Back to Home
Legal · Anti-Spam

Anti-Spam & Messaging Compliance Policy

Last updated 20 May 2026·Effective 3 June 2026·Version 1.0
Service provider
SMS Bite Limited
trading as SMSBite
5.17/F. Bonham Trade Centre, 50 Bonham Strand
Sheung Wan, Hong Kong
Company Registration N° 78685084

01Purpose and scope

This Anti-Spam & Messaging Compliance Policy (the “Policy”) sets out the consent, sender-identification, opt-out and record-keeping requirements that apply to every message submitted through the SMSBite platform, in every destination country, over every route and by every account.

SMSBite is a business-to-business technical communications infrastructure provider. Accounts are opened only for verified business entities following KYB/KYC review of business identity, traffic use case, sender identity and expected volumes. There are no consumer accounts and no self-serve consumer sign-up.

This Policy is incorporated by reference into the Terms of Service and expands on the anti-spam provisions contained there. A breach of this Policy is a breach of the Terms. Where a destination country, mobile network operator or regulator imposes a stricter requirement than this Policy, the stricter requirement applies.

02Message categories

Customers must declare the category of traffic they intend to send. Categories determine routing, sender-ID treatment and the consent standard that applies.

  • Transactional — messages triggered by, and strictly necessary to complete, a transaction the recipient has initiated: order confirmations, payment receipts, booking details, shipping notifications.
  • Service and notification — messages arising from an existing relationship that the recipient would reasonably expect: appointment reminders, outage or incident notices, account or policy changes, delivery windows.
  • One-time password and authentication — codes and links generated in response to a login, enrolment or verification attempt made by the recipient. These must be single-use, short-lived and must never carry promotional content.
  • Conversational (two-way) — human or agent-assisted dialogue in which the recipient has engaged, including support threads and inbound-initiated exchanges.
  • Promotional and marketing — any message whose purpose, in whole or in part, is to advertise, promote or induce the purchase of goods, services or content, including offers, discounts, re-engagement campaigns and referral prompts.

Consent requirements differ by category and by destination. A message that mixes a transactional payload with a promotional element is treated as promotional in its entirety. Where the applicable law or operator rule of the destination is ambiguous, the customer must apply the stricter interpretation.

The customer must hold a lawful basis for contacting every number to which it submits traffic. For promotional and marketing traffic, the customer must hold prior express consent from the recipient wherever the destination jurisdiction requires it.

Applicable regimes include, as examples and without limitation, the GDPR and the ePrivacy rules in the European Economic Area, the UK GDPR and PECR in the United Kingdom, the Telephone Consumer Protection Act and state equivalents in the United States, the Personal Data (Privacy) Ordinance and the Unsolicited Electronic Messages Ordinance in Hong Kong, Canada’s Anti-Spam Legislation (“CASL”), and the Spam Act in Australia. Determining which regimes apply to a given campaign, and making any registration or filing they require, is the customer’s responsibility. SMSBite does not file registrations, notifications or consent records with any authority on a customer’s behalf, and nothing in this Policy is legal advice.

Consent relied on by the customer must be:

  • Freely given — not a condition of access to an unrelated service.
  • Specific— tied to the identified sender and to the categories of message actually sent.
  • Informed— the recipient was told who would message them, about what, and how to stop.
  • Evidenced— captured in a record that can be produced later.
  • Revocable— withdrawable at any time, as easily as it was given.

The following are prohibited as a basis for sending: pre-checked or pre-ticked consent boxes; consent bundled into terms the recipient could not decline separately; purchased, rented, exchanged or co-registration lists; scraped, harvested or otherwise appended numbers; and lists inherited from a third party without a documented, transferable consent chain.

04Proof of consent records

For each recipient, the customer must retain an auditable opt-in record containing at minimum:

  • The date and time of consent, with time zone.
  • The source of consent — the specific web form, checkout step, keyword campaign, point-of-sale flow, application screen or paper form used.
  • The IP address, device or channel identifier through which consent was captured, where the capture method produces one.
  • The exact wording and version of the consent language shown to the recipient at the moment of capture.
  • The mobile number in full international format, as submitted.
  • The scope of consent — the sender identified, the message categories covered, and any stated frequency.
  • Any subsequent opt-out, suppression or do-not-contact request, with its timestamp and channel.

Records must be retained for the statutory period applicable in the destination jurisdiction and, in any event, for a minimum of five (5) years, as required by the Terms of Service. Where an investigation, complaint, operator query or regulatory request is open, records relating to the affected traffic must be preserved until it is closed.

On written request during an investigation, the customer must produce the requested consent records to SMSBite within forty-eight (48) hours. A shorter window may be specified where an operator or regulator has imposed one on us. Failure to produce records within the applicable window is treated as an absence of consent for the traffic in question.

05Sender identification

Every marketing message must clearly identify the business on whose behalf it is sent. Where the sender identifier alone does not make the sender obvious to the recipient, the sending party must be named in the message body.

Alphanumeric sender IDs, short codes and long numbers must be registered with SMSBite before use and, in destinations that operate a registration, pre-clearance or header-registry regime, registered with the relevant operator or authority before traffic is submitted. Traffic using an unregistered identifier in such a destination may be blocked or rejected.

Misleading, spoofed, impersonating or borrowed sender identities are prohibited, including identifiers that suggest a bank, government body, operator, delivery company or any other organisation the customer is not authorised to represent. The customer warrants that it holds the rights or authorisations necessary to use every sender identifier it registers, and must be able to evidence that authority on request.

06Opt-out and STOP handling

Every marketing message must carry a working, free and clearly described opt-out mechanism. Where the destination and route support two-way traffic, that mechanism must include a reply keyword; where they do not, an equally accessible alternative must be provided and stated in the message.

Customers must honour, at minimum, the keywords STOP, UNSUBSCRIBE, ARRET and the recognised local-language equivalents for the destination, in any case and with surrounding whitespace or punctuation ignored. Any clear expression of an intent to stop receiving messages must be treated as an opt-out, whether or not it matches a keyword.

Opt-outs are processed at the customer’s own list level. SMSBite does not operate a cross-customer suppression list on the customer’s behalf: an opt-out given to one customer suppresses that customer’s traffic to that number, and it is the customer’s obligation to apply it across its own brands, campaigns, sender IDs and downstream systems.

Customers must process an opt-out within one (1) business day of receipt, and sooner where the destination jurisdiction requires it. A number that has opted out must not be re-imported, re-appended, re-uploaded or otherwise reactivated through a later list load, data enrichment or system migration. Re-contact is permitted only where the recipient gives a fresh, separately evidenced opt-in.

07Quiet hours, frequency and local rules

Marketing traffic must respect the time-of-day windows that apply in the recipient’s destination, calculated in the recipient’s local time and not the sender’s. Where a destination sets no statutory window, customers must avoid night-time delivery and observe local public holidays and days of rest.

Customers must screen against national do-not-call, do-not-disturb and preference registries where such registration is operated in the destination, and must respect any operator-level or regulator-level frequency caps. Message frequency must remain consistent with what the recipient was told at opt-in.

Destination-specific content restrictions apply and vary widely. Categories that are commonly restricted, licensed or prohibited include gambling, adult content, financial promotions and credit offers, loans, cryptocurrency and investment products, pharmaceuticals and health claims, tobacco and alcohol, political and religious content, and URL shorteners on shared domains. Customers must verify the rules of each destination before sending and must not rely on acceptance of traffic by the platform as confirmation that a campaign is lawful.

08Prohibited spam practices

The following practices are prohibited without exception and are grounds for immediate enforcement action:

  • Unsolicited bulk messaging — sending at volume to recipients who have not given a valid, evidenced opt-in.
  • Snowshoeing— spreading traffic thinly across many sender IDs, sub-accounts, routes or numbers in order to stay under complaint or volume thresholds.
  • List-washing — removing only the complainers or known trap numbers in order to keep sending to an otherwise non-consented list, or otherwise cleaning a list to evade filtering rather than to honour opt-outs.
  • Dictionary attacks — generating or enumerating number ranges sequentially or algorithmically and sending to the results.
  • Sending to numbers obtained without consent — including purchased, rented, scraped, appended or inherited data, and numbers captured for an unrelated purpose.
  • Artificially Inflated Traffic (AIT) — generating, procuring or facilitating traffic — typically OTP or verification traffic — that exists to create billable volume rather than to reach a genuine end user, whether the customer is the originator or the victim’s upstream party.
  • Circumvention of filtering — obfuscated or homoglyph-substituted keywords, deliberate misspellings, cloaked or redirecting links, grey-route or unauthorised-route injection, and any other technique intended to evade operator, aggregator or SMSBite controls.

09Traffic monitoring and AIT detection

SMSBite operates automated and manual controls to detect abuse across the platform. Signals monitored include:

  • Complaint signals received from recipients, mobile network operators, aggregator partners and regulators.
  • Delivery-ratio anomalies and, where the customer reports them, conversion-rate anomalies — for example verification traffic delivered but never converted.
  • Unusual distribution across destination number ranges, including concentration in ranges inconsistent with the declared use case.
  • Velocity spikes and other departures from an account’s established sending profile.
  • Content pattern matching against known spam, phishing and fraud templates.

Where these signals indicate abuse, SMSBite may sample traffic, apply rate limits, restrict or change routes, block specific destinations, number ranges or sender IDs, or suspend submission, with or without prior notice.

Published complaint thresholds

So that customers know where the line sits rather than learning it from an enforcement action, the following default thresholds apply to marketing and promotional traffic, measured per sender ID per destination country over a rolling seven-day period:

  • 1 complaint per 1,000 delivered messages (0.1%) — the account is reviewed and the customer is asked to evidence consent for the affected campaign.
  • 3 complaints per 1,000 delivered messages (0.3%) — the affected traffic is rate-limited or route-restricted while the review is open.
  • 5 complaints per 1,000 delivered messages (0.5%) — submission for the affected sender ID and destination is suspended pending production of consent records.

An opt-out rate that is sustained and materially above an account’s own established baseline is treated as a complaint signal in its own right, whether or not a formal complaint is filed.

These are defaults, not entitlements. A mobile network operator, aggregator partner or regulator may impose a stricter threshold for a destination, sender ID or traffic type, in which case the stricter threshold applies and we will tell you which one governs your traffic. Conversely, conduct that is plainly abusive — phishing, impersonation, fraud or Artificially Inflated Traffic — is actioned immediately and is not subject to any threshold.

These controls exist for abuse prevention, network protection and compliance with operator and regulatory obligations. They are not used to profile recipients, to build marketing or analytics products, or to inspect message content for any purpose unrelated to the security and lawful operation of the Service. Personal data handled in the course of these controls is processed as described in our Privacy Policy.

10Complaint handling and enforcement

Recipients, operators, regulators and any other party may report suspected abuse to abuse@smsbite.com. Reports that include the receiving number, the sender identifier, the date and time and the message text can be traced fastest. Our target is to acknowledge a report within two (2) business days and to complete an initial assessment within five (5) business days. These are target response windows, not guarantees or resolution times; complex or multi-party investigations take longer.

Where a report is substantiated, or where monitoring indicates abuse, enforcement is normally graduated:

  • Warning— written notice with a request for consent evidence and a remediation plan.
  • Throttle— reduction of submission rate or daily volume pending evidence.
  • Route restriction — withdrawal of specific routes, destinations or sender IDs.
  • Suspension— temporary suspension of submission for the affected traffic or the account.
  • Termination— closure of the account under the Terms of Service.

SMSBite may skip stages and act immediately, including termination without prior notice, where traffic involves fraud, phishing, impersonation, AIT, illegal content, or a material risk to operators, other customers or end-recipients, or where an operator, regulator or law-enforcement authority so requires.

Fines, penalties, pass-through charges, blocking fees and remediation costs levied on SMSBite by an operator, aggregator or regulator as a result of a customer’s traffic are the customer’s liability and are recoverable in accordance with the Terms of Service. SMSBite cooperates with operators, aggregator partners, regulators and law-enforcement authorities in the investigation of abuse, and may disclose account and traffic information to them where lawfully required or where necessary to investigate a substantiated complaint.

11Customer responsibility statement

The customer is the sender of record for all traffic submitted through its account. The customer determines the recipients, the content, the timing and the purpose of every message, and is the controller of the recipient data it submits. The customer is responsible for the lawful basis, the consent, the notices given to recipients and the lawfulness of the message content in each destination.

SMSBite acts as a conduit and, in respect of personal data contained in submitted traffic, as a processor acting on the customer’s documented instructions. SMSBite does not originate campaigns, does not supply, sell, rent or enrich recipient lists, and does not author message content on a customer’s behalf.

Message delivery is best-effort and depends on mobile network operators, aggregator partners, regulators and handset conditions. Acceptance of a message for submission is not a representation by SMSBite that the message complies with this Policy or with any applicable law.

This Policy should be read together with:

SMS Bite Limited, trading as SMSBite5.17/F. Bonham Trade Centre, 50 Bonham StrandSheung Wan, Hong KongCompany Registration N° 78685084

SMSBite may update this Policy to reflect changes in law, operator requirements or platform controls. Material changes are notified in accordance with the notice provisions of the Terms of Service.