This page documents, screen by screen, how consent is collected before any SMS is sent through the DocLokr SMS Notifications program, and reproduces every email a recipient receives along the way. DocLokr sends transactional, one-time messages containing a secure document link. Messages are never marketing, are not recurring, and are only sent to a recipient after that recipient has opted in themselves on a DocLokr web page.
The recipient opts in personally, on DocLokr's own website. The professional firm that invites the recipient does not opt in on their behalf, and no consent is collected verbally or by any third party. The flow described below is the only way a mobile number enters the DocLokr SMS Notifications program.
The opt-in flow described on this page is live in production today. Consent is collected, validated and stored on every exchange exactly as shown.
While the A2P 10DLC campaign is pending, DocLokr does not send any SMS. After the recipient opts in, the secure link is delivered by email to the same address the passphrase was sent to. When SMS delivery is enabled, that identical, already-collected consent is what gates the single text message — the opt-in screen and the consent language do not change. Both outcomes are shown at step 7 below, tagged Today and When SMS is enabled.
1. How a Recipient Opts In — Summary
- A professional firm (a verified DocLokr business customer) creates a secure document exchange and enters the recipient's name, email address and mobile number.
- The firm user clicks Send passphrase email.
- DocLokr emails the recipient a three-word passphrase. The email contains no link, no token and no QR code.
- The recipient navigates to https://doclokr.com under their own power and clicks I Have a Pass Phrase.
- The recipient enters the three words from the email.
- The recipient lands on the confirmation page. Their name and the last four digits of the mobile number the firm supplied are shown read-only, so the recipient can see exactly which number they are consenting for. They then check a consent box that is unchecked by default. The button stays disabled until the box is checked.
- The recipient clicks Text my link. DocLokr stores the consent record and delivers the secure link — by email today, and by exactly one SMS to the confirmed number once SMS delivery is enabled.
2. Screen-by-Screen Walkthrough
Each step below shows the actual DocLokr screen. Where a screenshot is available it is displayed; every step also carries an exact, non-functional reproduction of the screen's text and controls so the wording and the default state of every control can be read directly on this page.
1.The firm creates the secure exchange
A verified firm user enters the recipient's first name, last name, mobile number and email address. All four are required. The firm never sees or chooses the recipient's consent — it only supplies contact details.
Person 1
Reproduction of the DocLokr create-exchange form. Every field is required.
2.The firm user sends the passphrase email
Before sending, DocLokr shows the firm user exactly what will happen: an email carrying a passphrase and nothing else. There is no consent checkbox on this screen, because the firm user is not the party who consents.
Send passphrase email
JORDAN ELLIS
DocLokr will email jordan.ellis@example.com
Reproduction of the DocLokr send dialog. No consent attestation is collected from the firm user — the recipient consents for themselves at step 6.
3.DocLokr emails a three-word passphrase — no link
The recipient receives an email containing only a three-word passphrase and an instruction to visit doclokr.com themselves. It contains no document link, no access token and no QR code, so it cannot be used to reach any document or to trigger any text message.
Hi Jordan, Harbor & Vale LLP has sent you a secure document request through DocLokr. DocLokr is a secure exchange that keeps wire transfer instructions out of email. To continue, go to https://doclokr.com yourself and choose "I Have a Pass Phrase". Your pass phrase is: Word 1: RIVER Word 2: MAPLE Word 3: ANCHOR We will not send you a link in this email. After you enter your pass phrase you will be asked to confirm your mobile number so we can text you a secure link. If you were not expecting this, you can ignore this message.
Reproduction of the DocLokr passphrase email. It contains no link and no token.
4.The recipient goes to doclokr.com and clicks "I Have a Pass Phrase"
The recipient navigates to https://doclokr.com under their own power. The I Have a Pass Phrase link sits in the utility bar at the top of every page of the public site.
5.The recipient enters the passphrase
The recipient types the three words from the email. Nothing is sent to their phone at this point — entering the passphrase only identifies which exchange they are responding to.
Enter your passphrase
The passphrase is the three words your lawyer sent you.
Your three-word passphrase is in the email from your attorney. Passphrases are case-insensitive.
Reproduction of the DocLokr passphrase entry dialog.
6.The confirmation page — where consent is given
This is the opt-in. The recipient's first and last name are displayed read-only, taken from the exchange. The mobile number is displayed read-only and masked — only the last four digits are shown, so the recipient can confirm which number they are consenting for without the page ever disclosing the full number to whoever holds the passphrase. The consent checkbox is unchecked by default and the Text my link button stays disabled until the recipient checks it. Links to the Terms of Service and the Privacy Policy are shown directly beneath the consent text.
Checking the box is the recipient's affirmative act, and it is the only thing that advances the flow. Nothing on this screen is pre-selected, nothing is bundled with another agreement, and closing the page without checking the box leaves the exchange untouched and sends nothing.
Confirm it's you
Your secure link is sent by text, so we need to know where to send it.
Terms of Service · Privacy Policy
Reproduction of the DocLokr confirmation page. The name and the masked mobile number are read-only, the consent checkbox is unchecked by default, and "Text my link" is disabled until the recipient checks it.
7.The recipient receives the secure link
On clicking Text my link, DocLokr writes the consent record, burns the passphrase so it cannot be reused, and delivers exactly one message containing the secure link. Delivery happens only after the consent record is written — there is no path in the software that produces a link without one.
Delivered todayToday
While the A2P 10DLC campaign is pending, no SMS is sent. The secure link is emailed to the same address that received the passphrase, in a separate message sent only after the recipient has opted in.
Hi Jordan, Harbor & Vale LLP has shared a secure document request with you. Open this link to begin: https://doclokr.com/v/68b41f2c9d3e4a17b2c05f8e/7c4a91d0be25 This link is for you. Do not forward it. — DocLokr
Reproduction of the DocLokr link email. It is sent only after the recipient has opted in at step 6.
Delivered once SMS is enabledWhen SMS is enabled
When SMS delivery is turned on, the same button sends exactly one text message to the confirmed mobile number instead. Nothing else about the flow changes: the same consent screen, the same consent sentence and the same stored consent record gate the message.
The on-screen confirmation
Check your phone
We just texted your secure link. Open it on your phone to continue.
Reproduction of the DocLokr screen shown immediately after the link is dispatched.
3. Exact Consent Language Shown to the Recipient
The consent text next to the unchecked checkbox on the confirmation page reads, in full:
The exact string displayed is stored with each consent record, alongside the mobile number, a UTC timestamp, the source IP address and a consent-template version, so a later copy change can never rewrite what a given recipient agreed to.
The page and the server are held to the same sentence. The consent text is defined in a single place in the source code, the confirmation screen renders it from there, and the server rejects any submission whose consent text or template version does not match it character for character. A recipient's consent therefore cannot be recorded against wording they were not shown.
This consent is collected and stored now, ahead of SMS delivery being enabled, so that no text message is ever the first thing a recipient sees. Every number in the program will already carry a dated consent record before the first SMS is sent.
4. The Message the Recipient Receives
Once SMS delivery is enabled, the full text of the single message is:
Message frequency: one message per document exchange. Messages are transactional and are triggered by the recipient's own consent — never automated marketing, never recurring.
Until SMS is enabled: the same link is delivered by email instead, as shown at step 7. No text message of any kind is sent in the meantime.
5. Opting Out and Getting Help
- Reply STOP to any DocLokr SMS to immediately unsubscribe.
- Reply HELP to any DocLokr SMS for assistance, or email support@doclokr.com.
- Message and data rates may apply, depending on your mobile carrier and plan.
- Consent to receive SMS is never a condition of using DocLokr or of any purchase.
- Declining simply means no message is sent. The recipient can close the page at any point before checking the box, and nothing is stored and nothing is delivered.
- Until SMS delivery is enabled there is no text message to reply to; opt-out and help requests can be sent to support@doclokr.com and are honoured the same way.
6. Privacy
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent will not be shared with any third parties. Mobile numbers collected for this program are used only to deliver the secure document link.
See our full Privacy Policy and Terms and Conditions for details about the DocLokr SMS Notifications program.