Permission means somebody took an action. Typing an address into a form to receive something, ticking a box that was not already ticked, or explicitly asking to be added. It does not mean somebody handed you a business card, appeared on a delegate list, or exists on a list you bought. Purchased and scraped lists are the source of most compliance problems and most deliverability damage, and the second consequence is usually worse: complaints from people who never asked for anything will harm your domain reputation in a way that takes months to recover.

Record what you obtained at the moment you obtained it. The date, the source, and what they were told they were signing up for. That record is your evidence if anybody ever questions it, and it is impossible to reconstruct later. Every established email platform stores this automatically, which is one of several reasons to keep the list there rather than in a spreadsheet.

Separate transactional from marketing email, because the rules differ. A receipt, an appointment confirmation, or a message about work in progress is transactional and may be sent to a customer without marketing consent. A newsletter or a promotion is marketing and requires it. Combining a promotion into a receipt is the manoeuvre that blurs this, and it is treated as marketing rather than as a receipt.

If your customers might be in Europe or California, additional rules apply and they are stricter about what counts as consent and what rights people have afterward. The safest posture, and the one that costs nothing extra, is to operate at the stricter standard everywhere: explicit opt in, clear description of what will be sent, easy withdrawal, and honouring deletion requests when they arrive.

This is general information rather than legal advice. The practical version of all of it is short: only email people who asked, tell them what they are getting, make leaving easy, and keep the record of when they said yes.