WhatsApp opt-in: how to collect it and what to keep

Opt-in is the part of a WhatsApp project that nobody budgets for and everybody eventually pays for. The integration is code. Template approval is paperwork. Opt-in is the thing that decides whether your account is still healthy in six months.

Why it decides more than it looks

WhatsApp gives recipients two buttons that matter: block, and report. Both feed your quality rating, and your quality rating governs how many people you are allowed to message.

This is the mechanism people miss. A template can pass review and still damage you, because review judges the wording while the rating judges the reaction. Message a list that never asked to hear from you and the template was never the problem.

Recovering a damaged rating is slow, and the restriction lands on the channel you have already told customers to use.

What counts as opt-in

Meta’s expectation is straightforward once you strip the policy language out of it. The person has to have agreed, knowingly, to receive messages from you, on WhatsApp. Three parts, all of them required:

  • WhatsApp is named. Consent to “receive updates” is not consent to WhatsApp. The channel has to be visible in what they agreed to.
  • You are named. The business sending the messages has to be identifiable, in the name the customer will see on the message.
  • It was a deliberate act. They ticked something, typed something, or sent you a message. Not a pre-ticked box, and not a line buried in terms they scrolled past.

Note that having someone’s phone number is not opt-in, and neither is an existing business relationship. A customer list, however legitimately acquired, is not a WhatsApp audience.

Where to collect it

Several of these are easier than a consent form, and better.

WhereHow it works
They message you firstThe cleanest opt-in there is. A click-to-chat link, a WhatsApp button on your site, or a click-to-WhatsApp ad – the inbound message is the consent, and it opens the 24-hour window too.
Checkout or booking formAn unticked checkbox next to the phone field: “Send me order updates on WhatsApp.” Specific, and it arrives exactly when the number does.
An existing channelAsk by email or SMS, with a link that starts a WhatsApp chat. Their reply is the opt-in.
In personA QR code that opens a chat with you. Common in retail and hospitality, and it records itself.
Inside your productA notification preference alongside email and push, where the customer is already signed in and identified.

If you can design the flow so the customer messages you first, do that. It satisfies opt-in, needs no record-keeping argument, and starts a conversation you can reply to freely.

What to store

Treat this as something you may have to produce later, for Meta or for a client. Store it per person, per purpose:

  • The phone number in full international format, as the one you will message
  • Timestamp with timezone
  • Where it came from – which form, which page, which campaign, which conversation
  • The exact wording they agreed to, or a version reference pointing at it. This is the field people leave out and the one that actually answers the question.
  • What they opted into – order updates, appointment reminders, marketing. Separately.
  • Any later withdrawal, with its own timestamp, and never by deleting the original record

Keep this in your own system, not only in Chatwoot. Chatwoot holds the conversation; the consent record belongs with your customer data, where it survives changing helpdesk.

Opt-in is per purpose

Agreeing to delivery notifications is not agreeing to promotions. This distinction is the one most likely to generate complaints, because the customer experiences it as a bait and switch – they said yes to something useful and started receiving offers.

Collect the two separately and store them as separate flags. It also maps onto how Meta categorises templates, so you will want the distinction in your data anyway.

Opt-out, and taking it seriously

Make stopping easy, because the alternative is that they block you instead – and blocking is the outcome that costs you.

In practice: put a stop option in marketing templates, honour plain-language replies like STOP or UNSUBSCRIBE automatically rather than waiting for an agent to notice, and apply it immediately. Honour it per purpose where you can, so someone who is tired of offers still gets their delivery notification.

If a customer asks an agent to stop messaging them, that has to reach your consent record too. A request handled only inside the conversation is a request that will be ignored by your next campaign.

The ways this goes wrong

  • Importing the old phone list. The single most common cause of a ruined new account. Those people consented to a different channel, or to nothing.
  • Pre-ticked boxes, or consent bundled into terms. Fails the deliberate-act test, and fails it in a way that is obvious from a screenshot of your own form.
  • Purchased lists. There is no version of this that ends well.
  • A long silence, then a campaign. Consent collected a year ago and never used reads as unsolicited when it finally arrives.
  • Opt-in you cannot evidence. If the answer to “where did this consent come from” is a shrug, you do not have consent – you have a phone number.

Before you send the first message

Three questions. Can you show, for any number on your list, where the consent came from and what it said? Is marketing consent stored separately from transactional? Does an opt-out take effect without a human remembering to act on it?

Three yeses and the channel will stay healthy. Any no, and fix it now – it is far cheaper than recovering a quality rating.

Meta’s messaging policies change regularly, and data protection law varies by country. This is practical guidance, not legal advice – check Meta’s current policy and your own jurisdiction’s rules before launching.

Scroll to Top