> ## Documentation Index
> Fetch the complete documentation index at: https://plivo.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Toll-Free Registration Guidelines

> Website, opt-in, and consent requirements for US/Canada toll-free SMS verification, plus the Plivo console submission steps.

<Info title="TL;DR">
  The customer's website is the first thing carriers check during review. A submission with an underdeveloped or non-compliant website will be rejected regardless of how clean the rest of the submission is.
</Info>

## Who this applies to

Any business submitting a toll-free number for SMS verification through the Plivo console, under **Compliance > Toll-Free Verification**.

## Key terms

* **DBA (Doing Business As)** - the trade name a business operates under when it differs from its registered legal name; required wherever a "DBA relationship" or "DBA name" applies to a submission.
* **CP575 / W9 / 147C** - government-issued documents used to confirm a business's exact legal name and EIN during review.
* **EIN** - the business registration number entered in Step 1 of the submission, which must match your government-issued documents exactly.
* **Use case** - the specific type of messages a toll-free number will send; select only the use cases in Step 4 that accurately reflect what you're sending.
* **Double opt-in** - a two-step consent flow where an initial opt-in (verbal, paper, or web) is followed by a secondary SMS asking the recipient to reply YES to confirm subscription.

## Website and digital presence requirements

### Pre-submission website requirements

The customer's website is the first thing carriers check during review. A submission with an underdeveloped or non-compliant website will be rejected regardless of how clean the rest of the submission is.

### Website existence and accessibility

1. Website is NOT a "coming soon" or placeholder page
2. Website URL uses the business's own domain
3. Website loads without errors and renders properly on desktop and mobile
4. Domain matches the business name on the submission (or DBA relationship is clearly established)
5. The website is publicly accessible without requiring login or account creation.
6. All navigation links and internal links are functional - no broken links or 404 errors

### Business information on website

* Business name displayed clearly on the homepage and consistently across all pages.
* Physical business addresses listed on the website must match the address provided during submission.
* Contact information (phone number, email)
* Description of products/services offered must be substantive.
* Business hours (if applicable)
* Footer contains links to Privacy Policy, Terms & Conditions, and Contact Us.

### Required legal pages

* Terms of Service / Terms and Conditions page (publicly accessible URL)
* Privacy Policy page (publicly accessible URL)
* Both URLs must load without authentication
* Both pages must be linked from the homepage footer or navigation
* Both links must also be present and clickable at the exact point of SMS opt-in

### Privacy policy specific requirements (critical)

* Privacy Policy must contain explicit no-sharing language for SMS opt-in data
* Include this language (or equivalent):

  > "No mobile information will be shared with third parties/affiliates for marketing/promotional purposes. All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties."

### Terms and conditions requirements (critical)

* Program or brand name
* Program description - what types of messages will be sent
* How customers can opt in to receive messages
* STOP - opt-out instructions
* HELP instructions
* Message frequency disclosure (e.g. "Message frequency may vary" or "Approx. X msgs/month")
* "Message and data rates may apply" statement
* Customer care contact - both an email address and a phone number
* A clickable link to the Privacy Policy
* The following carrier liability disclaimer: "Carriers are not liable for any delayed or undelivered messages."

### Digital footprint alternatives (if website is minimal)

* Active and verified Google Business Profile with customer reviews
* Or active Facebook/Instagram Business Page with recent posts, contact info, customer interactions
* Or listings on Yelp, Better Business Bureau, or industry directories

<Note>
  A dedicated business website is the most compliant and recommended option. Submissions using social media or Google Business Profile as a substitute may still be approved at the carrier's discretion but approval cannot be guaranteed.
</Note>

## Opt-in and consent requirements

### Web form opt-in

* Phone Number field is explicitly labeled and disclosed as for SMS use.
* SMS consent checkbox is present (separate from any general Terms of Service checkbox)
* Checkbox is **UNCHECKED by default** (pre-checked boxes trigger denials)
* Checkbox label includes the full disclosure:
  1. Business name (matching the registered legal name or DBA)
  2. Specific message types the user will receive (e.g., "appointment reminders, account notifications, promotional offers"). This must match the registered use-case.
  3. Message frequency (e.g., "approximately 2 messages per month" or "message frequency varies")
  4. "Msg & data rates may apply" language
  5. "Reply STOP to opt out, HELP for help" instructions
* Privacy Policy and Terms & Conditions links visible and clickable near the SMS consent checkbox or in the opt-in consent language.
* For mixed use cases (transactional + marketing): **TWO SEPARATE checkboxes** - one per use case category
* Form **must not require** SMS consent to submit (i.e., consent is genuinely optional)
* The CTA button (e.g. "Submit", "Sign Up") must not itself imply SMS consent. Consent must be captured via the checkbox only.

### Paper opt-in

* The paper form has a dedicated SMS consent section (not a generic intake form).
* Unchecked checkbox OR dedicated SMS consent signature line
* The business name printed on the form must match the legal entity name exactly as it appears on government-issued documents such as the CP 575 or W-9.
* DBA name (if required). The relationship between the Legal name and the legal name must be explicitly mentioned.
* Full disclosure language printed on form:
  1. Message types
  2. Message Frequency
  3. "Message & data rates may" apply statement
  4. STOP & HELP instructions
* Dedicated consent sections for each use case (if more than one).
* Customer signature line
* Signed forms are scanned and retained in business records
* Direct Privacy Policy URL printed on the form (e.g. "View our Privacy Policy at \[URL]")
* Consent is logged in a CRM or system with: timestamp, customer name, phone number, reference to signed form.

### Verbal opt-in

* Written script is available for staff/agents to read verbatim
* Script includes:
  1. Business name
  2. Specific message type/purpose
  3. Message frequency
  4. "Message & data rates may" apply statement
  5. STOP & HELP instructions
  6. Statement that SMS consent is optional and won't affect service
  7. Phone number confirmation question
* Caller must affirmatively say "Yes" (silence or continuation is NOT consent)
* Consent is captured in a CRM/system with timestamp, agent name, customer phone number
* Verbal opt-in is used ONLY for transactional use cases, Marketing messages have a separate, written consent capture mechanism

### Double opt-in (verbal/paper/web + SMS confirmation)

* First opt-in (verbal, paper, or web) is properly documented per above
* Secondary SMS confirmation is sent: "Reply YES to confirm subscription"
* Recipient must reply YES to be enrolled
* If no response within 24 hours, opt-in expires automatically

## Toll-free request submission guidelines

Toll-free verification requests are submitted directly through the Plivo console under **Compliance > Toll-Free Verification**. The submission is split into four steps: Business Information, Authorised Representative, Business Address, and Toll-Free Verification. Each step must be completed accurately before proceeding.

### Step 1: Business information

* **Brand Name:** The name your business operates under (DBA if applicable).
* **Website URL:** Your business's primary website URL (e.g. `https://www.businessname.com`) not a sub-page or Privacy Policy page. Ensure the URL does not return any errors when accessed.
* **Business Entity Type:** Select the correct entity type that matches your business registration. See entity type classifications below.
* **Industry:** Select the industry that best describes your business.
* **Registered Business Name:** Exact legal name as filed with the IRS or state corporate registry including punctuation, capitalization, and suffix (e.g. "Inc.", "LLC", "Corporation"). Must match government-issued documents such as the CP 575 or W-9 exactly.
* **EIN:** Your business registration number must match exactly what appears on official government-issued documents. Enter with no extra spaces or formatting errors.
* **EIN Issuing Country:** Select the country where your business is registered.
* **Entity Type Classification:**

| Entity Type | Description                                                                                                                                               |
| ----------- | --------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Public      | for publicly traded companies listed on a stock exchange                                                                                                  |
| Private     | for privately held businesses such as LLCs, Corporations, insurance carriers, and MGAs that operate for profit                                            |
| Non-Profit  | for organizations registered under 501(c) or equivalent that operate without a profit motive, such as charities, foundations, and community organizations |
| Government  | for federal, state, or local government agencies and public sector entities                                                                               |
| Individual  | for individuals operating without a formally registered business entity                                                                                   |

### Step 2: Authorised representative

The authorised representative is the individual permitted to register this submission on behalf of the business. Plivo or carrier partners may contact them if clarification is needed.

* **First Name:** First name of the business representative.
* **Last Name:** Last name of the business representative.
* **Email:** Official business domain email address (e.g. `name@businessname.com`). Avoid using personal email addresses from free providers such as Gmail or Yahoo.
* **Phone Number:** Valid, reachable phone number for the representative.
* **Position:** Select the representative's role within the business (e.g. Manager, Owner, Director).

### Step 3: Business address

Provide the official registered business address. For multi-property submissions, each toll-free number must reflect the unique address of the property it serves. No two submissions can share the same address.

* **Business Name:** Legal business name as registered.
* **Street Address:** Full street address of the business.
* **City:** City where the business is located.
* **State:** State or province where the business is located.
* **Country:** Country where the business is located.
* **Postal Code:** ZIP or postal code of the business address.

### Step 4: Toll-free verification

* **Toll-Free Number:** Select the toll-free number being verified from your account.
* **Use Cases:** Select only the use cases that accurately reflect the messages being sent. Do not select unrelated use cases to broaden your submission.
  * Notifications - for transactional alerts and status updates
  * Customer Care - for support and service-related communications
  * 2FA - for authentication codes only, not general notifications
  * Business Updates - for service or account updates
  * General Marketing - for promotional content and special offers
  * Higher Education - for communications from educational institutions
  * Public Service Announcement - for government or community announcements
* **Use Case Summary:** A detailed description of who sends the messages, who receives them, what types of messages are sent, and how recipients opted in. Must not be vague or generic and must not be a copy of the Use Case field.
* **Message Sample:** There must be a minimum of one sample message per registered use case. Each sample must begin with the brand name and include "Reply STOP to opt out", "Reply HELP for help", and "Message and data rates may apply".
* **Upload Files** - This field can be used to upload the opt-in flow images relating to the Toll Free request.
* **Opt-in Image URL:** A publicly accessible URL of the opt-in form or proof of consent. Do not use Google Drive links as they are often inaccessible to carriers. Alternatively, upload the opt-in proof directly via the file upload option.
* **Consent Method:** Select the method that accurately reflects how your users provide consent to receive messages.
  * Verbal - consent is obtained in person or over the phone using an approved script
  * Digital - consent is collected through a form on a website, app, or point of sale device / Web opt-in.
  * Written - users provide their phone number and sign or check a box on a paper form / Paper opt-in.
  * Via Text Message - users initiate contact by texting the number first and then providing consent.
  * Mobile QR Code - users scan a QR code on their mobile device to provide consent
* **Monthly Message Volume:** Provide a realistic estimate of the number of messages you expect to send per month.
* **Additional Information** - Provides context the carrier needs to understand the business:
  * Business overview (industry, what they do)
  * Customer base / audience
  * Opt-in process explanation
  * Clear justification explaining the use case of the number
  * Do not include internal notes
  * *Justification must be provided for a single entity having more than 5 TF Numbers.*
  * *Common uses: describe your opt-in flow, or link to your Privacy Policy and Terms & Conditions.*

<Note>
  Passing Plivo's review does not guarantee carrier approval. The carrier independently reviews all submissions and reserves the right to approve or deny any submission at their sole discretion, even when all guidelines have been followed.
</Note>

## Upcoming fields

The following fields are not currently available in the console submission flow but will be available in the upcoming console updates.

* **OptIn Confirmation Response** - The automated message sent to a user immediately after they opt in. Must include the brand name, confirmation of what they signed up for, message frequency, "Message and data rates may apply", and STOP and HELP instructions.

  Eg: "\[Business Name]: You're now signed up to receive \[message type]. Message frequency may vary. Message and data rates may apply. Reply STOP to opt out, HELP for help."

* **Help Message Response** - The message sent when a user texts HELP. Must include the brand name, a support contact, and STOP instruction.

  Eg: "\[Business Name]: For assistance contact us at \[email] or call \[phone number]. Message and data rates may apply. Reply STOP to unsubscribe."

* **Terms & Conditions URL** - A publicly accessible link to your Terms & Conditions page. Must include all required SMS disclosures as listed in Section A.

* **Privacy Policy URL** - A publicly accessible link to your Privacy Policy page. Must include the SMS no-sharing clause and all required data handling disclosures as listed in Section A.

## FAQ

### Does passing Plivo's review guarantee carrier approval?

No. The carrier independently reviews all submissions and reserves the right to approve or deny any submission at its sole discretion, even when all guidelines have been followed.

***

### Can I use a Google Drive link for my opt-in proof?

No. Google Drive links are often inaccessible to carriers. Provide a publicly accessible URL instead, or upload the opt-in proof directly using the file upload option.

***

### Can verbal opt-in be used for marketing messages?

No. Verbal opt-in is used only for transactional use cases. Marketing messages require a separate, written consent capture mechanism.

***

### What happens if a recipient doesn't reply YES to a double opt-in confirmation?

The opt-in expires automatically if there's no response within 24 hours, and the recipient is not enrolled.

***

### Can two toll-free number submissions share the same business address?

No. For multi-property submissions, each toll-free number must reflect the unique address of the property it serves — no two submissions can share the same address.

## Related resources

* [US and Canada Messaging](/docs/messaging/concepts/us-ca-messaging#toll-free-numbers) — where toll-free numbers fit among US/Canada source number types.
* [Toll-free Verification API](/docs/messaging/api/toll-free-verification) — create and manage verification requests programmatically.
* [Toll-free Verification quickstart](/docs/messaging/tf-verification/quickstart/toll-free) — SDK code samples for submitting a verification request.
* [10DLC Registration Guidelines](/docs/messaging/a2p-10dlc/registration-guidelines) — the equivalent guidelines for 10-digit long code brand and campaign registration.
