A checkbox is not consent: what proof looks like for cannabis loyalty and SMS
3 min read
By BudAlly
Published Reviewed by Regulatory counsel (advisory)
Not legal advice. TCPA, CAN-SPAM and state privacy rules are linked; counsel reviewed the page on the date above. The point is operational: what the record must contain, and what you may do with a contact depending on what it contains.
The problem with "opted_in = true"
Most POS and loyalty exports carry a single boolean. It tells you nothing an enforcement letter would ask about: when the person agreed, where, to what wording, and can you show it. Under TCPA, the burden of proving prior express written consent for marketing texts is on the sender; statutory damages are per message. A migrated list of booleans is therefore not an asset. It is a list of people you can't text.
Winston-style "recovered, sendable contacts" counts are only useful if "sendable" means "consent proven" — otherwise it's a liability count.
What a consent record must contain
| Field | Why |
|---|---|
| Channel | Email consent isn't SMS consent |
| Timestamp | TCPA/CAN-SPAM disputes turn on "when" |
| Source | POS screen, web form, kiosk, import — and from which system |
| Text version | The exact words shown; versioned so a wording change doesn't orphan old consents |
| Evidence reference | The form submission ID, the POS event, the signed card |
| Revocations | With the same fields; a stop request is a record too |
BudAlly stores this as a consent ledger per contact per channel. "Opted in" is derived from the ledger, never typed in.
Triage a legacy list
Split every contact into one of three buckets and let the bucket decide the action:
| Bucket | Test | Allowed action |
|---|---|---|
| Marketing consent with proof | timestamp + source + text version present | Email campaigns, with a holdout; SMS only if the store's own 10DLC is live and the SMS consent is proven separately |
| Transactional only | e-receipt relationship, no marketing consent | Transactional email only; a loyalty invite line on the receipt is defensible when the message's primary purpose stays transactional — counsel's call on wording |
| No record / bare flag | boolean only, or nothing | Nothing by email or SMS; counter prompt or printed receipt line; re-ask |
A real example from a three-store migration: 2,140 legacy opt-ins → 1,780 with proof, 360 without. The 360 kept their history and points and received no marketing until they re-opted. The store lost 17% of its reach and gained a list it could defend.
Enrollment is its own consent
Joining a loyalty program is a separate agreement from marketing consent, and in California a program that offers a financial incentive for data needs a Notice of Financial Incentive at enrollment. Don't auto-enroll from the POS; don't grant retroactive points to people who didn't ask; don't bundle "join rewards" and "text me deals" into one checkbox.
SMS specifically
- Carriers treat cannabis as a restricted category: the store registers its own 10DLC brand and campaign; shared numbers are filtered.
- Prior express written consent, per message exposure, honor STOP instantly, keep the revocation record.
- Frequency and timing limits vary by state; some states restrict cannabis marketing content (no health claims, no minor appeal, no "free") regardless of channel — the same linter that checks your menu should check the campaign.
What this means for "loyalty gap recovery"
Cross-referencing POS buyers against members finds the people you could enroll. Consent proof decides which of them you may contact and how. In the demo tenant: 14,280 non-members, 5,640 with a valid email, 1,210 with marketing consent proof (invitable by email with a holdout), 3,980 transactional-only (receipt line), 450 with no record (counter prompt). The 1,210 is the number that matters; the 14,280 is the number a vendor will quote.
Checklist
- Consent ledger fields present for every contact and channel; booleans retired.
- Legacy imports bucketed; "no proof" imported as unknown.
- Enrollment consent separate from marketing consent; CA Notice of Financial Incentive at enrollment.
- Own 10DLC registered before any SMS; STOP handling tested.
- Campaign copy through the same claims linter as the menu.
- Every campaign shipped with a holdout and reported with a confidence interval.
BudAlly's loyalty module keeps the consent ledger, buckets recovered contacts, and will not send what it can't prove — loyalty and customer relationships.
Sources
- FCC — Telephone Consumer Protection Act rules (47 CFR §64.1200) · 2026
- FTC — CAN-SPAM Act compliance guide · 2026
- California — Notice of Financial Incentive (CCPA regulations §7016) · 2026
- Birdeye — Updated SMS guidelines for cannabis companies (10DLC) · 2026
- Dailystory — Cannabis compliance text messaging · 2026