Before you can send anything
Sending is blocked for a new workspace until someone accepts the sending compliance terms. This is a hard gate, not a reminder.1
Open the compliance step
Go to Onboarding and open Sending compliance. It is the last of the
five setup steps and it cannot be skipped.
2
Read the Spam Law summary
The step shows a summary of the obligations under the Israeli
Communications Law amendment (Spam Law, 2008).
3
Tick all three approvals
You confirm that you have read and will follow the Spam Law, that you agree
to the data processing terms covering GDPR and the Israeli Privacy
Protection Law, and that you take responsibility for the opt-in of every
contact you import.
4
Save the step
The gate lifts for the whole workspace immediately.
- Scheduling a campaign is refused with Sending compliance required.
- Sending a campaign test is refused the same way.
- Publishing an automation is refused the same way.
- An amber Sending compliance required banner sits on the campaign wizard with a link straight to the step.
Acceptance is per workspace, not per user. Only a workspace owner or admin
can complete the step, and once one of them does, everyone in that workspace
can send. If you run several workspaces, each one needs its own acceptance.
What Senderz enforces, and what stays yours
Enforced automatically
Marketing consent per channel, suppression, STOP replies, quiet hours and
Shabbat on SMS, voice, push and WhatsApp, frequency caps, and the
unsubscribe link on every marketing email and SMS.
Still your responsibility
Israeli public holidays are not blocked. The accuracy of consent on
lists you import is not something Senderz can verify. So is the content of
your messages and whether they are genuinely transactional.
Explicit opt-in
A marketing message only goes out to a contact whose consent for that channel is Subscribed. There are four independent channels and four possible states.
Email, SMS, push and WhatsApp each carry their own consent state, their own source and their own timestamp. Someone who opted in to email has not opted in to SMS.
A send skipped for this reason is reported on the campaign as No marketing consent.
Consent on import
Contacts you import are not subscribed unless you say so. The last step of the import wizard is Subscription, and it gives you two ways to record consent.Read consent from a column in the file
Read consent from a column in the file
Map a consent column on the mapping step. A row with a positive value is
subscribed for that channel. A row with a negative value is recorded as an
opt-out. A row with anything else, including a blank, is left alone.
Subscribe every row for a channel
Subscribe every row for a channel
Tick Subscribed to email, Subscribed to SMS, Subscribed to
WhatsApp, or Subscribed to all channels. This overrides a consent
column in the file. Because it is a legal assertion about people who are
not in front of you, it also requires the acknowledgement checkbox
underneath.
An import can never bring an opt-out back. If a contact already
unsubscribed, a file that claims they are subscribed is ignored for that
channel, including when the force-subscribe checkbox is ticked. A genuine
re-subscribe has to come from the person, through the preference center. An
imported opt-out also writes a suppression entry, so it survives the contact
being deleted and re-imported later.
STOP handling
A reply of STOP from a mobile recipient reaches Senderz through the carrier delivery-receipt webhook. Within seconds it suppresses that number for your workspace, sets the contact’s SMS consent to unsubscribed, and appends a row to the consent log with the source SMS STOP reply. The keywords recognised are:stop, stopall, unsubscribe, cancel, end, quit, הסר, הסרה
A STOP withdraws the SMS channel only. It is deliberately narrow. The same person’s email consent, and WhatsApp consent on the same phone number, are left untouched, because they are separate permissions the recipient gave separately. If you want to remove someone from everything, use the suppression list or the preference center.
Quiet hours and Shabbat
Marketing SMS, voice, push and WhatsApp do not go out between 20:00 and 08:00 Israel time, or during Shabbat. Shabbat is computed from real sunset in Jerusalem, with a candle-lighting offset of 18 minutes before and a havdalah offset of 40 minutes after.Marketing email is exempt from the legal quiet-hours and Shabbat block.
This is a deliberate product decision, not an oversight. Israeli law regulates
the carrier-delivered channels; email marketing is not carrier-regulated the
same way, and it is the merchant, not a carrier, who carries the sender
reputation. So you decide when your marketing email goes out. Email still
honours any quiet window you configure, and any blackout window you set on
a campaign.
Transactional messages
Transactional messages are operational: an order confirmation, a shipping notice, a password reset, a one-time code. They are not marketing, and the law treats them differently. There are three ways to send on the transactional path:Public API
Send email or SMS directly. See
Messages.
OTP API
One-time codes over SMS or a voice call. See
OTP.
Transactional automation
Flag an automation transactional on its trigger card.
What transactional skips
- Marketing consent. The message reaches a contact who never opted in.
- Quiet hours, Shabbat and any blackout window.
- Frequency caps.
- Unsubscribe injection. No unsubscribe link is added, by design.
- Most suppression reasons, including STOP, spam complaints, manual unsubscribes and repeated soft bounces.
What transactional does not skip
Transactional SMS also still needs an approved SMS Sender name and still spends credits from your SMS wallet.The transactional automation flag
Open an automation, click the trigger card, and turn on This is a transactional automation.- The flag applies to every message step in that automation. You cannot mark a single step transactional.
- Turning it on requires a workspace owner or admin, and asks you to confirm.
- Turning it off can be done by anyone who can edit content.
- Every change is written to your audit log at Settings → Audit Log, so you can see who marked an automation transactional and when.
- A contact who unsubscribes will no longer leave a transactional automation, because the messages are not marketing. A spam complaint still ends their enrolment.
Unsubscribe requirements
Every marketing message must carry a way out. Senderz adds it for you.- Email
- SMS
- Push and WhatsApp
Every marketing email gets
List-Unsubscribe and
List-Unsubscribe-Post headers, which is what makes Gmail and Yahoo show
their own unsubscribe button next to the sender name. It also gets an
in-body link to your hosted preference center.If the email body contains no unsubscribe link at all, Senderz appends a
compliant footer with one. You cannot ship a marketing email without an
opt-out.To control where the link sits, insert the unsubscribe token from the
personalization menu in the email builder. Placing it yourself suppresses
the appended footer.Opting out is per channel
A one-click unsubscribe and a preference-center toggle remove the recipient from that channel, not from your account. Removing someone entirely is a separate action, either from the preference center’s remove-me button or from your suppression list.Pause and reduce frequency
The preference center can offer two softer options instead of a full opt-out, if you enable them on your consent page.- Pause stops marketing for a set number of days. Your consent page decides which durations are offered, from 30, 60 and 90 days. The pause clears itself when it expires.
- Reduce frequency limits that contact to one marketing email per week.
There is no merchant button to lift a pause. It is the recipient’s own
instruction, so overriding it would be a compliance problem. It clears when
the window ends, or immediately if the contact explicitly opts back in on a
channel they were not subscribed to. The remaining pause is shown on the
contact’s profile so you can see why they are being skipped.
Suppression
Suppression is the enforcement layer under consent. An address on the suppression list is blocked before anything else is checked.
Suppression is recorded per channel, so an email suppression does not stop SMS.
Manage it at Contacts → Suppression list. You can search, filter by channel and reason, add an address by hand, remove one that was suppressed by mistake, and export the whole list as a CSV.
The consent log is your evidence
Every consent change appends a row. Rows are never edited or overwritten, so the history is the record of what actually happened rather than a snapshot of the contact’s current state. Each row records:email | sms | push | whatsapp
Which permission changed.
subscribed | unsubscribed | never subscribed | cleaned
What it changed to.
string
Where it came from. A closed list of 18 values so labels never drift, including manual entry, import, API, embedded form, on-site popup, preference center, one-click unsubscribe, SMS STOP reply, store sync, and each connected platform by name.
string
The list the change was tied to, when there was one.
string
The IP address the opt-in or opt-out came from.
string
The browser or client it came from.
timestamp
When it happened. For a store-synced opt-in this is the platform’s own
timestamp, not the moment we imported it, so a two-year-old opt-in reads as
two years old.
The reversible opt-out for developers
The public API has a blacklist endpoint that takes a contact ID or an email, plus a channel ofemail, sms or both. Adding a contact to it records the opt-out and suppresses the address.
What makes it different from a normal unsubscribe is that it snapshots the contact’s previous consent first. Removing them from the blacklist restores that snapshot, including the original consent timestamp and source, rather than leaving them stranded as unsubscribed. Use it when your own system is the source of truth for opt-out and you need the change to be reversible.
See Profiles.
Where each rule is applied
Because the checks sit at the message rather than in a builder, they apply the same way to campaigns, automations and API-driven sends.
Test sends skip the consent, quiet-hours, Shabbat and frequency checks so you
can preview your own message. If you test-send at 02:00 on a Saturday and it
arrives, that does not mean the block is off for your real audience.

