Messaging Policy — Email & SMS (postal.ID)

This policy governs use of postal.ID messaging for OTPs and verification notifications.

1

1. Message types

  • Transactional/security: OTP codes, verification links, status updates required to complete a requested verification.
  • Operational notifications: reminders and delivery updates (customer-configurable).
  • Marketing: promotional messages (separate, consent-based; not part of verification by default).
2

2. Consent and lawful basis

Customer is responsible for obtaining any required consents and providing required notices to Subjects, especially for SMS where local laws may require express consent.

3

3. Opt-out

  • Marketing messages must support opt-out.
  • Transactional/security messages are limited to the verification purpose; opt-out may not apply but volume must be minimal and purpose-bound.
4

4. Templates

Customer may configure templates. postal.ID may require minimum compliance text (e.g., "You are receiving this because [Customer] requested verification").

5

5. Abuse prevention

Rate limits apply. Enumeration, harassment, and mass messaging are prohibited.

6

6. Quiet hours (optional)

Customer may configure quiet hours per region; certain security messages may be exempt.

7

7. Logging

Messaging events (sent, delivered, failed) may be logged for audit and troubleshooting, subject to retention settings.