Skip to content
Vestrum

SMS & Calling Compliance Policy

Vestrum LLC · Effective September 14, 2026

This policy explains how customers must use Vestrum CRM's calling and messaging features. It is not legal advice and does not replace Customer's own legal review.

1. Customer-Controlled Communications

Customer chooses recipients, content, campaigns, calling methods, and messaging use. Vestrum does not supply lead lists and does not place outbound campaigns for Customer.

Customer must obtain the consent required for each communication method and recipient. Consent requirements vary by channel, purpose, technology, and jurisdiction — including, without limitation, the TCPA and state law within the United States, CASL (Canada), the ePrivacy Directive and member-state law (European Union), and the Spam Act 2003 (Australia) for recipients located in those jurisdictions. The Service is not currently offered to businesses in the United Kingdom, and Customer must not use the Service to contact individuals located there.

3. Do-Not-Call and Opt-Out

Customer must maintain applicable suppression lists, honor entity-specific opt-outs, and comply with federal and state Do-Not-Call requirements (and non-U.S. equivalents where applicable). Customer must not use Vestrum to circumvent a suppression request.

4. Automated and Prerecorded Calls

Predictive dialing, automated dialing, voicemail drop, prerecorded messages, artificial voice, and similar features must be used only where lawful and with required consent. Customer is responsible for configuring campaigns accordingly.

5. SMS

Before sending SMS through the Service, Customer must complete any carrier-required registration applicable to its messaging use, including A2P 10DLC brand and campaign registration for long-code messaging or toll-free verification (TFV) for toll-free messaging, as applicable to the numbers Customer uses. Customer must obtain any required consent before marketing SMS, provide required sender identification/disclosures, honor STOP/HELP and other opt-out mechanisms (the Service automatically processes STOP-family keywords as described in the Terms of Service), comply with CTIA Messaging Principles and Best Practices, and avoid prohibited content and traffic patterns (including content related to firearms, cannabis, or other carrier-restricted categories, and content associated with SHAFT categories — sex, hate, alcohol, firearms, tobacco).

6. Email

Customer connects its own third-party email account to send email through the Service. Customer is responsible for complying with CAN-SPAM and other applicable email marketing laws, including identification, truthful headers/content, physical address requirements where applicable, and unsubscribe mechanisms, as well as with its own email provider's acceptable use terms.

7. Recording

Customer must determine whether one-party, all-party, or other consent requirements apply (which vary by U.S. state and by country) and must provide notices or obtain consent as required.

8. Answering-Machine Detection

Customer may use AMD to determine whether an outbound call reached a human or a machine. AMD results do not substitute for Customer's obligation to comply with prerecorded/artificial-voice-message consent requirements when a message is left.

9. Records

Customer should maintain evidence of consent, opt-outs, campaign configuration, carrier registrations, and compliance procedures sufficient to demonstrate lawful use.

10. Enforcement

Vestrum may restrict calling or messaging where carrier complaints, spam reports, regulatory inquiries, incomplete carrier registration, or suspicious traffic indicate risk.