Restaurant SMS Marketing Compliance and Opt-In Rules
Noncompliance can cost $500 to $1,500 per text, and lawsuits are climbing fast.

Restaurant SMS marketing works better than almost any channel a restaurant can throw money at, and it also carries enough legal exposure to turn a slow Tuesday promo into a six-figure mess. Open rates on restaurant texts run around 98%, click-through lands somewhere between 15% and 35%, and most messages get read within three to five minutes of landing on a phone. Conservative ROI estimates put SMS at $21 to $41 back per dollar spent, with peak seasonal campaigns reportedly climbing as high as $71. None of that pays out, though, if the list you built was built wrong, because the Telephone Consumer Protection Act doesn't grade on effort. It grades on paperwork.
What TCPA actually is and why it governs every restaurant text
TCPA is a federal law, and it applies to any business, in any industry, sending marketing texts to U.S. phone numbers. There's no exemption tucked away for restaurants just because you're slinging tacos instead of timeshares, and the law doesn't care that your SMS program is run by a general manager who also does the Tuesday schedule and occasionally wrestles the ice machine back to life.
Here's the number that should live somewhere in the back of every operator's skull: $500 to $1,500 per text. Per message, not per campaign, not per batch. Send one non-compliant blast to a few hundred subscribers and you've built a liability that starts in the low six figures before a single lawyer even shows up.
And the weather isn't calming down. TCPA lawsuits rose nearly 27% in early 2026 versus the same stretch in 2025, which tells you plaintiffs' attorneys have found a market and they like it. Here's the part that catches people off guard: TCPA puts the burden of proof on the sender, not the person suing, and the restaurant has to produce evidence that consent existed. Saying "we definitely had permission" carries exactly as much weight in front of a judge as it does written on a napkin, which is to say none. The FCC administers these rules and can shift them through rulemaking without Congress lifting a finger, which is exactly what happened in April 2025. More on that later.
The two consent tiers and where marketing texts fall
Forget the legal jargon for a second. There are two buckets of consent, and once you run through a handful of real restaurant scenarios, figuring out which bucket a message falls into turns out to be a lot simpler than the statute makes it sound.
Prior express consent, the lower bar, covers informational texts: reservation reminders, "your table is ready," fraud alerts, two-factor codes. This one can be oral or implied; giving your number to the host stand for a callback counts. Prior express written consent is the higher bar, and it's mandatory for anything that smells like a sales pitch, whether that's a discount, a specific menu item promoted, a call to action, or any kind of promotional framing at all.
Run through a few examples and the line gets clearer than any definition could make it. Ask yourself: would a reasonable customer read this and think "they're trying to sell me something"? If yes, it's marketing, no matter how it's dressed up. "Your table is ready" is informational. "Your table is ready, try our new dessert menu tonight" is marketing, because that second clause is doing sales work the first one never signed up for.
This is where restaurants trip over their own feet, constantly. A guest hands over their number for a reservation, or joins a loyalty program, and months later that number is on a list getting hit with weekly discount blasts. The consent collected at sign-up was informational, or loyalty-specific; it was never a green light for promotional texting. That gap, between what consent was given and what it's actually being used for, is one of the most common and most expensive mistakes in the industry.
What valid written consent for marketing texts must actually include
Valid written consent for marketing texts needs four things present, and missing any one of them means the consent doesn't count, no matter how sincerely the customer meant to sign up.
The brand name has to be explicit. A vague "join our list" without naming the business doesn't cut it, and the language has to specifically say marketing messages, not "updates" or "news" or some other softened phrase that could mean literally anything. Consent has to be captured in writing, which electronic forms, checkboxes, and web forms all satisfy, and it has to happen before the first promotional text goes out, never retroactively, because you cannot un-ring a bell you already rang.
Then there's the unchecked-box rule, which trips up more well-meaning operators than almost anything else here. The SMS marketing checkbox has to start unchecked; pre-ticking it, even as a small nudge to pad sign-up numbers, invalidates the consent entirely. The customer also has to be able to finish whatever they came to do, whether that's an online order, a table booking, or a loyalty enrollment, without agreeing to texts. Gating a discount behind SMS opt-in ("check this box to get 10% off") violates the standard, because it turns consent into a toll booth instead of a choice.
So where can restaurants actually collect this legitimately? Table tents or counter signage with a keyword-to-shortcode prompt work well, since the customer initiates contact by texting in, which is about as strong a form of consent as exists. On-site prompts offering a first-order incentive have produced opt-in rates in the 10% to 20% range, a real chunk of foot traffic worth protecting with clean process. Online ordering checkout with a clearly labeled, unchecked box works, and so does loyalty enrollment, paper or digital, with specific marketing language, or a QR code pointing to a web opt-in form.
What doesn't work: purchased lists from data vendors, even the ones marketing themselves as "compliant." The restaurant can't verify its own brand name appeared in whatever consent language the consumer originally saw, and since the burden of proof sits with the sender, that unknown becomes the restaurant's problem, not the vendor's. Consent to one brand doesn't transfer to a sister brand under the same ownership group either; multi-concept operators need separate consent per brand. And switching SMS platforms doesn't reset or regenerate consent, since the new platform is just a new mailbox. Consent records have to migrate with the list, or the list becomes dead weight.
What every compliant marketing text must contain at the time of send
Every welcome message, the first text a new subscriber gets, needs five specific things: the business name, a message frequency disclosure ("msg frequency varies" or a stated cadence), a data rate notice ("msg & data rates may apply"), an opt-out instruction ("reply STOP to unsubscribe"), and a help instruction ("reply HELP" or a support contact).
After that first message, every subsequent promotional text still needs to name the business. Feels redundant the first time you read it, sure, but think about how many restaurants a person's phone number might be signed up with three months from now, since nobody remembers which taco place or which pizza spot they opted into back in February.
Quiet hours matter too. TCPA and CTIA guidance restrict texts sent outside reasonable daytime hours in the recipient's local time zone, which makes time zone handling a systems requirement for any multi-location operator. Work through the math on a real multi-state footprint and the risk gets concrete fast: a restaurant group running locations in Texas and California that fires off a single send at 8:30 p.m. Eastern just texted California customers at 5:30 p.m., fine, that time, but flip the send an hour later and it's a violation waiting to happen.
On pacing, sending too often to a list nobody's bothered to clean compounds two problems at once: unsubscribe rates and legal exposure, since more sends against a stale list just means more chances for something to break. Content that's specific, a day-of special, a limited-time offer tied to an actual date, outperforms generic brand messaging and tends to keep opt-out rates lower too. Specificity is quietly doing two jobs at once here: better engagement, and better compliance hygiene.
The April 2025 FCC opt-out expansion and what changed for operators
As of April 11, 2025, the rules on opt-outs got a lot wider. Businesses now have to honor opt-out requests received through any reasonable channel, not just a STOP reply to a text. That's the headline, and it's a bigger operational shift than it sounds on paper.
The channels now in scope: text reply keywords (STOP, quit, unsubscribe, cancel, opt out, end, revoke), email requests, phone calls, website forms or chatbots, and in-person requests made at the restaurant itself. Processing has to happen within 10 business days, and delays past that window are independently actionable, meaning the opt-out failure itself becomes its own violation, separate from whatever texts triggered it in the first place.
There's exactly one permitted response beyond silence: a single confirmation text, no promotional content, sent within five minutes, clarifying which message types the person is stopping. After that one confirmation, nothing further goes out.
What does this mean for a restaurant floor on a Friday night? A server or host who takes a verbal "please stop texting me" now needs a documented process for getting that information to whoever runs the SMS platform, because that verbal request carries the same legal weight as a STOP reply. An opt-out buried in an Instagram DM, a Google review comment, or a random email to the info@ inbox is just as valid and just as time-sensitive as one that arrives by text, which means operators need one central opt-out log, not five channel-specific silos that nobody's cross-checking.
DSW, the shoe retailer under Designer Brands, paid $4.42 million in 2025 specifically for continuing to text customers after they'd already opted out. The consent was fine going in; the failure was entirely on the back end, in not honoring the stop request. Useful example, because it shows compliance is an ongoing obligation that follows the subscriber for the whole life of the relationship, not just the moment they checked a box.
What the real settlements show about where restaurants are most exposed
Look at the settlement record from 2024 and 2025 and a pattern falls out fairly cleanly, worth treating this less like a scary headline and more like an actual map of where things break.
Clover Network settled for $15 million in 2024 after sending over a million marketing texts with no consent on record at all. That's the most basic failure possible, texting people who never agreed to anything. Cash App settled for $12.5 million in 2025 over referral program texts sent without consent clear or specific enough to hold up; the company likely believed it had something, but "something" was never the standard. Zales Jewelers settled for $7.5 million in 2025 over SMS consent and messaging violations. DSW, covered above, paid $4.42 million for the opt-out failure specifically.
Four settlements, three failure patterns: texting with zero consent (Clover), consent that existed in some vague, unprovable form (Cash App), and consent that was clean at the door but broken the moment someone tried to leave (DSW). Three different points of failure, three different million-dollar tuition bills.
Restaurants shouldn't read "million dollar settlement" and file this under big-company problems. Run the per-text math and the picture changes fast: the penalty structure doesn't scale down for smaller lists, it just produces a smaller total number. A 500-subscriber list hit with one non-compliant blast sits on the same legal foundation as a national retailer's list of five million; same math, fewer zeros. And "we didn't know" or "we used a vendor's list that said it was compliant" buys you nothing in court, because good intent isn't a defense TCPA recognizes.
Record-keeping and the consent audit trail operators need to maintain
A defensible consent record needs four things: the timestamp of when consent was given, the exact language of the form or prompt the subscriber actually saw at that moment, the channel it was collected through (web form, keyword text, paper sign-up, QR code), and the phone number tied to whatever customer identifier the restaurant keeps.
Hold onto these records for as long as the subscriber relationship exists and well beyond it. TCPA claims can resurface well after the fact, and a deleted record can't prove consent that was, at the time, perfectly valid. If the record's gone, as far as a court's concerned, so is the proof, and it doesn't matter how sure you are that it existed.
Switching SMS vendors doesn't wipe this slate clean, and it doesn't grant a fresh start either. The consent archive has to move with the list to the new platform, since the new vendor's system doesn't regenerate permissions just because the list landed there. A gap anywhere in that record is a gap in legal protection, full stop.
Opt-out records deserve the same rigor: timestamp of the request, the channel it came through, confirmation it was processed inside that 10-business-day window. Treat the whole consent log with the rigor a restaurant applies to its financial records, an actual compliance asset everyone can access, not a spreadsheet marooned on one manager's laptop.
Turning a compliant subscriber list into a list that generates measurable revenue
Here's what makes all this paperwork worth doing beyond just staying out of court: a permission-built list outperforms a purchased one before legal risk even enters the room. Someone who opted in at the counter or during an actual transaction already has a relationship with the restaurant, distinct from a cold contact plucked off a vendor's spreadsheet; they've eaten there, or at least they meant to.
The 98% open rate and 8–15% conversion figures cited earlier reflect SMS marketing for restaurants broadly. Purchased or assumed-consent lists underperform those numbers by a wide margin, because the underlying relationship was never there to begin with. Trust gets earned one text at a time, apparently, rarely bought outright.
Attribution is where compliance and ROI actually shake hands. Unique promo codes and dedicated landing pages tied to specific sends are the bare minimum for figuring out whether a text actually filled seats or whether those covers would've shown up regardless. Connecting redemption data back to POS records closes the loop between message sent and table filled, the same measurement gap that quietly haunts a lot of unattributed social ad spend. Operators running structured, measured campaigns see meaningfully better ROI than those running ad hoc blasts, per 2025 industry data, which suggests the discipline compliance demands and the discipline measurement demands aren't separate skills. They're the same muscle, just flexed in different directions.
Segmentation follows naturally from a compliant list, because a compliant list is, by its nature, a known list. Consent collected through a loyalty sign-up or a reservation carries context with it: visit frequency, location, order history. Messages built around that context convert better and generate fewer opt-outs, which protects the list's long-term health along with this quarter's revenue.
None of this happens in isolation either. Combining SMS with email produces 56% higher ROI than email running alone, and the same attribution question, what actually drove this visit, applies whether the nudge was a text, a social post, or a paid ad. Restaurants that measure across every channel can put budget where it actually fills tables, instead of guessing based on whichever channel felt loudest that week.


