Culinary Ark
SMS MarketingLong read

SMS Compliance and Opt In Requirements for Restaurants

Small restaurants face the same SMS fines as big chains for noncompliance.

Reporter · · 13 min read
Cover illustration for “SMS Compliance and Opt In Requirements for Restaurants”
SMS Marketing · September 2, 2026 · 13 min read · 3,007 words

SMS marketing works because guests actually open the text, and open rates high enough to embarrass email are why restaurant operators keep chasing the channel. That reliability comes with a catch nobody prices in early enough: a twelve-table neighborhood bistro that sends one noncompliant message is exposed exactly the same way a 200-unit chain is. Table count doesn't factor into how the law fines you. Most owners don't find out how flat that playing field is until a complaint lands, and by then the lesson is expensive.

The three overlapping compliance layers every restaurant SMS program must satisfy

Most operators treat this like one law with one rulebook. There are three separate systems, each with its own enforcement mechanism, and clearing one doesn't clear the others; nearly every SMS compliance failure traces back to someone who nailed layer one and never found out layers two and three existed.

Layer one is the Telephone Consumer Protection Act, the federal law the FCC enforces to govern consent for marketing texts. Violations run per message, not per campaign, and the statutory damages add up quickly at scale. Send one noncompliant blast to a large list and the math stops being theoretical fast.

Layer two lives outside federal law entirely: CTIA messaging principles, the standards carriers enforce on their own network. A message can be perfectly legal under TCPA and still get blocked because Verizon or T-Mobile decided it violates carrier guidelines, and no appeal to the FCC changes that. Carriers answer to their own filters on this question, separate from anything Washington decides.

Layer three is A2P 10DLC registration, the carrier system for businesses sending texts at scale from a regular ten-digit number. Unregistered traffic gets blocked outright as of February 1, 2025.

On top of those three sits a patchwork of state law, some of it stricter than the federal floor, and where a state sets a higher bar, that state law governs regardless of what TCPA says. Texas SB 140, effective September 2025, expands "telephone solicitation" to include texts, with treble damages available under the state's Deceptive Trade Practices Act. Other states have enacted laws requiring businesses to honor text opt-outs as a matter of state law, independent of the FCC.

Here's the part that trips people up: a restaurant can have airtight written consent, checkbox, timestamp, the works, and still have every message bounced because nobody registered the campaign with the carriers. Consent is the first checkpoint. Treating it as the whole requirement is the single most common mistake in this subject, and it keeps happening because consent feels like the hard part, so people stop working once they've cleared it.

Prior express written consent has to exist before any marketing message goes out, and "marketing" covers more ground than most owners assume. A text mentioning a discount, a menu item, or any call to action counts. A reservation confirmation doesn't; "Reply CONFIRM for your 7pm table" is purely transactional. Add one clause and everything changes: "Reply CONFIRM for your 7pm table, and don't forget happy hour starts at 5" becomes marketing, and now it needs consent it probably doesn't have. Sit with that second example for a second, because it's exactly the sentence a well-meaning host stand employee writes without thinking twice.

"Written" doesn't require a signature on paper. It requires a documented, affirmative action: a checked checkbox, a keyword reply, a signed sign-up card, and the checkbox has to start unchecked. Here's the detail that actually matters operationally: the guest has to be able to finish the purchase or reservation without ever checking that box. Require it to complete the order, and a regulator reads that as coerced consent, full stop.

Compliance attorneys lean on one specific phrase for a reason: "Consent is not a condition of any purchase." That sentence, or something functionally identical, has to appear stated outright in the disclosure, not implied somewhere in the flow.

Where does this actually get collected? Online ordering and reservation checkout forms, in-store sign-up cards, loyalty enrollment forms, keyword campaigns ("Text JOIN to [number]" on table tents, receipts, social posts), and footer forms on the restaurant's own site all count, provided each one carries the same disclosure.

Best practice is double opt-in: after the initial signup, send a confirmation text the guest has to reply YES to. It's a small bit of friction, but it builds a second, independent record of consent. That record needs three things to hold up under a dispute: a timestamp, the IP address or location where the opt-in happened, and the exact disclosure text the guest saw at that moment. Restaurants that lose TCPA disputes usually had consent but couldn't prove it, which is a weaker position than never having collected it at all.

"Clear and conspicuous" sounds like legal filler until you look at how courts have actually applied it. The test is simple: would a reasonable person notice the disclosure and understand it without hunting for it? That's the whole standard, and it's stricter than it sounds.

Placement is where restaurants lose the argument fastest. The disclosure has to sit directly next to the checkbox or keyword prompt, visible in the same glance, rather than tucked behind a link to the privacy policy, buried in a footer six scrolls down, or left on a separate terms page a guest is trusted to click through to on their own. Courts have struck down disclosures rendered in light-gray text below a submit button; font size and contrast are part of the legal test now, not a design choice a brand team gets to make unilaterally.

Seven things have to sit in that one visible block, together: the business name sending the texts, a program description ("weekly specials and offers from [Restaurant Name]"), an estimated frequency ("approx. 2 to 4 messages per month"), the line "Msg & data rates may apply," opt-out and help instructions ("Text STOP to opt out, HELP for assistance"), the "consent is not a condition of any purchase" language, and a link to the full terms and privacy policy. All seven need to appear in one glance, at the moment the guest opts in, not assembled across three pages or split between a sign-up form and a confirmation email sent an hour later.

Paper doesn't get a pass either. A physical sign-up card at the host stand needs the full disclosure printed on it, not a blank line for a phone number and a pen dangling on a string. "Enter your number for specials!" with nothing else printed on the card carries no legal weight at all.

How opt-out requests must be handled — including the April 2025 rule change that expanded the obligation

Honoring a STOP reply is table stakes; every CTIA-compliant platform automates that already, so nobody gets credit for doing the bare minimum here. The April 2025 change is bigger. The FCC now requires businesses to honor opt-out requests made through any reasonable method, not just the keyword, and that shift is the one most restaurant workflows aren't built for yet.

What does that mean on an actual shift? A guest emails info@ asking to stop getting texts, and that's an opt-out that has to be processed. A voicemail saying "please take me off your list" also has to be processed, and a guest replying "stop texting me, thanks" instead of the literal word STOP still counts. The platform has no excuse for missing any of these, because the rule doesn't care which words the guest happened to choose.

This is a workflow problem, not a settings toggle. The platform handles keyword replies automatically, but a request arriving through email or a phone call needs a human to notice it and manually update the subscriber list. A restaurant without a defined process here is compliant only by luck, and luck runs out the moment one of those emails lands in an inbox nobody checks.

One more wrinkle: texting someone to ask if they'd like to re-subscribe after they've opted out is itself a violation. Re-consent has to come through a different channel entirely, whether that's email, an in-person conversation, or a new ad with its own fresh opt-in form. Once a guest opts out of SMS, that channel stays closed until they choose to reopen it themselves.

Quiet hours round this out. Messages can only go out between 8 a.m. and 9 p.m. in the recipient's local time zone, not the restaurant's. A restaurant in New York texting a guest in Los Angeles has to check Pacific time first, so that 8:45 p.m. "flash sale ends tonight" text is actually landing at 5:45 p.m. on the sender's own clock. That's the easy direction. The one that actually gets restaurants fined is the reverse: firing off a blast at what feels like a reasonable evening hour without checking where the guest lives at all.

A2P 10DLC registration: what it is, what it costs, and why skipping it means blocked messages

A2P 10DLC stands for Application-to-Person messaging over a ten-digit long code: a normal-looking local phone number sending business texts at scale. Every major U.S. carrier blocks unregistered traffic on these numbers entirely as of February 1, 2025, which means zero delivery, a harder failure than a spam-folder landing where the message at least technically arrives somewhere.

Registration runs in two stages. Brand registration establishes the business entity behind the messages, a one-time $4 fee. Campaign registration is where the actual vetting happens, at $100 per distinct use case, and "use case" catches people off guard: promotional marketing texts and reservation reminders count as two different use cases, ideally running on two separate campaigns, sometimes even two separate numbers. Add an ongoing $20-a-month carrier fee, plus a $40 appeal fee if the brand's trust score comes back low on first pass.

Starting in 2026, the requirements tighten further. Authentication+ becomes mandatory for public companies at $12.50, a reseller ID is required for anyone registering on behalf of another business, the EIN used has to be at least 15 days old at the time of registration, and any opt-in URL submitted has to be live and verifiable, not a placeholder page thrown up the night before the filing.

Here's the number that should end any debate about whether registration is worth the hassle: T-Mobile can charge up to $10,000 per content violation and $1,000 per incident for 10DLC evasion, on top of carrier surcharges of $0.006 to $0.017 per message segment for unregistered traffic that somehow still gets through. Set that against the $4 brand fee and $100 campaign fee, and skipping registration to save $104 upfront isn't a close call. It's a bad trade dressed up as a shortcut.

Shared short codes, the five- and six-digit numbers multiple businesses used to split, have been phased out by carriers, so that workaround doesn't exist anymore. Dedicated short codes carry a significantly higher monthly cost, out of reach for most independent operators before they even ask. For a restaurant without a chain's marketing budget, 10DLC registration is the only realistic door into SMS.

Message content rules that apply to every text a restaurant sends

Even a fully registered, fully consented program can get blocked by content, because carriers filter for SHAFT: Sex, Hate, Alcohol, Firearms, Tobacco. Messages containing that language get blocked or filtered regardless of registration status, regardless of consent, regardless of anything else the restaurant did right on paper.

Alcohol is the category that actually bites restaurants, and it's the one owners miss most often, because it feels like the safest promotional content in the building. A text promoting the new cocktail menu, the wine list, or a happy hour special can trip SHAFT filters outright. Alcohol is legal to sell, legal to print on a menu, legal to advertise in the window; a carrier's spam filter doesn't make that distinction, and it won't care that the drink special was cleared by the state liquor board. A restaurant advertising $2 off margaritas on Tuesdays needs to know that before the campaign gets written, not after it silently fails to deliver to half the list.

There's a mechanical limit too: 160 characters per message segment. Go over that and the text splits into multiple segments, each billed separately, so a rambling promo costs more per send, every single time it goes out, on top of being weak copywriting to begin with.

Every marketing text needs opt-out language, something as plain as "Reply STOP to unsubscribe," even for a subscriber who opted in months ago and clearly already knows how. Sender identity has to be unambiguous; a guest should know instantly which restaurant is texting, not guess from context. And the marketing test stays the one from earlier: a discount, a menu item, or a call to action makes it marketing, full written consent required, no gray zone no matter how tempting it is to pretend one exists.

On frequency, the operational standard sits at two to four messages per month per audience segment. Push past that and opt-out rates climb while carriers start treating the sender's traffic with more suspicion, which raises the odds of filtering down the road. Over-texting doesn't just annoy guests; it puts the restaurant's own deliverability at risk for every message after it, including the ones people would have actually wanted to see.

How to build the opt-in touchpoints across a restaurant's guest experience without violating consent rules

Consent has to be voluntary, affirmative, and documented, but it doesn't have to come from one spot. It can be gathered at nearly every point in the guest journey, provided each one follows the same rules without exception, which is exactly where most programs quietly start cutting corners.

Online ordering and reservation checkout is the most common: an unchecked box next to the phone field, the full disclosure visible on that same screen, a confirmation text as the double opt-in. In-store loyalty enrollment works too, whether that's a paper card carrying the full disclosure or a tablet at the host stand for faster capture during a rush. One rule holds regardless of format: staff should never check the box for a guest or pre-fill the consent field on their behalf, however tempting that shortcut feels on a packed Friday night with a line at the door.

Keyword campaigns on table cards, receipts, packaging, or social media, the "Text TACOS to [number]" approach, work fine as an entry point, but the disclosure requirement follows the keyword everywhere it's printed. A receipt that says only "Text JOIN for deals," with no disclosure attached, isn't compliant no matter how many people happily text in.

Wi-Fi capture deserves its own callout, because it's a common blind spot until someone points it out. A guest typing a phone number to unlock the restaurant's Wi-Fi hasn't consented to marketing texts; that's a separate opt-in requiring its own explicit step. Treating Wi-Fi sign-up as a backdoor into a marketing list is exactly the shortcut that shows up in a TCPA complaint later. It looks harmless in the moment, since nobody's forcing anyone to type a number, right up until the logic gets traced through to where it actually lands in front of a judge.

Some things never count as valid consent, whatever the source: a phone number gathered purely for a reservation with no SMS disclosure attached, a number bought from a third-party list, or a number a guest handed to a delivery platform. That last one trips people up constantly. Consent given to a delivery app belongs to the delivery app; it doesn't transfer to the restaurant just because the order happened to originate there.

What a compliant SMS program looks like in practice for a restaurant building one from scratch

Start with the platform, not the content calendar. Pick one that handles A2P 10DLC registration directly and automates opt-out processing, because building that infrastructure from scratch isn't a reasonable ask for anyone also trying to run a dining room at the same time. Register the brand and at least one campaign before a single message goes out; the $4 brand fee and $100 campaign fee are the floor, not a line item to skip because the launch date feels close.

From there, audit every existing opt-in touchpoint against the disclosure checklist above: placement, exact language, unchecked default, and the guest's ability to decline without friction. Build an opt-out workflow that covers channels outside SMS itself, a shared inbox or simple ticketing process so a staff member can act on a request that arrives by email or voicemail instead of a keyword reply. Segment the subscriber list before sending anything, keeping promotional messages and transactional ones apart, with distinct campaigns registered for each.

Set frequency caps at the platform level, two to four messages per month per segment, and configure send windows so nothing goes out before 8 a.m. or after 9 p.m. in the recipient's own time zone. Store every consent record somewhere retrievable: the timestamp, the opt-in method, the exact disclosure text shown at that moment. That record is the entire legal defense if a complaint gets filed, and without it, a restaurant is left arguing from memory against a a potentially steep per-message penalty, which is a weak position against a plaintiff's attorney with a spreadsheet.

The overhead here doesn't cancel out the return. Registration and disclosure work cost dollars and hours; a single TCPA violation costs per-message penalties that stack fast across a subscriber list of any real size. Restaurants that connect SMS sends to POS transaction data can see exactly which offer drove which visit, linking a text sent at 4 p.m. to a table filled at 6, the same standard every other marketing dollar in the building already gets held to. SMS just happens to be the channel where skipping that standard costs the most to find out the hard way.

Sources

  1. infobip.com
  2. activeprospect.com
  3. moengage.com
  4. callloop.com
  5. textedly.com
  6. leadcompliant.com
  7. leadcompliant.com
  8. completesms.com
Filed underSMS Marketing

More in SMS Marketing