Technology
Back to Blog

SMS Compliance for Gyms: Your 2026 Legal Playbook

SMS Compliance for Gyms: Your 2026 Legal Playbook - Martial Arts Studio Management Tips & Insights

To be SMS-compliant as a U.S. gym or fitness studio, you must obtain prior express written consent before sending any marketing text, log that consent with a timestamp and source, register your brand and campaigns with The Campaign Registry (TCR) for 10DLC delivery, and process STOP requests immediately. Skip any one of those steps and you face two separate risks: a lawsuit under the Telephone Consumer Protection Act (TCPA) and carrier-level message blocking that kills your deliverability before a single text reaches a member.

The TCPA’s statutory damages run $500 per violation for standard cases and can increase for willful ones. Courts routinely treat each individual message as a separate violation. A marketing campaign sent without proper consent can generate substantial statutory exposure before a class action is even certified. Carriers have compounded this by blocking unregistered 10DLC traffic outright, meaning non-compliance now costs you both legally and operationally.

Three things you can do today:

  • Audit every existing SMS list for documented, written consent records. If you cannot produce a timestamped opt-in record for a contact, stop texting them until you can.
  • Pause any marketing campaign running from an unregistered 10-digit local number and begin the TCR brand registration process through your SMS provider.
  • Add a STOP auto-responder to every active campaign and confirm it processes opt-outs within seconds, not hours.

Key Takeaways

Defensible SMS compliance for gyms requires prior express written consent, complete consent records, TCR registration for 10DLC, immediate opt-out processing, and a vendor contract that protects your data and your liability position.

Point Details
TCPA damages are per text Violations cost statutory damages per individual message; a single campaign can generate significant exposure.
TCR registration is mandatory Unregistered 10DLC traffic is blocked by carriers; register your Brand and each Campaign before sending.
Consent records win cases Log timestamp, source, IP, disclosure text, and Campaign ID for every opt-in; exportable logs are your primary defense.
State mini-TCPAs raise the floor Apply the strictest state rule that applies to any member you text, not just the state where your gym operates.
Dojotrack maps to the checklist Dojotrack provides consent capture templates, exportable logs, automated STOP processing, and TCR registration support in one platform.

Table of Contents

How U.S. law and carrier rules govern gym SMS programs

The legal framework for business texting in the U.S. has three layers: federal statute, FCC implementing rules, and industry carrier standards. Each layer creates distinct obligations, and violating any one of them carries real consequences.

The TCPA (47 U.S.C. § 227) is the primary federal law. It prohibits sending marketing texts to a cell phone using an automatic telephone dialing system (ATDS) or prerecorded message without prior express written consent. The statute’s private right of action is what makes it dangerous: any individual recipient can sue, and class actions are common. TCPA damages are $500 per violation, rising to $1,500 when the conduct is willful or knowing, with no cap on aggregate class exposure.

FCC implementing rules under 47 C.F.R. § 64.1200 define what “prior express written consent” means in practice, set disclosure requirements, and govern how consent must be obtained. The FCC’s telemarketing and robocall enforcement page also accepts consumer complaints, which can trigger investigations and referrals to the FTC or DOJ.

The National Do Not Call (DNC) Registry applies to voice calls and certain text campaigns. While the TCPA’s consent requirement is stricter for texts, DNC registration status is still a factor in some enforcement actions, particularly for hybrid voice-and-text programs.

State mini-TCPAs are multiplying fast. Florida’s FTSA, Texas SB 140, and laws in Oklahoma, Virginia, Washington, and Maryland each add their own consent requirements, per-text damages, or retention mandates. A gym headquartered in Texas but texting members in Florida must apply Florida’s rules to those Florida numbers. The practical compliance baseline is the strictest state rule that applies to any member you text, not the state where your gym is located.

CTIA messaging principles set the industry content standards that carriers use to filter messages. The CTIA’s messaging interoperability commitments include the SHAFT categories (Sex, Hate, Alcohol, Firearms, Tobacco) as content restrictions, plus guidelines on frequency, opt-out language, and disclosure. Violating CTIA standards can trigger carrier filtering even when your legal consent is valid.

The Campaign Registry (TCR) operates as the central hub for 10DLC brand and campaign registration. Carriers AT&T, T-Mobile, and Verizon use TCR vetting scores to determine throughput limits and whether to deliver or block your messages. This is no longer optional for any business sending application-to-person (A2P) texts from a local 10-digit number.

Key obligations at a glance:

  • Prior express written consent required for all marketing texts
  • FCC-compliant disclosures at the point of opt-in
  • Immediate opt-out processing for STOP, UNSUBSCRIBE, CANCEL, END, and QUIT
  • TCR brand and campaign registration for 10DLC numbers
  • CTIA content compliance to avoid carrier filtering
  • State-specific rules applied to the member’s location, not the gym’s

What your gym needs to do right now: the compliance checklist

Getting compliant is not a six-month project. The core actions break into three phases: what you fix today, what you complete in the first week, and what you build out over 30 days.

Immediate (today):

  1. Stop sending marketing texts from any number not registered with TCR.
  2. Identify every SMS list in use and flag contacts without a documented written opt-in.
  3. Confirm your SMS platform processes STOP replies automatically and immediately.
  4. Add a STOP instruction to the footer of every active campaign message.

Within 7 days:

  1. Begin TCR brand registration through your SMS provider or connectivity partner (CSP).
  2. Draft a compliant opt-in disclosure for your website, front desk, and membership forms.
  3. Set up a consent logging system that captures timestamp, source, IP address, and disclosure text for every new opt-in.
  4. Send a re-consent campaign to any contacts whose opt-in records are incomplete or missing.

Within 30 days:

  1. Complete TCR campaign registration for each message use case (promotions, class reminders, billing alerts).
  2. Implement time-zone suppression so messages only send during permitted hours (typically 8 AM–9 PM local time).
  3. Conduct an internal audit: export all consent logs, verify integrity, and store them in a format your attorney can access.
  4. Review your SMS vendor contract for indemnity clauses, data export rights, and opt-out SLA terms.

Sample opt-in prompt (web form):

Sample initial confirmation message:

Both samples include the required elements: named sender, content description, automated-text disclosure, frequency notice, and opt-out instruction.


Prior express written consent is the legal standard for marketing texts. It requires a clear, affirmative act by the consumer, a disclosure that specifically authorizes automated texts from your gym, and a record you can produce in discovery. Transactional messages (billing receipts, appointment confirmations) require only prior express consent, a lower bar, but the line between transactional and marketing blurs quickly in practice.

Permissible opt-in channels

  • Web form checkbox: Must be unchecked by default. The disclosure must appear adjacent to the checkbox, not buried in a linked privacy policy. The checkbox cannot be bundled with terms-of-service acceptance.
  • Signed paper form: Acceptable at the front desk or during membership enrollment. The form must include the full disclosure language and the member’s signature. Scan and store digitally.
  • In-app consent: A dedicated consent screen within your member app, with a tap-to-confirm action and a logged timestamp.
  • Text-to-join: Member texts a keyword (e.g., “JOIN”) to your number. Your auto-reply must include the full disclosure before any marketing content is sent. The initial keyword reply is the consent record.
  • POS entry: Member provides their number at checkout. The POS screen must display the disclosure, and the system must log the consent event separately from the transaction record.

What every opt-in record must contain

Twilio’s SMS compliance guide recommends making these logs exportable and tamper-evident, which means storing them in an append-only system or generating a hash of each record at creation so any modification is detectable.

Pro Tip: Export a sample of your consent logs monthly and run a spot-check: pick five random contacts from your active send list and confirm each has a matching, complete consent record. This 15-minute check catches data gaps before a plaintiff’s attorney does.

For automated SMS follow-up workflows, consent capture should be built directly into the lead intake form, not added as a separate step. Integrating it at the source reduces the chance of a contact entering your send list without a logged opt-in.


Not every text your gym sends carries the same legal weight. The consent standard depends on the message’s primary purpose, and misclassifying a promotional message as transactional is one of the most common TCPA pitfalls.

Marketing or promotional messages include class promotions, membership upgrade offers, referral incentives, seasonal campaigns, and any message whose primary purpose is to encourage a purchase or engagement. These require prior express written consent under 47 C.F.R. § 64.1200, the full standard with a signed or digitally confirmed authorization.

Transactional or relationship messages include billing receipts, payment failure alerts, class schedule changes, appointment confirmations, and account security notices. These require prior express consent, meaning the member gave you their number in the context of an existing relationship and reasonably expects to receive these messages. Written authorization is not legally required, but logging the consent event is still good practice.

One-to-one conversational texts sent by a staff member to a specific member in response to a direct inquiry generally fall outside ATDS restrictions, but only if the message is genuinely non-automated and individually composed. Bulk-sending a “personalized” message through a template system does not qualify as one-to-one.

Where the line blurs:

  • A class reminder that includes a promotional offer at the bottom is a marketing message, not transactional. Apply the written consent standard.
  • A billing alert that mentions a membership upgrade option is marketing. Keep promotional content out of transactional threads entirely.
  • A lead follow-up text to a prospect who filled out a trial form requires written consent if it promotes your services. The form itself must include the opt-in disclosure.
  • Third-party partner messages (a supplement brand, a local business cross-promotion) sent through your gym’s number require consent specifically naming that third party or the category of senders. Generic “partners” language is not sufficient.

For practical guidance on SMS lead follow-up flows that stay on the right side of this line, the key is separating your promotional and transactional campaigns at the platform level, not just in your messaging calendar.


10DLC, TCR registration, and why carriers will block you without it

10DLC (10-digit long code) is the standard number format for A2P business texting in the U.S. Since early 2025, carriers have been blocking unregistered 10DLC A2P traffic outright. The Campaign Registry is the centralized system that manages brand and campaign registration, and every gym sending marketing or transactional texts from a local number must be registered.

How to register: step by step

  1. Choose a CSP (Campaign Service Provider). Your SMS platform or provider acts as your CSP. They submit your registration to TCR on your behalf. Confirm your provider participates in the TCR ecosystem before signing a contract.
  2. Register your Brand. Submit your legal business name, EIN, address, and business type. TCR verifies your identity against business registries. You receive a unique Brand ID. Registration typically takes 24–72 hours.
  3. Register your Campaign(s). Each distinct use case (marketing promotions, class reminders, billing alerts) requires a separate Campaign registration. You declare the use case, provide sample messages, and confirm opt-in method. Each Campaign receives a unique Campaign ID.
  4. Link your phone numbers. Assign your 10DLC numbers to the appropriate Campaign ID. Messages sent from a number not linked to a registered Campaign will be filtered or blocked.
  5. Test STOP and HELP flows. Before launching, send a test STOP from a personal number and confirm the auto-reply fires and the number is suppressed from future sends within seconds.

Short code vs. 10DLC vs. toll-free: Short codes (5–6 digit numbers) offer higher throughput and are pre-approved by carriers, but they cost significantly more and take 8–12 weeks to provision. Toll-free numbers require separate toll-free verification through TCR and suit mid-volume programs. For most gyms and martial arts studios, 10DLC is the right starting point: lower cost, faster setup, and sufficient throughput for member communications.

Carrier vetting scores affect your throughput limits. AT&T, T-Mobile, and Verizon each apply their own scoring based on your TCR vetting result, campaign use case, and message content. Enhanced vetting (an optional paid upgrade through TCR) can increase throughput caps for high-volume programs.

Pro Tip: Small studios are registered as “Brands” in TCR just like enterprise companies. Your vetting score still affects your per-day message limits with each carrier. Register early, before you need high volume, so your score is established when a promotion or event drives a spike in sends.


How to pick an SMS provider and protect your gym contractually

Your SMS provider is not just a technology vendor. Under the TCPA, the gym (as the brand initiating the message) carries primary liability, but a provider whose platform fails to process opt-outs or mishandles consent data can expose you to violations you had no intention of committing. Vendor selection and contract terms matter.

Due-diligence checklist before signing:

  • Does the provider participate in TCR as a registered CSP or CNP (Campaign Network Provider)?
  • Can you export raw consent logs, including timestamp, IP, source, and disclosure text, in a standard format (CSV, JSON)?
  • Does the platform automate STOP, UNSUBSCRIBE, CANCEL, END, and QUIT processing within seconds?
  • Does it enforce time-zone suppression so messages only send during permitted local hours?
  • Does it support campaign tagging so each send is linked to a specific TCR Campaign ID?
  • Will the provider cooperate with a legal hold or discovery request?
  • Does it maintain its own CTIA compliance program and content filtering?

Contract clauses to require:

  • Indemnification: The provider indemnifies you for violations caused by their platform’s failure to process opt-outs or consent records correctly.
  • Data export rights: You own your consent logs and can export them at any time, including after contract termination.
  • Audit cooperation: The provider agrees to assist with regulatory inquiries and provide platform-level records on request.
  • Opt-out SLA: A contractual commitment to process opt-outs within a defined window (ideally under 60 seconds).
  • Retention schedule: The provider retains message logs and consent records for at least four years, or longer if your state requires it.

Red flags to walk away from:

  • The provider cannot tell you whether they are registered with TCR.
  • Consent logs are stored in a proprietary format with no export option.
  • STOP processing is described as “best effort” rather than guaranteed.
  • The contract places all TCPA liability on the gym with no shared responsibility clause.

SignalWire’s Campaign Registry documentation outlines what a CSP is responsible for in the registration chain, which gives you a useful benchmark for what to ask any provider during evaluation.


What records to keep and how long to keep them

Documentation is where most TCPA defenses are won or lost. Courts and regulators ask for opt-in records first. If you cannot produce a complete consent record for a plaintiff’s number, you are defending on the merits of the statute, not on proof of consent, which is a much harder position.

Record type What to keep Retention window
Consent logs Timestamp, source, IP, disclosure text, checkbox state, Campaign ID 4 years minimum; 5 years recommended
Message content Full text of each message sent, send timestamp, recipient number 4 years
Opt-out logs Number, opt-out timestamp, keyword used, campaign suppressed 5 years (Virginia requires specific opt-out retention)
Campaign IDs TCR Brand ID, Campaign ID, use-case declaration, sample messages Duration of campaign plus 4 years
Billing records Invoices from SMS provider, message volume by campaign 4 years
Re-consent records Date, method, and disclosure for any re-consent campaign 4 years from re-consent date

Virginia’s telephone privacy code requires specific retention of opt-out records, and failure to maintain them creates separate state enforcement exposure independent of federal compliance. Apply the strictest applicable state rule to your entire national list, not just to members in that state.

Twilio’s compliance guide recommends storing consent records in an append-only system and generating a hash at creation so any modification is detectable in discovery. That tamper-evidence standard is increasingly what courts expect.

Quarterly audit checklist:

  • Export all consent logs and verify completeness against your active send list.
  • Confirm STOP processing is functioning: send a test opt-out from a personal number on each active campaign.
  • Cross-check opt-out logs against your send list to confirm suppressed numbers are not receiving messages.
  • Review any new state mini-TCPA developments and update your retention schedule if a new state rule applies to your member base.
  • Confirm your TCR Campaign registrations are current and sample messages still match what you are actually sending.

Common mistakes gyms make and what they cost

The most expensive SMS compliance failures are not exotic legal theories. They are operational gaps that repeat across hundreds of gyms and fitness studios.

The most common pitfalls:

  • Pre-checked opt-in boxes. A checkbox that is checked by default does not constitute prior express written consent. Courts have consistently rejected this as a valid opt-in method.
  • Missing consent metadata. Keeping a phone number without a timestamped, sourced consent record is legally the same as having no consent at all. The number alone proves nothing.
  • Mixing promotional content into transactional threads. Adding a class promotion to a billing alert converts the entire message to marketing, requiring written consent even if the billing alert alone would not.
  • Skipping TCR registration. Unregistered 10DLC traffic is blocked by carriers, and sending from an unregistered number is also evidence of a non-compliant program in litigation.
  • Slow or manual STOP processing. A STOP reply that takes hours to process, or that only suppresses one campaign while others continue, is a separate violation for each subsequent message sent.
  • Importing purchased lists. Buying a contact list and texting those numbers without individual, gym-specific written consent is a textbook TCPA violation.

What the case record shows:

The aggregation math is the key lesson. A single text to a single member is a $500 exposure. A monthly promotional campaign to 2,000 members without proper consent is a $1 million exposure. Class certification multiplies that across every similarly situated recipient.

Pro Tip: Within 24 hours, do three things: confirm your opt-in checkboxes are unchecked by default, add “Reply STOP to unsubscribe” to every active campaign message, and pull a sample of 10 consent records to verify they include timestamp, source, and disclosure text. These three checks address the top three pitfalls immediately.


Your gym’s SMS compliance timeline: from day one to ongoing governance

Getting to defensible compliance requires sequencing. The table below maps the critical actions to a realistic timeline.

Phase Timeframe Key actions
Immediate Days 1–7 Audit consent records; pause unregistered campaigns; add STOP to all active messages; begin TCR brand registration
Short-term Days 7–30 Complete TCR campaign registration; implement consent logging system; deploy compliant opt-in disclosures across all channels; run re-consent campaign for incomplete records
Ongoing Quarterly/Annual Quarterly consent log audit; STOP flow testing; TCR campaign review; state mini-TCPA monitoring; vendor contract review

Owner and manager responsibilities by phase:

Immediate phase:

  • Owner: Authorize pause of non-compliant campaigns and approve re-consent messaging.
  • Manager: Execute the consent record audit and flag incomplete records.
  • Vendor: Begin TCR brand registration and confirm STOP automation is active.

Short-term phase:

  • Owner: Review and sign off on updated opt-in disclosure language.
  • Manager: Deploy new consent capture forms across web, POS, and front desk.
  • Vendor: Complete campaign registration and link all active numbers to Campaign IDs.

Ongoing governance:

  • Designate one staff member as the SMS compliance owner, responsible for quarterly audits.
  • Schedule an annual review with legal counsel to assess new state mini-TCPA developments.
  • Require your SMS provider to notify you within 48 hours of any platform change that affects opt-out processing or consent logging.

Why 10DLC registration matters even for small studios, and how Dojotrack fits in

Small studios often assume carrier registration is an enterprise concern. It is not. The Campaign Registry treats every business sending A2P messages from a local number as a Brand, regardless of size. A 50-member martial arts school texting class reminders from a local number faces the same blocking risk as a national chain if that number is unregistered.

Carrier filtering is automated. There is no human review that gives small studios a pass. If your number is not linked to a registered Campaign, your messages are blocked at the carrier level before they reach your members. That means missed class reminders, failed billing alerts, and promotional campaigns that simply disappear.

Dojotrack’s platform is built to address this directly. Here is how its features map to the compliance checklist:

  • Consent capture templates: Built-in opt-in forms with disclosure language that meets FCC guidance, deployable on web and in-app.
  • Exportable consent logs: Every opt-in event is logged with timestamp, source, and disclosure text, exportable in standard formats for discovery or audit.
  • Automated STOP processing: STOP, UNSUBSCRIBE, and related keywords trigger immediate suppression across all active campaigns, with no manual step required.
  • Time-zone suppression: Messages are scheduled and delivered within permitted local hours for each recipient’s time zone.
  • Campaign tagging: Each send is linked to a specific TCR Campaign ID, maintaining the audit trail from consent to delivery.
  • TCR registration support: Dojotrack’s team supports the brand and campaign registration workflow, so you are not navigating TCR documentation alone.

For studios using smart automation to connect with leads, consent capture is integrated directly into the booking flow, which means every lead who enters the SMS pipeline has a logged, timestamped opt-in before the first automated message fires.


The compliance reality most gym owners miss

Most gym owners treat SMS compliance as a legal checkbox. That framing misses the operational reality. The TCPA’s private right of action means any member on your list can become a plaintiff, and class certification turns a single non-compliant campaign into a seven-figure exposure almost automatically.

The 10DLC registration requirement adds a second layer that has nothing to do with lawsuits. Carrier blocking is silent. Your messages do not bounce with an error. They simply do not arrive. You may run a promotional campaign for two weeks, wonder why conversion is low, and never realize your messages were filtered before delivery. Registration is not just a legal obligation; it is the technical prerequisite for your SMS program to function at all.

What the industry consistently underestimates is how quickly documentation gaps become the central issue in litigation. Plaintiffs’ attorneys do not need to prove you sent a harmful message. They need to prove you sent a message without documented consent. That is a much lower bar, and it is the bar that most non-compliant gyms cannot clear because they never built the logging infrastructure in the first place.

The studios that handle this well treat consent logging the same way they treat billing records: as a permanent operational function, not a one-time setup task. That shift in mindset is what separates a defensible SMS program from an expensive liability.


Dojotrack gives your studio a compliant SMS foundation from day one

Compliance-ready SMS is one of the concrete advantages Dojotrack delivers for martial arts studios and combat sports gyms. Rather than piecing together a consent logging system, a separate SMS platform, and a manual TCR registration process, Dojotrack consolidates those functions into one platform built specifically for studios like yours.

The free core tier includes basic communication tools so you can get started without upfront cost. As your studio scales, paid features unlock automated STOP handling, exportable consent logs, campaign tagging for TCR, and time-zone suppression, the exact capabilities the compliance checklist requires. Dojotrack’s team also supports the TCR brand and campaign registration workflow, which means you are not reading carrier documentation alone at midnight before a promotion launch.

For studios ready to run compliant, high-converting SMS programs without the administrative overhead, start with Dojotrack’s free plan and see how the platform maps to every item on your compliance checklist.


Sources

This article provides general information about U.S. SMS compliance requirements. It is not legal advice. Consult a qualified attorney to confirm how current rules apply to your specific program and member base.


This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.

FAQ

Yes, SMS marketing is legal for gyms, but only with prior express written consent from each recipient. Sending marketing texts without documented consent violates the TCPA and exposes your gym to statutory damages of $500–$1,500 per message.

What is 10DLC registration and does my gym need it?

10DLC registration is the process of registering your business (Brand) and message use cases (Campaigns) with The Campaign Registry so carriers will deliver your texts. Any gym sending A2P messages from a local 10-digit number must register; unregistered traffic is blocked by carriers.

What happens if a gym member replies STOP?

You must suppress that number from all future marketing messages immediately, typically within seconds through automated processing. Sending any additional marketing text after a STOP reply is a separate TCPA violation, each carrying its own $500–$1,500 statutory damage.

What is an SMS compliance service?

An SMS compliance service is a platform or managed program that helps businesses meet TCPA, FCC, and carrier requirements by automating consent capture, opt-out processing, campaign registration, and record retention. Dojotrack provides these compliance-supporting features within its studio management platform.

Billing alerts and payment failure notices are transactional messages that require prior express consent, a lower standard than written consent. However, if a billing message includes any promotional content, the entire message is treated as marketing and requires prior express written consent.