You've seen the setup because you've probably built it yourself: a little acrylic sign by the register that says "Text us your number for 10% off!" or a clipboard where regulars scribble their cell number to "join the list." It feels like consent. Someone physically handed you their number and asked to be on it. What more could a regulator want?
Quite a bit, actually. What you collected at the counter is a phone number. What the law requires before you send marketing texts is express written consent — a specific, documented thing with specific ingredients. The gap between those two is where TCPA exposure lives, and each text sent without valid consent carries statutory damages of $500 to $1,500. A single blast to 400 improperly-opted-in contacts is a six-figure math problem.
Full disclosure: I work for Ready, an SMS platform. We handle a lot of the consent-logging and opt-out plumbing I'm about to describe, so I have skin in this. But the compliance standard itself isn't ours to define — it's the FCC's and the courts', and it applies no matter whose software you use.
Why "text us your number" fails the standard
Marketing SMS in the US falls under the TCPA, which requires prior express written consent for autodialed or pre-recorded marketing messages. The FCC spelled out what that consent has to contain, and a handwritten number on a clipboard misses most of it.
Express written consent, to actually hold up, needs to be:
- A clear, affirmative agreement — the person agrees to receive marketing texts, not just "give you their number for a coupon."
- Disclosed in writing that they're signing up for automated marketing messages, from your business, by name.
- Not conditioned on a purchase — you can't require the opt-in to complete a transaction.
- Accompanied by disclosures: message frequency ("msgs may vary" or "up to 4/mo"), that "message and data rates may apply," and how to opt out ("reply STOP").
- Documented — you need a record of who consented, to what, and when.
A number scribbled on a clipboard has none of that. There's no disclosure the person read, no record of what they agreed to, and no proof they weren't just handing you their number so you could call about a repair. Verbal collection is worse — there's literally nothing to produce if a contact disputes it.
The problem isn't that these people don't want your texts. Most of them do. The problem is you can't prove they agreed to receive them under the terms the law requires, and in a TCPA dispute the burden of proving consent is on you, the sender.
The one-line fix
You don't need to rip out the clipboard. You need to change what the person confirms and how you capture it. The fix is a self-opt-in step where the customer texts a keyword to your number — so the affirmative action comes from their phone, and your platform logs it.
Replace the "text us your number" sign with something like:
Get 10% off your next visit. Text JOIN to (555) 012-3456 to get deals from [Your Business]. Up to 4 msgs/mo. Msg & data rates may apply. Reply STOP to cancel.
That single card now does the whole job:
- The customer takes the affirmative action themselves (texting the keyword from their own device).
- The disclosures — business name, frequency, rates, STOP — are right there in what they read before acting.
- The inbound keyword is timestamped and stored, giving you the audit trail.
- Your reply confirms enrollment and repeats the opt-out instruction.
That's it. The friction cost is real — a few people won't bother pulling out their phone — but you're trading a handful of sign-ups for consent that survives a challenge. If you're weighing that tradeoff more broadly, we wrote about how double opt-in loses 20–30% up front but wins on revenue per contact.
What the audit trail actually needs to contain
If a contact ever claims they never agreed, "we had a sign up" isn't a defense. A timestamped record is. For each opt-in you want to be able to produce:
| Field | Why it matters |
|---|---|
| The phone number | Ties the consent to the person disputing it |
| Timestamp of opt-in | Proves consent existed before you sent |
| The keyword / method | Shows the affirmative action was theirs |
| The disclosure language shown | Proves what they agreed to |
| Opt-out events | Shows you honored STOP promptly |
This is exactly what Ready's consent and attestation capture records for bulk and inbound-keyword sign-ups — the inbound message, when it landed, and the enrollment. It's not that you can't keep this in a spreadsheet; it's that the spreadsheet falls apart the moment your counter staff forgets to log one, and the missing rows are the ones you get sued over.
The STOP problem you'll create if you're not careful
Here's the failure mode I see most with in-store lists: a customer texts STOP, someone marks them unsubscribed in one campaign, and then the next promo blast — run from a different list or a different staff member's export — texts them again. That second text, to someone who explicitly opted out, is its own violation.
Opt-out has to propagate across everything you send, automatically. Ready honors inbound STOP/UNSUBSCRIBE and suppresses that contact across campaigns, so a manual list export can't accidentally re-message someone who left. That's not a nice-to-have; it's the difference between "we handle opt-outs" and "we handle opt-outs reliably."
Worth noting: SMS opt-out often doesn't cross channels on its own. Someone who texts STOP may still be fair game for your calls unless you sync it, which is a separate trap we broke down in why opt-out rarely crosses channels. And if you also run a phone list, the internal do-not-call obligations are stricter than most businesses realize — see the internal DNC list regulators check first.
You still need 10DLC registered before any of this sends
Even perfect consent doesn't get your texts delivered if you're sending unregistered. Application-to-person traffic — which is what a business-to-customer marketing list is — has to run over a registered 10DLC brand and campaign, or carriers filter it. Your beautifully-opted-in JOIN keyword replies won't arrive at all.
Registration runs roughly ~$10/mo per brand and ~$20/mo per campaign in carrier fees, with approval typically 1–3 days. In Ready that happens in-app, and most brand approvals come back same-day. If the term's new to you, we have a plain-English 10DLC explainer. The order of operations matters: register first, then launch the keyword sign, then start collecting.
The cost side, so you can size it honestly
Say the JOIN card works and you build a list of 800 regulars over a few months. You send a monthly promo — a 150-character text, no emoji, so one segment each.
- 800 contacts × 1 segment × ($0.02 + $0.0045 carrier) = $19.60 per monthly blast on Ready's Standard tier.
- Add ~$30/mo in 10DLC carrier fees (one brand, one campaign).
So the recurring cost of a compliant, register-based local SMS program is under $50/month at this size — which, not coincidentally, is the same ballpark as building an app to reach your regulars for $40K, except this one starts working this week. Full current numbers are on the product and pricing page.
One more optional layer if your list has grown from mixed sources over time: a one-time litigator/DNC scrub at $0.005/contact screens known TCPA-litigator and DNC-complainer numbers before you send. On 800 contacts that's $4 — cheap insurance against the one flagged number that turns a routine blast into a claim.
The practical takeaway
The sign by your register isn't the problem — the wording and the capture method are. Swap "text us your number" for "text JOIN to [number]" with the disclosures right on the card, let the customer's own inbound message be the consent event, and make sure your platform logs it and honors STOP across every campaign. Register your 10DLC before you flip it on.
Do that and the acrylic sign that used to be a liability becomes a documented, defensible opt-in funnel. If you want to see how the consent logging and automatic opt-out handling work before committing, Ready starts with 2,500 free credits, no card required — enough to stand up the keyword, run a first blast, and check the audit trail yourself. Take a look when you're ready.