Rejected by carriers? The website is one of the most common reasons. Fix it today →

What does a 10DLC privacy policy need to say?

Quick answer

Your 10DLC privacy policy must be public, easy to find, and state that mobile numbers and SMS opt-in data are not shared with or sold to third parties or affiliates for marketing. Twilio also asks for message frequency and "Message and data rates may apply". Use one brand-specific policy, not a generic template.

A privacy policy tells people what you do with their information. For texting, reviewers look for a promise that the phone numbers and consent you collect stay with you. CTIA's Messaging Principles ask senders to keep a clear, easy-to-understand privacy policy, show it with clearly labeled links, and make it reachable from the place where people opt in. Providers then add their own specific wording rules.

What must the SMS part of the policy include?

Item Why Who asks for it
No sharing or selling of mobile numbers for marketing Core consent protection Twilio (30908), Telnyx, Bandwidth, Vonage, Plivo
SMS opt-in data and consent excluded from any sharing Closes the "we share with partners" loophole Telnyx, Bandwidth, Vonage, Twilio (30932)
How you collect, use, and share information Basic privacy notice CTIA 5.2.1
Message frequency Tells people what to expect Twilio (collect business info, 30896)
"Message and data rates may apply" Fee disclosure Twilio (collect business info, 30896)
Public, no login needed Reviewers must be able to open it Twilio
Brand-specific and clearly labeled Shows it is your policy Telnyx

What does sample SMS privacy language look like?

Sample language, not legal advice. Adapt it to your business and have a lawyer review it if you are unsure.

SMS and Text Messaging

[Business Name] may send text messages to people who opt in on
[https://yourdomain.com/contact] or by other methods described in our SMS Terms.

How we use your mobile number: We use your mobile number and consent only to
send the messages you signed up for, such as [appointment reminders / order
updates / offers], and to respond to your requests.

No sharing: We do not sell, rent, or share your mobile phone number or your
SMS opt-in data and consent with third parties or affiliates for their
marketing or promotional purposes. Any sharing of personal information
described elsewhere in this policy excludes SMS opt-in data and consent.

Frequency and rates: Message frequency varies. Message and data rates may apply.

Opting out and help: Reply STOP to any message to stop receiving texts.
Reply HELP for help. See our SMS Terms at [https://yourdomain.com/terms].

Contact us: [Business Name], [email], [phone].

Why does Twilio want only one privacy policy?

Twilio error 30908 lists "multiple conflicting policies" as a rejection reason. If your site has an old policy in the footer and a new one on another page, a reviewer may find the wrong one. Keep one policy at one URL, link to it everywhere, and paste that same URL into your campaign form.

What are common privacy policy mistakes?

  1. Sharing language. Phrases like "we may share your information with partners for marketing" conflict with the no-sharing rule. Twilio 30908 and 30932 both flag this.
  2. No SMS clause at all. A general website policy that never mentions texts or mobile numbers.
  3. A generic or reseller policy. Telnyx says the policy must be brand-specific, not a template or a reseller's policy.
  4. More than one policy. Conflicting versions on the same site (Twilio 30908).
  5. Hard to reach. Behind a login, in a download, or broken. Twilio says it must be public with no login.
  6. Hidden link. CTIA asks for a clearly labeled link, and Telnyx says links should not be pop-ups.

Put it in three places:

  1. Your site footer, labeled "Privacy Policy".
  2. Next to the SMS consent checkbox on your opt-in form.
  3. The Privacy Policy URL field of your campaign registration.

Bandwidth says the link goes in Campaign Details. Twilio added a dedicated Privacy Policy URL field to its Console on February 18, 2026.

Which providers say this?

Provider What they say
Twilio One clear policy stating mobile numbers and messaging consent are not shared with or sold to third parties or affiliates for marketing (30908); no sharing opt-in data with lead generators (30932)
Telnyx Brand-specific, clearly labeled; not sold or shared for promotional or marketing purposes; exclude SMS opt-in data if other data is shared
Bandwidth Mobile info not shared with third parties or affiliates for marketing; opt-in consent data not shared
Vonage No mobile info shared for marketing; originator opt-in data and consent excluded from any sharing
Plivo Includes a no-sharing clause

How does 10DLC Site handle it?

Every site we build includes one privacy policy at a single URL, written for your brand name, with an SMS section that covers the no-sharing clause, frequency, rates, STOP, and HELP. It is linked in the footer and next to the opt-in checkbox. Compliance Watch checks daily that the policy page is live and the SMS clause is still there.

Sources

Want to know if your current policy has the SMS clause? Check your site free, or see pricing for a site with it built in.

Built to these requirements

Get a carrier-ready website in about 15 minutes

A new .com with hosting, SSL, a privacy policy that covers SMS, SMS terms and a compliant opt-in form, built to the requirements on this page. You submit your own 10DLC registration, and no one can guarantee approval, but a reviewer will have nothing on your site to flag.

Get my website: $149 →

One-time price · 14-day money-back guarantee · Daily Compliance Watch

Frequently asked questions

Does my privacy policy need a special SMS section?

Yes. Twilio, Telnyx, Bandwidth, Vonage, and Plivo all ask for language saying mobile information and SMS opt-in consent are not shared with third parties or affiliates for marketing or promotional purposes. A general privacy policy without this clause is a reason Twilio lists for rejecting a campaign (error 30908).

Can my privacy policy say we share data with partners?

Not for mobile numbers or SMS consent. Twilio error 30932 says the policy must not allow sharing mobile opt-in data with third parties, affiliates, or lead generators. Telnyx says if you share other data, add a line that excludes SMS opt-in data and consent from that sharing.

Can I use my software vendor's privacy policy?

No. Telnyx says the privacy policy must be specific to your brand, not a reseller's policy or a generic template. The reviewer needs to see your business name and your rules for the messages you send.

Is a privacy policy URL required on the campaign form?

At Twilio, yes, for new campaigns. Since June 30, 2026, Twilio rejects new A2P 10DLC campaigns submitted through the API without a privacy policy URL. TCR lists the field as optional in its own system but says a compliant privacy policy is required.

What website do I need for 10DLC approval?

The 8 website requirements reviewers check for A2P 10DLC: privacy policy, SMS terms, opt-in form, brand match, contact info, HTTPS...

Why was my 10DLC campaign rejected for a privacy policy that is missing SMS language?

A 10DLC privacy policy needs a clear SMS no-sharing clause. See why campaigns get rejected for it, a sample clause, and how to res...

What should SMS terms and conditions include for 10DLC?

What SMS terms need for A2P 10DLC: program name, message types, frequency, rates, HELP, STOP, and a public https page. Includes sa...

What does a compliant 10DLC opt-in form look like?

How to build an SMS opt-in form reviewers accept: unchecked checkbox, optional consent, disclosure next to the box, privacy and te...

What counts as SMS opt-in consent?

SMS opt-in consent is a person's clear permission to get your texts. Learn CTIA's three consent levels and what a compliant web op...

Carrier-ready website: $149Get started