Summary
WhatsApp's rules for business accounts live in two separate documents that most people talk about as one thing: the Commerce Policy and the Business Messaging Policy. This post explains what each one actually covers, walks through the specific rules this whole series keeps circling back to, points to where the real documents live, and looks at why a business on the free App experiences enforcement differently than one on the Business Platform. It closes with a plain admission: reading the policy rarely prevents the mistakes that actually get accounts blocked, because the policy states the rule, not the implementation detail that trips people up.
TL;DR
- WhatsApp splits its business rules into two documents. The Commerce Policy governs what you can sell or promote. The Business Messaging Policy governs how and when you can message someone at all.
- The rules that actually get accounts flagged in practice, opt in consent, the 24 hour window and templates, no modified apps, and the quality rating, all sit inside the Business Messaging Policy, not the Commerce Policy.
- Both documents live on Meta's own Business Help Center and developer documentation, not inside the WhatsApp app itself, which is part of why most people have never actually read them.
- The rules are identical whether you run the free App or the Business Platform. What differs is enforcement visibility, and that gap is most of why this series exists in the first place.
Every post in this series has referenced the policy without pointing at it directly. The account blocks piece talks about rules businesses broke. The bulk messaging guide says opt in is required, without saying required by what. The mod apps piece calls GB WhatsApp a Terms of Service violation, again without naming which terms. There is no single document called the policy. There are two, they cover different things, and conflating them is part of why the rules feel vague even to businesses trying hard to follow them. This post is the plain language version of both.
Two documents, not one
WhatsApp's rules for businesses split across two separate policies, and the split is not arbitrary. The Commerce Policy governs what a business is allowed to sell, list, or promote through WhatsApp, the product and content side of things. The Business Messaging Policy governs how a business is allowed to communicate at all: consent, timing, automation, and the technical rules around what counts as an authorized way to send a message. A business can be fully compliant on one and still get flagged on the other. Most of what gets an account blocked, the specific failures covered across this whole cluster, traces back to the messaging policy, not the commerce one.
What the Commerce Policy actually restricts
The Commerce Policy is closer to what a marketplace or ad platform publishes: categories of products and services that cannot be sold or advertised through WhatsApp at all, restrictions on regulated goods, and rules around how a catalog or product listing has to be presented. It is the document to check if a business sells something in a regulated category, alcohol, supplements, financial products, and wants to know whether WhatsApp allows that category to be discussed commercially at all. For most of the businesses in this cluster, retailers, service providers, hospitality, wholesale, the Commerce Policy rarely causes problems, because the products themselves are not restricted. That is exactly why it gets so little attention here. It is worth checking once, at setup, and then it mostly stays out of the way.
What the Business Messaging Policy actually restricts
This is the document doing almost all the work in this cluster, and it breaks down into four rules worth naming plainly.
Consent has to be real and recorded. WhatsApp requires opt in before a business initiates contact with someone, and an assumption based on a past purchase or an old form fill does not count. We cover exactly what this looks like in practice in our guide to bulk and broadcast messaging.
Conversations outside the 24 hour customer care window need an approved template. Reply within a day of a customer's last message and free text is fine. Reach out after that window closes and the message has to come from a template Meta has already reviewed. Our piece on template guidelines covers how that approval process actually works and why templates get rejected.
Modified or unauthorized clients are banned outright, no judgment call involved. This is the one rule in the whole policy that leaves no room for interpretation. Using GB WhatsApp, WhatsApp Plus, or any reverse engineered build is a direct violation the moment it is installed, not a pattern Meta's systems infer over time. We go into why that distinction matters in our piece on GB WhatsApp and similar mod apps.
Behavior gets scored, and the score sets a hard limit. The quality rating is WhatsApp's ongoing measure of how recipients respond to a number, and it is not written into the policy as a fixed number so much as a mechanism the policy authorizes Meta to run. We explain how that scoring actually works, and what moves it, in our piece on the quality rating.
| Rule | What it requires |
|---|---|
| Consent | Real, recorded opt-in before a business initiates contact |
| 24 hour window & templates | Free text within 24 hours of the customer's last message; an approved template outside that window |
| No modified clients | GB WhatsApp, WhatsApp Plus, or any unauthorized build is a direct violation on installation |
| Quality rating | An ongoing score based on recipient behavior that sets a hard messaging limit |
Every other post in this cluster is really a deep dive into one clause of this one document.
Where the actual documents live
Neither policy lives inside the WhatsApp app itself, which is a real reason most business owners never read them. Both are published on Meta's own Business Help Center and developer documentation, under WhatsApp Business Platform policies, alongside the separate commerce and platform terms that developers and Business Solution Providers agree to. They are not hidden exactly, but they are written for a technical and legal audience, in the layout of a compliance document rather than a guide, which is a large part of why a plain language version of what they actually say is worth having somewhere else.
Does it matter if you are on the App or the Platform
The rules themselves do not change based on which surface you are using. What changes is enforcement visibility, and that gap is worth being honest about. Our comparison of the App versus the Business Platform covers the structural differences in depth, but the policy angle specifically comes down to this: on the free App, a business finds out it broke a rule when the number gets blocked, with no dashboard, no quality score visible ahead of time, and no template review to catch a problem before it ships. On the Business Platform, the same underlying rules apply, but a Business Solution Provider like Saysimple surfaces the quality rating, enforces template review before a send goes out, and structurally prevents a modified client from ever entering the picture. The policy is identical. What a business can see coming is not.
Why reading the policy rarely fixes anything
Our honest view, after writing this entire cluster, is that reading WhatsApp's actual policy documents rarely prevents the failures that get an account blocked. The policy states the rule in the abstract. It says templates are required outside the 24 hour window. It does not say that a template gets rejected for burying a promotional line inside a transactional message, the specific mistake covered in our template guidelines piece. It says opt in is required. It does not say that a broad blast to an entire contact list drags down a quality score even when every individual recipient technically opted in once, the mistake covered in our bulk messaging guide. The gap between the rule and the mistake is where every post in this cluster actually lives, and it is also the gap a policy document, by its nature, cannot close on its own.
Closing thoughts
None of the individual rules covered here are complicated once they are written down plainly. What is hard is catching the implementation details before they turn into a blocked number, a rejected template, or a quality score that quietly caps a campaign. Saysimple runs on the official WhatsApp Business Platform as a Meta approved provider, and the whole point of that setup, template review, consent tracking, quality rating visibility, is to keep a team compliant with these rules by construction, rather than relying on someone having read the fine print correctly. Book a demo to see how that setup handles the policy details this post just walked through.
Sources
- WhatsApp's Business Messaging Policy, covering opt in, the 24 hour window, templates, modified clients and the quality rating.
- WhatsApp's Commerce Policy, covering what businesses can sell, list or promote.

