Skip to content

A checkbox is not consent: what proof looks like for cannabis loyalty and SMS

3 min read

By BudAlly

Published Reviewed by Regulatory counsel (advisory)

Not legal advice. TCPA, CAN-SPAM and state privacy rules are linked; counsel reviewed the page on the date above. The point is operational: what the record must contain, and what you may do with a contact depending on what it contains.

The problem with "opted_in = true"

Most POS and loyalty exports carry a single boolean. It tells you nothing an enforcement letter would ask about: when the person agreed, where, to what wording, and can you show it. Under TCPA, the burden of proving prior express written consent for marketing texts is on the sender; statutory damages are per message. A migrated list of booleans is therefore not an asset. It is a list of people you can't text.

Winston-style "recovered, sendable contacts" counts are only useful if "sendable" means "consent proven" — otherwise it's a liability count.

What a consent record must contain

FieldWhy
ChannelEmail consent isn't SMS consent
TimestampTCPA/CAN-SPAM disputes turn on "when"
SourcePOS screen, web form, kiosk, import — and from which system
Text versionThe exact words shown; versioned so a wording change doesn't orphan old consents
Evidence referenceThe form submission ID, the POS event, the signed card
RevocationsWith the same fields; a stop request is a record too

BudAlly stores this as a consent ledger per contact per channel. "Opted in" is derived from the ledger, never typed in.

Triage a legacy list

Split every contact into one of three buckets and let the bucket decide the action:

BucketTestAllowed action
Marketing consent with prooftimestamp + source + text version presentEmail campaigns, with a holdout; SMS only if the store's own 10DLC is live and the SMS consent is proven separately
Transactional onlye-receipt relationship, no marketing consentTransactional email only; a loyalty invite line on the receipt is defensible when the message's primary purpose stays transactional — counsel's call on wording
No record / bare flagboolean only, or nothingNothing by email or SMS; counter prompt or printed receipt line; re-ask

A real example from a three-store migration: 2,140 legacy opt-ins → 1,780 with proof, 360 without. The 360 kept their history and points and received no marketing until they re-opted. The store lost 17% of its reach and gained a list it could defend.

Enrollment is its own consent

Joining a loyalty program is a separate agreement from marketing consent, and in California a program that offers a financial incentive for data needs a Notice of Financial Incentive at enrollment. Don't auto-enroll from the POS; don't grant retroactive points to people who didn't ask; don't bundle "join rewards" and "text me deals" into one checkbox.

SMS specifically

  • Carriers treat cannabis as a restricted category: the store registers its own 10DLC brand and campaign; shared numbers are filtered.
  • Prior express written consent, per message exposure, honor STOP instantly, keep the revocation record.
  • Frequency and timing limits vary by state; some states restrict cannabis marketing content (no health claims, no minor appeal, no "free") regardless of channel — the same linter that checks your menu should check the campaign.

What this means for "loyalty gap recovery"

Cross-referencing POS buyers against members finds the people you could enroll. Consent proof decides which of them you may contact and how. In the demo tenant: 14,280 non-members, 5,640 with a valid email, 1,210 with marketing consent proof (invitable by email with a holdout), 3,980 transactional-only (receipt line), 450 with no record (counter prompt). The 1,210 is the number that matters; the 14,280 is the number a vendor will quote.

Checklist

  • Consent ledger fields present for every contact and channel; booleans retired.
  • Legacy imports bucketed; "no proof" imported as unknown.
  • Enrollment consent separate from marketing consent; CA Notice of Financial Incentive at enrollment.
  • Own 10DLC registered before any SMS; STOP handling tested.
  • Campaign copy through the same claims linter as the menu.
  • Every campaign shipped with a holdout and reported with a confidence interval.

BudAlly's loyalty module keeps the consent ledger, buckets recovered contacts, and will not send what it can't prove — loyalty and customer relationships.

Questions

What does a valid marketing consent record contain?
At minimum: the channel (email, SMS), a timestamp, the source (POS screen, web form, import), the exact text the person agreed to (versioned), and evidence (the form submission, the POS log). A boolean with none of those is a flag, not consent.
Can a dispensary text customers from a shared number?
Carriers require cannabis senders to register their own 10DLC brand and campaign; shared short codes and unregistered numbers are filtered or blocked, and the sender bears TCPA exposure. BudAlly sends no SMS unless the store's own 10DLC is registered and SMS consent is proven.
What about the 2,000 opt-ins I imported from my old POS?
If they carry timestamp, source and text, treat them as consented. If they are bare flags, import them as 'unknown': keep the history and the loyalty status, send nothing, and re-ask at the next visit or on the receipt.

See the ledger on your own data.

Free variance audit · read-only · no call.

Start free audit
© 2026 BudAlly, Inc. · Team Winston and Treez are trademarks of their owners. Posts are not legal or tax advice.All postsCompare