Proof of Consent
Othentica – Proof of Consent (Opt-In) for Two-Factor Authentication (2FA)
1. Overview
Othentica requires user consent prior to sending two-factor authentication (2FA) messages via SMS and/or email. These messages are used exclusively to verify user identity and secure access to gift card transactions and wallet activities.
This document outlines how Othentica collects, records, and maintains proof of user consent.
2. Purpose of Messaging
Othentica sends transactional messages for the following purposes:
- Identity verification during login or sensitive actions
- Authorization of gift card usage at participating merchants
- Security alerts related to suspicious or unusual activity
These messages are not promotional and are strictly related to account security and transaction authorization.
3. Consent Collection Methods
User consent is obtained through one or more of the following methods:
A. Account Registration / Onboarding
During account creation or wallet activation, users are presented with a consent statement and must explicitly agree before proceeding.
Sample consent language:
“By providing your phone number and/or email, you agree to receive security and verification messages from Othentica, including one-time passcodes for authentication. Message and data rates may apply. You can opt out at any time.”
Users must take an affirmative action (e.g., checkbox or button) to provide consent.
B. Gift Card Activation Flow
When a user activates an Othentica-enabled gift card (e.g., via QR scan or merchant flow), they are prompted to enter their contact information and consent to receive verification messages.
Sample consent language:
“To secure your gift card, Othentica will send verification messages to your phone or email. By continuing, you consent to receive these messages.”
C. Transaction Authentication Prompt
At the point of first transaction or authentication setup, users may be asked to confirm their contact details and consent to receive 2FA messages.
4. Double Opt-In (Recommended / Optional)
In certain cases, Othentica may implement a double opt-in process, where:
- User provides phone number or email
- Othentica sends a verification code
- User enters the code to confirm ownership
This confirms both:
- consent to receive messages
- ownership of the contact method
5. Data Captured for Proof of Consent
Othentica maintains records of user consent, including:
- User identifier (e.g., account ID)
- Phone number and/or email provided
- Timestamp of consent
- Method of consent (registration, activation, etc.)
- IP address and device metadata (where applicable)
- Version of consent language presented at time of opt-in
These records are securely stored and retained for compliance and audit purposes.
6. Opt-Out Mechanism
Users may opt out of SMS messages at any time by replying:
STOP
Upon opt-out:
- SMS delivery will cease
- Users may still receive critical security communications via alternate channels (e.g., email)
Email communications include standard unsubscribe mechanisms where applicable.
7. Message Frequency
Message frequency varies based on user activity. Users will receive messages only when required for:
- authentication
- transaction approval
- security notifications
Othentica does not send recurring or marketing messages as part of 2FA.
8. Compliance
Othentica’s messaging practices are designed to comply with applicable regulations and guidelines, including:
- TCPA (Telephone Consumer Protection Act)
- CTIA Messaging Principles and Best Practices
- Carrier requirements for A2P messaging (e.g., 10DLC in the U.S.)
9. Contact Information
For questions regarding messaging consent or to report issues, users may contact:
Email: info@othentica.com
Phone: 1 888 988 6704
10. Acknowledgment
By providing contact information and completing the opt-in process, users acknowledge and agree to receive 2FA and security-related communications from Othentica as described above.
