How it worksPricingLog InSign Up Free

What is WhatsApp opt-in? Permission must be traceable

Definition

A WhatsApp opt-in is the permission basis that allows a business to contact a person through WhatsApp. The contact must comply with WhatsApp Business Platform policy and applicable law.

WhatsApp opt-in

WhatsApp opt-in

The current 2026 nuance is easy to state badly. Meta’s April 2026 marketing-message guidance says WhatsApp-specific opt-in consent is no longer required. That does not mean “businesses no longer need permission.” WhatsApp’s Business Messaging Policy still says a business may contact people when they have provided their mobile number. The business must also have received opt-in permission confirming they wish to receive subsequent messages or calls from that business.

The useful interpretation is simple: permission remains required. Consent does not need a ritual branded as a separate “WhatsApp-only opt-in.” The broader permission context must clearly authorize the business’s messaging. Applicable law must also be satisfied.

Permission, not channel ceremony

Imagine 2 signup flows.

Flow A: explicit WhatsApp wording

> Get order updates and offers from Acme on WhatsApp. [Join] This is easy to understand and easy to evidence.

Flow B: broader messaging permission

A customer provides their mobile number and affirmatively agrees to receive a clearly described class of business messages from Acme, with WhatsApp among the messaging experiences the business uses.

Meta’s 2026 guidance allows more flexibility than an older rule of thumb that demanded a WhatsApp-specific consent artifact. But the business still needs a permission basis it can explain. A phone number collected only for delivery is not magically opt-in because the channel-specific wording requirement changed. The same applies to an address book upload or a customer record created from an unrelated purchase.

How businesses can collect permission

Meta’s current guidance describes many possible collection surfaces, including:

  • a website form
  • SMS or another owned channel
  • a customer-service call or IVR
  • QR code or in-person interaction
  • a transaction flow
  • Messenger or another conversational entry point
  • an ad that clicks to WhatsApp
  • an existing WhatsApp conversation

The collection surface is less important than whether the person understands the business and the communications they are agreeing to receive.

Store evidence that can answer a complaint

When a user asks “Why did you message me?”, the system should not need to guess. Useful evidence includes:

  • mobile number
  • brand/business identity
  • permission purpose or categories
  • the disclosure or prompt shown
  • affirmative action
  • collection source
  • timestamp
  • campaign/form/transaction identifier
  • versioned privacy/terms links when relevant
  • later opt-out/block events

If permission was collected outside WhatsApp, keep the external source. If collected in a WhatsApp thread, keep the conversation/event ID needed to reconstruct it.

Opt-out belongs in the same lifecycle

WhatsApp’s Business Messaging Policy requires businesses to respect requests to block, discontinue or opt out of communications. A durable permission record therefore includes negative events as well as positive ones. When a user says “stop sending offers,” your system should:

  1. identify the relevant business and purpose
  2. update the current permission/suppression state
  3. prevent queued promotional templates from sending
  4. preserve the event
  5. keep narrower requested/essential messaging separate only when policy and law support that distinction

Do not keep re-adding the person because another data source still says “customer.”

Permission should survive provider changes

Many businesses access WhatsApp through a Business Solution Provider rather than building directly on Meta’s APIs. Do not let the BSP become the only place where permission evidence exists.

The merchant or platform should keep its own auditable permission ledger and map provider-specific user/account IDs to it. If the business changes BSPs, the consent history and opt-out history must not disappear.

“The user messaged us first” is context, not perpetual marketing consent

A user-initiated message is strong evidence that the person wanted that interaction. It opens the customer service window and supports a conversational response. It still has a scope. Examples:

  • “Where is my package?” supports order-related service
  • “Send me weekly deals” can be an affirmative marketing request if captured clearly
  • Clicking a support ad and asking one product question does not by itself mean “send recurring sale broadcasts forever.”

Store the actual event and purpose rather than converting every inbound conversation to a global opted_in flag.

Permission state and template eligibility should meet only at dispatch

An approved marketing template can exist before a recipient opts in. A recipient can be opted in while a template is paused. These are independent timelines. At dispatch, check:

Figure 1

One WhatsApp opt-in does not authorize every kind of message

Permission remains required.

Marketing
PurposeOffers, e.g. 20% off abandoned cart
Permission questionExplicit marketing permission
24h windowSeparately permissioned regardless
Utility
PurposeAccount update, e.g. shipping
Permission questionTied to the triggering transaction
24h windowOften, but not only, inside it
Authentication
PurposeOne-time passcode, e.g. login OTP
Permission questionIdentity check, not marketing consent
24h windowIndependent of the window
Service
PurposeUser inquiry, e.g. "Where is my order?"
Permission questionContext, not ongoing consent
24h windowStrongly tied to the window
"WhatsApp-specific opt-in wording no longer required" describes a collection-method change, not a permission deletion.
Marketing, utility, authentication and service messages each answer a different permission question. A service reply is context, not a standing invitation to send offers.

This structure makes skip reasons explicit and avoids “template approved” being treated as consent.

Prefer purpose-specific preference controls

If a merchant sends both order updates and promotions, a preference center can let the customer keep useful operational updates while stopping offers where policy/law permit that separation.

That is better than an opaque single toggle when the business genuinely offers several communication purposes. But the product must still honor broad requests as broad when that is what the user clearly communicates.

Separate channel permission from purpose permission

A single “WhatsApp yes/no” field is often too coarse for a business that sends both requested service updates and recurring marketing. The useful canonical model is closer to a permission vector:

The exact legal basis still depends on jurisdiction and use case, but the data model should not erase the distinction before policy is even evaluated.
OptionPurposeExampleState
Order/service updatesOrder/service updatesShipping and delivery status the customer requestedpermitted / not permitted / unknown
MarketingMarketingSales, launches, replenishment promotionspermitted / not permitted / unknown
AuthenticationAuthenticationOne-time authentication messagesgoverned separately by the use case and current platform rules

“WhatsApp-specific opt-in no longer required” is a collection-method change, not a permission deletion

Meta’s 2026 marketing guidance is useful precisely because it removes a misleading implementation assumption: permission does not have to be captured through a WhatsApp-only ceremony merely to count as WhatsApp permission. A merchant may have appropriate consent collected through another compliant touchpoint.

That does not mean an email subscriber, customer record or phone number can automatically be promoted to WhatsApp marketing eligibility. The platform still needs evidence that the person authorized the relevant business messaging purpose. Keep the origin channel and evidence in the record so imported permission can be distinguished from assumed permission.

What does this page teach beyond a generic glossary definition?

It teaches the 2026 rule correctly: WhatsApp-specific opt-in collection is no longer a mandatory ceremony, but permission is still required. The system should model permission by business, purpose and evidence, and keep that state separate from the 24-hour customer service window and template mechanics.

Worked example

A shopper buys a sofa and opts to receive WhatsApp delivery updates. That permission should be recorded as an order/utility purpose.

  • After delivery, the merchant wants to send a “20% off matching cushions” promotion. The fact that the shopper previously received utility updates does not by itself establish permission for promotional messaging. The platform should look for the marketing permission state relevant to that use

If the merchant had collected a broader, clear permission covering promotional WhatsApp messages, the marketing gate can use that record. If not, the route and template may be technically available while the recipient remains ineligible for that promotion.

What WhatsApp opt-in requires

WhatsApp currently distinguishes marketing, utility, authentication and service messages. A customer who asks “Where is my order?” has created a service context. That is not the same thing as agreeing to receive future promotional broadcasts. Likewise, a person who supplies a number for an authentication code is not necessarily agreeing to abandoned-cart offers.

For marketing, Meta’s own guidance emphasizes transparency about the kinds of updates people will receive. An ecommerce system should therefore preserve the purpose of permission rather than storing only whatsapp_opted_in = true. A useful permission matrix can distinguish:

  • marketing offers and recommendations
  • utility/order/account updates
  • authentication messages
  • customer-initiated service replies

Applicable law and Meta policy determine which permission basis is sufficient for each case. The data model’s job is to preserve enough structure to make that decision honestly.

What passes and what does not

  • When a user messages a business, WhatsApp opens a 24-hour customer service window in which the business can respond without an approved message template. That window changes message-format/initiating rules. It is not a blanket conversion of a support conversation into permission for unrelated future marketing
  • If a shopper asks about sizing at 2 p.m., the business can continue the service conversation under the platform’s window rules. That does not mean the business can add the shopper to an indefinite promotional audience without the required permission
  • This distinction is important because “inside the window” and “opted in” answer different questions
Try OnVoard free

Every app on every plan. Connect your store and switch on the flows in an evening.

Sign Up Free
Share
Commonly confused with

Sources

All retrieved September 14, 2026
WhatsApp / MetaWhatsApp Business Platform Featureswhatsappbusiness.com/products/business-platform-features/
WhatsApp / MetaWhatsApp Marketing Messageswhatsappbusiness.com/products/conversation-categories/marketing/
WhatsApp / MetaBest Practices for Marketing Messages on WhatsAppwhatsappbusiness.com/wp-content/uploads/2026/04/Best-Practices-for-Marketing-Messages-on-WhatsApp-.pdf
WhatsApp / MetaWhatsApp Business Messaging Policywhatsappbusiness.com/policy/
WhatsApp / MetaWhatsApp Utility Messageswhatsappbusiness.com/products/conversation-categories/utility/