Compliance
The part most marketing tools leave entirely to you
TCPA statutory damages
$500–$1,500
Per message. Not per campaign, not per complaint — per message sent without valid consent, trebled where the violation is found to be wilful.
2,000
contacts
1
campaign
$1M+
theoretical exposure
Rule by rule
What the law asks for, and where we enforce it
| Requirement | Regime | How it is handled | Enforced at |
|---|---|---|---|
| Prior express written consent before marketing texts | TCPA | SMS consent is captured with the exact disclosure wording, stored alongside the source URL, IP and the time the person acted. | Lead form · consent record |
| Consent may never be a condition of service | TCPA | There is no way to make an SMS consent box required on a lead form. No toggle, no attribute, no column. | Form builder · absent by design |
| Honour opt-outs across all future sends | TCPA / CAN-SPAM | An unsubscribe click or an inbound STOP writes a suppression entry and flips consent to revoked, for every campaign thereafter. | Send gate · database |
| An opt-out must not be undone | TCPA | Neither a CSV import nor a staff member editing a contact can lift a withdrawal. Only the contact themselves can. | Application + database trigger |
| Working unsubscribe in every commercial email | CAN-SPAM | The unsubscribe link is inserted by the platform, not typed by the sender, so it cannot be forgotten or broken. | Composer · enforced footer |
| Physical postal address in every commercial email | CAN-SPAM | Your agency's address is part of sender setup and is written into the footer of every message. | Composer · enforced footer |
| Register the sending number before texting | A2P 10DLC · toll-free verification | Registration is part of onboarding, per agency: a brand and campaign for a local number, a verification for a toll-free one. Nothing sends until the carriers approve it, and the workspace shows it as pending meanwhile. | Onboarding · carrier registry |
| Keep proof of consent for years, not days | TCPA | Consent records are append-only. There is no interface, and no database permission, to edit or delete one. | Database grants |
Who is responsible for what
A straight division of labour
We handle
- Capturing consent with the wording, source, IP and timestamp
- Storing that evidence where it cannot be edited or deleted
- Filtering non-consented and suppressed contacts before dispatch
- Inserting the unsubscribe link and postal address into every email
- Processing STOP replies and unsubscribe clicks automatically
- Validating your SMS disclosure wording before a form can go live
- Running carrier registration per agency and showing its real status
You remain responsible for
- Only uploading contacts you genuinely have permission to message
- What your messages say and who you choose to send them to
- Honouring requests that arrive outside the platform — by phone, in person
- Your agency's own privacy notice and record-keeping obligations
- State-level rules that go beyond the federal baseline
- Keeping your postal address and sender identity accurate
Decisions you may disagree with
Three places we chose the stricter option
Imports cannot re-subscribe
Re-uploading last year's list is the ordinary way an opt-out gets erased. It happens by accident, nobody notices, and it is precisely the fact pattern behind a claim. So it is blocked — in the application and again in the database.
Consent is four states, not a toggle
Never asked and told-me-no are different facts. Collapsing them teaches you the wrong thing about what you may send, and the difference is exactly what a dispute turns on.
SMS consent can never be required
Conditioning service on agreeing to marketing texts is prohibited outright, so there is no setting for it. Not a default — an absence.
Common questions
The ones worth answering plainly
Does using Swift Pivot make my agency compliant?
No, and any vendor who says otherwise is selling you something. You are the sender. You choose who to contact and what to say, and the legal responsibility for that sits with your agency.
What we do is remove the failure modes that create most exposure: consent that was never recorded, opt-outs that were not honoured, imports that quietly re-subscribed people, and messages sent without the required disclosures. Those are mechanical problems, so we solved them mechanically.
What actually happens if I import a list I bought?
The import asks you to declare where the list came from and to attest to it, before a single row is written. Contacts arrive without marketing consent unless you can state how it was obtained, and anyone on that list who previously opted out stays opted out. The summary tells you how many rows it refused to re-subscribe, so you can see what was prevented.
How much is the exposure, really?
TCPA statutory damages run $500 per violation, trebled to $1,500 for wilful ones — assessed per message, not per campaign. A 2,000-person list texted once without consent is not a warning letter; it is arithmetic. This is why consent is a four-state record here rather than a checkbox.
Do you handle protected health information?
No, and our terms ask you not to put it here. Swift Pivot is a marketing system: names, contact details, enquiry sources and consent. Care plans, diagnoses and clinical notes belong in your agency management software, and we do not sign HIPAA business associate agreements for this product.
Is this legal advice?
It is not. It is a description of what the software does. Your obligations depend on your state, your list and your practices — talk to counsel about those, and use this page to tell them what the tooling already enforces.
This page describes product behaviour and is not legal advice. Swift Pivot is not a law firm. Requirements vary by state and by how you obtained your list — consult qualified counsel about your own obligations.
Start with a list you can defend
Questions first? contact@swift-pivot.com
