[Blog](<https://nightlysoftware.com/en/blog>)WhatsApp permissions 

# WhatsApp for customers: contact permission, templates and opt-outs

A phone number or approved template does not establish permission to send. Opt-outs must reach the message queue too.

**[Jonathan Perez](<https://nightlysoftware.com/en/company#jonathan-perez>)**Co-founder · Design, product and sales October 8, 2026 · 7 min read 

**Short answer**

Before sending through WhatsApp, check applicable permission, message type and current provider rules. Retain authorization evidence and an opt-out route that updates contacts and pending tasks. An approved template does not replace contact permission, and a retry must not ignore a recent opt-out.

## Test worksheet: WhatsApp: contact permission, templates and opt-outs

A phone number or approved template does not establish permission to send. Opt-outs must reach the message queue too. Record inputs, expected outcome, evidence, owner and observed result.

[Download CSV worksheet](<https://nightlysoftware.com/plantillas/whatsapp-consentimiento-baja-en.csv>)

In this guide

-   [Separate number, authorization and message type](<https://nightlysoftware.com/en/blog/whatsapp-opt-in-opt-out#permission>)
-   [Fictional example: three contacts in a queue](<https://nightlysoftware.com/en/blog/whatsapp-opt-in-opt-out#example>)
-   [Check template and permission separately](<https://nightlysoftware.com/en/blog/whatsapp-opt-in-opt-out#template>)
-   [Propagate opt-outs to every sending location](<https://nightlysoftware.com/en/blog/whatsapp-opt-in-opt-out#dependencies>)
-   [Rehearse without contacting real customers](<https://nightlysoftware.com/en/blog/whatsapp-opt-in-opt-out#prepare>)

## Separate number, authorization and message type

A distributor may have the number of someone who received goods, but that does not show they requested promotions. Separate operational contact details from communication preferences. Record what the person was told, when and where authorization was given, and which message types it covered. Do not mark an entire imported address book as authorized.

The [WhatsApp policy](<https://business.whatsapp.com/policy>) requires a provided number or username plus permission for subsequent communications, and respect for opt-out requests made on or off WhatsApp. [Infobip](<https://www.infobip.com/docs/whatsapp/compliance/user-opt-ins>) documents permission and preference management. Platform rules do not replace review of obligations applicable to your business.

## Fictional example: three contacts in a queue

A rehearsal list contains C-WA11, with documented permission for delivery notices; C-WA12, authorized for commercial updates; and C-WA13, who left only a phone number. A promotional notice is proposed. C-WA11 is not included solely on operational permission, while C-WA13 receives nothing until permission is resolved. These synthetic records are not real contacts or measured response rates.

C-WA12 opts out by email while the message remains queued. The team updates the preference and the sender checks it again before dispatch. If the message has already reached the provider, the team does not claim it can be withdrawn: it records observed state and blocks subsequent sends. Rehearsal distinguishes local cancellation from delivery already in progress.

| Data |Purpose |Care |
| --- | --- | --- |
| Contact and scope |Decide which message may be considered |Do not infer permission from a number |
| Authorization text or reference |Reconstruct what the person agreed to |Keep version and channel |
| Opt-out and received time |Update preferences and pending tasks |Accept the agreed route and assign an owner |
| Message state |Separate queued, sent and unknown outcome |Never claim external cancellation without evidence |

## Check template and permission separately

For WhatsApp Business Platform (API), the [Meta policy](<https://business.whatsapp.com/policy>) requires approved templates outside the 24-hour service window. Check current rules and message category with your provider. Template approval does not establish that each recipient authorized it or that your list is current. It also does not guarantee delivery or a reply.

| Case |Expected result |Evidence |
| --- | --- | --- |
| C-WA13 has only a number |No promotion without applicable authorization |Preference and reason |
| C-WA11 authorized delivery notices |Do not assume promotional permission |Authorization scope |
| C-WA12 opts out while queued |Pending message canceled or held under the rule |Time and queue state |
| Opt-out received outside WhatsApp |Preference updated and later sends blocked |Request and record |
| Retry after opt-out |Fresh check prevents continuing the send |Attempt and current preference |
| Send response is lost |Unknown state queried before repeating |Provider reference |

## Propagate opt-outs to every sending location

Identify CRM, address books, campaign tools and automated jobs using the same number. Define the authoritative preference source and how changes propagate. If an exported file still sends from an old list, recording an opt-out in the CRM is insufficient. Agree how to detect that dependency and stop the batch.

Interpreting free-text opt-outs, synchronization timing and available features depend on the provider. Do not assume one button updates every tool. Retain what is needed to apply preferences and resolve questions under agreed access and retention rules. Avoid requesting personal documents for an ordinary opt-out without a justified need.

## Rehearse without contacting real customers

Use an authorized test environment or numbers, rather than a real campaign to test the process. Review [WhatsApp automation](<https://nightlysoftware.com/en/blog/whatsapp-automation>) for platform choice and [webhooks and retries](<https://nightlysoftware.com/en/blog/webhook-retry-acceptance>) for delivery states. Preference changes also need a [useful audit log](<https://nightlysoftware.com/en/blog/business-change-audit-log>).

The worksheet proposes ten cases without real contact details. Bring current authorization text, opt-out path and a diagram of your tools to a [free consultation](<https://nightlysoftware.com/en/book>) on [WhatsApp for business](<https://nightlysoftware.com/en/solutions/whatsapp-for-business>). We can review workflow and dependencies before considering sends or automation.

## Review a contact's permission and opt-out

Using the permission text and an anonymized opt-out, review which tools can still send to that contact. A free consultation helps identify who records the request and how to verify that sending queues apply the decision.

-   Current anonymized authorization text and evidence
-   Opt-out routes and their response owner
-   Tools and queues that can message the same contact

[Book a free consultation](<https://nightlysoftware.com/en/book>)[Ask on WhatsApp](<https://wa.me/524622212236?text=I%20want%20to%20review%20WhatsApp%20permission%20and%20opt-outs.%20I%20have%20the%20authorization%20text%2C%20opt-out%20routes%20and%20the%20tools%20and%20queues%20that%20can%20send%20to%20the%20same%20contact.>)

Related

-   [Process automation](<https://nightlysoftware.com/en/solutions/business-process-automation>)
-   [Custom ERP and CRM](<https://nightlysoftware.com/en/solutions/custom-erp>)

## Frequently asked questions

### Does a WhatsApp inquiry authorize promotions? 

Do not automatically convert it into general permission. Review what was requested, available authorization and current policy. Responding to an inquiry and sending later communications are different decisions that the workflow must verify.

### Does an approved template work for everyone? 

No. Template approval and recipient permission are separate checks. Current preferences, category, window and provider conditions also matter. The rehearsal should block an unauthorized contact even when the template is approved.

### Can I remove a sent message after opt-out? 

Do not promise that. Distinguish local queued work from messages already passed to the provider. Block later sends and retain observed state. Cancellation options depend on platform and timing.

### What if someone authorizes messages again? 

Record new authorization with date, scope and reference without erasing the earlier opt-out. Check which message types it covers. A changed preference should not automatically reactivate old queued tasks.

## Sources

1.  [WhatsApp Business Messaging Policy](<https://business.whatsapp.com/policy>)Meta / WhatsApp 
2.  [Collect and manage user opt-ins](<https://www.infobip.com/docs/whatsapp/compliance/user-opt-ins>)Infobip 

Last updated: October 8, 2026

## Keep reading

[AutomationOct 2, 2026

### WhatsApp automation for business: costs and how to start](<https://nightlysoftware.com/en/blog/whatsapp-automation>)[AutomationOct 2, 2026

### WhatsApp as your front door: connect chats to your operations](<https://nightlysoftware.com/en/blog/whatsapp-front-door>)[Integration eventsOct 8, 2026

### Failing webhooks: retrying without duplicate work or lost events](<https://nightlysoftware.com/en/blog/webhook-retry-acceptance>)

---

Canonical: https://nightlysoftware.com/en/blog/whatsapp-opt-in-opt-out

Updated: 2026-10-08

Description: Retain contact permission, apply opt-outs to queued messages and check retries. Includes acceptance tests for a verifiable WhatsApp workflow.

