AAllison
Back to blog

The 2026 SMS Marketing Compliance Guide: TCPA, 10DLC, and A2P for Small Businesses

Allison Team14 min read

The 2026 SMS Marketing Compliance Guide: TCPA, 10DLC, and A2P for Small Businesses

If you've been putting off learning the rules around business texting because it sounds like reading a law textbook, you're not alone. Most hairstylists, HVAC techs, dentists, and independent contractors didn't open a business to become telecom compliance specialists.

But here's the reality: SMS compliance isn't optional, and the rules have gotten more specific since the FCC updated its TCPA guidance. The good news is that for the typical small-business use case — appointment reminders, follow-ups, check-ins with existing customers — compliance is genuinely achievable without a lawyer on retainer.

This guide covers everything you need to know in plain English, with practical checklists at the end of each section. By the time you finish, you'll understand what you can and can't do, what you need to set up, and how to stay out of trouble as you grow.

Legal disclaimer: This article is for informational purposes only and does not constitute legal advice. SMS regulations are complex and vary by state. Consult a licensed attorney for guidance specific to your business.


What Is the TCPA, and Why Should You Care?

The Telephone Consumer Protection Act (TCPA) is a federal law passed in 1991 that regulates how businesses can contact consumers by phone and text. The FCC enforces it, and courts have interpreted it broadly in favor of consumers.

The TCPA matters to small businesses for one simple reason: the penalties are steep. Statutory damages run $500–$1,500 per individual violation — meaning per text message sent without proper consent. Class action lawsuits targeting businesses that blast bulk texts without consent have resulted in settlements in the millions.

The TCPA applies to you if you:

  • Send text messages to customers using an automated system or a bulk messaging platform
  • Use a short code or a 10DLC long code to send messages at volume
  • Send marketing or promotional content via SMS

For most Allison users, you're sending transactional messages (appointment reminders, confirmations, follow-ups) to people who are already your customers and have given you their number. That's the easiest compliance case. But you still need to do it right.


Express Written Consent: The Foundation of Everything

The single most important concept in SMS compliance is express written consent. Under TCPA rules as interpreted through 2025–2026 FCC guidance, before sending marketing or promotional texts to someone, you generally need:

  1. A clear disclosure that by providing their number, they agree to receive text messages from your business
  2. A description of the message type (e.g., "appointment reminders and occasional promotions")
  3. Your business name in the consent language
  4. Message frequency disclosure ("Message frequency varies" or "Up to 4 messages/month")
  5. Standard rate disclosure: "Message and data rates may apply"
  6. Opt-out instructions: "Reply STOP to unsubscribe"
  7. Help instructions: "Reply HELP for help"

Transactional vs. Marketing Messages

There's an important distinction worth understanding:

  • Transactional messages are tied to an existing relationship — appointment confirmations, reminders 24 hours before a visit, post-appointment follow-ups. Courts and regulators have historically applied lighter consent requirements here, though you should still have the customer's knowing agreement.
  • Marketing messages — promotions, discounts, sales alerts — require the full express written consent described above.

If you're using Allison primarily for appointment reminders for existing clients, you have an easier path. But if you ever want to send a "book again" promo or a seasonal discount text, you need the full consent on file.

How to Collect Consent the Right Way

Consent must be:

  • Voluntary — not buried in fine print or required to receive a service
  • Clear — the customer understands what they're agreeing to
  • Documented — you can prove they gave it if you're ever challenged

Practical methods for small businesses:

At the point of sale or booking: Add a checkbox to your booking form or intake paperwork: "I agree to receive appointment reminders and occasional promotional texts from [Your Business Name] at the number provided. Message and data rates may apply. Reply STOP to opt out."

Online booking forms: Include consent language near the phone number field. Don't pre-check the box — the customer must actively check it.

Verbal consent: Verbal consent is harder to prove but acceptable for transactional messages if you document it (e.g., note in your CRM). For marketing texts, written records are strongly preferred.

Existing customers: If you already have a customer's phone number from past appointments, you can text them — but a first message asking them to confirm they want texts ("Reply YES to get appointment reminders from us — Reply STOP to opt out") is a safe, professional approach.

What Doesn't Count as Consent

  • Buying a list of phone numbers
  • Importing phone numbers from a third-party database
  • Having someone's number in your contacts app from a referral
  • Website visitors who filled out a contact form without SMS-specific consent language

10DLC: What It Is and Why You Need to Register

The Short Version

10DLC stands for 10-digit long code — essentially a regular-looking phone number (like +1 760 555 1234) used for business A2P (Application-to-Person) messaging at scale. In 2021, the major US carriers — AT&T, Verizon, T-Mobile — established a registration system requiring businesses that send volume texts through long codes to register their brand and campaigns. By 2023, unregistered traffic was being blocked or filtered. In 2026, registration is effectively mandatory if you want your messages to be delivered reliably.

Why Carriers Did This

Before 10DLC, bad actors used the same long-code phone numbers that legitimate businesses used, sending spam and fraud at scale. Carriers couldn't tell the difference. The 10DLC registry (managed by The Campaign Registry, or TCR) is how carriers verify that a business sending texts is legitimate.

The Registration Process: Step by Step

Step 1: Register your Brand This is your business identity with TCR. You'll need:

  • Legal business name
  • EIN (Employer Identification Number). If you're a sole proprietor without an EIN, you can use your SSN, though getting an EIN is recommended for any business.
  • Business type and industry vertical
  • US phone number and address
  • Website URL

Brand registration typically costs a one-time fee (around $4 when done through carriers) and is usually instant or same-day.

Step 2: Create a Campaign A campaign describes the type of messages you'll send. You'll select a use case — options include "Customer Care," "Appointment Reminders," "Marketing," and others. For most Allison users, "Appointment Reminders" or "Customer Care" is the right choice. You'll need to provide:

  • Campaign description (2–3 sentences about your messaging program)
  • Sample messages (2–3 actual examples of texts you'll send)
  • Confirmation that you have opt-in/opt-out processes in place

Campaign review takes 1–7 business days. Some use cases require additional vetting.

Step 3: Link Your Number Once your campaign is approved, your sending phone number is linked to that campaign. Messages sent from that number will be recognized by carriers as registered A2P traffic.

If you're using Allison, we handle 10DLC registration as part of onboarding. Start your free trial and we'll walk you through it.

What Happens If You Don't Register

Unregistered A2P messages on 10DLC numbers are subject to carrier filtering, which means:

  • Messages get silently blocked — no error, no delivery, no notification to you
  • Delivery rates drop to 20–40% on some carriers
  • Your number can be flagged and your account suspended by your SMS provider

Don't skip registration. For service businesses sending appointment reminders to real customers, the process is straightforward and approval rates are high.


A2P Messaging: The Technical Layer

A2P (Application-to-Person) is the industry term for messages sent from a software platform to individuals — as opposed to P2P (person-to-person) texting between two phones. When you use Allison to send appointment reminders, that's A2P messaging.

A2P vs. P2P: Why It Matters

Carriers treat A2P and P2P traffic differently:

  • P2P has no registration requirement but is rate-limited at the platform level
  • A2P at volume requires 10DLC (or toll-free or short code) registration
  • Trying to send A2P volume over P2P pathways will get your number flagged

Short Codes vs. Long Codes vs. Toll-Free

| Type | Example | Best For | Registration | |------|---------|----------|--------------| | 10DLC Long Code | +1 760 555 1234 | Local businesses, conversational | 10DLC via TCR | | Toll-Free | +1 800 555 1234 | High-volume, national | Toll-free verification | | Short Code | 12345 | Very high volume (10k+/day) | Dedicated SC approval |

For most small businesses — hairstylists, HVAC companies, dental offices — a 10DLC long code is the right choice. It looks like a real local number, which increases trust and response rates.


Quiet Hours: When You Cannot Send

The TCPA has explicit quiet hours: you may not contact consumers before 8:00 AM or after 9:00 PM in the recipient's local time zone.

This is not the time zone your business is in — it's the recipient's time zone. If your HVAC company is in Phoenix and a customer's number has a New York area code, you're limited to 8 AM–9 PM Eastern.

Best practice for small businesses:

  • Set your Allison account quiet hours to 8:00 AM – 8:30 PM in your local time zone as a conservative buffer
  • Never schedule campaigns to send at the edge of the window
  • For appointment reminders, send the day before at a mid-afternoon time (e.g., 2:00 PM) to maximize opens without risking quiet hours violations

Many state laws have stricter quiet hours — we cover the main ones in the State-Specific Rules section below.


Opt-Out and HELP Requirements

Every SMS marketing program must support these two keywords, and your platform must handle them automatically:

STOP (and Variants)

When a recipient texts STOP, STOPALL, UNSUBSCRIBE, CANCEL, END, or QUIT, you must:

  1. Immediately cease all messages to that number
  2. Send a single confirmation reply ("You've been unsubscribed from [Business Name] messages. You won't receive any more texts.")
  3. Never text them again unless they affirmatively opt back in

There is no grace period. One message after an opt-out is a TCPA violation.

HELP

When a recipient texts HELP or INFO, you must send a reply with:

  • Your business name
  • A short description of the messaging program
  • How to opt out: "Reply STOP to unsubscribe"
  • Contact information (website, phone, or email)

Example HELP response: "Allison from [Business Name]: Appointment reminders. Reply STOP to unsubscribe. Visit [your website] or call [your number] for help."

Including Opt-Out Language in Messages

Best practice (and required for many campaigns): include opt-out language in your first text to a new subscriber and periodically after that. You don't need it in every single reminder, but it should appear:

  • In the initial welcome/consent confirmation
  • In any marketing or promotional message
  • At least once per month if you're sending recurring messages

Record-Keeping Requirements

You should be able to prove, for any number you've texted:

  • When consent was obtained
  • How consent was obtained (form, verbal, check-in kiosk)
  • What the consent language said
  • Opt-out history — when they opted out and when messaging stopped

Keep these records for at least 4 years (the statute of limitations for TCPA claims is 4 years for most cases). Allison stores consent audit records in your account automatically. For contacts you import, keep your source data.

What to log:

  • Date/time of consent
  • IP address or form submission ID (for web forms)
  • Exact consent language shown
  • Opt-out date and confirmation
  • Any "opt back in" events

Penalties for Non-Compliance

TCPA violations carry statutory damages of:

  • $500 per violation for negligent violations
  • $1,500 per violation for willful or knowing violations

Because each text message to each recipient counts as a separate violation, a single blast to 200 people without proper consent could expose you to $100,000–$300,000 in liability before any attorney fees or class action multiplier.

Beyond TCPA:

  • State AG enforcement — state attorneys general can and do pursue businesses for SMS violations
  • Carrier suspension — your SMS provider can terminate your account for violations, effectively shutting down your messaging
  • FCC enforcement — the FCC can issue cease-and-desist orders and civil penalties

The pattern with TCPA litigation is that plaintiffs (and their attorneys) look for businesses that are easy targets — usually those that bought lists, didn't have clear consent processes, or continued texting after opt-outs. If you're texting your own customers with proper consent, you are in a dramatically lower risk category.


State-Specific Rules: California and Florida

Federal TCPA is the floor. Several states have added their own requirements on top.

California: CCPA and CalSPAM

CCPA (California Consumer Privacy Act) applies if you do business in California and meet certain thresholds (revenue, volume of data processed). Key implications for SMS:

  • Consumers can request deletion of their data, including phone numbers and consent records
  • You must disclose in your privacy policy what personal information you collect and how it's used
  • You cannot discriminate against consumers who exercise privacy rights (e.g., by refusing service to someone who opts out)

California Business & Professions Code 17538.43 (CalSPAM) mirrors and in some cases expands federal requirements. California courts have been plaintiff-friendly in TCPA litigation.

Practical steps for California businesses:

  • Ensure your privacy policy mentions SMS and phone number data
  • Have a clear process to honor deletion requests
  • Keep consent records — California regulators have been active

Florida: FTSA

The Florida Telephone Solicitation Act (FTSA), significantly amended effective 2021, created a private right of action for Florida consumers similar to TCPA. Key differences from federal law:

  • The FTSA's definition of "automated system" has been interpreted broadly — even manual batch sends may qualify in some cases
  • Express written consent requirements are explicit
  • Damages: $500 per call or text for violations

Florida has seen significant FTSA litigation. If you serve Florida customers:

  • Make sure your opt-in process is documented and unambiguous
  • Honor opt-outs immediately
  • Avoid any marketing texts to Florida numbers without clear written consent

Other States to Watch

  • Texas has a commercial spam law (Section 46.101, Penal Code) with criminal provisions for high-volume spam
  • Washington State has consumer protection statutes that regulators have applied to SMS
  • Illinois — while BIPA (Biometric Information Privacy Act) primarily targets biometric data, Illinois has generally aggressive consumer privacy enforcement

If your business serves customers in multiple states, the safest approach is to apply the most restrictive applicable standard uniformly.


Compliance Checklist for Small Businesses

Use this checklist before you send your first text campaign.

Consent Collection

  • [ ] Consent language is on your booking form or intake paperwork
  • [ ] Consent language includes: business name, message type, frequency disclosure, "Msg & data rates may apply," STOP instructions
  • [ ] Checkboxes are not pre-checked
  • [ ] You have a documented record of who consented and when
  • [ ] You have a process to handle data deletion requests

10DLC Registration

  • [ ] Brand registered with The Campaign Registry (via your SMS provider)
  • [ ] Campaign registered and approved
  • [ ] Sending number linked to approved campaign
  • [ ] Sample messages approved match what you actually send

Message Configuration

  • [ ] Quiet hours set: no sends before 8 AM or after 9 PM recipient local time
  • [ ] STOP keyword handled automatically (immediate unsubscribe + confirmation)
  • [ ] HELP keyword returns business name, opt-out instructions, contact info
  • [ ] First message to new subscribers includes opt-out instruction
  • [ ] Marketing messages include opt-out instruction

Record-Keeping

  • [ ] Consent records stored and accessible
  • [ ] Opt-out log maintained
  • [ ] Records retained for at least 4 years

State Compliance

  • [ ] California: privacy policy mentions SMS; deletion request process in place
  • [ ] Florida: written consent documented for any Florida numbers
  • [ ] Review requirements for other states where you have customers

How Allison Handles Compliance Automatically

Building and maintaining a compliant SMS program is genuinely easier when your platform does the heavy lifting. Here's what Allison handles for you:

  • 10DLC registration guidance built into the onboarding flow
  • Automatic opt-out processing — STOP/UNSUBSCRIBE responses are handled instantly and permanently
  • HELP auto-response configured with your business name
  • Quiet hours enforcement — messages scheduled outside your quiet window are automatically held
  • Consent audit log — every opt-in and opt-out is timestamped and stored
  • State-specific templates — templates are pre-reviewed for compliance language

You still need to collect consent properly at the point of intake, but everything downstream is handled. See how it works on our pricing page or explore the hairstylist-specific setup guide.


Frequently Asked Questions

Can I text people who gave me their number years ago but never explicitly agreed to texts? This is legally risky. The safest approach is to send a single opt-in request to existing customers: "Hi, this is [Business Name]. We'd like to text you appointment reminders. Reply YES to opt in, STOP to decline." Keep records of who replies YES.

What if a customer gives me their number verbally at the desk? Verbal consent is generally acceptable for transactional messages (appointment reminders) if you document it in your CRM at the time. For marketing promotions, written consent is strongly preferred. A quick "I'll text you a confirmation — is that okay?" followed by a note in your system is a reasonable minimum.

Do I need to re-obtain consent if I switch SMS platforms? Generally, no — consent is tied to your business, not your platform. The customer agreed to receive texts from your business. You should update your records to reflect the new sending number. Sending a re-introduction message ("Same appointments, new number — this is [Business Name]") is good practice.

I'm a sole proprietor. Do the same rules apply to me? Yes. TCPA applies to any person or entity sending commercial text messages to consumers, regardless of business size.

Can I text people who filled out my website contact form? Only if your contact form included SMS-specific consent language. A general "contact us" form is not SMS consent.


The Bottom Line

Compliant SMS marketing for a small service business comes down to three core practices:

  1. Collect consent properly — clear, documented, voluntary opt-in before sending anything
  2. Register with 10DLC — so your messages are actually delivered
  3. Honor opt-outs immediately — no exceptions, ever

If you do those three things, you're ahead of the vast majority of small businesses and in a substantially lower risk category for the sticky legal issues. Everything else in this guide is refinement on top of those fundamentals.

Ready to set up a compliant SMS reminder program? Book a demo or check out our plans starting at $29/month.


This article was last updated on July 1, 2026. SMS regulations evolve — check back for updates and consult a licensed attorney for advice specific to your situation. Nothing in this article constitutes legal advice.

Let Allison text your clients for you.

AI reminders that bring repeat customers back — TCPA-compliant out of the box.

Start your free trial →