careCycle
Stay compliant

TCPA Compliance

The calling and texting rules careCycle enforces automatically, and the practices that keep your outreach clean.

The Telephone Consumer Protection Act (TCPA) governs when and how businesses may call and text consumers. careCycle enforces the core rules at the platform level, on every channel, so a campaign cannot be configured around them. This page explains exactly what is enforced and what remains your responsibility.

Quiet Hours: 8 AM to 9 PM, the Customer's Time

careCycle never places an outbound campaign call or sends a campaign SMS outside 8:00 AM to 9:00 PM in the customer's local time. This window is fixed in the platform and cannot be turned off, widened, or overridden per campaign. Even campaigns configured to dial outside your business hours still respect it.

How careCycle knows the customer's local time. The platform resolves each customer's timezone in order of confidence:

  1. The customer's timezone, if their record has one.
  2. Their ZIP code, looked up to a timezone.
  3. Their state, as a last resort. Because some states span multiple timezones, careCycle is deliberately conservative here: the contact is only made when the time is compliant in every timezone the state touches.

No location means no outreach. If none of those resolve, the contact is blocked. This is why the import guide requires a postalCode or timezone on every record: a customer without one is invisible to outbound campaigns. If a campaign seems to be skipping people, missing location data is the first thing to check.

Blocked contacts are handled safely. Campaign calls that come due outside the window are deferred to the next compliant time (8 AM in the customer's timezone), so nothing is lost. Individual SMS sends outside the window are skipped and reported, and Pulse reschedules its retries into the next compliant window.

Quiet hours are separate from your business hours and holidays. Your operating hours decide when your agency works; the TCPA window is a legal floor that applies on top, always.

Do Not Call and Opt-Outs

careCycle treats do-not-call as a one-way door:

  • Every customer record carries doNotCall and doNotSMS flags, and setting either one automatically sets the other. A member who says "stop texting me" is not called instead, and vice versa.
  • Verbal do-not-call requests are caught automatically. After every call, careCycle analyzes the conversation for do-not-call requests. A confident detection sets the flags and records the Do Not Call disposition, with no agent action required. This analysis is a required step of call processing: if it cannot run, the call fails processing rather than skipping the check.
  • STOP replies suppress instantly. A STOP reply sets both flags, ends the member's active campaign enrollments, and removes any queued outreach for them. Every outbound text automatically carries opt-out instructions, and custom opt-out messages must include the word STOP.
  • Carrier-level blocks are honored as opt-outs. If a carrier reports that a member blocked your number, careCycle treats it exactly like a STOP: both flags set, nothing retried.
  • Opt-outs are sticky. Lead files and CRM syncs re-imported later cannot un-suppress anyone: incoming data can only tighten consent flags, never loosen them. A vendor's daily file that says doNotCall: false will not overwrite a member's opt-out.

Best Practices

  • Import consent flags with your book. Mark doNotCall and doNotSMS on known-suppressed contacts at import time so they are never touched, rather than relying on them opting out again.
  • Keep ZIP codes on every record. Location data is what makes quiet-hours enforcement (and therefore outreach) possible for each contact.
  • Keep voice and SMS consent separate when collecting leads. This is the number one reason 10DLC registrations get flagged; see Proving Compliant Opt-In.
  • For purchased calls, capture consent evidence. careCycle's ping-post endpoint records vendor consent attestations and evidence (consent basis, timestamps, TrustedForm and similar artifacts) on every ping, so each transferred call carries its consent trail.
  • Do not look for a bypass. There is not one, by design. If a legitimate workflow seems blocked by quiet hours, the answer is usually fixing the customer's location data.

On this page

What's next

SOC 2 and HIPAA