OpenLot Book audit
Compliance

SMS Appointment Reminders: Consent, Timing, Opt-Out

OpenLot 9 min read

SMS is the highest-response channel a dealership has and the one with the most specific obligations attached. The store is the accountable party for every automated message, regardless of which vendor sends it — and that accountability rests on three records most systems capture incompletely.

The three records a dealership SMS programme must keep — consent at time of send, contact-time compliance and opt-out handling

This guide covers the three records that matter, how consent has to be captured, contact-time limits, how opt-outs must behave, what to require from a vendor, and what to measure.

This is operational guidance, not legal advice. Messaging rules change and vary by state. Have counsel review your specific programme, and treat what follows as the questions to bring to that conversation.

The three records

Record What it has to show Common gap
Consent That permission existed at the moment each message was sent, with a timestamp and a source Systems store a flag, not a dated record
Contact time That the message went out within permitted hours in the recipient's time zone Scheduled from store time, not customer time
Opt-out That a request was honoured, and how quickly Honoured on one channel, not across the account

The first is the one that fails under examination. A field reading "opted in: yes" cannot demonstrate that consent existed for a specific message sent on a specific date — which is precisely the question that gets asked.

How consent has to be captured

Four properties, and the fourth is routinely missing:

  1. Specific to the channel. Permission to be emailed is not permission to be texted.
  2. Specific to the purpose. Transactional appointment confirmations and marketing messages are treated differently; a single blanket consent blurs a distinction that matters.
  3. Timestamped, with a source. When, and from where — a web form, a verbal confirmation logged by a rep, a reply to an opt-in message.
  4. Retrievable per message. You must be able to answer "what consent existed when this text was sent on the 14th", which requires the consent state to be stored with the message rather than only on the contact record.

The fourth is an architecture decision, and it is far cheaper to require at purchase than to retrofit — the same point made about audit trails in AI data security.

Contact-time limits

The practical rule most programmes work to is a daytime window in the recipient's local time, not the store's.

Three things go wrong:

Scheduling from store time. A dealership in one time zone messaging a customer in another sends at the wrong local hour, and the system does not flag it because it never knew.

Automated sequences running overnight. A follow-up cadence with a fixed interval will eventually fire at 3am unless the sequence has a contact-time window applied — the stop-condition discipline covered in follow-up cadence design.

Responding versus initiating. Responding to an inbound message at 11pm is good service, and it is most of the point of covering the uncovered hours. Initiating at 11pm is not, and the distinction has to be built into the system rather than assumed — including in confirmation sequences, which run on timers.

How opt-outs must behave

Immediately, and across the account. A customer who replies STOP to a service reminder should not receive a sales message the following week. If your sales and service systems hold separate lists, an opt-out in one must propagate to the other, and that is an integration requirement rather than a preference.

Standard keywords, honoured. STOP, UNSUBSCRIBE, END, QUIT, and variations. A system that only recognises an exact keyword will miss "stop texting me."

Verbal opt-outs logged. A customer who tells a salesperson on the phone to stop texting has opted out. If that is not logged into the system, the sequence continues, and that failure is both visible to the customer and entirely avoidable.

Latency recorded. The gap between request and compliance is itself a measurable exposure, and it should be close to zero.

What to require from a vendor

Requirement Why
Consent state stored with each message, not only on the contact The question is per-message
Contact-time window enforced in recipient time zone The most common silent violation
Opt-out propagation across all systems and message types Where the visible failures happen
Keyword matching that handles natural phrasing "stop texting me" is an opt-out
Exportable audit log You need it without asking them
Named breach and incident contact Part of the standard service provider clauses

Ask to see a real log entry in the demo, showing a specific message with its consent state attached. Documentation claims are not the same as a working capability.

Where SMS programmes go wrong

1. One consent for everything. Appointment confirmations, service reminders and marketing offers bundled under a single permission.

2. Consent as a boolean. No date, no source, no per-message retrievability.

3. Store time zone. Silent, systematic, and easy to fix once noticed.

4. Opt-out honoured on one system only. The customer experiences this as being ignored.

5. Verbal opt-outs lost. Nobody logged it, so the sequence kept running.

6. No audit export. You find out what your own system recorded by asking the vendor, at the worst possible time.

7. Assuming the vendor carries the obligation. They do not. The dealership is the accountable party, and the contract allocates cost rather than responsibility.

What should you measure?

Metric How to compute What it catches
Messages with retrievable consent Sampled, per message Should be 100%
Out-of-window sends Messages outside permitted local hours Should be zero
Opt-out latency Request to last message sent Should be immediate
Cross-system opt-out failures Messages after an opt-out elsewhere The visible failure
Verbal opt-outs logged Logged ÷ reported by staff Usually a process gap
Keyword miss rate Natural-language opt-outs not caught Sample inbound replies

Row four is the one customers notice and the one that produces complaints. Running it once, across sales and service together, tells you whether your systems are actually connected — and whether a reminder is reaching someone who already told the greeting desk to stop.

Frequently asked questions

Who is responsible for SMS compliance at a dealership?

The dealership, regardless of which vendor sends the messages. Contracts can allocate cost and remediation between the parties, but they do not transfer the obligation, which means the store needs its own visibility into consent records, contact times and opt-out handling.

What does a proper consent record look like?

It records the channel, the purpose, a timestamp and a source, and it is retrievable per message rather than only as a flag on the contact. The question that gets asked is what permission existed when a specific message was sent on a specific date, and a boolean field cannot answer it.

What hours can a dealership send text messages?

Programmes generally work to a daytime window in the recipient's local time zone rather than the store's, which is where the most common silent violation occurs. Responding to an inbound message outside those hours is different from initiating contact, and that distinction should be built into the system.

How quickly must an opt-out be honoured?

Immediately in practice, and the gap between the request and the last message sent is itself worth measuring. The harder requirement is that the opt-out propagates across every system and message type the store runs, so a STOP sent to service does not leave a sales sequence running.

Does a verbal opt-out count?

Yes, and it is a frequent failure point, because a customer telling a salesperson to stop texting is only effective if someone logs it. Staff need a simple way to record it, and the rate of verbal opt-outs logged versus reported is a useful process check.

Is consent for service reminders the same as consent for marketing?

They are treated differently, and bundling them under one blanket permission blurs a distinction that matters. Capturing consent per purpose as well as per channel is more work at setup and substantially less exposure later.

What should we require from an SMS vendor?

Consent state stored with each message rather than only on the contact record, contact-time windows enforced in the recipient's time zone, opt-out propagation across all systems, keyword matching that handles natural phrasing, an exportable audit log, and a named incident contact. Ask to see a real log entry during the demo.

What is the most common silent violation?

Scheduling from the store's time zone rather than the customer's. It produces messages sent outside permitted local hours without anything in the system flagging it, because the system was never told where the recipient is.

Conclusion

  • Three records: consent at time of send, contact time in the recipient's zone, opt-out with latency.
  • A consent flag is not a consent record. The question is always per message.
  • Opt-outs must propagate across systems, or the customer experiences being ignored.
  • Verbal opt-outs are real and depend entirely on someone logging them.
  • The vendor does not carry the obligation. The contract allocates cost, not responsibility.

Last updated: