Writing an SMS-Compliant Privacy Policy
TCR reviewers actually visit the privacy policy URL you submit and check it against a specific set of required language — this is the single most common reason a real A2P campaign gets rejected.
Why it matters for A2P approval
Your Campaign registration includes a privacy policy URL. TCR's automated review fetches that page and checks it for specific mobile-data-sharing language — not just "do you have a privacy policy," but "does it say the exact right thing about SMS consent data."
The exact required phrase
This needs to appear on your privacy policy page, word for word:
It should appear more than once if your policy has multiple relevant sections — for example as the first sentence of an "SMS/Mobile Messaging" section, again in a "No Sharing of Consent" subsection, and again in your general Data Sharing section.
Other required elements
- Message frequency disclosure
- "Message and data rates may apply"
- STOP opt-out instructions
- HELP instructions
- What data you actually collect and why
Common rejection: error 30908
This is Twilio's specific error code for "privacy policy non-compliant." If you hit it, the fix is almost always adding the exact phrase above, verbatim, rather than a paraphrase of it — reviewers (and whatever automated check runs before a human ever looks at it) match against the specific wording, not just the general sentiment.
A working example
Linxi's own privacy policy at linxi.app/privacy includes this exact language and has passed A2P review — worth a look if you want a concrete reference alongside the requirements above.
