Compliance

Sending compliance (CAN-SPAM, TCPA, opt-outs)

Early access — this feature is rolling out to early partners and may not be enabled on your account yet.

Request access →

Important: SignalBack does not send email or SMS today. No sending infrastructure is live on any account. This page describes design intent for campaigns that are not yet built, so that you can evaluate the approach — it is not a description of behavior you can rely on, and it is not legal advice.

What exists today

The free CSV audit is the only live part of SignalBack. It reads a file you upload, classifies the rows, and produces a report. It does not contact anyone in your file, and it does not create any obligation under CAN-SPAM or the TCPA, because no message is sent.

How the sending path is intended to work

When campaigns are enabled, the sending path is designed so that the following behaviors are part of the send pipeline rather than optional settings. None of this is implemented or verified yet, and details may change as it is built.

  • List hygiene: invalid emails and numbers suppressed before sending, and prior opt-outs honored
  • Identification: every message identifies your business, per CAN-SPAM's requirements for commercial email
  • Opt-out propagation: an unsubscribe or STOP intended to suppress the contact across every channel, promptly
  • Ramp-up: sending volume increasing gradually rather than starting at full volume, to protect deliverability
  • Channel gating: SMS only after A2P registration and with consent standing; calling intended to remain human click-to-dial

What US email law requires

CAN-SPAM applies to commercial email. The FTC's compliance guide is the authoritative summary; the core requirements are below. Whoever ultimately sends the mail is responsible for meeting them.

  • Don't use false or misleading header information
  • Don't use deceptive subject lines
  • Identify the message as an advertisement
  • Include a valid physical postal address for your business in every commercial message
  • Tell recipients how to opt out, and honor opt-out requests promptly
  • Monitor what others do on your behalf — liability is not delegated away

The valid physical postal address requirement is worth calling out: message templates shown elsewhere on this site are illustrative previews and do not include one. Any template used for real sending needs your business's postal address added.

Data handling

For the CSV audit as it works today, you provide the data and SignalBack processes it to produce your report. In data-protection terms this is intended to be a controller/processor relationship, but the contractual terms that would formalize that — along with accounts, billing, and a signed DPA — do not exist yet, so treat the characterization as intent rather than a completed legal arrangement.

Audit data is processed on US cloud infrastructure. There is no intention to sell or share it with third parties for their own marketing, and no such arrangement exists today. Deletion requests are honored — email us and we will remove your file and report.

Sources and further reading

Questions this page didn't answer? hello@signalback.ai · Guides on the main site