Messaging Policy — Email & SMS (postal.ID)
This policy governs use of postal.ID messaging for OTPs and verification notifications.
1. Message types
- Transactional/security: OTP codes, verification links, status updates required to complete a requested verification.
- Operational notifications: reminders and delivery updates (customer-configurable).
- Marketing: promotional messages (separate, consent-based; not part of verification by default).
2. Consent and lawful basis
Customer is responsible for obtaining any required consents and providing required notices to Subjects, especially for SMS where local laws may require express consent.
3. Opt-out
- Marketing messages must support opt-out.
- Transactional/security messages are limited to the verification purpose; opt-out may not apply but volume must be minimal and purpose-bound.
4. Templates
Customer may configure templates. postal.ID may require minimum compliance text (e.g., "You are receiving this because [Customer] requested verification").
5. Abuse prevention
Rate limits apply. Enumeration, harassment, and mass messaging are prohibited.
6. Quiet hours (optional)
Customer may configure quiet hours per region; certain security messages may be exempt.
7. Logging
Messaging events (sent, delivered, failed) may be logged for audit and troubleshooting, subject to retention settings.