Notification Consent & Compliance

Modified on Sun, 19 Jul at 3:20 PM

Notification Consent & Compliance

Civify takes notification consent seriously because two federal regulations govern how you're allowed to contact residents: the Telephone Consumer Protection Act (TCPA), which covers calls and text messages, and the CAN-SPAM Act, which covers commercial email. Both require consent before contacting someone, and both require an easy way for that person to opt out.

This page is a general overview to help you understand why Civify's notification tools work the way they do. It isn't legal advice, and it doesn't cover every state or local rule that may also apply. Talk to your organization's legal counsel about how these regulations apply to your specific communications.

What the TCPA requires

The TCPA governs calls and text messages sent using automated systems — autodialers, prerecorded voice, or SMS platforms. In broad terms, it requires:

  • Consent before contacting someone. The consent standard depends on the type of message; purely informational messages generally have more flexibility than marketing messages, but obtaining clear consent up front is the safest approach in either case.
  • An easy way to opt out, such as replying STOP to a text or pressing a key during an automated call — and that opt-out has to be honored, not just offered.
  • Restricted calling hours. Telemarketing calls and texts are generally limited to between 8 a.m. and 9 p.m. in the recipient's local time zone.

Violations can carry statutory penalties per message, and TCPA litigation — especially around consent and calling hours — has increased in recent years. Some states layer additional restrictions on top of the federal rules.

What CAN-SPAM requires

CAN-SPAM governs commercial email. Per the FTC, senders must:

  • Use accurate "From" and "To" information — no misleading sender names or domains
  • Avoid deceptive subject lines
  • Include a valid physical postal address
  • Provide a clear, easy way to opt out of future emails
  • Honor opt-out requests promptly — the law allows senders up to 10 business days, though most platforms process these automatically and immediately

Each violating email can carry its own FTC penalty, and the obligation applies regardless of whether the recipient previously consented to receive email.

How Civify's built-in mechanics map to these requirements

Civify has opt-in and opt-out mechanics built into every notification channel, so your organization doesn't have to build this compliance layer yourself:

  • SMS: Residents can text STOP at any time to unsubscribe, and START to opt back in. Their profile updates automatically either way — satisfying the TCPA's opt-out requirement.
  • Voice: Residents can press 1 during an automated call to unsubscribe from future calls.
  • Email: Every email includes an unsubscribe link, along with sender and address information — covering CAN-SPAM's opt-out and disclosure requirements.
  • Disclosure language: The subscription screen includes the required consent disclosure, which must be read to the resident whenever their preferences are being set on their behalf.
  • Quiet hours: Your organization can set a quiet-hours window (under Organization → Admin Panel Settings) that restricts notifications from being sent during quiet-hours. This is off by default; the suggested window is 9:00 PM to 8:00 AM in your organization's local time, which lines up with the TCPA's calling-hour guidance. Staff also see a separate, informal reminder when composing or scheduling a send outside of roughly 9:00 AM–7:59 PM — that reminder is advisory only and doesn't block sending, so it's not a substitute for turning on the quiet-hours setting if that's the protection you want.
  • SMS content safeguards: Outgoing SMS text is also checked against platform-wide compliance rules before it's sent, which can warn on or block wording that's disallowed or risky. These rules are managed by Civify rather than by your organization, as an added layer of protection on top of your own review process.

What's your organization's responsibility

Civify's built-in mechanics keep the system compliant, but consent itself has to come from the resident. Before manually adding someone to Civify — through bulk import, a sign-in sheet at a public meeting, or by hand — or changing their notification preferences on their behalf, you need their consent first. The disclosure language on the subscription screen exists for exactly this reason: read it to the resident before setting their preferences for them.

Civify can't verify that real-world consent happened before a resident is entered into the system — that responsibility sits with your organization. Similarly, since quiet hours are off by default, your organization needs to turn that setting on under Admin Panel Settings if you want queued notifications held during local nighttime hours.

Learn more

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article