ConvoHut
Compliance

Most WhatsApp marketing problems are not marketing problems. They are consent problems.

ConvoHut is being built compliance-first: consent gating, opt-out processing, quiet hours and a pre-send check that will not let a non-compliant campaign leave the building. This section explains the rules in each market we are building for, whether or not you ever use our product.

Is WhatsApp marketing legal?

Yes, where you have valid consent from the recipient and identify your business clearly. The rules come from each country's electronic marketing and privacy law rather than from WhatsApp itself — the Spam Act in Australia, the TCPA in the United States, PECR and UK GDPR in Britain. Meta's policies sit on top of those.

Key takeaways

  • Consent is the whole game. Everything else is detail.
  • The rules come from national law, not from Meta.
  • Penalties are per message or per breach, so they scale with your list.
  • You must be able to prove consent, not just claim it.

Why we are building this in before the features

Most platforms in this category treat compliance as a checkbox in settings and a paragraph in the terms of service. The result is predictable: the software will happily send a marketing message to a purchased list, in a country with a strict consent regime, at 11pm, and the merchant finds out it was a problem when a regulator or a law firm tells them.

We think that is the wrong way round. The expensive failure in WhatsApp marketing is not a badly written message. It is a message that should never have been sent at all — and the platform is the only thing standing between a well-meaning merchant and a penalty they cannot afford.

So the consent model, the opt-out handling and the pre-send checks are being built as part of the core, not bolted on for a later enterprise tier. If a campaign fails a check, the send button will not work. That is deliberate, and occasionally it will be annoying.

Our position

We would rather block your send than defend your fine.

This will sometimes make ConvoHut slower to use than a tool that lets you do whatever you want. That is the trade, and we are making it on purpose.

The six markets, side by side

Australia is where we launch. The rest follow in this order. Penalties below are the published maximums under each regime — they are not typical outcomes, but they set the scale of the risk you are managing.

MarketLawEnforcerRiskOpt-out SLAMaximum penalty
🇦🇺 AustraliaSpam Act 2003, Privacy Act 1988ACMAHIGH RISK5 business daysUp to A$2.2 million per breach, per day
🇮🇳 IndiaDPDPA 2023, TRAI RegulationsData Protection Board / TRAIMEDIUM RISK7 daysUp to ₹250 crore
🇿🇦 South AfricaPOPIA, Consumer Protection ActInformation RegulatorMEDIUM RISKImmediateUp to R10 million, or imprisonment
🇬🇧 United KingdomUK GDPR, PECR 2003ICOHIGH RISKImmediateUp to £17.5 million or 4% of global turnover
🇺🇸 United StatesTCPA, CAN-SPAM, CCPA/CPRAFCC / FTCVERY HIGH RISK10 business daysUS$500–1,500 per unsolicited message, and class actions are common
🇪🇺 Europe (EU/EEA)EU GDPR, ePrivacy DirectiveNational Data Protection AuthoritiesVERY HIGH RISKImmediateUp to €20 million or 4% of global turnover

The controls we are building

ConvoHut is pre-launch. Everything below is in active development for the first release unless marked otherwise, and we will update this page as each ships rather than quietly leaving it aspirational.

Consent gating on import

Planned for launch

A CSV upload with contacts that have no documented consent is blocked, not warned about. Purchased lists trigger an explicit warning.

Automatic opt-out processing

Planned for launch

STOP, UNSUBSCRIBE, OPT OUT, CANCEL, QUIT and END are recognised on inbound messages and suppress the contact immediately — faster than any market requires.

Pre-send compliance check

Planned for launch

Six checks run before a campaign can be sent: documented consent, sender identification, unsubscribe present, template approved, quiet hours respected, market active. If one fails, the send button stays disabled.

Per-market quiet hours

Planned for launch

Configurable per country in the local timezone, defaulting to 9pm–9am. Messages that would land inside quiet hours are queued rather than sent.

Consent audit trail

Planned for launch

Every contact carries when consent was given, how, and from which source — so you can answer a regulator rather than guess.

Per-market data residency

Planned

Storage regions aligned to each market rather than one global bucket.

Unsubscribe footer enforcement

Planned for launch

Templates without an unsubscribe instruction fail the compliance check before they reach Meta for approval.

DSAR handling

Roadmap

Data subject access and erasure request workflows.

This is guidance, not legal advice. We are a software company, not a law firm. The summaries in this section are written to help you ask your own adviser the right questions. Compliance with the law in your market remains your responsibility as the sender.

Compliance by market

Each market has its own law, its own regulator, its own consent standard and its own penalty. Read the one you sell into.

Questions this raises

Is WhatsApp marketing legal in Australia?

Yes, with express consent and a working unsubscribe in every message. The Spam Act 2003 governs commercial electronic messages and ACMA enforces it, with penalties reaching A$2.2 million per breach per day.

Does ConvoHut make me compliant automatically?

No, and any platform claiming that is overselling. We build the guardrails — consent gating, opt-out processing, quiet hours, pre-send checks — but the consent you collect and the messages you write remain yours.

What counts as consent for WhatsApp?

It varies by market. Australia requires express consent for commercial messages; the UK and EU require explicit, unbundled GDPR-standard consent; the US requires prior express written consent for marketing. A ticked, unbundled box with clear wording, recorded with a timestamp and source, is the safe standard everywhere.

Can I upload a purchased contact list?

You should not, and ConvoHut is being built to stop you. Purchased lists have no documented consent, which makes every message to them a potential breach in every market we support.

What happens when someone replies STOP?

The contact is suppressed immediately, faster than any of our markets require. Australia allows five business days, the US ten, India seven. We do not use that grace period.

Do I need consent for order confirmations?

Transactional and utility messages generally sit under a different basis from marketing, but the boundary matters and it moves by jurisdiction. Do not let a utility template carry a promotion — that is the most common way a compliant message becomes a non-compliant one.

Compliance-first, from the first line of code.

We are building in the open and working with a small group of Australian Shopify merchants first. Join the waitlist and we will show you the compliance engine before we show you anything else.

Join the waitlist