only by design, and a contact who withdraws consent exits the journey with a visible exited_consent status.
  • STOP and START are honoured in the same transaction. Inbound opt-out keywords apply the consent decision atomically with the event being processed — an opt-out is never lost to a race.
  • Exports carry consent state. When you export your contacts, each row includes its per-channel consent record, so your compliance travels with your data.

The ten-point checklist

  1. Every opt-in names your business, not just “us” or a partner.
  2. The opt-in action is unambiguous — a ticked box the user ticked, a reply the user sent.
  3. You can produce the evidence for any contact’s consent on request.
  4. Marketing consent is separate and optional; a demo request is not marketing consent.
  5. Withdrawing is as easy as granting — a single STOP, link or reply.
  6. No purchased or scraped lists. There is no valid consent to message them.
  7. Quiet hours are configured before the first campaign, not after the first complaint.
  8. Frequency caps are set, so enthusiasm cannot become spam.
  9. Consent state is re-checked at send time, not only at collection time.
  10. Your team knows who owns consent decisions — a named human, not “the system”.

What this guide is not

Not legal advice. This guide summarizes Meta’s messaging policy and general DPDP expectations as accessed on 15 August 2026; both evolve, and your specific obligations depend on your business. For legal positions, take legal advice. The platform’s enforcement is real — but the platform enforcing a rule is not the same as a lawyer approving your consent copy.

Content reviewed October 2026 · owner: Zcode (implementation) · independent factual review: Codex QC, pending.