The rules of WhatsApp
WhatsApp isn't email. You can't message everyone whose number you happen to have, and anything you send first has to be approved in advance. This is where most questions come from, and the one area where a mistake can cost you your number.
Getting consent
Before you send someone a message you started, that person has to have agreed to it. The agreement has to be explicit, it has to mention WhatsApp, and it has to make clear which business the messages come from. A checkbox reading 'send me updates on WhatsApp from Atelier Noord' qualifies. A list of numbers out of your point of sale that nobody ever asked does not.
You're free to collect consent outside WhatsApp: on your site, at the counter, on paper, or in conversation. What you do need is proof that you have it. When you import contacts you record per contact whether consent exists, where it came from, and when.
- Never buy or rent a list of phone numbers.
- Ask per channel. Consent for email is not consent for WhatsApp.
- Keep a record of where and when someone agreed. GDPR expects the same of you.
- Make opting out easy. Tobachat recognizes the stop words you configure and marks the contact as opted out right away.
The 24-hour window
The moment a customer messages you, a 24-hour window opens. Inside it you can reply freely: plain text, photos, documents, whatever fits. Every new message from the customer resets the clock to 24 hours.
Once the window closes, an approved template is the only thing you can send. The inbox shows this. With under 6 hours left a countdown appears, and once the window is shut the text field is disabled.
| Situation | What you can send | Rate |
|---|---|---|
| The customer wrote within 24 hours | Free-form text, media, internal notes | Service. The first 1,000 per number per month are free |
| The window has closed | An approved template only | Marketing, utility, or authentication, per message |
| You've never spoken before | An approved template only, and only with consent | Marketing, utility, or authentication, per message |
Templates are reviewed up front
Every message you start is a template Meta has seen before it can go out. You submit the text, Meta approves or rejects it, and only then can you use it. That usually takes a few minutes.
Meta also sets the category: marketing, utility, or authentication. You don't pick it, and it decides what you pay per message. A template meant as a confirmation that carries an offer becomes marketing.
Quality rating and sending limit
Meta tracks how recipients respond to each of your numbers. If people block or report you, your quality rating drops. A low rating gets your sending limit cut, and sustained problems can get the number restricted.
You start at 250 unique recipients per rolling 24 hours. Keep the rating healthy and Meta raises that on its own to 1,000, then 10,000, then 100,000, then unlimited. Settings shows the current rating and limit per number.
A campaign larger than your limit isn't rejected. Tobachat spreads it across the following days instead.
Where this goes wrong in practice
The classic mistake is a business messaging its entire customer list at once when those customers never asked for WhatsApp. Blocks come in, the rating collapses within a day, and Meta can restrict the number. No phone call undoes that.
- Message people who know you, not everyone whose number you hold.
- Start small. Run your first campaign to a few hundred contacts and watch what happens.
- Say who you are in the first line. A number nobody recognizes gets blocked.
- Send less often than you would by email. WhatsApp feels personal, and patience runs out faster.
Where the rules actually live: the binding ones are Meta's, in the WhatsApp Business Messaging Policy and the Commerce Policy. What you agree with us is in our anti-spam policy, which you accept when your account is created.