MESSAGING POLICY
Last updated August 28, 2026
This Messaging Policy sets the operating standards for every message sent through the Kubbly platform. It is incorporated by reference into the Kubbly Terms of Service and into any Master Services Agreement between Kubbly, Inc. (“Kubbly”) and its customers (“Customer”), and applies to all SMS, MMS, RCS and WhatsApp traffic Customer originates through the Services.
The Terms of Service state what Customer is obligated to do. This Policy states what that compliance requires in practice. Where a wireless carrier, aggregator, The Campaign Registry, the CTIA, Google or Meta imposes a stricter requirement, the stricter requirement governs.
The Privacy Policy governs how Kubbly handles personal information. This Policy governs how messages may be sent. Neither replaces the other.
1. Consent
1.1 Every recipient must opt in
No message may be sent to a mobile number that has not given prior express consent to receive it, from the brand that appears in the message, for the category of message being sent.
Consent obtained for one category does not authorize another. A guest who opted in to order confirmations has not opted in to promotions. Marketing messages require prior express written consent under the TCPA; transactional and conversational messages require prior express consent. Where a single program sends both, consent must be captured and stored separately.
1.2 Required call-to-action disclosures
The point at which a guest opts in — a web form, a printed sign, a checkout screen, a keyword campaign, a POS prompt — must display all of the following before consent is captured:
- the brand name that will appear in the messages
- the types of messages that will be sent (for example, order updates, promotions)
- expected message frequency
- “Message and data rates may apply.”
- “Reply STOP to opt out, HELP for help.”
- a link to Customer’s terms and privacy policy
Consent may not be a condition of purchase, and a consent checkbox may not be pre-ticked. Consent bundled with unrelated agreements in a single checkbox is not valid consent.
1.3 Consent is not transferable
Opt-in data may not be bought, sold, rented, shared with or transferred to any third party, including affiliates and other brands under common ownership. Lists that were purchased, scraped, appended or inherited from a previous vendor may not be loaded into the Services.
1.4 Multi-location and franchise programs
Where a program covers locations operated by legally separate entities, the disclosure shown at opt-in must name the entity or brand on whose behalf messages will be sent. Consent captured at one location extends to other locations only if the disclosure said so at the time of capture.
1.5 What a consent record must contain
For every opted-in number, Customer must be able to produce:
- the mobile number in E.164 format
- the date and time of opt-in
- the opt-in method and source (URL, keyword, POS terminal, location)
- the exact call-to-action text displayed at the time of opt-in
- the message categories consented to
- the submitting IP address, for web form opt-ins
Records must be kept for the life of the consent and for at least four years after the last message is sent to that number, matching the federal limitations period for TCPA claims. Production timelines are set by the Terms of Service.
2. Opt-out and HELP
2.1 Opt-out keywords
STOP, QUIT, END, CANCEL, UNSUBSCRIBE, REVOKE and OPT OUT must terminate all messaging to that number. Federal rules treat each of these words as a per se reasonable revocation of consent, so none of them may be redefined to mean something else. Any other reply that a reasonable person would read as a request to stop must be honored in the same way. Kubbly processes these automatically. Where one of these words carries enough context to show that the guest is managing a service they asked for, cancelling an order or a reservation, for example, it may be handled as a service instruction; where that context is absent, it must be treated as an opt-out and resolved under 2.2. Customer may not send further messages to an opted-out number, may not require a guest to call or email in order to opt out, and may not re-add an opted-out number without a fresh opt-in.
2.2 Opt-out confirmation
A single confirmation message may be sent. It must confirm the opt-out and must not contain marketing content or any attempt to retain the guest. Where the guest has consented to more than one category of message, that confirmation may also ask which categories the guest meant to stop. All messaging that requires consent must stop unless and until the guest answers.
2.3 HELP
HELP must return the brand name, a support contact and opt-out instructions.
3. Message identification and formatting
3.1 Identify the sender
Every promotional message, and the first message of any conversation Customer initiates, must identify the sending brand by the name disclosed at opt-in and registered with the carriers. Replies and follow-ups within a conversation already under way need not repeat the brand name, and neither must a conversation the guest/recipient started. On RCS and WhatsApp, where the verified sender profile displays the brand name and logo in the thread itself, that display satisfies this requirement. Messages may not misrepresent who is sending them.
3.2 Links
Links must resolve to a domain the recipient can recognize as Customer’s, or as belonging to a named provider acting for Customer: Customer’s own domain, a Kubbly-provided branded domain, or the domain of a service used to provide the service to the recipient. Public URL shorteners — bit.ly, tinyurl, goo.gl and equivalents — are prohibited. Carriers block them, because they conceal the destination and are shared with unrelated senders.
3.3 Sending hours
Promotional messages may not be sent before 8:00 a.m. or after 9:00 p.m. in the recipient’s local time zone, and Customer must observe stricter state-level restrictions where they apply. The restriction derives from the federal limit on telephone solicitations, so it does not apply to transactional messages such as order, delivery and reservation updates, and it does not apply to replies within a conversation the guest/recipient is having with the brand.
3.4 Frequency
Actual message volume must match the frequency disclosed at opt-in.
4. Prohibited content
The following may never be sent through the Services. No exception or approval is available for them:
- Sex — sexual, adult or pornographic content
- Hate — content promoting hatred, violence or discrimination
- cannabis, CBD and controlled or illegal substances, regardless of state legality — carriers require content to be lawful federally and in all fifty states
- third-party lead generation and affiliate marketing
- phishing, fraud, deceptive claims and any content designed to mislead
- malware, or links to malware
Restricted content. The categories below are not banned outright. They may be sent only where Kubbly has approved the use case in writing beforehand and, where a carrier requires one, an exception has been granted for that campaign. Approval is decided case by case, is frequently refused, and may be withdrawn. Sending any of this content without that approval breaches this Policy:
- Alcohol — alcohol content, subject to the age gating described below
- Tobacco — tobacco, vaping and nicotine products
- Firearms — firearms, ammunition, weapons or related content
- gambling, sweepstakes and contests
- high-risk financial offers, including payday and short-term loans, debt relief, credit repair and cryptocurrency
- prescription medication
Alcohol and age gating. Restaurant and hospitality brands may reference alcohol only where age is verified at opt-in through a date-of-birth or age-affirmation gate, the verification is stored with the consent record, and the message complies with applicable state alcohol advertising law.
5. Prohibited practices
These practices are prohibited whether or not the underlying content is permitted:
- Snowshoeing — spreading traffic across multiple numbers or campaigns to dilute per-number volume and evade carrier filtering
- rotating or cycling numbers to escape blocks or reputation damage
- sending from unregistered numbers, or from a campaign registered for a different use case
- Use case drift — sending message types materially different from those registered
- altering content, spelling or spacing to defeat carrier filters
- sharing a registered brand or campaign with an unrelated business
- sending to numbers acquired without consent in order to test deliverability
- generating artificially inflated traffic, including to numbers or ranges with which Customer has no genuine relationship
- failing to scrub reassigned or disconnected numbers
6. Registration and campaign integrity
Kubbly registers brands and campaigns with The Campaign Registry on Customer’s behalf. The accuracy of that data is warranted in the Terms of Service. Operationally, Customer must:
- notify Kubbly within five business days of any change to legal entity name, EIN, registered address, website or authorized contact
- notify Kubbly before materially changing the use case, content or message volume of a registered campaign
- respond to vetting and identity verification requests without delay
- keep the opt-in mechanism live and unchanged in the form submitted at registration — where a URL was submitted it must stay publicly reachable, because carriers verify it directly, and where opt-in happens offline through a kiosk, QR code, POS prompt or printed sign, Customer must keep that mechanism in place and current evidence of it, such as a photograph or screenshot of the call to action, available on request
Inaccurate registration can result in an EIN being suspended across all carriers, which affects every campaign registered to that legal entity — not only the one at issue.
7. Complaints, audits and remediation
Carrier and aggregator complaints flow to Kubbly, which is accountable to its aggregator for all traffic originating on its platform. When a complaint, audit or information request arrives, Customer must cooperate, produce consent records for the numbers identified, and — where a violation is confirmed — implement a written remediation plan before messaging resumes.
Kubbly’s rights to suspend or throttle messaging and to recover pass-through charges are set out in the Terms of Service.
8. Channel-specific requirements
8.1 SMS and MMS (United States)
Traffic must run on a registered 10DLC brand and campaign, or on an approved toll-free or short code sender. Programs using fifty or more numbers must declare number pooling at registration. Throughput is set by the carriers and may change without notice.
8.2 RCS
Senders must be verified by Google and the carriers, and content must comply with the Google RCS Business Messaging Acceptable Use Policy. Verified sender branding may not be used to imply an affiliation that does not exist. Where a device or carrier does not support RCS, messages fall back to SMS and remain subject to this Policy in full.
8.3 WhatsApp
Traffic is subject to Meta’s Business Messaging Policy and Commerce Policy. Business-initiated messages sent outside the 24-hour customer service window require a template approved by Meta. Consent to receive WhatsApp messages must be captured separately from SMS consent. Sustained low quality ratings can cause Meta to restrict or disable the sender.
9. Changes to this Policy
Carrier, CTIA and platform requirements change frequently. Kubbly may update this Policy on reasonable notice, or on shorter notice where a Network Operator or applicable law requires it. The current version is always published at kubbly.ai/messaging-policy. Continued use of the Services after an update takes effect constitutes acceptance of it.
10. Contact
Questions about this Policy may be sent to info@kubbly.com.
Kubbly, Inc.
11 E Loop Rd, Suite 381
New York, NY 10044
United States
