Consent Resolve
Compliance & Privacy Blog

Consent-First vs. Buy-a-List: The Difference That Keeps You Out of Court

Picture the shop that bought 5,000 contacts, started texting, and got a demand letter three weeks later. Here's how that story goes — and the consent-first version that never ends in court.

By Andy Mentges, Chief Executive Officer at Consent Resolve 7 min readReviewed by Stefan Dimitrov, Head of Engineering

The shop that bought a list on Monday

Let me tell you a story you’ve probably heard a version of. A contractor — let’s say a five-truck HVAC shop — gets pitched 5,000 homeowner contacts in their service area for a few hundred dollars. Pennies a name, instant pipeline. They buy it Monday, load it into their texting tool, and start blasting “Need AC service? We’re booking this week” by Tuesday lunch.

Three weeks later, a certified letter shows up. A recipient who never asked to hear from them — and who happens to know the law — is demanding statutory damages, and their attorney is asking how many other people got the same text. Suddenly the cheapest marketing decision of the year is the most expensive one.

That story isn’t rare, and it isn’t bad luck. It’s the predictable ending of the buy-a-list playbook.

Where the cheap list turns into a lawsuit

The trap was never the price of the list. It’s what happens the instant you contact it. Privacy law is built around one question — did this person agree to be contacted? — and a purchased list gives you no honest way to answer it. A bought or rented list isn’t a list of people who want to hear from you. It’s a list of people who agreed to something, somewhere, on terms you can’t see and can’t prove.

That’s where the per-message math turns ugly. The TCPA carries statutory damages of $500 to $1,500 per unsolicited call or text, and it includes a private right of action, so the recipient can sue you directly. Across a few thousand strangers, those numbers don’t stay theoretical for long. California’s CIPA adds $5,000 per violation and is mass-filed by plaintiffs’ firms hunting for exactly this pattern. These figures aren’t a prediction about your shop — they’re the reason it’s worth never being in range of them.

And where your leads come from is its own exposure, separate from how you contacted them. When the FTC ordered Angi’s HomeAdvisor to pay a $7.2 million settlement — with over $3 million refunded to pros — it was over deceptive claims about lead quality and source. Regulators don’t just ask how you reached someone. They ask whether the lead was ever legitimate to begin with.

So what should the HVAC shop have done instead?

Here’s the version of the story that doesn’t end in court. The same shop has homeowners on its website every week — people who found them on purpose, pricing a new system right now. Those visitors didn’t need to be bought. They needed to be kept.

A bought list is a stranger who agreed to nothing you can see. You can’t prove consent, you don’t know how the data was gathered, and the same names were probably sold to a dozen other shops. When one asks “where did you get my number?”, you’re guessing — and guessing is what the demand letter feeds on.

A consent-first lead is a homeowner who landed on your site, accepted a clear consent banner, and got logged with a timestamp. You know exactly when they agreed and to what. The lead is exclusive to you — never resold — and it comes with a receipt you own. Same goal, fill the pipeline. Opposite ending.

Owners worry the clean way means fewer leads. It’s the reverse. The list you buy is full of people who don’t know you and didn’t ask for you. The visitors already on your site found you and are shopping the job today. Identifying them on consent turns the traffic you already paid for into real, defensible contacts — instead of paying again for a spreadsheet of strangers who can sue you.

The follow-up is the part that keeps the story clean. With consent-first, you never get handed a phone number to cold-dial. Leads are email-grade, dropped into the funnel you already run — Jobber, Housecall Pro, ServiceTitan, Klaviyo, GoHighLevel — so you reach people who agreed to hear from you, by the channel that carries the least risk. The behavior that put the shop in the cautionary tale simply isn’t on your menu.

How to fill the pipeline without buying the lawsuit

  • Don’t rent strangers. A list you can’t prove consent for is liability with a price tag, not an asset.
  • Capture the people already on your site, on consent, with a clear banner — they came to you on purpose.
  • Follow up by email, into your existing funnel, never a cold call or text to a number you bought.
  • Keep the receipt. A timestamped consent log on a 7-year audit trail means proof exists before anyone asks.

The whole thing costs a flat $7 per lead, exclusive and never resold — a fraction of what a single TCPA claim would run you, and without the certified letter.

Consent Resolve was engineered to the strictest privacy regime in the world — GDPR, whose maximum fine reaches €20 million or 4% of global revenue — so a lead you capture this way holds up anywhere. Every figure here is sourced on our stats page.

Write yourself the better ending

The choice was never “more leads” versus “fewer leads.” It’s “leads you can defend” versus “leads that can sue you.” The shop that bought the list got a docket; the shop that captured its own consented visitors got a pipeline and a receipt. See why consent-first keeps your shop out of court, then look at what your current lead channels actually cost — in fees and in exposure. This article is general information, not legal advice.

FAQ

Frequently asked questions

Yes — and it's one of the most common ways contractors land in legal trouble. The people on a bought list never agreed to hear from you, and the TCPA carries $500 to $1,500 per unsolicited call or text with a private right of action, so a recipient can sue you directly. A single campaign to a purchased list is per-message math that can end in a demand letter. This is general information, not legal advice.
Get Started — $7 Email Us