> ## Documentation Index
> Fetch the complete documentation index at: https://docs.ycloud.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Customer opt-in

> Collect and retain permission for expected business messages, with a clear scope and an easy opt-out.

Before proactively contacting a customer, establish that they gave you their number and agreed to receive the relevant communications from your business.

WhatsApp's [Business Messaging Policy](https://business.whatsapp.com/policy) requires opt-in; it is not merely a suggestion. You are responsible for the collection method and compliance with applicable law.

This page explains messaging consent, not a legal determination for a particular country or industry.

## Define what the customer agrees to

Make the business identity and communication purpose clear. Separate order updates, promotional offers, and calling where customers need different choices.

Recommended consent design:

* Name the business that will contact the customer.
* Describe the messages they should expect.
* Make the choice clear and voluntary.
* Explain how to stop the messages.
* Link to relevant privacy information.
* Identify WhatsApp as a delivery channel so the contact is expected.

The exact consent wording depends on your use case and applicable requirements. Do not assume a copied form is legally sufficient everywhere.

## Choose a collection point

You can collect permission where the customer interacts with your business, such as a website form, checkout, account preferences, a WhatsApp conversation, or an in-person process.

For example, a fictional preference form could offer:

```text theme={"theme":{"light":"github-light","dark":"github-dark"}}
Send me delivery updates from Northstar Books on WhatsApp.
Send me book recommendations and offers from Northstar Books on WhatsApp.
I can change my preferences or opt out at any time.
```

Treat these as distinct choices if your product offers them. The example illustrates clear scope; it is not a legal template.

<a id="opt-in-methods" />

## Keep evidence you can use

A contact record alone does not show what the customer agreed to. Recommended records include:

| Record | Why it helps |
| - | - |
| Customer identifier | Matches the decision to the intended recipient. |
| Consent source and time | Shows where and when the choice was made. |
| Wording or form version | Preserves what the customer saw. |
| Business and message purposes | Defines the scope of permission. |
| Later preference changes | Prevents an older opt-in from overriding a newer opt-out. |

Limit access to these records and retain them according to your privacy obligations.

## Do not mistake other events for consent

Importing a phone number, buying a contact list, receiving a business card, or having a template approved does not by itself establish permission for a campaign.

A customer asking one support question does not automatically subscribe to future promotions. Respond to the current request within the [service-message rules](/en/documentation/whatsapp-business-platform/messaging/service-messages), and separately establish permission for later proactive communication.

Similarly, permission to receive messages is not the same as WhatsApp's technical permission for an outbound call. See [WhatsApp Calling](/en/documentation/whatsapp-business-platform/more-whatsapp-features/whatsapp-calling).

## Check permission when sending

Apply consent and opt-out checks to the final audience, including scheduled sends and retries. A segment created last week may include customers who changed their preferences today.

If you cannot establish the relevant permission, do not treat missing data as consent. Use an appropriate existing touchpoint to offer a choice.

## Design consent your team can actually enforce

Here is an illustrative evidence record, not a mandatory API schema:

```json theme={"theme":{"light":"github-light","dark":"github-dark"}}
{
  "customer_ref": "CUSTOMER-123",
  "channel": "whatsapp",
  "business": "Example Store",
  "purposes": ["order_updates"],
  "decision": "opted_in",
  "source": "checkout_preferences",
  "wording_version": "order_updates_v2",
  "recorded_at": "2026-09-06T09:00:00Z"
}
```

Keep the original wording or a retrievable version alongside the record. Do not store an `opted_in` flag without enough context to know which business, channel, and purpose it covers.

This example covers order updates only. It should not select the customer for a promotional campaign or authorize business-initiated WhatsApp calling.

### Review real collection scenarios

| Scenario | What you can infer |
| - | - |
| Customer checks a clear order-updates option at checkout | Permission for the described order updates, subject to applicable requirements. |
| Customer sends “Where is my order?” | Intent to receive help with that request; not an automatic marketing subscription. |
| Customer clicks an ad but sends no message | Not an inbound WhatsApp conversation and not evidence of ongoing messaging consent. |
| A salesperson imports a list marked “leads” | Lead status alone does not establish opt-in. Verify the collection evidence. |
| Customer selects “Stop offers” after a prior opt-in | The newer preference must suppress the affected marketing. |
| A returning customer buys again after opting out | Do not silently restore promotional permission; collect a new choice where needed. |

### Acceptance tests before launch

Use a test contact to confirm that declining the option does not create consent, choosing one purpose does not enable every purpose, and a later opt-out wins over a stale imported record.

Where several systems exchange preferences, define which event is newer and preserve its scope. A nightly CRM import must not reactivate customers who opted out that afternoon. These are implementation recommendations; your legal team should confirm the consent design for the markets you serve.

## Put the process into YCloud

Connect your consent source to your customer records and suppression process. Use [Customer opt-out](/en/documentation/whatsapp-business-platform/consent-policies-and-account-health/customer-opt-out) for withdrawal and [Manage unsubscribers](/en/api-reference/guides/customer-data-and-operations/manage-unsubscribers) for API-based synchronization.

Also review [Business and commerce policies](/en/documentation/whatsapp-business-platform/consent-policies-and-account-health/business-and-commerce-policies): customer permission does not make prohibited content acceptable.

## Frequently asked questions

<AccordionGroup>
  <Accordion title="A customer placed an order and gave us a phone number. Can we add them to promotions?">
    Do not infer promotional permission from a checkout phone field alone. Separate necessary order communication from optional offers, and retain what the customer was told and chose. If your records do not establish the intended promotional purpose, collect an appropriate opt-in before adding that person to the audience.
  </Accordion>

  <Accordion title="Can a returning purchase restore a customer's earlier marketing subscription?">
    Not by itself. A new purchase is not a reversal of an opt-out. Preserve the withdrawal until there is a new, recorded choice covering the relevant purpose. Ensure CRM imports and checkout updates do not overwrite a newer unsubscribe event.
  </Accordion>

  <Accordion title="Can we message an imported lead list just to ask for WhatsApp consent?">
    An import label does not establish permission to contact each person. Check the original collection evidence before using WhatsApp for that request; do not treat a consent-request message as exempt from the messaging rules. Use an appropriate existing collection point, such as your website or a customer-initiated interaction, and confirm the legal requirements for your markets.
  </Accordion>
</AccordionGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.