Register Early
Campaign vetting is a manual review process. SMS campaign approval typically takes days to weeks; RCS carrier approval takes four to six weeks, longer if you are launching in multiple regions. Each rejection costs a full review cycle, so registration should begin at project kickoff, not during integration testing. Your PolyAI deployment team will drive the registration process, but the items below need input from your web, marketing and legal teams, and they are the most common cause of delay.SMS: What Carriers Check (A2P 10DLC)
Every SMS campaign registration is reviewed against your brand, your website, your published policies, your opt-in flow and your sample messages (Twilio’s A2P 10DLC registration guide covers the full process). Reviewers look for consistency across all of them, and a mismatched or unrelated website is a documented reason for rejection. Since 30 June 2026, all new A2P 10DLC campaign registrations must include two publicly accessible URLs: a Privacy Policy and Terms and Conditions. Both must be relevant to the business registering the campaign, and Twilio’s guidance is that they should be hosted on the same domain as your business website. This is why PolyAI cannot host these pages on your behalf: the registered brand is your business, and reviewers, carriers and regulators expect the policies to live with you.Your Privacy Policy Must State
Your privacy policy needs one specific commitment, worded to cover SMS consent data:Text messaging opt-in data and consent will not be shared with, sold to, or bought by third parties or affiliates for marketing or promotional purposes.Two scoping points your legal team will want to know. First, the requirement covers SMS opt-in data and consent only, not “mobile information” in the broad sense, so it does not restrict how your website or app collects data generally. Second, the prohibition is on sharing for marketing or promotional purposes. Sharing with service providers to deliver messages and operate the programme is permitted and can be stated explicitly.
Your Terms Must Include
- The programme name and a description of what it sends
- “Message and data rates may apply”
- Message frequency (for example, “1 to 3 messages per interaction”)
- A customer support contact (email or phone)
- Complete HELP and STOP opt-out instructions, in bold
- A link to your privacy policy
- The statement “carriers are not liable for delayed or undelivered messages”
Publish a Standalone Page, Not a Policy Amendment
The fastest route through review, and the one Twilio’s own compliance team recommends in writing, is a single new page on your website (for example, yourcompany.com/sms-terms) scoped only to the SMS programme, rather than an amendment to your corporate privacy policy. A standalone page needs far lighter legal review, leaves your corporate policies untouched, and insulates them from future carrier requirement changes. Your PolyAI deployment team can provide a pre-vetted template covering every required element; your legal team reviews one page and fills in the brackets.Consistency Between Opt-In and Registration
The opt-in flow described in your campaign submission must match what your customers actually experience. If your registration says callers verbally consent during a call with the assistant, that is what the assistant must do, and your sample messages must reflect the real messages the programme sends. Consent must be sender-specific and informed, and proof of consent must be retained.RCS: Agent Registration and Verification
RCS is branded messaging, so registration has a few more requirements than SMS and runs through both Google and the US carriers (Twilio’s RCS onboarding guide covers the full process). Plan for four to six weeks. RCS senders cannot be onboarded programmatically at scale; each one goes through the same review. Creating the sender requires your brand assets and public details: a unique display name, a logo (PNG or JPEG, 224 x 224 pixels, under 50kB), a banner image (1140 x 448 pixels, under 200kB), an accent colour meeting minimum contrast, a description of the sender and how users interact with it, at least one labelled phone number, email address or website, and your privacy policy and terms of service URLs. The same policy pages you publish for SMS can serve here, provided they cover the RCS programme. Compliance registration then requires, for Google: an authorised representative (name, business email, title, website), your opt-in and opt-out policies with publicly accessible image URLs evidencing them, a use case description with a video demonstration, agent access instructions so reviewers can test the sender, and a notification contact. For US carriers, additionally: your legal business name as it appears on IRS documentation, company type and EIN, business address, industry classification, a brand contact number, current and projected message volumes, campaign description and message flow, sample HELP and STOP responses, and confirmation of CTIA handbook compliance.Pre-Flight Before You Submit
Twilio provides a pre-submission compliance checker at a2pcheck.com. It assesses your privacy policy, terms and campaign details against the carrier vetting criteria before anything is formally submitted, and it is the same tool Twilio’s own team uses. Your deployment team will run your campaign through it before submission, and after any rejection the next step is a pre-review with Twilio’s compliance team rather than a blind resubmission. If a campaign is rejected, the rejection code maps to Twilio’s error documentation (30908, 30932, 30933 are the common privacy-policy and terms failures).What You Provide and What PolyAI Handles
Your business provides: the published policy and terms pages on your domain, brand details (legal name, EIN, address), brand assets for RCS, and sign-off on the opt-in flow and sample messages. PolyAI handles: campaign drafting and submission, pre-flight checks, liaison with Twilio’s compliance and partner teams, and tracking of registration status through to approval.Country-Specific Requirements Outside the US
Every country in the table below shares the same baseline: opt-in consent before any non-essential message, HELP and STOP support in the recipient’s local language, sending during daytime hours unless urgent, and respect for do-not-call registries. On top of that baseline, sender ID rules, registration requirements and sending windows vary by country. The table summarises the headline differences; each country name links to Twilio’s full guideline page, which is the authoritative and current source. If your deployment covers a country not listed here, or you are unsure which rules apply, contact your PolyAI representative.Related pages
SMS
Two-way SMS messaging on the same agent brain as voice and chat.
RCS
Rich, branded messaging over the RCS channel with SMS fallback.
SMS API
Send outbound SMS messages through the PolyAI outbound webhook API.
Chat handoffs
CCaaS handoff integrations to transfer SMS threads to live agents.

