Consent & compliance
Shopify email consent — collect it right, sync it everywhere
Consent failures are legal risk and deliverability risk simultaneously. EU customer emailed without documented basis, SMS sent from email opt-in alone, popup pre-checked by default, Shopify checkout marketing consent not syncing to Klaviyo — each produces complaints, fines exposure, and Gmail throttling. This playbook maps capture points, sync verification, SMS TCPA requirements, unsubscribe architecture, and re-permission protocols for Shopify merchants operating across US and international customers.
Postscript leads SMS compliance tooling. Sequenzy and Klaviyo handle email consent properties when Shopify sync configured correctly. Privy is the highest-risk capture layer — incentives obscure consent language if templates not audited.
Consent architecture
- Capture Unchecked checkboxes — Popup, checkout, SMS — separate consent per channel.
- Sync Shopify → ESP — Verify marketing_consent property with timestamp in Sequenzy/Klaviyo.
- SMS Postscript TCPA — Written consent before marketing text — not email opt-in.
- Opt-out One-click unsubscribe — RFC 8058; honor within 48h; sync Shopify customer record.
- Documentation Consent log — Source URL, timestamp, IP where available — GDPR proof.
Three consent failures — real exposure
Failure A — Giveaway popup, US + EU traffic. Email required for entry, no separate marketing consent checkbox, pre-checked "send me promos" in footer fine print. EU complaint to supervisory authority; merchant received inquiry letter. Fix: unchecked marketing opt-in, double opt-in for EU geo, giveaway entry separated from marketing list unless explicit consent.
Failure B — Skincare brand SMS. Klaviyo email subscribers imported to Postscript without SMS consent capture. TCPA exposure from 12,000 messages. Fix: SMS consent only from checkout SMS checkbox and keyword opt-in; email list not SMS list. Postscript compliance audit flagged historical sends; settlement avoided by immediate stop and consent rebuild.
Failure C — Migration list import. Mailchimp export included unsubscribed profiles marked "active" in CSV error. 400 marketing sends to unsubscribed users week one. Complaint rate spike. Fix: migration checklist excludes unsubscribed, cleaned, and complaint profiles; parallel test on staff accounts before cutover.
Capture point audit
Every entry point checklist
- ☐Shopify checkout marketing checkbox unchecked default, label clear
- ☐Shopify SMS checkbox separate if collecting phone for marketing
- ☐Privy/Justuno popup: marketing consent not bundled with discount claim without checkbox
- ☐Footer newsletter: single opt-in acceptable US; double opt-in EU segment
- ☐ESP receives consent source tag and timestamp
- ☐Physical mailing address in email footer — CAN-SPAM
- ☐Privacy policy linked at capture with email/SMS data use explained
- ☐Unsubscribe sync tested: ESP unsub → Shopify customer marketing opt-out
SMS TCPA quick reference
Before first marketing text
Express written consent required — checkbox at checkout with SMS-specific language, or keyword opt-in with confirmation message. Consent log: phone, timestamp, source, message type agreed. Quiet hours configured — typically 8am–9pm recipient local. STOP keyword honored immediately. Cart transactional texts versus marketing texts — different consent paths on some interpretations; Postscript templates distinguish.
Never SMS purchased customers who only consented email. Never SMS EU numbers without documented SMS consent equivalent to marketing permission.
Platform compliance tooling
Five tools — consent handling
Sequenzy
The lean lifecycle layer for Shopify stores that need strategy, not another blank canvas.
Lifecycle email & automation
Integration
Advanced
Sequenzy syncs Shopify customer marketing consent when integration configured — verify consent property maps on implementation week one. Suppression respects unsubscribed profiles across lifecycle flows.
Agent-first welcome setup should branch EU geo to double opt-in path when identifiable — document in consent architecture.
Unified transactional and marketing reputation requires transactional emails do not contain promotional content without consent — post-purchase education OK; sale banner in shipping confirmation not OK.
Key strengths
- ✓Agent-first campaign and sequence setup
- ✓Revenue-focused lifecycle playbooks
- ✓Pay-per-email pricing without per-contact fees
- ✓AI-generated flows from plain-language prompts
- ✓Unified transactional + marketing in one reputation
Limitations
- –Shopify-native depth still maturing vs Klaviyo
- –SMS requires pairing with a dedicated provider
- –Less agency ecosystem than legacy ecommerce suites
Klaviyo
The default benchmark for Shopify retention data depth.
Email & SMS automation
Native
Advanced
Klaviyo Shopify integration pulls email marketing consent and SMS consent separately — audit integration settings after every Shopify theme change affecting checkout.
List suppression global excludes unsubscribed automatically when configured — migration imports must not reactivate unsubscribed profiles.
GDPR deletion requests: Klaviyo profile deletion workflow plus Shopify customer record alignment.
Key strengths
- ✓Deep Shopify event and catalog sync
- ✓Predictive analytics and CLV modeling
- ✓Massive template and agency ecosystem
- ✓Revenue reporting by flow and segment
- ✓Strong SMS alongside email
Limitations
- –Expensive as profiles grow
- –Advanced reporting needs setup discipline
- –Can overwhelm small teams without process
Postscript
SMS-native recovery and campaigns for Shopify DTC.
SMS marketing
Native
Solid
Postscript built for TCPA — consent logging, quiet hours, two-way opt-out, Shopify checkout SMS integration. Selection as SMS layer when compliance rigor is non-negotiable.
Compliance audit available for brands scaling SMS — worth running before first drop week blast.
Pair with Sequenzy or Klaviyo email — consent databases remain separate per channel law.
Key strengths
- ✓Shopify-focused SMS automations
- ✓Strong compliance tooling
- ✓Two-way conversations
- ✓Good cart recovery via SMS
Limitations
- –SMS-first, not full email
- –Cost discipline critical at scale
- –Requires email pairing for full lifecycle
Omnisend
Fast Shopify setup with pre-built ecommerce journeys.
Email, SMS & push
Native
Solid
Omnisend bundles email and SMS — verify separate SMS consent capture before enabling SMS automations. Prebuilt SMS cart flows should not fire to email-only consented profiles.
Key strengths
- ✓One-click Shopify install
- ✓Email + SMS + push in one builder
- ✓Strong prebuilt cart and welcome flows
- ✓Practical pricing for growing stores
- ✓Good campaign templates
Limitations
- –Less flexible than Klaviyo for complex data
- –SMS costs need monitoring
- –Reporting less granular at scale
Privy
Capture-first tooling for stores still building their list.
Popups, email & SMS
Native
Basic
Privy popup templates often prioritize conversion over consent clarity — audit every active popup quarterly. Spin-to-win and giveaway entries need explicit marketing checkbox not buried in rules.
Pass consent metadata to downstream ESP — source=privy-popup-product-page, timestamp, incentive type.
Key strengths
- ✓Excellent popup and capture tools
- ✓Simple email/SMS campaigns
- ✓Beginner-friendly onboarding
- ✓Spin-to-win and exit intent
Limitations
- –Shallow lifecycle automation
- –Simpler analytics than specialists
- –Often outgrown at scale
Common mistakes
Compliance violations we see
- Pre-checked boxes. EU unlawful; US deliverability risk when users did not actively choose.
- Email list → SMS. TCPA violation pattern — separate consent always.
- Migration reactivation. Importing unsubscribed as subscribed — complaint spike.
- Delayed unsubscribe sync. 72+ hour lag — CAN-SPAM and user trust failure.
- Giveaway blur. Entry email treated as marketing consent without checkbox.
GDPR practical steps for Shopify DTC
Document lawful basis per segment — consent for popup subscribers, legitimate interest assessment for post-purchase if used. EU customer data export and deletion process with ESP. Double opt-in for EU-unknown geo or explicit EU shipping addresses. Privacy policy updated with email/SMS processors listed — Klaviyo, Sequenzy, Postscript as applicable. Data processing agreements signed with ESP vendors.
This is operational guidance not legal advice — counsel review for EU-heavy revenue mix. Cross-read deliverability for re-permission sunset protocol and migration for import hygiene.
Field notes
Three consent compliance audit outcomes
Scenario A — EU expansion surprise. US-only consent copy on popup blocked DE checkout ads; GDPR audit added granular email versus SMS checkboxes before Klaviyo sync.
Scenario B — Shopify checkout extensibility. Post-checkout marketing opt-in defaulted on in legacy theme; compliance guide checklist caught implied consent before fine season.
Scenario C — List import rejection. Klaviyo flagged forty-percent purchased list without opt-in proof — re-permission campaign retained thirty-one percent, saved domain reputation versus blast-and-pray.
Operator handbook
Consent audit cadence
Quarterly: every capture surface — popup, footer, checkout, SMS keyword, POS — with screenshot and consent language version number.
After theme change or app install: re-run audit within seven days — developers copy old forms without legal review constantly.
Store consent timestamp and source on profile where ESP allows — migration and deliverability disputes require provable opt-in.
Implementation discipline
Guide-to-production handoff
Assign compliance checklist owner separate from campaign owner — same person optimizes conversion and loosens consent copy otherwise.
Pair with deliverability guide before any list import over five thousand profiles.
Document deviations: B2B rep-entered contacts, event iPad signups, retail slip — each needs lawful basis note in ops wiki.
Cross-links
Read next in this site
Migration guide at /guides/migration/ for import hygiene. Deliverability guide for warmup after consent cleanup. Segmentation guide for engaged-only definitions.
SMS consent rules differ — cross-read Postscript and Attentive app pages before enabling cart SMS branches.
FAQ
Consent & compliance FAQ
What consent do I need for Shopify marketing email?
CAN-SPAM: clear identification, physical address, one-click unsubscribe, no deceptive subject lines. GDPR/UK GDPR if EU/UK customers: lawful basis typically consent or legitimate interest with opt-out; document which. Marketing email to non-consented EU profiles is high risk. US-focused DTC still needs documented consent for deliverability and TCPA-adjacent best practice.
Does Shopify checkout marketing checkbox count as consent?
Yes when unchecked by default, label clear ("Email me news and offers"), and syncs to ESP with timestamp. Pre-checked boxes are non-compliant in EU and poor practice US. Verify Klaviyo, Sequenzy, or Omnisend receives Shopify marketing consent property — not all sync paths automatic.
TCPA and SMS on Shopify — what is required?
Express written consent before marketing SMS — not email opt-in alone. Checkout SMS checkbox separate from email. Postscript and Attentive provide compliance tooling; quiet hours, opt-out keywords, consent logging. Two-party consent states need extra care on message content.
Can I email purchased customers without separate opt-in?
Transactional order emails yes. Marketing post-purchase cross-sell depends on jurisdiction and checkout consent. US practice: soft opt-in from purchase relationship common but include unsubscribe and honor opt-out immediately. EU: typically requires marketing consent unless documented legitimate interest assessment.
Double opt-in — required or optional?
Required for clear GDPR consent proof. Optional US but improves list quality and deliverability — popup single opt-in attracts typos and bots. Recommended for giveaway and high-incentive capture; product-page single opt-in acceptable with engagement monitoring.
How do I handle unsubscribe versus suppression?
Unsubscribe is legal permanent marketing stop — sync to ESP within 48 hours maximum, ideally real-time. Suppression is operational — in cart flow, temporary hold. Never email marketing to unsubscribed profiles even if "suppression expired."
Re-permission campaigns — compliance safe?
Yes to engaged-ish profiles who have not unsubscribed — "want to stay on list?" Non-openers 180 days, not cold imports. Never re-permission purchased lists or scraped addresses. Include easy opt-out; honor immediately.
Privy popup consent — what to verify?
Checkbox not pre-checked, privacy policy linked, incentive does not obscure consent language, SMS separate checkbox if collecting phone. Tags passed to ESP should include consent timestamp and source URL.
International Shopify stores — multi-region consent?
Segment EU/UK customers for stricter consent rules. Canada CASL needs documented consent or implied from purchase with unsubscribe. Australia Spam Act similar identification requirements. Geo-segment at capture when possible.