A2P 10DLC Guide

The A2P 10DLC Privacy Policy Template That Actually Passes Carrier Review

Missing or vague Privacy Policy language is the #1 reason A2P 10DLC campaigns get rejected by The Campaign Registry (TCR) and downstream carriers. This guide walks through the exact two clauses reviewers look for — no lead sharing and a clear opt-out — plus a copy-and-paste Privacy Policy template you can drop onto your site today.

Why most Privacy Policies fail carrier review

When you submit an A2P 10DLC campaign through Twilio, GoHighLevel, Bandwidth, or any other CSP, TCR and the mobile carriers (T-Mobile, AT&T, Verizon) sample the Privacy Policy URL you provide. Reviewers are checking two specific things — not the entire document. If either is missing or ambiguous, the campaign is rejected with generic reasons like "Privacy Policy does not meet requirements" or "opt-in language incomplete."

The two mandatory disclosures are: (1) a statement that mobile opt-in data will not be sold or shared with third parties for their marketing, and (2) a clear description of how a user can opt out of SMS.

Required clause #1: No lead sharing

This is where lead-gen businesses trip up. If your Privacy Policy hints — even accidentally — that phone numbers can be shared with "partners," "affiliates," or "third parties for marketing," carriers will reject the campaign. Language like "we may share your information with our marketing partners" is an automatic fail.

The safe phrasing carriers look for is explicit:

"No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Information sharing to subcontractors in support of our services may be permitted. All other categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties."
Rejected language

"We may share your information with trusted partners to send you offers you may be interested in."

Approved language

"We do not sell, rent, lease, or trade your mobile phone number or SMS opt-in status to any third party."

Required clause #2: Clear opt-out

Every A2P 10DLC campaign must document a working opt-out path in both the Privacy Policy and the message content itself. At minimum, your policy must state:

  • STOP is honored on every message and stops all SMS from the program.
  • HELP returns support contact info.
  • A non-SMS opt-out path (email or phone) is also available for users who no longer have the number.
  • Opt-out is unconditional — you can't require a reason, a login, or a form submission.

Bonus points with reviewers: state your message frequency ("varies" is acceptable) and that consent is not a condition of purchase. Both are CTIA best-practice items that reviewers actively look for.

Full copy-paste Privacy Policy template

Replace the bracketed placeholders with your company's information. This template covers the TCR, CTIA, and carrier disclosures required for a standard A2P 10DLC campaign — it is not a substitute for legal review, and you should have counsel confirm it fits your specific business.

PRIVACY POLICY

Effective date: [DATE]

[COMPANY LEGAL NAME] ("we," "us," "our") operates [WEBSITE URL] and
sends SMS/MMS text messages to individuals who have provided their
mobile number and expressly opted in. This Privacy Policy explains
what information we collect, how we use it, and — most importantly for
SMS — how we protect your mobile number and consent.

1. Information We Collect

We collect the information you provide directly, including your name,
business email, mobile phone number, and any information you submit
through forms on [WEBSITE URL]. We also collect standard log data such
as IP address, browser type, and pages viewed.

2. How We Use Your Information

We use your information to:
  - Respond to your inquiries and provide the services you request.
  - Send SMS/MMS messages you have expressly opted in to receive
    (see Section 4).
  - Operate, maintain, and improve [WEBSITE URL].
  - Comply with legal obligations.

3. No Sale or Sharing of Mobile Information (Carrier-Required)

No mobile information will be shared with third parties or affiliates
for marketing or promotional purposes. Information sharing to
subcontractors in support of our services (for example, a message
delivery platform such as our SMS provider) may be permitted; all
such subcontractors are contractually prohibited from using mobile
opt-in data for their own marketing. Mobile opt-in data and consent
are not shared with any third party for their own purposes.

We do not sell, rent, lease, or trade your mobile phone number,
SMS opt-in status, or any information collected in connection with
SMS consent. This restriction applies to all parties, including
affiliates, partners, and lead buyers.

4. SMS Program & Consent

By checking the SMS consent box on a form on [WEBSITE URL] and
providing your mobile number, you agree to receive SMS/MMS messages
from [COMPANY LEGAL NAME] related to [DESCRIBE MESSAGE CONTENT — e.g.,
appointment reminders, account updates, or requested information].
Consent is not a condition of purchase. Message frequency varies.
Message and data rates may apply.

  - HELP: Reply HELP to any message for assistance, or contact us at
    [SUPPORT EMAIL] / [SUPPORT PHONE].
  - STOP: Reply STOP at any time to opt out. You will receive one
    final confirmation message and no further SMS from this program.
  - Carriers are not liable for delayed or undelivered messages.

5. How to Opt Out

You may opt out of SMS at any time by replying STOP to any message.
You may also request removal by emailing [SUPPORT EMAIL] with the
subject line "STOP." Opt-out requests are honored promptly and
without condition. Opting out of SMS does not affect your ability to
receive non-SMS communications you have separately requested.

6. Data Retention

We retain SMS consent records (including opt-in timestamp, IP
address, and the exact language shown at opt-in) for as long as
required to demonstrate compliance with the TCPA, CTIA guidelines,
and carrier requirements, and for a minimum of four (4) years after
the last message sent.

7. Security

We use commercially reasonable administrative, technical, and
physical safeguards to protect your information. No method of
transmission over the Internet is 100% secure.

8. Your Rights

Depending on your jurisdiction, you may have the right to access,
correct, or delete your personal information, or to opt out of
certain uses. To exercise these rights, contact us at
[SUPPORT EMAIL].

9. Children

[WEBSITE URL] is not directed to children under 13, and we do not
knowingly collect information from children under 13.

10. Changes to This Policy

We may update this Privacy Policy from time to time. The "Effective
date" above indicates when it was last revised.

11. Contact Us

[COMPANY LEGAL NAME]
[MAILING ADDRESS]
[SUPPORT EMAIL]
[SUPPORT PHONE]

Pre-submission checklist

Before you resubmit your A2P 10DLC campaign, run through this list. If any answer is "no," fix it before you file — resubmissions after a rejection often take longer than the initial review.

  • The Privacy Policy is on the same domain as the opt-in form (not a subdomain or third-party site).
  • The URL is public — no login wall, no "coming soon" page.
  • There is an explicit no-sharing statement for mobile/SMS data.
  • STOP and HELP behavior is documented in the policy and honored by your platform.
  • The opt-in form has an unchecked SMS consent checkbox and disclosure text linking to this Privacy Policy and your Terms.
  • You store the opt-in timestamp, IP, and exact disclosure text shown to each subscriber.

Want us to review your policy before you submit?

Our free compliance audit checks your Privacy Policy, Terms of Service, and opt-in flow against current TCR and carrier guidance — line by line. If something will get you rejected, we'll flag it in plain English.

This guide is informational and does not constitute legal advice. TCR, CTIA, and individual carrier requirements change periodically — verify current guidance before submitting your A2P 10DLC campaign.