Imagine someone asks a simple question about a customer on your list: how did this person agree to receive your texts?
For most businesses, answering means checking a few places. A web form export. A spreadsheet someone kept. A paper sign-up sheet in a drawer. And for older contacts, often nothing at all.
A consent record fixes that. It's a small piece of information saved at the moment someone joins your list, and it turns that question into a two-second answer. This guide covers what belongs in one, how long to keep it, and how to capture it without adding work.
What a consent record is
A consent record is proof that someone agreed to receive your messages.
It isn't a contract or a signed form. It's a short note attached to the contact: when they agreed, how they agreed, and what they were told at the time.
The point is simple. Permission is the foundation of business texting. Without a record, permission is something you remember rather than something you can show.
What belongs in a good record
Five pieces cover almost every situation.
- Who. The phone number, and a name if you have one.
- When. The date and time they agreed. A timestamp, not a rough month.
- How. The method — texted a keyword, filled in a web form, checked a box at checkout, signed a paper form.
- What they saw. The wording they agreed to. If your form said "get appointment reminders and occasional offers," that's the promise you made.
- Where it happened. The specific form, keyword, or location, so you can tell one sign-up route from another.
That fifth one gets skipped most often, and it's the one that helps later. If a particular sign-up form was worded badly, knowing which contacts came through it lets you fix a defined group instead of guessing across your whole list.
Pro Tip
Save the exact wording your sign-up used, not a summary of it. "Agreed to marketing" tells you almost nothing a year later. The actual sentence they read tells you exactly what you promised.
How long to keep it
Keep the record for as long as the contact is on your list, and for a reasonable period after they leave.
The reason is practical. Questions about consent rarely arrive while someone is an active customer. They arrive after a complaint, which usually comes after someone has already opted out. If you delete the record the moment they unsubscribe, you delete it right before it becomes useful.
Keeping the opt-out record matters just as much — the date they left, and how. Together the two records tell the full story: they joined this way on this date, and they left this way on that date.
Important
Some states set specific retention periods, and a few are considerably longer than you'd expect. Treat "as long as they're active, plus a reasonable period after" as a floor rather than a target, and confirm what applies to your state and industry with your own lawyer.
This guide explains what consent records generally contain and how the product stores them. It isn't legal advice.
Why capture beats reconstruction
Here's where most businesses run into trouble.
Consent is easy to record at the moment it happens. Someone texts your keyword, and the date, method, and wording are all sitting right there. Capturing them costs nothing.
Reconstructing consent later is a different job. You're looking at a phone number added eight months ago and trying to work out where it came from. Was it the website form? The clipboard at the front desk? Did someone type it in after a phone call? Often the honest answer is that nobody knows.
That gap doesn't close with effort. It closes only by capturing properly from now on.
AutoCampaign.ai Recommendation
If your list has contacts you can't account for, don't try to backfill the records. Start capturing properly today, and treat the older contacts carefully — send only what they'd clearly expect, and act quickly on any opt-out. A clean process going forward is worth more than an invented history.
The scattered sign-up problem
Most businesses collect sign-ups in more than one place. A form on the website. A keyword on a window sign. A checkbox at checkout. Someone adding numbers by hand after a phone call.
Each route on its own is fine. The problem is that each one usually stores its record somewhere different — or doesn't store one at all. So the answer to "how did this person join?" depends on which route they came through, and nobody can see the whole picture in one place.
The fix isn't fewer sign-up routes. More routes means a bigger list, which is the point. The fix is having every route write to the same place, so the record looks identical whether someone scanned a QR code or filled in a form. That's what text-to-join and web forms do when the sign-up runs through one system — the contact and the record arrive together.
What to do with the record
A consent record is quiet by design. Most of the time it just sits there.
It earns its keep in three moments. When someone questions whether a contact opted in, you have an answer. When you're deciding whether an older contact should receive a promotional message, the record tells you what you promised them. And when you want to know which sign-up route is bringing in the best contacts, the "where" field tells you.
That last one is a genuine benefit rather than a defensive one. Knowing that your counter QR code brings in more engaged contacts than your website form is useful information, and it comes free with good records.
A quick check on your own setup
Pick a contact who joined your list about six months ago. Try to answer three questions about them: what date did they join, how did they join, and what were they told they'd receive?
If you can answer all three in under a minute, your record-keeping is in good shape. If you can't, the gap isn't unusual — but it's worth closing before your list gets bigger.


