Messaging Consent Policy
Effective: April 25, 2026 — Version 2.0
1. Purpose and Regulatory Framework
This Messaging Consent Policy establishes the mandatory requirements for sending messages through the Wappi platform. Compliance is an essential condition of the service. This policy is based on and seeks to ensure compliance with: (a) WhatsApp Business Policy and Meta Commerce Policy; (b) the Telephone Consumer Protection Act (TCPA) of the United States; (c) the CAN-SPAM Act of the United States; (d) the General Data Protection Regulation (GDPR) of the European Union; (e) telecommunications and consumer protection regulations in jurisdictions where Users operate; and (f) any other applicable legislation regarding commercial electronic communications.
2. Prior Consent Requirement (Opt-in)
Before sending any message through Wappi, the User (business) must obtain prior, explicit, free, specific, informed, and unambiguous consent (opt-in) from each End Customer. The consent must meet the following requirements:
- Voluntary: must not be conditioned on the provision of an unrelated service or be a pre-checked box
- Specific: must clearly indicate that the End Customer agrees to receive messages via WhatsApp or another messaging channel
- Informed: must identify the name of the business that will send the messages, the type of communications (transactional, commercial, or both), and the estimated frequency
- Documented: consent must be recorded with timestamp, collection channel, text shown to the End Customer, and IP address or device identifier when technically possible
- Revocable: must inform the End Customer of their right to withdraw consent at any time
3. Valid Consent Collection Methods
The following consent collection methods are considered valid under Meta's policies and applicable law:
- Web form with explicit checkbox (not pre-checked) and clear consent text
- WhatsApp message initiated by the End Customer themselves (customer-initiated conversation constitutes implicit session consent)
- Explicit affirmative response (e.g., "YES" or "I AGREE") to a consent request message
- Double opt-in (recommended): additional confirmation after initial acceptance to verify number ownership
- In-person registration with handwritten or electronic signature, or documented verbal confirmation with recording
- WhatsApp opt-in API (when available) with direct confirmation in the application
4. WhatsApp Conversation Window
The WhatsApp Business API establishes a conversation model based on time windows that every User must understand and respect:
4.1 Session conversations (24-hour window)
When an End Customer sends a message to the business, a 24-hour window opens during which the User can respond freely without needing templates. The window resets with each new message from the End Customer. Messages sent within this window are classified as "service conversations" or "session conversations".
4.2 Out-of-session proactive messages (HSM templates)
To contact an End Customer outside the 24-hour window, the User must use message templates (HSM — Highly Structured Messages) previously submitted for review and approved by Meta. These templates must comply with Meta's content guidelines and may not contain prohibited content. Available template categories are: utility conversations (transactional), authentication, and marketing.
5. Right to Revoke Consent (Opt-out)
End Customers have the irrevocable right to cancel message reception at any time. The User must implement and maintain the following mechanisms:
- Provide clear, visible, and accessible unsubscribe instructions in each communication (e.g., "Send STOP to stop receiving messages")
- Process opt-out requests automatically and immediately, without requiring additional steps or justification from the End Customer
- Send a brief cancellation confirmation to the End Customer (e.g., "You have been unsubscribed. You will receive no further messages")
- Immediately and permanently cease sending messages to the End Customer after opt-out, with the exception of direct responses to messages initiated by the End Customer themselves
- Maintain an updated suppression list to prevent accidental resending to contacts who have unsubscribed
- Configure AI Agents to automatically recognize and respect opt-out requests, including linguistic variations ("stop", "no more", "cancel", etc.)
6. Message Classification
6.1 Transactional messages
Transactional messages are communications directly related to the delivery of the service contracted by the End Customer. These include: order confirmations, shipping status updates, payment receipts, delivery notifications, appointment reminders, security alerts, and changes to service terms. These messages do not require specific marketing consent but do require the pre-existing commercial relationship and general messaging consent.
6.2 Marketing and promotional messages
Marketing messages include: promotions, offers, discounts, product launches, satisfaction surveys, loyalty programs, and any communication with a commercial or advertising purpose. These messages require specific and additional consent beyond transactional consent and must be clearly identified as commercial communications. The User must offer a visible opt-out mechanism in each marketing message.
7. User Obligations and Responsibilities
The Wappi User assumes the following obligations regarding messaging consent:
- Obtain, verify, and document consent from each End Customer before initiating communications
- Maintain accessible, auditable opt-in records with demonstrable integrity throughout the commercial relationship and 3 years thereafter
- Process opt-out requests without delay and maintain updated suppression lists
- Comply at all times with WhatsApp Business and Meta Commerce policies
- Configure AI Agents to respect opt-outs and not contact End Customers who have revoked their consent
- Not share, sell, or transfer contact lists to third parties without express consent from each contact
- Respect reasonable sending hours and not abuse messaging frequency
- Maintain messaging quality to avoid Meta-imposed restrictions on the WhatsApp number
8. Wappi's Responsibility
Wappi provides the technical tools for the User to manage consent, opt-outs, templates, and recipient segmentation. However, the legal responsibility for obtaining, maintaining, documenting, and demonstrating adequate consent from each End Customer lies exclusively with the User. Wappi acts as a technical message processor and not as the party responsible for the content or lawfulness of each communication sent by the User.
9. Non-compliance Consequences
Sending messages without adequate consent or in violation of this policy may result in: (a) restriction or suspension of the WhatsApp number by Meta, with possible permanent loss of API access; (b) suspension or termination of the Wappi account in accordance with our Acceptable Use Policy; (c) direct legal liability for the User under TCPA (fines up to USD $1,500 per unsolicited message), GDPR (fines up to 4% of global annual turnover or 20 million euros), CAN-SPAM Act, or other applicable legislation; and (d) obligation to indemnify Wappi in accordance with the Terms and Conditions of Service.
10. Contact
For inquiries, requests, or reports related to messaging consent: [email protected]