Consent and opt-out management that respects permission on every message after it
Consent and opt-out management that starts with the lead: consent arrives with it, is kept per channel and purpose with its evidence, and is checked again at every step a message takes — while unsubscribes, STOP replies, bounces and privacy requests all land in the same place, so nobody on the team has to remember who said no.
- Consent captured with the lead, never pre-ticked
- Checked when queued, released, retried and sent
- Every opt-out lands on one list
- points where every outreach message is checked again
- 4
- channels, each with its own consent: email, SMS and WhatsApp
- 3
- outreach emails a day and a week, at most, per person
- 5 / 15
Where consent is captured, kept and checked
- CaptureForm consent boxes, Meta disclaimers, API and imports
- Consent recordPer channel and purpose, with evidence
- Send checksRun again before anything leaves
- Preference pageSigned links people use without an account
- Do-not-contactOpt-outs, bounces and your own entries
- Privacy requestsAccess, erasure and anonymise, approved
Nobody can say where a yes came from
A lead ticked a box on a form months ago, or a rep heard a customer agree on a call. When someone later asks why they are getting messages, the team has a spreadsheet column that says Yes and no idea which notice they agreed to, or when.
An opt-out that only one tool knows about
Someone unsubscribes from an email, then gets a WhatsApp offer the same week because the messaging tool never heard about it. Every separate list is another place a no can be missed, and the customer only sees one company ignoring them.
Checks that run once and then go stale
Consent is looked at when a campaign is planned, but the send waits overnight or is retried the next day. By then the person has replied STOP, and the message goes out anyway because nothing looked again.
Consent that arrives with the lead
Add a consent box to a website or embedded form and choose what it covers: marketing, sales outreach, or both, on email, SMS or WhatsApp. The form can't be saved without the notice people read, and the box is never ticked for them. A ticked box records consent with the notice, its version and the time; an unticked box records nothing. Disclaimer checkboxes on Meta lead ad forms and consent sent to the Lead API are recorded the same way.
- A consent box with the notice written beside it
- Never ticked by default, and silence records nothing
- Meta disclaimer checkboxes mapped to channels
- Consent claims accepted on the Lead API
One consent record for each channel and purpose
Consent is kept separately for email, SMS and WhatsApp, and for marketing and sales outreach, so a yes to offers by email says nothing about sales calls on WhatsApp. Each entry holds where it came from and the policy version it was given under. It sits on the lead and on the address itself, moves to the contact when the lead converts, and every change is added to a history that is never edited.
- Email, SMS and WhatsApp kept apart
- Marketing and sales outreach kept apart
- Evidence source and policy version on each entry
- Carried from the lead to the contact on conversion
Checked again at every step a message takes
One set of rules decides whether a message may leave, and it runs when the message is queued, when it is released from a hold, when someone retries it, and just before it is sent. The do-not-contact list is checked first, then consent for marketing and sales outreach. Receipts and security notices are never blocked by a marketing opt-out. Blocked conversations collect in the inbox's Consent blocked desk.
- Checked at queue, release, retry and send
- Do-not-contact comes before any consent on file
- Unknown and withdrawn consent blocked by default
- A Consent blocked desk in the inbox
A preference page people can use without signing in
Outreach email carries a signed link to a simple page in your workspace's name. People choose what to stop, Marketing and newsletters or Sales follow-ups, and unsubscribe from what they picked or from everything at once. Mail apps can also unsubscribe in one click from the email header. The page tells them plainly that receipts, bookings and security notices will still arrive.
- A signed link, so no login and no guessing
- Marketing and sales follow-ups listed separately
- Unsubscribe from selected, or from all
- One-click unsubscribe from the email header
STOP means stop, whichever word they use
A text or WhatsApp reply of STOP, UNSUBSCRIBE, CANCEL, END, QUIT or a similar word withdraws marketing and sales outreach consent. The number is added to your do-not-contact list and the change is written to the audit log. If the customer later texts START or UNSTOP, only what their STOP changed is put back. An opt-out from a link, an import or a colleague stays exactly as it was.
- Ten opt-out words understood on SMS and WhatsApp
- Both marketing and sales outreach withdrawn
- The number added to do-not-contact and audited
- START by text undoes only what STOP did
One do-not-contact list that outranks everything
Your workspace keeps a single list of email addresses and phone numbers that must not be contacted. Opt-outs and STOP replies join it on their own, and so do hard bounces and spam complaints unless you switch that off. Paste in numbers from an old list, remove entries your team added, or switch Do not contact on from a lead or contact page. A rep's toggle can never remove a customer's own opt-out.
- Matched on email address and phone number
- Hard bounces and complaints added automatically
- A Do not contact switch on every lead and contact
- A customer's own opt-out locked against removal
Limits on how often, and quiet hours for when
Even someone who agreed shouldn't hear from you every hour. Each person receives at most five outreach emails a day and fifteen a week, and two texts or WhatsApp messages a day and five a week, counted by the day and the week. A message over the daily limit waits for tomorrow; one over the weekly limit isn't sent. Automated messages also wait out your quiet hours, while a reply typed by hand goes when it's sent.
- 5 emails a day and 15 a week per person
- 2 SMS or WhatsApp messages a day and 5 a week
- Receipts and security notices never counted
- Quiet hours with your own start, end and time zone
Access, erasure and anonymise requests, with a second approver
When someone asks what you hold about them, raise an access request and download a copy of their data once it has run. A request to be forgotten can erase their leads and contacts or anonymise them, keeping deal and reporting figures with nobody identifiable. Every request waits for someone other than the person who raised it to approve or reject it, whenever your workspace has a second privacy admin, and each request carries a due date so none is quietly forgotten.
- Access, erasure and anonymise requests
- A downloadable copy for access requests
- Decided by someone other than the requester
- A due date on every request, 30 days by default
From a ticked box to a respected no, in five steps
- STEP 01
Capture it with the lead
Forms, Meta disclaimers, the Lead API and imports record consent as leads arrive.
- STEP 02
Keep one record
Consent per channel and purpose, with its evidence, follows the lead to the contact.
- STEP 03
Check every send
Do-not-contact, consent and limits are checked at each step before a message leaves.
- STEP 04
Honour every no
Unsubscribes, STOP replies and bounces land on one do-not-contact list.
- STEP 05
Answer privacy requests
Raise access, erasure and anonymise requests, and have a second person decide.
Consent in a CRM vs an opt-out spreadsheet
| What it covers | A spreadsheet of opt-outs and separate messaging tools | |
|---|---|---|
| Where consent comes from | A Yes column with no source or date | The form notice, disclaimer or rep attestation behind it |
| Channels and purposes | One yes that covers everything | Email, SMS and WhatsApp, marketing and sales, kept apart |
| When consent is checked | Once, when the list is pulled | At queue, release, retry and just before sending |
| Unsubscribes and STOP replies | Copied across tools by hand, eventually | Recorded on one list the moment they arrive |
| Bounced and complaining addresses | Mailed again next week | Added to do-not-contact automatically |
| How often people hear from you | Whatever each campaign decides | Daily and weekly limits per person, per channel |
| Requests to be forgotten | Deleted by whoever reads the email | Raised, decided by a second person and tracked to a due date |
The lead sources that bring consent with them
Consent is recorded as leads arrive from the sources that can carry it: the consent box on hosted and embedded website forms, disclaimer checkboxes on Meta lead ad forms, consent claims sent to the Lead API, and consent columns in an import file.
Consent and opt-out questions, answered
How does DigiPix Flow record consent when a lead comes in?
From the sources that can carry it. A website or embedded form can include a consent box with its own notice; a ticked box records consent with the notice, its version, the time, IP address and browser. Disclaimer checkboxes on Meta lead ad forms can be mapped to the channels and purposes they cover, and the Lead API accepts consent claims. An unticked box records nothing.
Can a consent box be ticked by default?
No. There is no setting for it. People tick the box themselves, and a form can't be saved with a consent box that has no notice for them to read. Editing the notice later starts a new version, so earlier consent stays tied to the words people actually saw.
What happens to consent columns in an imported file?
An opt-out in an import is always recorded. An opt-in is accepted only when your workspace allows consent from imports and the row says where and when it was given, because a spreadsheet on its own isn't evidence. A blank cell is treated as no answer rather than a no.
Is consent kept separately for each channel?
Yes, for each channel and each purpose. Email, SMS and WhatsApp each have their own consent, and so do marketing and sales outreach. A person can agree to offers by email and still have no consent for sales messages on WhatsApp, and DigiPix Flow treats them that way.
When is consent checked?
Every time it matters. The same rules run when a message is queued, when it is released after quiet hours or a limit, when someone retries it, and just before it is sent. Do-not-contact is checked first. Consent applies to marketing and sales outreach, so receipts and security notices still reach people who opted out.
What does the preference page let people do?
It opens from a signed link in outreach email, so nobody needs an account. People can stop Marketing and newsletters, Sales follow-ups, or everything at once, and mail apps can unsubscribe in one click from the email header. The page only records opt-outs.
What happens when someone replies STOP?
A reply of STOP, UNSUBSCRIBE, CANCEL, END, QUIT or a similar word by SMS or WhatsApp withdraws their marketing and sales outreach consent, adds the number to do-not-contact and writes an audit entry. A later START or UNSTOP by text restores only what that STOP changed.
Can a rep remove someone from the do-not-contact list?
From a lead or contact page, only entries your team added by hand or through an import. An entry that came from the person themselves, such as an unsubscribe or a STOP reply, or from a hard bounce stays when Do not contact is switched off there. A workspace admin can remove it from the list in settings, after a warning that messages will reach that person again.
Will DigiPix Flow take care of privacy law for us?
No software can do that for you. DigiPix Flow keeps the records that help: where each consent came from and under which notice, every opt-out, and privacy requests with their approvals and due dates. How you use them, and what your notices say, is still your team's responsibility.
Something we haven't covered? Talk to an expert
Keep exploring
Visit the blog- FEATURESSales email from your own domainVerified domains, replies on the thread and a one-click unsubscribe on outreach.Explore the feature
- FEATURESWhatsApp CRM and SMSTwo-way messaging with templates, DLT checks and STOP handled on both channels.Explore the feature
- FEATURESShared team inboxEvery conversation in one list, with consent shown beside each thread.Explore the feature
- FEATURESContact managementEach person's consent, Do not contact switch and privacy requests on one page.Explore the feature
- FEATURESCSV import and exportBring in existing lists with their consent columns and opt-outs intact.Explore the feature
- FEATURESCustomer segmentsSee how many members of a segment have consent before you message them.Explore features
GUIDEDPDP Act for Marketing: A Practical Checklist for Indian Sales and Marketing TeamsWhat the DPDP Act for marketing and sales teams means in plain language: the key terms, notice and consent, withdrawal, security, breaches, children's data and people's rights, with a checklist for handling leads. General information from the official texts, not legal advice.Read the guide
GUIDEMarketing Consent Examples: Wording That Works on Forms, WhatsApp, SMS, Calls and ImportsThese marketing consent examples show good and bad wording for website forms, WhatsApp, SMS, phone calls, events and ad lead forms, and what to record each time. Because a tick box is where consent starts, not where it ends.Read the guide
Know who agreed to hear from you, and who said no
Talk to an expert — bring your forms, your old opt-out lists and the channels you message on, and see consent followed from capture to a privacy request.
- A real person, not a bot
- Bring your forms and opt-out lists
- See a no respected end to end


