Skip to main content
Compliance Last updated: September 2026 10 min read

Import your old customer list and text it: what UK PECR allows

C
CaptiFi Editorial Team
CaptiFi · September 2026
Import your old customer list and text it: what UK PECR allows
Row by row
An opt-in column is honoured per contact; no clear yes, no subscription
Separate
Permission to text is asked for and recorded apart from permission to email
£60 (GBP)
For 500 SMS credits; five other currencies priced on the same basis
21:00 to 09:00
Default quiet hours for marketing texts, in the venue's local time

Most venues that come to guest WiFi marketing already own a list: a booking export, a till, an old mailing tool, a spreadsheet behind the bar. Emailing it is the obvious first campaign and texting it is the next thought. Two questions decide whether either is wise: does UK law let you contact those people, and can you show later what permission you had?

This guide answers both, quoting the Information Commissioner's Office (ICO) on the Privacy and Electronic Communications Regulations (PECR) as its pages read on 29 September 2026, and describing what CaptiFi records. None of it is legal advice; where a list matters, check it with a solicitor before the first send.

What you can lawfully import, and the list you cannot

Under PECR, marketing emails and texts to individuals are treated alike. The ICO's Guide to PECR page on electronic mail marketing puts the rule in two sentences: "You must not send marketing emails or texts to individuals without specific consent. There is a limited exception for your own previous customers, often called the 'soft opt-in'." Uploading a file changes none of that; the permission has to exist before the first message.

The lists you can use are those where each person consented to marketing from your venue, or is a past customer the soft opt-in covers: a booking export where guests ticked a marketing box, or a mailing tool export with its subscribed status intact.

The list you cannot use is the one you did not build. The same ICO page says: "The soft opt-in rule means you may be able to email or text your own customers, but it does not apply to prospective customers or new contacts (eg from bought-in lists)." Where a seller claims the contacts consented, the ICO's Collect information and generate leads guidance expects you to establish who compiled the list, what people were told and what records of consent exist; a seller's assurances alone are not enough.

The soft opt-in: when it applies and why a bought list never qualifies

The soft opt-in is the exception most venues hope covers their old list. The Guide to PECR describes the person it covers as "an existing customer who bought (or negotiated to buy) a similar product or service from you in the past, and you gave them a simple way to opt out both when you first collected their details and in every message you have sent." The ICO's Plan direct marketing guidance breaks that into five conditions, all of which must hold:

  1. You obtained the contact details yourself.
  2. You did so during the course of a sale, or the negotiation of a sale, of a product or service.
  3. You are marketing your own similar products and services.
  4. You gave an opportunity to refuse or opt out when you collected the details.
  5. You give an opportunity to refuse or opt out in every subsequent communication.

Condition four is where old hospitality lists usually fail. A booking form that took an email for the confirmation and said nothing about marketing offered no opt-out, so the soft opt-in is not available for those rows. A form with an unticked marketing box is a different case: the rows where it was ticked carry consent in their own right, and the ICO is explicit that "pre-ticked boxes or default settings do not show consent". A bought list fails earlier still, because you did not obtain the details and there was no sale between you and the people on it.

Email permission is not text permission

PECR groups emails and texts together as electronic mail. The ICO still expects the permission to name the channel. Its Plan direct marketing guidance says: "If you want to rely on consent, you must ensure it is specific to the particular type of electronic mail you want to send. For example, consent specifically for emails or consent specifically for text messages; simply saying 'electronic mail' is not specific or informed enough."

A subscribed status from a mailing tool is evidence of email consent, because email is what the person was asked about. A mobile number in the next column is contact data; its presence says nothing about whether the person agreed to be texted.

CaptiFi's import wizard is built around that distinction. When you map a phone number column, a separate tick-box appears, "I have permission to text these contacts", and your answer is recorded against the import separately from the email confirmation. Leave it unticked and the numbers are still saved and shown in exports; those contacts are simply left out of SMS campaigns.

Cleaning the file first

An old list carries dead weight: mistyped addresses, closed mailboxes, duplicates, and people who have asked you to stop. Bounces damage your sending reputation, and a message to someone who opted out breaks the rule the ICO states in Respect people's preferences: "If someone opts out of your direct marketing, you must stop using their information for the direct marketing purposes that the opt-out covers."

Since the release of 18 September 2026, the CaptiFi team can run a contact file through a pre-import check. It separates the addresses safe to import from the ones that would bounce: missing or malformed addresses, duplicates, contacts the venue already holds, anyone on a suppression list, disposable and social-network domains, and domains that no longer accept mail. Mailbox-level verification through ZeroBounce can be switched on when credits are available. You get back a clean file for the wizard, a rejects file with a reason per dropped row, and a count summary.

Keep the contacts on one sheet, because only the first is read, and keep the opt-in column and the original sign-up date column: the wizard can store that date instead of today's, which is the one you will want if anyone asks when permission was given. Files can be CSV, TSV, Excel or OpenDocument, up to 20 MB and 100,000 rows.

The import wizard: an opt-in column or a recorded confirmation

On my.captifi.io, open Guests, choose Import contacts, pick the venue and drop the file in. CaptiFi matches the usual column names on its own and highlights anything it could not place for you to assign.

The permission step has two paths. If your file has an opt-in column, it is honoured row by row: Yes/No, True/False, 1/0 and Subscribed/Unsubscribed are all understood, and a row without a clear yes is imported but left unsubscribed. If your file has no opt-in column, the import will not run until you confirm you have permission to email these contacts, and CaptiFi records that confirmation, who made it and when, against the import.

Two protections apply whatever the file says. An address that has previously unsubscribed, bounced or complained anywhere in CaptiFi stays unsubscribed, so an upload can never re-subscribe someone who has told you to stop. A number that has already replied STOP to you stays opted out, whatever the file or the text tick-box says. The ICO's position is the same: "If someone has objected to your direct marketing, you can't contact them at a later date to ask if they've changed their mind."

The Opt-outs tab in CaptiFi SMS Marketing listing numbers that cannot be texted, with the venue and the date each opted out
The Opt-outs tab: who opted out, from which venue, and when.

A review screen then shows how many contacts will be imported, how many are already in CaptiFi, how many are repeated in the file, how many have no usable email, and how many can be texted. Nothing existing is overwritten, and no welcome email, review request or integration sync fires. If the file was wrong, Undo import removes every contact it added and leaves your WiFi guests untouched.

Keeping imported contacts apart from WiFi guests in your numbers

An import of 5,000 old contacts should not make it look as though 5,000 people walked through the door, and in CaptiFi it does not. Imported contacts are marked Imported, filterable by Source, with a Source column in your CSV export. Their profile reads "Added to your list" in place of "First seen", with no visit history until one of them joins your WiFi.

They are excluded from everything that measures footfall: guest and visit counts, returning visitor rates and dwell time, device breakdowns, peak hours, and your plan's monthly guest allowance. They do count in campaign audiences, segments and your monthly email allowance. Our guide to building an email list from guest WiFi covers the list the WiFi builds alongside them.

The CaptiFi guest list on my.captifi.io showing contacts with their email and SMS consent flags
The guest list, with email and SMS consent recorded per contact.

The first campaign and the first text

Send the email before the text. The ICO's electronic mail marketing page adds a requirement for every message: "You must not disguise or conceal your identity, and you must provide a valid contact address so they can opt out or unsubscribe." CaptiFi adds a one-click unsubscribe to every email; an unsubscribe applies across every venue on your account and goes on your suppression list. The email campaign tools handle the send and the reporting.

For the text, open Marketing then SMS Marketing in the sidebar. The audience panel beside the composer shows who will receive the campaign: estimated recipients in total and per venue, a by-country breakdown, and the opted-out numbers and duplicates removed. A footer, "Reply STOP to opt out", is added to every marketing text automatically. Send the draft to your own phone first; a test costs the same credits as one real message.

The CaptiFi SMS composer with the audience panel showing estimated recipients, excluded numbers and the credit cost before sending
The SMS composer: recipients, exclusions and credit cost before sending.

Cost: credits, segments and quiet hours

SMS Marketing runs on prepaid credits: one credit buys one SMS segment to one recipient. A plain-text segment holds up to 160 characters, and a longer message is split into segments of 153. An emoji or special character switches the message to unicode, which cuts a segment to 70 characters (67 when split). The STOP footer counts towards that, and the audience panel shows recipients multiplied by segments as the credits required, next to your balance.

Since the release of 24 September 2026, credit packs cost £60 (GBP) for 500 credits, £220 (GBP) for 2,000 and £1,050 (GBP) for 10,000, with the other five currencies (USD, EUR, CAD, AUD and NZD) priced on the same basis and shown in the dashboard. Pick the currency your subscription is billed in, because Stripe allows one currency per customer. A first text to 1,000 imported contacts, one plain segment each, needs 1,000 credits: two packs of 500, or part of a 2,000 pack.

Marketing texts are not sent overnight: by default quiet hours run from 21:00 to 09:00 in the venue's local time, and anything queued in that window goes out afterwards. SMS Marketing is included on the Growth plan and above with no separate SMS licence; plan prices in your currency are on the pricing page, and the channel is described on the SMS Marketing page.

Email versus SMS under PECR, and what CaptiFi records

The table puts the two channels side by side. The GDPR compliance page explains exports and erasure from a guest's profile, and our guest WiFi GDPR checklist covers lawful basis and privacy notices for the WiFi list.

Question Email under PECR SMS under PECR What CaptiFi records or does
Can I message an individual on the list? Their specific consent, or the soft opt-in for your own past customers The same: PECR treats texts as electronic mail The opt-in value per row, or your confirmation of permission with who made it and when
Does one permission cover both channels? Consent for email covers email Consent must be specific to the type of electronic mail, so a text needs its own A separate "I have permission to text these contacts" tick-box, recorded against the import
Can I use a bought or rented list? The soft opt-in does not apply to bought-in lists The same A named person on your account confirms permission before the import runs; the name and time are kept
What must every message carry? Your identity and a valid contact address so people can opt out The same, in far fewer characters A one-click unsubscribe on every email; a "Reply STOP to opt out" footer on every text
What happens after someone opts out? Stop marketing to them, keep a suppression record, and do not ask again The same, with STOP as the usual route Previous unsubscribes, bounces and complaints stay suppressed on import; STOP numbers stay opted out
When can it be sent? Not addressed in the ICO pages cited Not addressed in the ICO pages cited Marketing texts wait out quiet hours, 21:00 to 09:00 venue local time by default

Sources

The ICO pages quoted are, from the Guide to PECR, Electronic mail marketing, and from the ICO's Direct marketing guidance, Plan direct marketing, Collect information and generate leads and Respect people's preferences. Quotations were checked against the live pages on 29 September 2026; the ICO revises its guidance, so read the current page first. Product behaviour comes from the CaptiFi customer guides Import Existing Contacts and SMS, and from the release notes of 18 and 24 September 2026.

Frequently asked questions

Quick answers to the most common questions about this topic.

Can I import a customer list I bought and email or text it?
Not under UK PECR as the ICO explains it. The ICO's Guide to PECR page on electronic mail marketing says the soft opt-in "does not apply to prospective customers or new contacts (eg from bought-in lists)", and individuals must otherwise have given specific consent to marketing from you. A seller's assurance that the contacts consented is not enough on its own; the ICO expects you to check who compiled the list, what people were told and what records of consent exist. CaptiFi's import wizard asks a named person on your account to confirm permission before a list without an opt-in column is imported, and records who confirmed it and when.
Does the soft opt-in let me text the customers on my old booking list?
Only if all of the ICO's conditions hold: you obtained the details yourself during a sale or the negotiation of a sale, you are marketing similar products or services, you offered an opt-out when you collected the details, and you offer one in every message. The condition old hospitality lists most often fail is the opt-out at collection. A booking form that took an email for the confirmation and said nothing about marketing did not offer one, so the soft opt-in is not available for those rows.
If a customer agreed to marketing emails, can I text them as well?
The ICO's Plan direct marketing guidance says consent must be specific to the type of electronic mail you want to send, giving "consent specifically for emails or consent specifically for text messages" as the example, and that saying "electronic mail" alone is not specific enough. An email opt-in in your file is evidence of email consent only. In CaptiFi, mapping a phone number column brings up a separate tick-box, "I have permission to text these contacts", and that answer is recorded against the import apart from the email confirmation. Left unticked, the numbers are stored but the contacts are not texted.
What does CaptiFi record when I import a list without an opt-in column?
The import will not run until you confirm you have permission to email the contacts, and CaptiFi records that confirmation, who made it and when, against the import. If the file does have an opt-in column, it is honoured row by row instead, and any row without a clear yes is imported but left unsubscribed. In both cases an address that has previously unsubscribed, bounced or complained anywhere in CaptiFi stays unsubscribed, and a number that has replied STOP stays opted out whatever the file says.
Will imported contacts inflate my visitor numbers?
No. Imported contacts are marked Imported, can be filtered by Source, and are excluded from everything that measures footfall: guest and visit counts, returning visitor rates, dwell time, device breakdowns, peak hours and your plan's monthly guest allowance. Their profile shows the date they were added to your list, with no visit history until one of them joins your WiFi. They do count in campaign audiences and segments and towards your monthly email allowance like any other contact.
How much does it cost to text 1,000 imported contacts?
One credit buys one SMS segment to one recipient, and a plain-text message of up to 160 characters, including the automatic "Reply STOP to opt out" footer, is one segment. So 1,000 contacts at one segment each need 1,000 credits. Since 24 September 2026 packs cost £60 (GBP) for 500 credits, £220 (GBP) for 2,000 and £1,050 (GBP) for 10,000; the other five currencies (USD, EUR, CAD, AUD and NZD) are priced on the same basis and shown in the dashboard. The audience panel shows recipients multiplied by segments before you send, and SMS Marketing is included on the Growth plan and above.
Can a re-import text someone who replied STOP?
No. A number that has already replied STOP to you stays opted out regardless of what the file says or whether the text permission box is ticked, and a guest who replies STOP after a campaign is suppressed across all your venues immediately. The Opt-outs tab lists every number that cannot be texted, with the venue and the date. This matches the ICO's position in Respect people's preferences that once someone has objected you cannot contact them later to ask whether they have changed their mind.
What files and sizes does the CaptiFi contact import accept?
CSV, TSV, Excel (.xlsx or .xls) and OpenDocument (.ods) files up to 20 MB and 100,000 rows, with an email address column required. Only the first sheet of a spreadsheet is read, so keep the contacts on one tab. Semicolon and tab separated files are handled automatically, and a file with no header row still works because the columns are listed by position for you to match. Larger lists are split and imported one after another.
C
Written by
CaptiFi Editorial Team

The CaptiFi Editorial Team writes about guest WiFi marketing, captive portals, GDPR-compliant data capture, and local SEO for venue operators. We base our recommendations on real customer outcomes and verified third-party reviews from G2.com.

Ready to turn your guest WiFi into a marketing engine?

CaptiFi captures customer data from every WiFi login, automates Google reviews and email follow-ups, and plugs into the tools you already use. Hardware included (refundable deposit), transparent pricing, 30-day free trial.

Related reading