Naunihal Son’s Ventures.Contact

You may only message WhatsApp users who have opted in to hearing from you. This is the platform’s rule, it is separate from template approval, and it is the one businesses most often assume they have satisfied when they have not.

Approval means Meta reviewed your content. Opt-in means the recipient agreed. A perfectly approved template sent to someone who never opted in is still a violation, and the consequence lands on your account rather than on the template.

What “opt-in” has to be

Three properties, and all three matter:

Explicit. The person took an affirmative action. Not a pre-ticked box, not consent buried in terms they accepted for something else, not “we have their number because they bought from us”.

Specific. They agreed to receive messages from your business on WhatsApp. Consent to email marketing is not consent to WhatsApp. Consent to transactional SMS is not consent to WhatsApp marketing.

Evidenced. You can produce, later, a record of when and how it was given.

That third one is where most implementations are thin. Teams collect consent correctly and then store the fact as a boolean.

What a defensible record contains

A boolean tells you that someone opted in. It does not survive a question about what they agreed to.

Store, per contact:

  • Timestamp — when consent was given, with a timezone.
  • Source — the specific surface. checkout_v3, whatsapp_widget_homepage, in_store_qr_mathura. Not “website”.
  • Wording shown — or a version identifier pointing at the exact copy they saw. Consent language changes; the record needs to say which version applied.
  • Scope — what categories they agreed to. Someone who opted into order updates has not necessarily opted into promotions.
  • Channel confirmation — evidence the number belongs to the person consenting.

That scope field is the one that pays for itself. Marketing and utility messages are different categories with different rules; if your consent record cannot distinguish them, you either over-message people who wanted receipts only, or you under-message people who wanted everything.

Where it goes wrong

The bundled checkbox. “I agree to the terms and to receive marketing on WhatsApp.” Two agreements, one action. Separate them.

The imported list. A spreadsheet of numbers from a previous system, a partner, or an offline event with no record of what was said. There is no way to reconstruct consent after the fact. If you cannot evidence it, treat it as absent.

Silence as consent. Someone messaging your business opens a 24-hour service window and lets you reply freely. It does not enrol them in your campaigns. Those are different permissions with different lifespans — the window expires in a day, consent does not.

Opt-out that only half works. If someone replies STOP, that has to propagate to every list, immediately, including campaigns already queued. An unsubscribe that takes effect next week is not an unsubscribe.

Make opting out easy

This feels counterproductive and is not.

A visible, low-friction opt-out — a footer line, an honoured STOP keyword — is what stands between an uninterested recipient and the block button. A block is a quality signal against your account. An unsubscribe is a row in a database.

The footer’s sixty characters are enough for “Reply STOP to unsubscribe” with room to spare. Use them.

The commercial argument

Everything above reads as compliance work. It is also the highest-leverage thing you can do for delivery performance.

WhatsApp maintains quality signals per business account. Blocks and negative feedback push that quality rating down, and a lowered rating reduces your daily messaging limits — which means poor consent hygiene does not just risk a policy problem, it directly shrinks how many people you can reach at all.

A smaller list of people who genuinely opted in will outperform a larger list that did not, on every metric you care about, and it will keep outperforming it because the account stays healthy.