Skip to main content

Keep marketing preferences aligned

Help your business respect a client’s marketing choices across the systems you use. An integration can connect the marketing consent recorded in MyCRM with the platform that sends your communications.

What this could look like​

A client unsubscribes through your communication platform. Your integration records that preference in MyCRM, so a later update from MyCRM does not accidentally restore an older consent value.

The result depends on an agreed rule for handling changes in both systems, as well as matching the correct contact.

Agree how a preference becomes authoritative​

Before connecting the systems, decide:

  • Which changes should be passed on? Identify the actions that change consent in each system.
  • Which system owns the decision? If both can change a preference, agree how conflicts and older updates are resolved.
  • How will the same client be matched? Keep a reliable connection between their records in the two systems.
  • Who checks failed updates? Make sure an unsuccessful update can be found and corrected.

Aligning one consent value is part of a communication process. Confirm how that value maps to your platform’s own lists and preferences before using it to drive campaigns.

Your responsibilities when sending marketing email​

Using MyCRM or an external marketing platform does not remove your business’s responsibility for the messages it sends or authorises. An email address in a contact record is not, by itself, permission to send marketing.

In Australia, the Spam Act 2003 requires consent for commercial electronic messages with an Australian link. Identify the business that authorised the message, include accurate contact details and provide a clear, easy unsubscribe facility. Honour unsubscribe requests within 5 working days and keep the facility working for at least 30 days after sending. Do not require a login, additional personal information or a fee to unsubscribe. Keep evidence of consent, including when and how express consent was obtained. These responsibilities still apply when someone sends on your behalf; you cannot send a marketing email simply to ask for consent. See ACMA’s guidance on avoiding spam.

In New Zealand, the Unsolicited Electronic Messages Act 2007 prohibits unsolicited commercial electronic messages with a New Zealand link. Establish a valid basis for consent, accurately identify the sender and provide a functional unsubscribe facility. Act on requests within 5 working days, with the facility remaining usable for at least 30 days. The law also restricts address-harvesting software and harvested lists. See DIA’s explanation of New Zealand spam law and unsubscribe requirements.

What this means when you use two systems​

Plan the integration so a preference change affects the actual sending process:

  • Stop sending in the marketing platform promptly. An unsubscribe there should take effect there immediately; updating MyCRM alone does not cancel a queued campaign or stop another system sending.
  • Pass the change back to MyCRM. Likewise, an opt-out recorded in MyCRM needs to reach the external platform. Aim to sync promptly enough to meet the legal deadline, and check preferences before each send.
  • Prevent accidental re-subscription. A later contact import or an older consent value must not overwrite an unsubscribe. Only restore marketing permission when you have a valid new basis for consent.
  • Keep the evidence and scope. Record when, how and for which business, channel or mailing list consent was given or withdrawn. A single MyCRM consent flag cannot capture every platform’s subscription rules or prove consent by itself.
  • Monitor failures. Give someone responsibility for failed preference updates and reconcile both systems regularly. Hold affected marketing sends while an opt-out remains unresolved.

These are integration practices to support your compliance process. Use the regulators’ guidance to assess the consent basis and requirements for your own campaigns.

Implementation notes for your technical team

The marketing resource uses the contact’s identifier. It supports read-by-ID and PATCH operations, with no collection-search endpoint. Use your contact mapping to identify the record to read or update.

PATCH /jsonapi/contact-marketing/1001
Authorization: Bearer {ACCESS_TOKEN}
UserId: {ADVISER_CONTACT_ID}
Content-Type: application/vnd.api+json
Accept: application/vnd.api+json

{
"data": {
"type": "contact-marketing",
"id": "1001",
"attributes": { "hasMarketingConsent": false }
}
}

Request the appropriate scopes, such as the marketing capability granted to your application. The token must request a permitted applicable scope, and the application must also have access to the record.

See Read marketing consent, Update marketing consent and scope behaviour.