Communications and Consent Policy

Leer en español

What the law requires before writing to or calling a client or a lead, how the CRM records it, and which consent wording to use.

Version 1.1 · effective 2026-09-06 · Available in English and Spanish. In case of discrepancy, the English version prevails.

1. Who it applies to

Every agency and agent that uses the CRM to contact people: email (through our provider with your domain, or from your Gmail), calls logged from the CRM, WhatsApp messages the CRM prepares for you to send from your phone, and forms and landing pages that collect data.

The CRM does not send SMS or WhatsApp messages by itself: it opens the message on your phone and you send it. That does not change your obligations: the law looks at who sends, not at the tool.

2. What the law requires, in short

  • TCPA (Telephone Consumer Protection Act): to call or text a mobile number for marketing using automated systems or prerecorded messages you need the person's prior express written consent, clear about who will contact them and why, and not a condition of purchase. The person may revoke it by any reasonable means and you must honor that immediately.
  • National Do Not Call Registry: before cold-calling a number, check that it is not on the national registry or on your internal list of people who asked not to be called. The CRM logs your calls, but it does not check the registry for you.
  • Hours: no marketing calls or messages before 8:00 a.m. or after 9:00 p.m. in the recipient's local time. Some states are stricter.
  • CAN-SPAM (email): identify yourself clearly, use truthful subject lines, include your postal address, offer a way to unsubscribe and honor it within ten days at most. The CRM puts the unsubscribe link and your address in every commercial email and applies the unsubscribe immediately.
  • Medicare: if you market Medicare Advantage or Part D plans, CMS's communications and marketing rules also apply (prior permission to contact, scope of appointment, required content and disclaimers). The CRM's Medicare templates and reminders are aids; compliance is yours.
  • State laws: several states (Florida, Oklahoma, Washington and others) have their own rules on calls and texts, sometimes stricter than the federal ones. Apply the law of the state where the person lives.

3. How the CRM records consent

  • Landing pages: the form carries a mandatory consent checkbox. Without it, the lead is not created. It stores where consent was given (which landing and which page), when, and from which address.
  • Forms: every form carries a consent checkbox that cannot be removed; its wording can be adapted. It is stored with the response.
  • Lead API (integrations with your website or a lead vendor): every lead must arrive with proof of consent (source, date, wording). Without it, it is rejected.
  • Lead record: the email consent checkbox can be ticked by hand. By doing so you declare that you hold the proof (a signed form, a recording, an email). Keep it: if someone makes a claim, it is what defends you.
  • Automations: no sequence writes to a lead without recorded consent. If you remove it, running sequences for that person stop.

4. Recommended consent wording

Use it on your landing pages and forms, replacing your agency's name and email. In English:

By checking this box, I authorize [agency name] to contact me by phone, text message (SMS), WhatsApp and email, including through automated systems or prerecorded messages, about insurance products and services. I understand that consent is not a condition of purchase, that message and data rates may apply, and that I can revoke it at any time by replying STOP to a message or writing to [agency email].

In Spanish:

Al marcar esta casilla autorizo a [nombre de la agencia] a contactarme por teléfono, mensajes de texto (SMS), WhatsApp y correo electrónico, incluso mediante sistemas automáticos o mensajes pregrabados, sobre productos y servicios de seguros. Entiendo que este consentimiento no es condición para comprar nada, que pueden aplicarse tarifas de mensajes y datos, y que puedo revocarlo en cualquier momento respondiendo STOP a un mensaje o escribiendo a [correo de la agencia].

If you will also call with an autodialer or use prerecorded messages, say so in those words. If you will only call by hand, you may drop that mention.

5. Unsubscribes and revocations

  • Every commercial email that leaves the CRM carries an unsubscribe link and the standard one-click unsubscribe headers. The unsubscribe takes effect immediately and the CRM never writes to that person again in campaigns or automations.
  • Messages about the policies the person already holds (renewals, appointments, payment reminders, replies to what they ask) are not commercial and keep going out. Explain it that way if asked.
  • A person may revoke consent by any means: replying STOP, calling, writing. Record it in the CRM as soon as you receive it. An unsubscribe cannot be reactivated without new, provable consent.

6. Sending limits and reputation

Each organization may send up to 5,000 emails per month and 1,000 per day through our provider. A newly verified domain starts with a lower daily cap that grows day by day (ramp-up). If spam complaints exceed 0.3% or bounces exceed 2% of what was sent, sending pauses automatically and the CRM tells you why. An email subject must never contain sensitive data (the CRM warns you).

7. Content

No promises you cannot keep, no misleading comparisons, no undue pressure. Always identify your agency as the sender. If an agent sends an email from their Gmail, they are the one who signs it and answers for it.

8. Who is responsible

The agency is the sender of everything that leaves the CRM and is responsible for complying with these rules. The Terms of Service provide that it will defend and hold us harmless from claims over communications sent without consent. If we detect a pattern of non-compliance, we may pause the organization's sending while we clarify it.