Consent and opt-in
Arino One records messaging consent per contact, per channel and per purpose, storing the capture source, timestamp and exact wording shown, then checks that record at the moment of send rather than when a segment is built. This means a contact's consent status can change between campaign build and send, and the platform will still respect it.
Why consent is stored this way
GDPR requires a lawful basis for processing, and for marketing messages that basis is almost always consent — specific, informed and freely given. A single "opted in" flag on a contact record cannot show any of that, which is why Arino One stores three things for every consent event: where it came from (QR opt-in, web form, inbound keyword, verified import), when it happened, and what the contact actually saw at the point of capture. That combination is what makes the record usable as evidence, not just as a filter.
Consent is also scoped per channel and per purpose. Opting in to WhatsApp marketing does not opt a contact into SMS marketing, and opting in to marketing does not affect the separate legitimate-interest basis you may already have for transactional messages like delivery updates or appointment reminders. Keeping these separate avoids the common failure mode of one broad "marketing consent" flag being used to justify sends it was never intended to cover.
Capture sources the platform supports
| Source | Typical use | What is stored |
|---|---|---|
| QR opt-in | In-store or print-to-digital sign-up | Scan timestamp, campaign code, consent text shown |
| Web form | Website or app sign-up | Form field values, submission timestamp, page/version |
| Inbound keyword | Contact texts a keyword to opt in | Message text, channel, timestamp |
| Verified import | CRM or list migration | Source system, original consent date if supplied, importer identity |
An import with no source and no timestamp is not treated as valid marketing consent — it is a contact you can hold, but not lawfully market to until you obtain fresh, evidenced opt-in.
Withdrawal and enforcement
Inbound STOP-style keywords and unsubscribe link clicks are processed immediately and write an opt-out event with the same rigour as an opt-in: source, timestamp, channel. From that moment the contact is excluded from marketing sends on that channel. Because enforcement happens at send time, a contact who opts out after a campaign is scheduled but before it dispatches will still be excluded — you do not need to rebuild the segment.
How this differs by connection state
Consent capture and enforcement logic is the same product feature regardless of connection state. Every client owns and operates their own Infobip and Meta accounts directly — Arino never holds client keys — so what changes with the $50/month Arino Core connection is whether Arino assists with configuring and evidencing consent, not who owns the underlying account.
| Connection state | Who configures consent capture | Who holds the Infobip/Meta account | Who is accountable for evidence |
|---|---|---|---|
| Connected ($50/month Arino Core connection) | Client, with Arino support and management | Client, always | Client is Controller; Arino is Processor for the connected instance and assists with the controls |
| Unconnected | Client, entirely | Client, always | Client is both Controller and solely responsible for configuring and evidencing consent |
In every case, the client is the Data Controller for the messaging data and decides what counts as adequate consent for their business; Arino is the Data Processor, acting on the client's documented instructions and processing only what the client's instance is configured to process.
Common mistakes to avoid
Do not treat a contact's reply to any message as implied marketing consent — a reply to a transactional message shows engagement, not opt-in to marketing. Do not carry consent across channels or purposes by assumption. And do not run a marketing send against a segment built days earlier without re-checking status, even though Arino One's send-time check makes this less risky than in platforms that only filter at build time.
Steps at a glance
- Choose the lawful basis before you messageDecide whether the message is transactional (legitimate interest or contract) or marketing (consent), because Arino One enforces sends differently depending on the purpose stored against the contact.
- Capture consent with evidenceCollect opt-in through a QR code, web form, inbound keyword or verified import, and let the instance store the source, timestamp and the exact wording the contact saw.
- Confirm the record before a campaignBefore running a marketing send, check the segment against live consent status rather than a cached list — Arino One checks consent at send time, not at segment-build time.
- Handle withdrawal immediatelyProcess inbound STOP-style keywords and unsubscribe clicks as an instant opt-out per channel, so the contact is excluded from the next send automatically.
- Review imported lists before useReject or quarantine any imported contact that has no consent source and timestamp attached, because the console cannot manufacture evidence you did not import.
Frequently asked
Is consent required to send transactional WhatsApp or SMS messages?
No. Transactional and service messages — order updates, appointment reminders, one-time passcodes — are usually justified under legitimate interest or contractual necessity, not consent. Marketing messages need explicit opt-in.
Does one opt-in cover every channel?
No. Arino One stores consent per channel and per purpose. A contact who opted in to WhatsApp marketing has not, by that action alone, opted in to SMS or email marketing — each needs its own recorded basis.
What happens to consent when a contact is imported from a CRM?
The import must carry its own source and timestamp for the consent claim. Arino One does not infer consent from presence on a list; an import with no evidence is treated as unconsented for marketing purposes.
Who is the data controller for consent records?
The client. Arino One's platform captures and stores the record as the client's Data Processor; the client decides what counts as valid consent for their business and is answerable for that decision to regulators and data subjects.
Can a contact opt back in after opting out?
Yes. A fresh, explicit opt-in event overwrites the withdrawn status and is recorded with its own timestamp and source, exactly like the original capture.
Does Meta's WhatsApp policy replace the need for GDPR consent?
No. Meta's opt-in requirement for WhatsApp Business messaging is a platform policy, separate from and additional to GDPR's lawful-basis requirement. You need to satisfy both.
Apply this to your own deployment
This guide describes decisions we make on live instances. Tell us your channels, systems and region and we will map it to an architecture outline, a provisioning plan and an indicative commercial model — usually within one business day.