Compliance

Opt-in collection

What counts as valid opt-in, where to collect it, and how Callduck stores it.

Opt-in collection

Before you send any business-initiated WhatsApp message, the customer must have opted in. Valid opt-in is clear, specific to WhatsApp, and tied to your business name. This is the foundation of Marketing broadcast compliance.

What counts as valid opt-in

  • The customer actively agreed to receive WhatsApp messages from your business.
  • The opt-in names WhatsApp and your business.
  • It is not pre-checked or buried — the customer took a clear action.

Where to collect it

  • Website widget — a WhatsApp opt-in checkbox or chat entry point
  • Checkout checkbox — explicit "message me on WhatsApp" at purchase
  • IVR / phone — spoken or keypad consent
  • In-store — a signed or tapped agreement
  • Inbound message — when a customer messages you first, that starts a conversation and is itself a strong signal of consent

What to log

Always record the source and a timestamp for every opt-in, so you can demonstrate consent later.

How Callduck stores it

  • Each contact has an opt-in status: UNKNOWN, OPTED_IN, or OPTED_OUT.
  • The opt-in source is one of: WIDGET, IMPORT, MANUAL, INBOUND_MESSAGE, API, CAMPAIGN_REPLY.
  • A ConsentLog row captures each opt-in event with its source, timestamp, and detail.
  • When a customer messages you first, Callduck sets them to OPTED_IN with source INBOUND_MESSAGE automatically.

> Practical and honest: opt-in is your legal basis to message. Keep the proof. Callduck stores the trail, but obtaining genuine consent is your responsibility.

تذكير: تبدأ كال داك في الوضع التجريبي الذي لا يرسل رسائل حقيقية. اربط بيانات اعتماد منصة واتساب للأعمال الرسمية الخاصة بك للانتقال إلى التشغيل الفعلي.

نبي نقيس أي الصفحات تفيد الناس. ما فيه كوكيز إعلانات، ولا بيع بيانات، ولا شي مربوط بهويتك. سياسة الخصوصية