The privacy policy clause and SMS terms a 10DLC review looks for
The most common rejection is a missing sentence in a policy that already reads fine. Here is the sentence, and the lines you have to delete for it to count.
BrandBloom7 min read

The most common single reason an A2P 10DLC submission is refused is a missing sentence in a privacy policy. Not a missing page. A missing sentence, on a page that already exists and that reads perfectly well to a human being.
This post has the sentence in it, along with the SMS terms clauses that sit beside it. Both are the ones published on this site, which were reviewed as part of BrandBloom's own campaign and approved on 24 September 2026.
Before anything else: we are a web development company, not a law firm. What follows is what passed a carrier review, which is a different thing from legal advice about your business. If your situation is unusual, or you are in a regulated industry, take it to a lawyer.
The one clause that matters most
This is the paragraph, as published:
No mobile information will be shared with third parties/affiliates for marketing/promotional purposes. Information sharing to subcontractors in support services, such as customer service, is permitted. All other use case categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties. We will NOT sell, rent, share, or disclose your SMS opt-in information.
Four sentences, and each one is answering a question a reviewer has.
Sentence one is the requirement itself, close to the wording carriers publish. Keep it near-verbatim. This is the one place in the whole submission where sounding like everybody else is an advantage: the check is looking for a known statement, and creative paraphrasing is how a compliant policy fails an automated read.
Sentence two is the carve-out, and it is there to keep you honest. You almost certainly do share phone numbers with subcontractors, because your CRM is one, your email platform is one, and your hosting is one. A policy that flatly claims you share with nobody is false, and a false policy is worse than a missing clause because it will not survive contact with your own data flows. Naming support subcontractors as permitted, and marketing as not, is both true and acceptable.
Sentence three closes the gap the first two leave. Without it, a reviewer can read "not shared for marketing purposes" and reasonably ask what happens under every other purpose. This says opt-in data is excluded from all of them.
Sentence four is the plain-English version for the person who is actually reading your policy because they are deciding whether to trust you. Not a compliance requirement. Worth having anyway.
What to delete, which nobody tells you
Adding the clause is half the job. The other half is removing what contradicts it, and this is where most policies fail even after the right paragraph has been pasted in.
Generic privacy policies, and every template generator, include a section that says something close to:
We may share your information with trusted partners who help us operate our business and market our services.
That sentence, sitting anywhere on the page, undoes the clause above. A reviewer reads the whole document. Two contradictory statements about sharing is a failure, and it is a failure that the person who pasted in the correct paragraph will not understand, because they added exactly what they were told to add.
Go looking for all of these and take them out or rewrite them:
- "trusted partners", in any sentence about sharing
- "affiliates" listed as people you share with, as opposed to people you do
not share with
- "resellers", "referral partners", "marketing partners"
- any mention of selling or buying leads or lead lists, anywhere in the
document, including in a section about something else entirely
- "we may share your information with third parties for marketing purposes",
which templates include by default because most sites do exactly that
- data broker language, and anything about enriching or appending contact records
The pattern to look for is not the word share. It is share plus a recipient. Saying you never share with affiliates is fine. Listing affiliates as a recipient is not.
SMS terms, which are not your terms of service
Your terms of service are about your service. What is wanted here is specific to messaging, and a general terms page with no messaging section does not satisfy it.
Six things have to be stated. These are ours, as published:
Program Description: Messages may include marketing updates, new lead follow-up, appointment reminders, service onboarding notifications, and general business communications.
How to Opt In: By checking the SMS consent checkbox on any BrandBloom web form. Consent is never required to purchase or receive services.
Message Frequency: Message frequency varies based on your engagement with BrandBloom.
Costs: Message and data rates may apply depending on your mobile carrier plan. For questions about your text or data plan, contact your wireless provider.
How to Opt Out: Reply STOP to any message.
Help: Reply HELP to any message, or contact us at the email address below.
Supported Carriers: AT&T, T-Mobile, Verizon, and other major US carriers.
Age: You must be 18 years of age or older to opt in to text messages.
Two of those are doing more work than they look like they are.
"Consent is never required to purchase or receive services." This is not decoration. If agreeing to messages is a condition of buying from you, the consent is not freely given and the whole opt-in is invalid. Stating it here, and meaning it on your forms, are both required.
Supported carriers and the age line are not universally demanded, and they cost nothing. We include them because a reviewer working down a checklist finds them rather than wondering.
On frequency: "varies based on your engagement" is acceptable and is what most businesses can honestly say. If you can be more specific, be more specific. What you cannot do is leave it out, because "message frequency" is one of the things an automated check looks for by name.
Where these pages have to live
Publishing the right words in a place a reviewer cannot reach is the same as not publishing them.
- Reachable from the footer of every page, as plain links. Not inside a menu
that needs a click to open, not behind a cookie wall that has to be dismissed first, not in an accordion that loads its contents with JavaScript after the fact.
- Linked from the consent text itself. Both the privacy policy and the terms
should be linked inside each consent checkbox's label, not only in the footer. The automated scan reads label text, and policy links are among the things it reads it for. This is covered in more detail in why GoHighLevel keeps rejecting your A2P campaign.
- On their own URLs, publicly, with no login.
/privacy-policyand
/terms-of-service are fine. A PDF is not.
- Carrying a visible Last Updated date. A policy with no date could have
been written at any time, including after your submission. Ours says "Last Updated: March 18, 2026" at the top, and a date there is a small, cheap signal that the document is maintained.
A check you can run yourself in five minutes
- Open your privacy policy in a private window. It loads with no login and no
wall.
- Search the page for "mobile". The non-sharing clause is there, close to the
published wording.
- Search for "partners". Read every hit. Delete or rewrite any that name a
recipient of your data.
- Search for "sell". Make sure nothing on the page sells or buys leads.
- Search for "Last Updated". There is a date.
- Open your terms. Search for "frequency", "STOP", "HELP" and "rates". All four
are present.
- Search your terms for "opt in". The mechanism is described and it matches
what your form actually does.
- Open your homepage. Both pages are linked from the footer, as links.
If all eight pass, the part of your submission that fails most often is no longer failing.
Two honest limits
This is one registration's worth of experience. Ours. It was rejected first and approved second, and everything above is what changed in between. We are not going to claim a track record we do not have.
Requirements move. Carriers revise what they look for and they do not announce it. This was accurate in September 2026. Treat it as a strong starting point and check the current requirements in your own account before you submit.
The rest of the picture is in the other two posts: the campaign description and sample messages that passed, and the consent wording and what the automated scan actually reads.
Or send us your site and we will write down what is failing, at no charge and with no call to book first: get a review.
Written September 2026, from our own registration, approved 24 September 2026. Due for review March 2027. Not legal advice.
Read next

SMS compliance
The 10DLC campaign description and sample messages that passed
Ours, word for word, with what each part is doing. Plus what "not qualified for this use case" actually means, which is rarely about your wording.
8 min read

SMS compliance
Why GoHighLevel keeps rejecting your A2P campaign
The rejection is not from GoHighLevel, and the check that fails most often is one nobody mentions. What we found getting our own campaign approved.
8 min read
