This article is for Enrollsy customers preparing to go live. By the end, you'll know what your website's Privacy Policy and Terms & Conditions need to contain, why both are required, and where to get help drafting them.
⚠️ Note: This is general guidance, not legal advice. We recommend reviewing your final policies with an attorney to make sure they're compliant with the laws that apply to your business.
What a Privacy Policy and Terms & Conditions are
Privacy Policy. A Privacy Policy is a public-facing document on your website that explains what personal information you collect from customers and visitors, how you use it, how you store it, and whether you share it with anyone else.
Personal information can include the following:
Name
Street or Mailing Address
Email Address
Phone number(s)
Age
Gender
Marital status
Race or Nationality
Religious beliefs
Terms & Conditions. Your Terms & Conditions (sometimes called "Terms of Service" or "Terms of Use") are the rules customers agree to when they register for your programs or use your website. They cover things like program descriptions, payment and refund expectations, SMS messaging disclosures, and limits on liability.
Both documents should be linked from your website footer and from your registration form's opt-in. It's okay to have these on the same web page, however, make sure they have clear headings separating them.
Why You Need Them
There are three reasons every Enrollsy customer needs a Privacy Policy and Terms & Conditions on their site.
1. It's the law. Most regions require any website that collects personal information to publish a Privacy Policy. A few examples of laws that may apply to your business:
United States — The California Online Privacy Protection Act (CalOPPA) requires any website that collects personal data from California residents to display a clearly accessible Privacy Policy. Because most Enrollsy customers serve a national audience, CalOPPA effectively applies even if you're not based in California. If your programs serve children under 13, the federal Children's Online Privacy Protection Act (COPPA) also applies.
Canada — PIPEDA (the Personal Information Protection and Electronic Documents Act) requires Canadian businesses to publish a Privacy Policy in plain language and to make it accessible for customer inquiries.
Australia — The Privacy Act of 1988 requires Australian companies to publish a Privacy Policy describing how they collect, use, and disclose personal information.
2. Third-party services require it. Many of the services your website depends on — including Twilio, which Enrollsy uses to send SMS messages on your behalf — require you to publish a Privacy Policy and Terms & Conditions that meet specific standards before they'll let you send messages to your customers. Without compliant policies, registrations that include SMS opt-ins may be rejected.
3. It builds customer trust. A clear, plain-language Privacy Policy reassures parents and adult students that their personal information is handled responsibly. Even if you collect very little data, customers expect to find a Privacy Policy on your site — and not having one can make them assume the worst.
We recommend consulting with your legal counsel to make sure that your terms and conditions and privacy policy are compliant with applicable laws and consistent with standards for your particular campaign and industry. You can also use a free service like RocketLawyer to help you generate a policy.
What to include in Privacy Policy and Terms & Conditions
Because Enrollsy uses Twilio to send SMS messages on your behalf, your website's Privacy Policy and Terms & Conditions need to meet both general privacy-law standards and Twilio/CTIA messaging requirements. Below is a single checklist that satisfies both.
Your privacy policy should clearly explain:
What Information You Collect
What types of personal information you collect (like name, email, phone number, etc.).
How you collect this information (for example, when users sign up, use your service, or contact you).
How You Use the Information
Why you collect personal information (such as to provide your service, send updates, or improve your product).
If you use the information for marketing, analytics, or other purposes, say so.
Who You Share Information With
If you share user information with other companies (like Twilio, payment processors, or partners), explain who and why.
Make it clear if you never sell user information.
How You Protect Information
Describe the steps you take to keep user information safe and secure.
User Choices and Rights
Explain how users can see, update, or delete their information.
Tell users how they can opt out of marketing messages or other communications.
Cookies and Tracking
Say if you use cookies or similar tracking technologies, and what they do.
How Users Can Contact You
Provide a way for users to contact you with questions or concerns about their privacy.
Changes to the Privacy Policy
Let users know how you will tell them if you make changes to your privacy policy.
Special Rules for Certain Countries
If there are extra privacy rights or rules for users in certain countries (like the EU or California), explain those.
Your terms and conditions should include:
Agreement to Terms
Tell your users that by using your service, they are agreeing to your rules and to Twilio’s rules.
Extra Rules for Certain Services or Countries
Let users know that there may be extra rules if they use certain features or if they are in specific countries. These rules can change, so users should check for updates.
How You Handle User Data
Clearly explain what personal information you collect, how you use it, and how you keep it safe.
Mention that you follow Twilio’s privacy and data protection standards.
What’s Not Allowed
Clearly state that users cannot use your service to send spam, harmful, illegal, or abusive messages.
Let users know they must follow Twilio’s Acceptable Use Policy.
Which Rules Matter Most
If there are ever conflicting rules (for example, between your contract, privacy policy, or Twilio’s terms), explain which ones take priority.
How Payments Work
Explain how and when users need to pay you, what payment methods you accept, and any limits or special rules about payments.
Changes to the Rules
Let users know that your terms may change if Twilio’s terms change, and that using your service after changes means they accept the new rules.
Country-Specific Requirements
If there are special rules for users in certain countries, make sure to include those.
How Disagreements Are Handled
Explain how you will resolve any disputes or complaints, and which country’s laws will apply.
Pro tips:
Use simple language and short sentences. Make it easy for anyone to understand how their information is handled.
Consider creating messaging-specific Privacy Policy and T&C pages rather than editing your main company documents. Dedicated messaging policies are easier to keep current as Twilio/CTIA requirements change.
For the source language behind these requirements, see Twilio's Messaging Policy (section 5.2.1) and the CTIA Messaging Principles and Best Practices.
How to Create Yours
You have two options for creating your Privacy Policy and Terms & Conditions:
Work with an attorney. This is the safest route, especially if your programs serve children, you operate in multiple states or countries, or you handle sensitive information like medical or financial data. An attorney can tailor your policies to the specific laws that apply.
Use a policy generator. Free and paid services like RocketLawyer can generate a starter Privacy Policy and Terms & Conditions that you can adapt. Generators are a fine starting point but not a substitute for legal review — especially for the SMS-specific clauses Twilio requires.
Whichever route you take, use the outline below as a checklist to make sure your final Privacy Policy covers the basics.
Privacy Policy Outline
Privacy Policy Outline
Businesses might need to tailor their privacy terms based on the industry when drafting a privacy policy. While we can't provide you with a privacy policy for your company, here are some general outlines for a privacy policy.
The outline below provides a foundation, but your attorney will help ensure that the policy is comprehensive and compliant with relevant laws, such as the Children's Online Privacy Protection Act (COPPA) and any state-specific regulations.
Introduction
Briefly describe the purpose of the policy and its importance in protecting personal information.
Information Collection
Detail the types of personal information collected (e.g., student's names, birthdates, medical information, parent/guardian contact details).
Explain how this information is collected (e.g., enrollment forms, website interactions).
Use of Information
Describe how the collected information is used (e.g., for child care services, classes, emergency contact, billing).
Information Sharing and Disclosure
Specify circumstances under which information may be shared (e.g., with staff, and government agencies for compliance). Assure that information is not sold or shared with third parties for marketing.
Data Security
Outline the measures taken to protect personal information (e.g., secure storage, restricted access).
Access to Information
Explain how parents/guardians can access or update their child's personal information, or how students can access or update their personal information.
Policy Changes
State that the policy may be updated and how changes will be communicated.
Contact Information
Provide a way for parents/guardians or adult students to contact you with questions or concerns about privacy.
Compliance Statement
Affirm adherence to applicable privacy laws and regulations.
Next Steps
Once your Privacy Policy and Terms & Conditions are published on your website, return to the Going Live checklist to continue your Enrollsy launch.
