Compliance
Consent, do-not-contact and calling hours
Updated October 1, 2026
In Drop Cowboy® you can see each contact's consent and keep a do-not-contact list for your team. Campaign sends are held to federal and state-specific calling hours. Getting consent from the people you contact is your responsibility, so ask your legal counsel which rules fit your business.
How consent works
Consent is recorded per channel, so a contact can have telephone consent without text consent.
- Open Contacts in the left menu and click a contact.
- Click the Consent tab. Telephone Consent, SMS Consent, Email Consent, E-Sign Consent and Web Tracking each show Granted or Opted Out, with a date.
- Under Consent History, click View Evidence to see the proof saved with a change.
When someone texts STOP
An opt-out reply clears the contact's SMS Consent and Telephone Consent. Their number is added to your do-not-contact list as SMS opt-out (STOP keyword). They get a text saying they are unsubscribed and can reply START to resubscribe.
These count as an opt-out, in any capitals and punctuation:
- A reply of only STOP, STOPALL, END, CANCEL, QUIT, REVOKE, UNSUBSCRIBE, OPTOUT or OPT-OUT.
- A reply of only STOP TEXTING, NOT INTERESTED, TAKE ME OFF YOUR LIST or REMOVE ME FROM YOUR LIST.
- A reply that starts with STOP, STOPALL, UNSUBSCRIBE or OPTOUT, like "STOP PLEASE".
- A tap on an opt-out button in an RCS message.
START, UNSTOP or SUBSCRIBE opts the contact back in. HELP or INFO gets your help message.
Opt-outs on other channels land on the same list, as Phone tree opt-out for a keypress or Email unsubscribe for email.
If it doesn't work:
- A contact said stop in their own words and still shows Granted. Only the replies above count. Add the number to your do-not-contact list yourself.
- A contact who opted out wants your texts again. Only they can undo their opt-out. Ask them to reply START.
How calling hours work
Campaigns follow federal and state-specific calling hours automatically, with nothing to set. A contact's local time is checked by their postal address and by their area code. Both must fall inside calling hours.
- Campaigns. Contacts outside calling hours are held, then sent once calling hours start in their time zone. Campaigns don't offer Send anyway.
- One-to-one texts. A text you send from the inbox outside calling hours opens Outside TCPA calling hours. Click Cancel and send it later, or click Send anyway.
- Calls you dial by hand. Calling hours don't apply on their own. These calls follow Manual Dial TCPA Hours in Dialer Settings, which is Off until someone changes it. See Set dialer rules.
- Before you reach out. A contact's Overview tab shows Local Time with Callable, or when they can next be reached.
If it doesn't work:
- A campaign is still sending hours after launch. Contacts in later time zones send when their calling hours start. Track progress on See campaign results.
- A contact is outside calling hours during their business day. Their address and area code may be in different time zones. Correct the address.
Add numbers to your do-not-contact list
Numbers and emails on your do-not-contact list are left out of your calls, texts and campaigns.
- Open Contacts in the left menu, then click the DNC tab.
- Click Add. In Add to DNC List, choose Phone Number or Email, and type it.
- With more than one brand, pick a Brand, or leave All brands to block the contact everywhere.
- Optional: type a Reason. Click Add.
To add a file, click the More actions menu (three dots), then Bulk Import. Drop a CSV, TSV or TAB file of up to 1 million rows. Map one column to Phone Number or Email, pick Choose a country and Brand, then click Submit.
On a contact, the Do Not Contact switch in the side panel does the same. To block their calls to you too, open the entry on DNC and use Block Inbound Calls.
If it doesn't work:
- "Phone number is not valid". Include the area code, then click Add again.
- "The fields are not mapped. Please select columns under the list." Map a column to Phone Number or Email, then click Submit.
- Remove from DNC is greyed out. The contact opted out themselves. Those entries can't be removed.
Set consent rules
Consent rules decide which contacts your automated sends reach. Choose them with your legal counsel. All four start off.
- Open Settings in the left menu, then click Consent Rules.
- Click the switch next to a rule. It saves right away.
| Rule | What it does when on |
|---|---|
| Require TCPA Consent (PEWC) | Automated campaigns, such as ringless voicemail, texts, voice broadcasts and predictive dialing, reach only contacts with recorded consent for that channel. Calls you dial by hand are not affected. Dialer Settings shows the same switch as Require PEWC for Automated Campaigns. |
| Require SMS Double Opt-In | Contacts confirm by text before they get campaign texts. See Use double opt-in for texts. |
| Require Email Consent | Marketing emails go only to contacts with Email Consent granted. |
| Universal Opt-Out (Revoke All) | An opt-out on any channel revokes consent on all channels. |
If it doesn't work:
- "Failed to update setting. Please try again." The switch goes back. Refresh the page and click it again.
- Fewer contacts got a campaign than expected. Contacts without consent recorded for that channel were left out. Check their Consent tab.
Set region rules
Region rules decide which countries and US states your calls and texts can reach.
- Open Settings in the left menu, then click Region Settings.
- Under Countries, click the switch for United States, Canada or All Other Countries.
- Under United States Regions, click the switch for each state. Select All and Deselect All change every state at once. Each change saves right away, and you see "Your region settings were saved".
If it doesn't work:
- "Must select at least one country". Leave at least one country switched on.
- The state switches are greyed out. Switch on United States first.
- "We were unable to update your settings. Try again later." Refresh the page and make the change again.
Use double opt-in for texts
Double opt-in asks each contact to confirm by text before their first campaign text. It confirms consent you already have. It doesn't collect it. Decide with your legal counsel whether to use it.
- Open Settings in the left menu, then click Consent Rules.
- Click the switch next to Require SMS Double Opt-In.
- Send your text campaign as usual.
For a contact who hasn't confirmed, the campaign text is held. They get a text with your company name asking them to reply YES, or STOP to opt out. Your text sends after they reply Y, OPTIN, OPT-IN, or anything starting with YES.
If it doesn't work:
- Some contacts never got your campaign text. They haven't replied YES yet. Check SMS Consent on their Consent tab.
- A contact replied "OK" or "Sure". Those don't confirm. Ask them to reply YES.
If you don't see DNC, Consent Rules or Region Settings, ask your account owner for access.
This information is for educational purposes only and does not constitute legal advice. Regulations vary by jurisdiction and use case. Always consult with qualified legal counsel to ensure your specific practices comply with applicable federal and state laws.