A customer posts a photo of your product, your social manager asks if the brand can use it, the customer replies “love this, use it!”, and somebody screenshots the reply. Months later a colleague asks for the permission file and gets a cropped image of a comment thread with no date on it. That is the gap here, screenshot versus record.
Why a comment reply isn’t a permission record
The informal yes is real. The customer meant it. The problem is the artifact you kept. A screenshot carries whatever the platform rendered beside the comment, usually a relative label like “2w” rather than a date tied to the grant, and its file date records only when somebody pressed the shortcut. A three word reply also says yes without saying to what: organic feed or website gallery, one campaign or the permanent library, paid promotion in or out. It points at no specific asset either, only a handle and a thumbnail.
Then the deletion problem, the one that bites. The customer deletes the comment, changes their handle, or removes the post, and the screenshot becomes an unverifiable image of text. Ordinary enough that a small set of vendors built request and track workflows into their products instead.
What a usable permission record actually contains
Setting vendors aside, this is what separates a record from a screenshot. Read your own file against it.
- A grant attached to a specific asset. A post URL or platform post ID, not “the beach photo”. If it resolves to no identifiable piece of media, it is a sentiment, not a grant.
- A stated scope. Which channels and surfaces are covered, written down when the request is sent, including whether paid promotion is in or out. That is the boundary teams assume rather than ask about.
- A timestamp on the grant itself. Not on the screenshot or the folder, but the moment permission was given, recorded by the system that collected it.
- An identifiable requester and grantor. Which account sent the request and which answered, still legible after whoever ran it has left.
- The request, not just the reply. The field teams skip most often. A yes is interpretable only against what was asked.
How three vendors built for this actually request rights
Everything below is quoted from each vendor’s own page, fetched 2 September 2026. These are vendors describing their own products, not behaviour tested here, and quoting keeps a product claim from growing in the retelling.
Nosto’s Shoppable UGC page carries an FAQ item titled “How do I get legal rights to use customer content?”. The answer states that its “integrated Rights Management workflows makes it easy for you to request and document permission via hashtag approvals or customizable forms, creating a clear audit trail”. The same page describes a Chrome extension as letting teams “aggregate content, send rights requests, and manage assets directly from social platforms”, and says the workflows give the brand “full control over the T&Cs of UGC rights requests”, the closest statement here to the scope question. Nosto is the successor to Stackla; stackla.com returns a 301 resolving to that page, checked 2 September 2026.
Dash Social’s UGC platform page has a Content Rights block stating that “With one click, request content rights for earned media on Instagram, Dash Social will do the rest”, and that a team can “Easily manage approvals as they come in and confidently share earned content across your channels”. The named network is Instagram, and the flow is a one click send into an approvals queue. Dash Social is the current name for Dash Hudson; dashhudson.com returns a 301 to dashsocial.com, checked 2 September 2026.
Taggbox’s Rights Management page describes a Chrome extension “that enables you to send bulk UGC rights requests to users”, and a Send Tailored Requests block saying a brand can “Create & send trustful content right requests to the users with tailored message & genuine branding”. A Personalised Requests For More Impact block says requests can be customised “by including your brand’s logo, terms of service, and custom messages”. Taggbox is the only one of the three to itemise what goes into the outgoing request that way; Nosto states control over the T&Cs without naming the components. The page also covers “maintaining rights status for all your UGC posts”.
This is not stock photo licensing
The two get filed under “image rights” and behave nothing alike. Permission from a customer who shot and posted their own photo is a one off grant negotiated with an individual, on terms you write, at the moment you ask. Licensing from a stock media library is a purchase, its terms pre-set and attached to that purchase rather than agreed with the person in the frame. The stock side is a separate topic queued on this site. Everything here is the first transaction.
Comparing what each tool actually documents
Documented mechanics only, from the pages under Sources. No ranking is implied.
| Vendor | How the request is sent | What the page says happens after | Category the feature ships inside |
|---|---|---|---|
| Nosto | Hashtag approvals or customizable forms; Chrome extension sends requests from social platforms | Permission documented, “creating a clear audit trail”; brand controls the T&Cs | Shoppable UGC inside a commerce experience platform |
| Dash Social | One click request for earned media on Instagram | Approvals arrive in a queue the team manages, then content is shared across channels | UGC platform inside a social content platform |
| Taggbox | Chrome extension sending bulk requests; tailored message with brand logo, terms of service and custom message | Rights status maintained per post | Rights Management inside a UGC and reviews suite |
When a lighter-weight record might be enough
Nothing here is legal advice and this site is no legal authority. But the tools’ framing supports a proportionality read. All three vendors describe collecting something durable rather than something instant, and two of the three describe attaching terms to the outgoing request. That design choice says what worried the buyers of these products, and it was not the one off repost.
An organic repost is short lived and visible to the person who granted it, so if they change their mind you take it down. The same photo as a paid ad reaches people who follow neither account, for as long as the budget runs. Match the record to the use, and if the use might later become paid, ask for that scope up front.
Where to take this next
Pull one piece of UGC you are running now and check its permission record against the five fields above. Read the vendor pages below directly, because product pages change and the wording quoted here is dated.
Standing disclosure: followedapp is published by the team behind RecurPost, and RecurPost is covered vendor #34 under the same rules as every other vendor on this site.
FAQ
Is a screenshot of a comment saying “love this, use it!” good enough?
Structurally it lacks four things: a scope stating which channels and uses are covered, a timestamp tied to the grant rather than to the shortcut, a link to the exact asset cleared, and any durability if the customer deletes the comment. It may reflect a genuine yes. It just does not answer a later question about what that yes covered, which is the gap the workflows above were built to close.
What’s the difference between UGC rights management and stock photo licensing?
Rights management collects a bespoke, one off grant from the person who shot and posted the content, on terms the requesting brand writes. Stock licensing is a purchase of a pre-cleared asset under fixed terms that arrive with the purchase rather than being negotiated with anyone. This post covers the first only. Stock licensing is a separate topic queued on this site and is not detailed here.
Do these tools cover using the photo in a paid ad, or only an organic repost?
Answering only from the vendors’ own pages: Nosto states its workflows give the brand “full control over the T&Cs of UGC rights requests”, which implies scope is settable but does not itself name paid use. Dash Social describes sharing approved content “across your channels” without splitting that into organic and paid. None of the three pages read here states that a granted request covers paid promotion. [EVIDENCE NEEDED: a first party vendor page or help article stating explicitly that a rights request covers paid advertising use, or that paid use requires a separately scoped request.] Name paid use in your own request terms rather than assuming a tool covered it.
Does posting with a branded hashtag count as granting permission?
It is one documented mechanism, not a universal rule. Nosto’s key features list says consent is obtained by “directly requesting creators’ permission through a simple hashtag confirmation, or by using clear, customizable forms”, and its FAQ names “hashtag approvals or customizable forms” as the two routes. Hashtag confirmation is therefore a workflow one vendor supports and documents, sitting alongside forms rather than replacing them. Nothing on the pages read here says the hashtag by itself is the grant.
Sources
- Nosto, Shoppable UGC, fetched 2 September 2026
- Dash Social, UGC Platform, fetched 2 September 2026
- Dash Social, home, fetched 2 September 2026
- Taggbox, UGC Rights Management, fetched 2 September 2026
Vendor claims and page wording verified 2 September 2026 by fetching each page above. Redirect status for stackla.com and dashhudson.com checked the same day. This is not Watchdog data and it is not on the re-verification schedule.
