TCPA Texting for Reviews: What Small Businesses Need to Know
TCPA Texting for Reviews: What Small Businesses Need to Know ! Decorative title card illustration You can text customers to ask for reviews.

TCPA Texting for Reviews: What Small Businesses Need to Know

You can text customers to ask for reviews. The catch is consent, and specifically the right kind of consent for the message you’re sending. If a customer gave you their number when they booked, paid, or checked out, and you’re asking them about that specific transaction, you’re usually on solid ground sending a same-day or next-day review request. If you bought a list, scraped numbers from an old spreadsheet, or you’re bundling a discount offer into the ask, you’ve likely crossed into telemarketing territory, which demands a much higher consent standard.
The legal test that matters here comes straight from the Telephone Consumer Protection Act and the FCC’s interpretation of it. Review requests tied to a real, recent transaction are typically treated as informational or transactional messages, which require prior express consent. Anything promotional, anything with an incentive attached, or anything sent to a number you didn’t collect directly usually needs prior express written consent, the stricter standard.
Before you send a single review-request text, run through this:
- Confirm the source of consent. Did the customer give you their number for this transaction, and did they know texts might follow?
- Check your sending window. Same-day to 48 hours after service keeps your transactional argument strongest.
- Verify opt-out processing works. STOP, CANCEL, and similar keywords need to trigger an immediate, automatic suppression, not a manual process someone might forget.
Get those three right and you’ve handled most of the risk. Get them wrong and you’re exposed to statutory damages that add up fast, which we’ll get into below.
Key Takeaways
Review-request texts are legal when tied to a genuine transaction, sent within days of service, and backed by documented consent, immediate opt-out processing, and a registered sending number.
| Point | Details |
|---|---|
| Classify before you send | Confirm whether your message is transactional (prior express consent) or promotional (prior express written consent required). |
| Time it tight | Same-day to 72 hours after service keeps your transactional argument strongest and matches industry best practice. |
| Document everything | Store timestamp, source, consent language, and device/IP data for every consent event, retained for at least four years. |
| Register your sending number | A2P 10DLC registration prevents carrier throttling and supports your compliance posture. |
| Consider a managed approach at scale | Repvive’s RepBoost software and attorney-led review removal service help businesses that outgrow manual compliance tracking. |
Table of Contents
- TCPA Texting for Reviews: Informational or Telemarketing?
- What Kind of Consent Do You Actually Need?
- Building an Audit-Ready Consent Record
- Message Rules: Opt-Outs, Quiet Hours, and Carrier Registration
- Templates and Opt-In Language That Minimize Risk
- Keeping Your List Clean and Your Risk Low
- State Rules and Federal Guidance Worth Tracking
- Your Pre-Send Checklist
- Why Conservative Sends Beat Aggressive Ones
- A Simpler Path if DIY Compliance Feels Like Too Much
- Sources
- FAQ
TCPA Texting for Reviews: Informational or Telemarketing?
The FCC draws its consent requirements around the purpose of the message, not the industry sending it. A text that requests feedback on a service the customer just received is informational. A text that pushes a coupon, a referral bonus, or a new product alongside the review ask is telemarketing, even if you tacked “by the way, please review us” onto the end.
Here’s the decision rule in plain terms: does the message exist to promote something you sell, or does it exist to gather feedback about something the customer already bought? If it’s the former, you need prior express written consent. If it’s the latter, prior express consent typically covers you, according to practitioner guidance on the consent distinction.
| Message type | Example wording | Likely classification |
|---|---|---|
| Straight review ask | “Hi Maria, thanks for visiting Riverside Dental! Mind leaving us a quick review? [link] Reply STOP to opt out.” | Informational/transactional |
| Review ask with an offer | “Thanks for your visit! Leave a review. [link]” | Telemarketing (incentivized) |
| Delayed, bundled ask | A review request sent three weeks later alongside a seasonal promotion | Telemarketing (context shift) |
| Verbal-consent, same-day ask | Front desk tells the customer “we’ll text you a review link today,” customer agrees | Informational/transactional |
A few contextual details will flip a message from one bucket to the other:
- Timing relative to the transaction. The further you get from the actual service, the weaker your transactional argument becomes.
- Presence of an offer. Discounts, contest entries, or loyalty points attached to a review ask pull the message into marketing.
- Wording that references future purchases. “Come back and see us” or “use code SAVE10” signals promotional intent even if a review link is included.
- Volume and frequency. A one-time ask reads differently than a recurring campaign to the same list.
If you’re a law firm, medical practice, or another regulated profession, the classification question gets an extra layer of scrutiny. Repvive’s guide on law firm reputation management covers some of the added caution professional-service businesses need when soliciting client feedback.
What Kind of Consent Do You Actually Need?
Prior express consent means the customer gave you their number in a context that reasonably includes receiving a text back, like a booking form or a checkout screen. Prior express written consent means you have a signed or digitally-confirmed agreement that specifically discloses you’ll send marketing messages, and it typically has to satisfy ESIGN Act requirements for electronic signatures.
For most small businesses running straightforward review campaigns, here’s how the standard maps to real scenarios:
- In-person checkout at a retail shop or salon. If the customer hands over their number specifically so you can text them a receipt or review link, prior express consent usually covers a same-day review ask.
- Appointment bookings (dental, auto repair, home services). A booking form that mentions text communications generally supports a post-appointment review request without needing the written standard.
- Customer-initiated texts. If the customer texts your business first, you can typically respond, including with a review request tied to that conversation.
- Any scenario involving an incentive or recurring marketing. This always needs prior express written consent, collected through a clear, unambiguous opt-in.
Sample opt-in language you can drop into a booking form or invoice:
Place that line directly under the phone number field on booking forms, near the signature line on paper intake forms, and in the footer of digital receipts. The goal is visibility, not fine print. A customer should never have to hunt for it.
Building an Audit-Ready Consent Record
If a customer ever disputes receiving a text, or a regulator asks you to prove consent, you need more than a gut feeling that “we always ask first.” You need a record.
At minimum, capture these fields for every consent event:
| Field | Why it matters |
|---|---|
| Timestamp | Establishes exactly when consent was given, which matters for timing-based classification. |
| Source of consent | Identifies the channel (booking form, in-person, phone call, web checkout). |
| Exact consent language shown | Proves the customer saw specific disclosure language, not vague boilerplate. |
| IP address or device ID | Ties digital consent to a specific device for online opt-ins. |
| Staff member or form ID | Creates accountability for in-person or phone-collected consent. |
Different collection channels produce different evidence types. An in-person signature on an intake form is your paper trail. A checked box on an online booking page pairs with a timestamped IP address. A text-based opt-in (“Reply YES to receive updates”) generates its own message log. A phone booking should have the staff member note verbal consent directly in the customer record at the time of the call.

Pro Tip: Export your consent records to a separate, timestamped spreadsheet or database monthly, not just when you think you’ll need them. Regulators and plaintiffs’ attorneys move slowly, and by the time a dispute surfaces, your original records might be buried in a system you’ve since upgraded or replaced.
Retention matters as much as collection. Keep consent records for at least four years, which covers the typical statute of limitations window for TCPA claims, and store them somewhere your team can pull a single record on demand without digging through unrelated files.
Message Rules: Opt-Outs, Quiet Hours, and Carrier Registration
Every review-request text needs to honor a specific set of opt-out keywords: STOP, QUIT, END, REVOKE, OPT OUT, CANCEL, and UNSUBSCRIBE. The moment a customer sends any of these, you’re required to stop texting them, and that suppression needs to happen automatically. A manual process where someone updates a spreadsheet once a week isn’t good enough.
Quiet hours add another hard boundary. You cannot send marketing or informational texts outside 8:00 a.m. to 9:00 p.m. in the recipient’s time zone, based on industry guidance built around FCC timing rules. If you have customers across multiple time zones, your sending platform needs to account for that automatically rather than assuming everyone operates on your local clock.
A single non-consensual text can carry statutory damages of $500, tripled to $1,500 for willful violations. Send that same mistake to a list of 200 customers and you’re looking at exposure into six figures before a single case even reaches a judge.
Then there’s the carrier layer, separate from TCPA itself but just as important operationally. A2P 10DLC (Application-to-Person, 10-Digit Long Code) is the registration system carriers require for businesses sending texts from standard phone numbers. Skip registration and carriers will throttle or block your messages outright, regardless of whether your consent is airtight.
Here’s the practical breakdown:
- 10DLC works for most small business volumes and requires registering your brand and campaign with a mobile carrier gateway.
- Short codes (five or six digit numbers) suit high-volume senders but cost more and take longer to provision.
- Toll-free numbers offer a middle ground with simpler verification, though throughput limits are lower than 10DLC in some cases.
To register A2P 10DLC, you’ll typically work through your SMS platform or carrier gateway to submit your business details, campaign use case, and sample message content. CTIA’s messaging guidelines exist because unregistered traffic is the primary source of spam and robotext complaints, and carriers use registration status as their first filter.
Templates and Opt-In Language That Minimize Risk
The safest review-request templates share three traits: they’re short, they identify your business by name, and they include opt-out language every single time, not just on the first message.
Opt-in snippets for common collection points:
- Booking form checkbox: “Text me a review request after my appointment. Msg & data rates may apply. Reply STOP anytime.”
- Verbal, in-person opt-in: Front desk staff says, “We’ll send you a quick text after your visit asking how it went, is that okay?” and logs the customer’s verbal yes with a timestamp.
- Phone booking script: “Before we finish up, can we text you a link to leave a review once your service is done? You can always text STOP to opt out.”
- Web checkout: An unchecked box labeled “Text me a receipt and follow-up review request” placed below the phone number field, never pre-checked.
Templates by timing scenario:
Same-day (best for retail, salons, restaurants): “Hi [Name], thanks for stopping by [Business Name] today! Would you mind leaving us a quick review? [link] Reply STOP to opt out.”
Next-day (best for appointments, home services): “Hi [Name], this is [Business Name]. Hope everything went well yesterday. If you have a minute, we’d appreciate a quick review: [link] Text STOP anytime to opt out.”
48 to 72 hour follow-up (best for longer service cycles, like auto repair or contracting): “Hi [Name], following up from [Business Name] on your recent service. If you’re happy with the work, a quick review means a lot to us: [link] Reply STOP to unsubscribe.”
Every one of these stays low-risk because they contain no offers, no incentives, no mention of future purchases, and clear identification of the sending business. What turns any of them risky is adding a discount code, gating the review request so only happy customers get asked (a practice that also violates most platform policies), or stretching the send window past a week without a fresh transactional trigger.
Keeping Your List Clean and Your Risk Low
List hygiene is where a lot of well-meaning businesses trip up, usually by accident rather than negligence. A staff member imports an old customer list without checking it against current suppressions, or a marketing intern grabs numbers from a spreadsheet nobody’s updated in two years.
The core hygiene steps:
- Maintain an internal suppression list that updates in real time whenever someone opts out, and check every new send against it before the message goes out.
- Scrub against the National Do Not Call Registry for any numbers you didn’t collect through a direct transactional relationship.
- Check the Reassigned Numbers Database periodically, since phone numbers get recycled and the person who consented last year might not be the person holding that number today.
- Cap frequency. One review request plus one polite follow-up is the practical ceiling; anything more starts to look like harassment regardless of your consent status.
Litigation exposure scales with list size, and that’s the part small business owners underestimate. Class-action filings over unsolicited texts have become common enough that plaintiffs’ firms actively monitor SMS marketing patterns looking for repeat violations across a customer base.
| Common failure | Mitigation |
|---|---|
| Sending to a purchased or scraped list | Never text numbers you didn’t collect directly through a transaction or opt-in |
| No suppression list in place | Build automated STOP processing before your first send, not after a complaint |
| Sending outside quiet hours | Configure your platform to detect recipient time zone automatically |
| Reusing an old customer list without a scrub | Run a Reassigned Numbers Database check before any bulk resend |
| Bundling promotions into review texts | Keep review requests and marketing offers as two separate, separately-consented streams |

A single mistake, like a promotional review text sent to a purchased list, can trigger the kind of exposure covered in Repvive’s guide on legal options for handling fake or problematic reviews if the fallout includes retaliatory or fraudulent reviews from frustrated recipients.
State Rules and Federal Guidance Worth Tracking
Federal TCPA rules set the floor, not the ceiling. A handful of states layer their own “mini-TCPA” statutes on top, often with lower consent thresholds or steeper per-message penalties. Florida’s Telephone Solicitation Act and Washington’s state-level texting statute have both drawn attention from plaintiffs’ attorneys specifically because they can be easier to trigger than the federal standard. California’s consumer protection statutes add another layer businesses operating there need to watch.
If you send review-request texts to customers in multiple states, assume the strictest applicable state rule governs that segment of your list, not just the federal baseline.
On the federal side, keep an eye on:
- FCC rulemaking updates and interpretive guidance on the TCPA, since the agency periodically revisits consent definitions and enforcement priorities.
- CTIA messaging principles and carrier-level content rules, which shift as spam and fraud patterns change.
- Legal industry commentary from firms that track TCPA litigation trends, since case law shapes practical risk even when the statute itself hasn’t changed.
A reasonable monitoring cadence: check FCC and CTIA guidance quarterly, and do a full review of your consent language, templates, and 10DLC registration status any time you expand into a new state or your message volume jumps significantly. When a rule changes, the action items are the same every time: update your opt-in wording, re-verify your consent collection flow, and confirm your carrier registration still matches your actual use case.
Your Pre-Send Checklist
Run through this before any review-request campaign goes out, whether it’s a single text or an automated batch:
- Verify the consent source. Confirm the customer’s number came from a transaction or a documented opt-in, not a purchased or scraped list.
- Confirm your sending number is registered. Check that your 10DLC registration or toll-free verification is active and matches your actual campaign use case.
- Test STOP processing. Send a test message to a number you control and confirm STOP triggers immediate, automatic suppression.
- Validate your send window. Make sure your platform respects the 8:00 a.m. to 9:00 p.m. recipient time zone rule and your message timing sits within the same-day to 72-hour transactional window.
- Apply suppression lists. Cross-check your send list against internal opt-outs, Do Not Call scrubs, and any recent Reassigned Numbers Database results.
For each item, here’s the one-line action a non-technical owner can verify or hand to a vendor:
- Consent source: pull three random records and confirm the timestamp, source, and language field are all populated.
- Registration: log into your SMS platform and check the campaign status shows “verified” or “active.”
- STOP processing: text STOP from a personal phone and confirm you stop receiving messages within minutes.
- Send window: check your platform’s time zone settings against your customer base’s actual locations.
- Suppression: confirm your list import process automatically excludes anyone flagged as opted out.
One more rule worth repeating: one review request, one polite follow-up, and nothing more unless the customer re-engages with you directly. Businesses that push a third or fourth reminder are the ones that show up in TCPA complaint data most often.
Why Conservative Sends Beat Aggressive Ones
The instinct in small business marketing is to push volume: text everyone, text often, and let the review numbers climb. That instinct is exactly backward when it comes to review requests, and the data on TCPA litigation backs that up. The businesses that get sued aren’t usually the ones sending too few review texts. They’re the ones sending texts to numbers they can’t document consent for, or stretching a transactional relationship into something that looks a lot like a marketing list.
I’d rather see a business send review requests to half its customer base with airtight consent records than blast its entire list and hope nobody complains. The math on statutory damages makes that trade obvious once you run the numbers: a clean list of 500 well-documented sends generates far more usable reviews, with zero legal exposure, than a sloppy list of 5,000 where even a handful of complaints can trigger damages that erase months of profit.
Attorney-led approaches to reputation work exist precisely because the legal nuance here rewards caution over speed. Repvive built its review-removal process around that same principle, using customized legal claims rather than generic mass-reporting tools, because generic approaches tend to miss the specific facts that actually get a review removed or a compliance question answered correctly. If your business is sending review requests at real volume, or you’re already dealing with the fallout from an aggressive campaign gone wrong, that’s the point where talking to counsel or a managed compliance service stops being optional caution and starts being basic risk management.
A Simpler Path if DIY Compliance Feels Like Too Much
Everything above works if you’re willing to build the consent forms, train your staff, register your 10DLC campaign, and audit your lists on a regular schedule. Plenty of businesses do exactly that. But if you’d rather hand the technical and legal detail to someone who does it full time, that’s where Repvive fits in.

Repvive’s RepBoost software handles the parts of this article that take the most ongoing effort: automated opt-out processing, suppression list management, send-window timing, and activity logging that gives you the audit trail this guide walks through. On the other side of the reputation equation, Repvive’s attorney-led review removal service uses customized legal claims built for each specific negative review, with no upfront fees and payment only after a confirmed removal. If your review-request program ever produces retaliatory or fake reviews, or you’re dealing with existing negative content dragging down your rating, that’s a direct fit for what Repvive does.
If you’re running review requests at real volume, or you’ve already run into a review problem that needs professional attention, visit Repvive to see how a managed, attorney-backed approach compares to handling it all in-house.
Sources
- Rules and Regulations Implementing the Telephone Consumer Protection Act
- Messaging interoperability and industry commitments — CTIA
- TCPA compliance for marketing campaigns: Practical steps to reduce risk — Hunton Andrews Kurth
Check the FCC and CTIA pages directly before launching any large-scale review-request campaign, since both bodies periodically revise guidance that affects consent standards and carrier registration requirements.
This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.
FAQ
Can I text a customer asking for a review without written consent?
Yes, if the message is purely informational and tied to a recent transaction, prior express consent from providing their number is usually sufficient. Promotional or incentivized review requests need prior express written consent.
What happens if a customer doesn’t respond to STOP requests being honored?
Automatic opt-out processing should suppress that number immediately across all future sends; manual handling creates gaps that lead to statutory violations. Each non-consensual text after an opt-out can trigger damages of $500 to $1,500.
Do I need 10DLC registration to send review request texts?
Yes, if you’re sending from a standard 10-digit business number, carriers require A2P 10DLC registration or your messages risk being throttled or blocked. This is separate from TCPA legal compliance but equally necessary for deliverability.
How long should I wait before sending a review request text?
Same-day to 48 hours after service keeps your message clearly tied to the transaction and supports the informational classification. Waiting longer than a week weakens that argument and increases legal risk.
Can Repvive help if my review-request campaign generates negative feedback?
Yes, Repvive’s attorney-led review removal service handles negative or fake reviews that surface after a review campaign, using customized legal claims with no upfront fees. Its RepBoost software also helps manage compliant review collection going forward.