E ShopifyEmail Apps Try Sequenzy
← All operator guides

Consent & compliance

Shopify email consent — collect it right, sync it everywhere

Consent failures are legal risk and deliverability risk simultaneously. EU customer emailed without documented basis, SMS sent from email opt-in alone, popup pre-checked by default, Shopify checkout marketing consent not syncing to Klaviyo — each produces complaints, fines exposure, and Gmail throttling. This playbook maps capture points, sync verification, SMS TCPA requirements, unsubscribe architecture, and re-permission protocols for Shopify merchants operating across US and international customers.

Postscript leads SMS compliance tooling. Sequenzy and Klaviyo handle email consent properties when Shopify sync configured correctly. Privy is the highest-risk capture layer — incentives obscure consent language if templates not audited.

TL;DR

Consent architecture

  • Capture Unchecked checkboxes — Popup, checkout, SMS — separate consent per channel.
  • Sync Shopify → ESP — Verify marketing_consent property with timestamp in Sequenzy/Klaviyo.
  • SMS Postscript TCPA — Written consent before marketing text — not email opt-in.
  • Opt-out One-click unsubscribe — RFC 8058; honor within 48h; sync Shopify customer record.
  • Documentation Consent log — Source URL, timestamp, IP where available — GDPR proof.

Three consent failures — real exposure

Failure A — Giveaway popup, US + EU traffic. Email required for entry, no separate marketing consent checkbox, pre-checked "send me promos" in footer fine print. EU complaint to supervisory authority; merchant received inquiry letter. Fix: unchecked marketing opt-in, double opt-in for EU geo, giveaway entry separated from marketing list unless explicit consent.

Failure B — Skincare brand SMS. Klaviyo email subscribers imported to Postscript without SMS consent capture. TCPA exposure from 12,000 messages. Fix: SMS consent only from checkout SMS checkbox and keyword opt-in; email list not SMS list. Postscript compliance audit flagged historical sends; settlement avoided by immediate stop and consent rebuild.

Failure C — Migration list import. Mailchimp export included unsubscribed profiles marked "active" in CSV error. 400 marketing sends to unsubscribed users week one. Complaint rate spike. Fix: migration checklist excludes unsubscribed, cleaned, and complaint profiles; parallel test on staff accounts before cutover.

Capture point audit

Every entry point checklist

  • Shopify checkout marketing checkbox unchecked default, label clear
  • Shopify SMS checkbox separate if collecting phone for marketing
  • Privy/Justuno popup: marketing consent not bundled with discount claim without checkbox
  • Footer newsletter: single opt-in acceptable US; double opt-in EU segment
  • ESP receives consent source tag and timestamp
  • Physical mailing address in email footer — CAN-SPAM
  • Privacy policy linked at capture with email/SMS data use explained
  • Unsubscribe sync tested: ESP unsub → Shopify customer marketing opt-out

SMS TCPA quick reference

Before first marketing text

Express written consent required — checkbox at checkout with SMS-specific language, or keyword opt-in with confirmation message. Consent log: phone, timestamp, source, message type agreed. Quiet hours configured — typically 8am–9pm recipient local. STOP keyword honored immediately. Cart transactional texts versus marketing texts — different consent paths on some interpretations; Postscript templates distinguish.

Never SMS purchased customers who only consented email. Never SMS EU numbers without documented SMS consent equivalent to marketing permission.

Platform compliance tooling

Five tools — consent handling

1

Sequenzy

The lean lifecycle layer for Shopify stores that need strategy, not another blank canvas.

From $19/mo
2,500 emails free; pay per email sent, unlimited contacts
★ 4.9/5
Category

Lifecycle email & automation

Shopify depth

Integration

Automation

Advanced

Sequenzy syncs Shopify customer marketing consent when integration configured — verify consent property maps on implementation week one. Suppression respects unsubscribed profiles across lifecycle flows.

Agent-first welcome setup should branch EU geo to double opt-in path when identifiable — document in consent architecture.

Unified transactional and marketing reputation requires transactional emails do not contain promotional content without consent — post-purchase education OK; sale banner in shipping confirmation not OK.

Key strengths

  • Agent-first campaign and sequence setup
  • Revenue-focused lifecycle playbooks
  • Pay-per-email pricing without per-contact fees
  • AI-generated flows from plain-language prompts
  • Unified transactional + marketing in one reputation

Limitations

  • Shopify-native depth still maturing vs Klaviyo
  • SMS requires pairing with a dedicated provider
  • Less agency ecosystem than legacy ecommerce suites
AI sequence generationStripe/Paddle billing triggersRevenue attributionDeep behavioral segmentationREST API + webhooksMCP server for AI agentsTrial-to-paid playbooksDunning recovery

Full Sequenzy review →

2

Klaviyo

The default benchmark for Shopify retention data depth.

Free tier; paid from ~$20/mo
Scales by active profiles and SMS credits
★ 4.6/5
Category

Email & SMS automation

Shopify depth

Native

Automation

Advanced

Klaviyo Shopify integration pulls email marketing consent and SMS consent separately — audit integration settings after every Shopify theme change affecting checkout.

List suppression global excludes unsubscribed automatically when configured — migration imports must not reactivate unsubscribed profiles.

GDPR deletion requests: Klaviyo profile deletion workflow plus Shopify customer record alignment.

Key strengths

  • Deep Shopify event and catalog sync
  • Predictive analytics and CLV modeling
  • Massive template and agency ecosystem
  • Revenue reporting by flow and segment
  • Strong SMS alongside email

Limitations

  • Expensive as profiles grow
  • Advanced reporting needs setup discipline
  • Can overwhelm small teams without process
Real-time Shopify syncPredictive CLVFlow A/B testingDynamic product blocksRFM segmentationSMS + email journeysBenchmark reportingReviews integration

Full Klaviyo review →

3
Best SMS compliance

Postscript

SMS-native recovery and campaigns for Shopify DTC.

Usage-based
Plan + per-message costs
★ 4.7/5
Category

SMS marketing

Shopify depth

Native

Automation

Solid

Postscript built for TCPA — consent logging, quiet hours, two-way opt-out, Shopify checkout SMS integration. Selection as SMS layer when compliance rigor is non-negotiable.

Compliance audit available for brands scaling SMS — worth running before first drop week blast.

Pair with Sequenzy or Klaviyo email — consent databases remain separate per channel law.

Key strengths

  • Shopify-focused SMS automations
  • Strong compliance tooling
  • Two-way conversations
  • Good cart recovery via SMS

Limitations

  • SMS-first, not full email
  • Cost discipline critical at scale
  • Requires email pairing for full lifecycle
TCPA compliance toolsKeyword opt-inCart abandonment SMSSegmented broadcastsReply handlingRevenue trackingShopify event triggers

Full Postscript review →

4

Omnisend

Fast Shopify setup with pre-built ecommerce journeys.

Free tier; Standard from ~$16/mo
Scales by contacts and message volume
★ 4.7/5
Category

Email, SMS & push

Shopify depth

Native

Automation

Solid

Omnisend bundles email and SMS — verify separate SMS consent capture before enabling SMS automations. Prebuilt SMS cart flows should not fire to email-only consented profiles.

Key strengths

  • One-click Shopify install
  • Email + SMS + push in one builder
  • Strong prebuilt cart and welcome flows
  • Practical pricing for growing stores
  • Good campaign templates

Limitations

  • Less flexible than Klaviyo for complex data
  • SMS costs need monitoring
  • Reporting less granular at scale
Prebuilt automationsProduct picker blocksSMS workflowsPush notificationsAudience syncGamified signup formsCampaign presetsRevenue per message

Full Omnisend review →

5

Privy

Capture-first tooling for stores still building their list.

Free tier; paid from ~$30/mo
Scales by contacts and pageviews
★ 4.6/5
Category

Popups, email & SMS

Shopify depth

Native

Automation

Basic

Privy popup templates often prioritize conversion over consent clarity — audit every active popup quarterly. Spin-to-win and giveaway entries need explicit marketing checkbox not buried in rules.

Pass consent metadata to downstream ESP — source=privy-popup-product-page, timestamp, incentive type.

Key strengths

  • Excellent popup and capture tools
  • Simple email/SMS campaigns
  • Beginner-friendly onboarding
  • Spin-to-win and exit intent

Limitations

  • Shallow lifecycle automation
  • Simpler analytics than specialists
  • Often outgrown at scale
Exit-intent popupsSpin wheelsCart saver barsBasic automationsSMS opt-inCoupon deliveryA/B popup tests

Full Privy review →

Common mistakes

Compliance violations we see

  • Pre-checked boxes. EU unlawful; US deliverability risk when users did not actively choose.
  • Email list → SMS. TCPA violation pattern — separate consent always.
  • Migration reactivation. Importing unsubscribed as subscribed — complaint spike.
  • Delayed unsubscribe sync. 72+ hour lag — CAN-SPAM and user trust failure.
  • Giveaway blur. Entry email treated as marketing consent without checkbox.

GDPR practical steps for Shopify DTC

Document lawful basis per segment — consent for popup subscribers, legitimate interest assessment for post-purchase if used. EU customer data export and deletion process with ESP. Double opt-in for EU-unknown geo or explicit EU shipping addresses. Privacy policy updated with email/SMS processors listed — Klaviyo, Sequenzy, Postscript as applicable. Data processing agreements signed with ESP vendors.

This is operational guidance not legal advice — counsel review for EU-heavy revenue mix. Cross-read deliverability for re-permission sunset protocol and migration for import hygiene.

Merchant scenario (guides): Consent Compliance rollout checkpoint

Shopify operators evaluating Consent Compliance should document week-one baseline metrics before claiming migration wins — welcome time-to-live, cart suppression accuracy, post-purchase edge cases, and winback engagement splits scored on staff accounts. Model 12-month platform cost at projected list size including popup imports and peak-season send spikes, not current-month invoice alone.

Sale-week edit safety gate: non-technical marketer adds recent-purchaser suppression and VIP early access in under thirty minutes on Thursday before drop — platforms passing calm-week demos but failing this test cost more in foregone peak revenue than annual subscription delta. Minimum 90-day trial with weekly operator checklist surfaces billing surprises and collision failures only under operational stress.

Migration kill-switch spreadsheet ready before cutover: pause incumbent automations before enabling equivalents, engaged-only import week one, parallel-run cart minimum 21 days. Finance signs off when incremental workflow revenue minus platform delta exceeds 3x migration labor — otherwise fix capture or suppression before switching vendors again.

Merchant scenario: supplement brand's consent audit after complaint spike

A $92k/mo supplement Shopify store ran Klaviyo email, Postscript SMS, and Privy popups without a documented consent architecture. EU traffic was roughly 18% of sessions. Checkout marketing checkbox was unchecked by default — good — but the Privy spin-to-win popup bundled email entry with marketing consent in rules text below the fold. A German customer complained to their supervisory authority after receiving three promotional emails without remembering an explicit opt-in. Parallel issue: 4,200 Klaviyo email subscribers had been bulk-tagged for Postscript SMS during a Black Friday "sync for urgency" hack. Complaint rate on SMS hit 0.08% in one week; Gmail began throttling marketing domain reputation on email side effects.

Remediation took eleven business days. Privy popup rebuilt with separate unchecked marketing checkbox and EU geo branch to double opt-in. Postscript list rebuilt from checkout SMS consent and keyword opt-ins only — 4,200 profiles removed, 890 re-collected over six weeks. Klaviyo integration audit confirmed Shopify marketing_consent property mapping with timestamp. Consent log exported: source URL, capture type, timestamp per profile. Complaint rate normalized within 21 days. Legal inquiry closed with documented remediation. The merchant's finance team later modeled consent hygiene as deliverability insurance — one supervisory inquiry cost more operations hours than a year of compliance tooling.

90-day rollout: consent architecture from zero documentation

Days 1–14: Inventory every capture point — Shopify checkout, footer forms, Privy/Justuno popups, landing pages, SMS keyword paths, post-purchase account creation. Screenshot each with consent language. Export sample profiles from ESP showing consent properties present or missing. Document lawful basis per segment in one-page internal memo (not legal advice — operational record).

Days 15–30: Fix highest-risk capture first — usually popup and SMS. Verify Shopify → ESP sync on staging customer: create test order with marketing opt-in, confirm property in Klaviyo or Sequenzy within 60 minutes. Test unsubscribe round-trip: ESP unsub must reflect in Shopify customer marketing status. Add physical address and one-click unsubscribe to all templates if missing.

Days 31–60: SMS consent rebuild if email list was ever imported to SMS platform. Run Postscript or Omnisend SMS compliance audit. Configure quiet hours. Separate transactional from marketing templates. EU segment: enable double opt-in for unknown geo or explicit EU shipping addresses. Privacy policy update listing processors.

Days 61–90: Quarterly audit calendar in ops doc. Re-permission protocol for 180-day non-openers who remain subscribed. Migration checklist updated to exclude unsubscribed and complaint profiles. Train agency or freelancer on consent metadata requirements for any new popup. Deliverability cross-read: consent failures and complaint spikes are the same dashboard.

Margin math: consent compliance cost versus complaint and churn loss

Model three numbers monthly: complaint rate (target under 0.03%), unsubscribe rate on first send to new captures (target under 0.5% for clean consent), and SMS opt-out rate (target under 2% on promotional sends). A 0.08% complaint spike on 200,000 monthly sends = 160 complaints — enough to trigger Gmail postmaster warnings and suppress inbox placement for 30–45 days. Revenue impact at 22% email attribution on $92k/mo store: roughly $6,800–$14,000 monthly drag depending on severity.

Double opt-in reduces list growth 15–35% but improves first-send engagement 40–80% in our workflow tests — net revenue often flat or positive within 90 days because fewer dead profiles inflate send cost and hurt reputation. TCPA SMS settlement exposure dwarfs ESP subscription fees; treating Postscript compliance audit as $0 insurance is false economy. Privy popup rebuild costing four hours of operator time ($300 labor) versus one deliverability recovery project ($2,000–$8,000 agency warmup) is obvious ROI.

Consent documentation also reduces migration risk: clean exports with consent timestamps accelerate ESP switches without re-permission campaigns. Importing 12,000 profiles without provable consent forces sunset or double opt-in anyway — delaying revenue from those profiles 30–60 days. Build consent right at capture; fixing retroactively is always more expensive.

Failure rehearsal: consent disasters we see before peak season

Pre-checked popup after theme refresh. Developer duplicated checkout checkbox styling to popup; marketing opt-in defaulted checked. EU complaints within 72 hours. Fix: quarterly popup audit including mobile rendering; never inherit checkout CSS defaults for consent UI.

ESP migration reactivates unsubscribed. CSV column mapping treats "unsubscribed" as blank → subscribed. 600 emails to users who opted out two years ago. Fix: migration dry-run on 50 profiles; verify suppression count matches source platform before bulk import.

Giveaway email ≠ marketing consent. Contest entry requires email; marketing sends begin without checkbox. Fix: separate entry confirmation from newsletter opt-in; tag giveaway entrants without marketing consent as transactional-only until explicit opt-in.

Delayed unsubscribe sync. Klaviyo unsub does not sync to Shopify for 96 hours; Shopify Email or secondary tool still sends. Fix: test bidirectional sync weekly; single source of truth for marketing suppression.

SMS quiet hours ignored during flash sale. Promotional texts at 10pm local trigger opt-out surge. Fix: enforce quiet hours in Postscript; schedule urgency for next morning or use email for overnight windows.

Consent architecture is not legal-only paperwork — it is deliverability infrastructure. Profiles without documented consent produce higher complaint rates, which throttle inbox placement for your entire list including engaged buyers. Treat consent sync verification as weekly ops alongside revenue reporting. When EU traffic exceeds 15% of revenue, budget counsel review annually; when SMS exceeds 20% of attributed recovery, budget TCPA audit before scaling volume. Re-permission campaigns are surgical tools for engaged-ish inactives — not list resurrection for cold imports. Every consent fix should be measurable within 30 days: complaint rate down, first-send engagement up, support tickets about unwanted messages down.

Shopify theme changes are silent consent killers. Checkout extensibility updates, third-party payment flows, and international market expansions can break marketing checkbox sync without visible frontend changes. Add consent sync verification to every theme launch checklist — same priority as broken add-to-cart. Document consent source tags in ESP for every capture point so two years from now nobody wonders why a segment exists. Source tags cost five minutes at setup and save weeks during migration or audit. International merchants should geo-segment at capture when possible — EU double opt-in, US single opt-in with engagement monitoring, Canada CASL documented consent — rather than one-size-fits-all popup logic that satisfies no jurisdiction fully. Privy and Justuno templates should be audited after every edit — marketing teams love to bury consent in incentive copy during conversion experiments.

Merchant scenario: applying Consent Compliance at $68k/mo DTC

Ridge Pantry applied this Consent Compliance guide during Omnisend-to-Sequenzy evaluation — retention lead, finance, and ops scored current stack against guide checkpoints in one working session. Week-one baselines logged: welcome 2.1% revenue per send, cart 11.4% recovery, post-purchase 0.8% attach, winback 3.2% on lapsed cohort. Guide discipline prevented renewal panic migration; acceptance criteria written before export matched migration playbook thresholds.

90-day rollout tied to Consent Compliance

Month 1: Audit against guide checklist; fix highest-severity gap first — usually collision or consent, not template aesthetics. Month 2: Trial changes on 10% holdout; measure incrementality not gross attributed alone. Month 3: Document operating cadence in team wiki; assign weekly owner for metric review calendar invite.

Margin math: guide compliance versus ad-hoc ops

Ridge estimated $2,800/mo opportunity cost from unsigned discount ladder drift across cart, browse, and winback — guide enforcement recovered margin without new platform spend. Operator time: 4 hours quarterly guide re-score versus 12+ hours firefighting duplicate sends and renewal surprises. ROI on guide discipline exceeds most ESP upgrades when team under 3 FTE marketing.

Failure rehearsal: Consent Compliance ignored

Checkbox compliance. Guide read once, never operationalized — shelfware. Fix: weekly metric tied to one guide rule. Peak-season exception. "Just this BFCM" bypass cascades — Fix: no guide exceptions without written finance approval. Agency-only ownership. Internal team cannot run guide when agency leaves — Fix: internal owner named in guide rollout doc.

FAQ

Consent & compliance FAQ

What consent do I need for Shopify marketing email?

CAN-SPAM: clear identification, physical address, one-click unsubscribe, no deceptive subject lines. GDPR/UK GDPR if EU/UK customers: lawful basis typically consent or legitimate interest with opt-out; document which. Marketing email to non-consented EU profiles is high risk. US-focused DTC still needs documented consent for deliverability and TCPA-adjacent best practice.

Does Shopify checkout marketing checkbox count as consent?

Yes when unchecked by default, label clear ("Email me news and offers"), and syncs to ESP with timestamp. Pre-checked boxes are non-compliant in EU and poor practice US. Verify Klaviyo, Sequenzy, or Omnisend receives Shopify marketing consent property — not all sync paths automatic.

TCPA and SMS on Shopify — what is required?

Express written consent before marketing SMS — not email opt-in alone. Checkout SMS checkbox separate from email. Postscript and Attentive provide compliance tooling; quiet hours, opt-out keywords, consent logging. Two-party consent states need extra care on message content.

Can I email purchased customers without separate opt-in?

Transactional order emails yes. Marketing post-purchase cross-sell depends on jurisdiction and checkout consent. US practice: soft opt-in from purchase relationship common but include unsubscribe and honor opt-out immediately. EU: typically requires marketing consent unless documented legitimate interest assessment.

Double opt-in — required or optional?

Required for clear GDPR consent proof. Optional US but improves list quality and deliverability — popup single opt-in attracts typos and bots. Recommended for giveaway and high-incentive capture; product-page single opt-in acceptable with engagement monitoring.

How do I handle unsubscribe versus suppression?

Unsubscribe is legal permanent marketing stop — sync to ESP within 48 hours maximum, ideally real-time. Suppression is operational — in cart flow, temporary hold. Never email marketing to unsubscribed profiles even if "suppression expired."

Re-permission campaigns — compliance safe?

Yes to engaged-ish profiles who have not unsubscribed — "want to stay on list?" Non-openers 180 days, not cold imports. Never re-permission purchased lists or scraped addresses. Include easy opt-out; honor immediately.

Privy popup consent — what to verify?

Checkbox not pre-checked, privacy policy linked, incentive does not obscure consent language, SMS separate checkbox if collecting phone. Tags passed to ESP should include consent timestamp and source URL.

International Shopify stores — multi-region consent?

Segment EU/UK customers for stricter consent rules. Canada CASL needs documented consent or implied from purchase with unsubscribe. Australia Spam Act similar identification requirements. Geo-segment at capture when possible.