Error code

30908: Campaign vetting rejection - Compliant Privacy Policy Required

Eligible for resubmission. Stated by: GHL 155000007572; LC 155000004749.

What this error means

The privacy policy couldn't be verified as compliant.

Causes, most likely first

  1. No PrivacyPolicyUrl in the request, required for all new campaign submissions.
  2. No compliant policy found on the submitted website or in message_flow.
  3. Multiple or inconsistent policies, so reviewers can't tell which applies.
  4. Policy says mobile information, opt-in data or consent is shared, sold or provided to third parties or affiliates for marketing.
  5. Policy doesn't explain what data you collect and how it's used for messaging.

Fields Twilio names for this error

Twilio’s page for this error names these submission fields:

  • PrivacyPolicyUrl
  • message_flow

How to fix it

If your numbers are managed by a platform

If your numbers sit inside a reseller platform, for example LeadConnector numbers inside GoHighLevel, you do not have access to the Twilio Console, and the interface shows the rejection without the code. Ask that platform's support team for the Twilio rejection error code, in writing, before you change anything. You can also read it yourself from your browser, which is faster: see how to get the code.

The substance of the fix is yours to make: the business details, the website, and the opt-in flow described in the Twilio path all belong to you, not to the platform. Make those changes first, confirm they are live, then ask support to resubmit. A resubmission filed before the underlying facts change will fail again on the same reason.

If you own the Twilio account

Add a publicly accessible PrivacyPolicyUrl, not behind a login, relevant to the registered brand, and include the direct link in message_flow. Update the policy to state that mobile information and messaging consent are not shared with third parties or affiliates for marketing or promotional purposes, and to explain what customer data you collect and how it's used. For website opt-in, include the required messaging disclosures in the policy.

Timing and resubmission

Edit and resubmit. Distinct from 30933, which is the URL field simply being absent from the API request.

Twilio publishes an indicative review timeline for campaigns: Sole Proprietor campaigns are typically approved or rejected within hours to days, and Standard campaigns go through several layers of vetting and can take up to several weeks. Twilio also states that the vetting fee is assessed only once per campaign, so editing and resubmitting the same campaign does not incur a new fee, while deleting and recreating it does.

Two ways forward

Have it handled for you

A2P registration is handled for you on Growth at $597/mo and on Scale at $1,197/mo. Registration, resubmissions, and the compliance work behind them are included.

See Growth and Scale

Fix it yourself

Send your email and we will send the fix playbook for registration rejections.

Verified against Twilio documentation on 2026-08-10.