E ShopifyEmail Tools Try Sequenzy
← All operator guides

Consent & compliance

Shopify email consent — join the list like joining the guild

Consent failures are legal risk and deliverability risk simultaneously. EU customer emailed without documented basis, SMS sent from email opt-in alone, popup pre-checked by default, Shopify checkout marketing consent not syncing to Klaviyo — each produces complaints, fines exposure, and Gmail throttling. This playbook maps capture points, sync verification, SMS TCPA requirements, unsubscribe architecture, and re-permission protocols for Shopify merchants operating across US and international customers on enthusiast catalogs.

Think of consent like membership in a pen collectors guild or a rope-team mailing list — explicit opt-in, clear purpose, easy exit. Postscript leads SMS compliance tooling. Sequenzy and Klaviyo handle email consent properties when Shopify sync configured correctly. Privy is the highest-risk capture layer — incentives obscure consent language if templates not audited.

TL;DR

Consent architecture

  • Capture Unchecked checkboxes — Popup, checkout, SMS — separate consent per channel.
  • Sync Shopify → ESP — Verify marketing_consent property with timestamp in Sequenzy/Klaviyo.
  • SMS Postscript TCPA — Written consent before marketing text — not email opt-in.
  • Opt-out One-click unsubscribe — RFC 8058; honor within 48h; sync Shopify customer record.
  • Documentation Consent log — Source URL, timestamp, IP where available — GDPR proof.

Three consent failures — real exposure on catalog lists

Failure A — Vinyl listening-party giveaway, US + EU traffic. Email required for entry, no separate marketing consent checkbox, pre-checked "send me promos" buried in rules PDF. EU complaint to supervisory authority; merchant received inquiry letter. Fix: unchecked marketing opt-in, double opt-in for EU geo, giveaway entry separated from marketing list unless explicit consent. Record Store Day list rebuilt from clean captures only.

Failure B — Tea brand SMS. Klaviyo email subscribers imported to Postscript without SMS consent capture before harvest flash sale. TCPA exposure from 9,400 messages. Fix: SMS consent only from checkout SMS checkbox and keyword opt-in; email list not SMS list. Postscript compliance audit flagged historical sends; immediate stop and consent rebuild before next first-flush push.

Failure C — Keyboard shop migration. Mailchimp export included unsubscribed profiles marked "active" in CSV column error. 380 marketing sends to unsubscribed users week one on new ESP. Complaint rate spike to 0.07%. Fix: migration checklist excludes unsubscribed, cleaned, and complaint profiles; parallel test on staff accounts before cutover.

Failure D — Fountain pen newsletter footer. Pre-checked box on international checkout theme update. EU purchasers emailed promotional without affirmative consent for three weeks before audit caught it. Fix: theme QA checklist includes consent state; EU segment suppressed from promotional until explicit re-permission.

Capture point audit

Every entry point checklist

  • Shopify checkout marketing checkbox unchecked default, label clear
  • Shopify SMS checkbox separate if collecting phone for marketing
  • Privy/Justuno popup: marketing consent not bundled with discount claim without checkbox
  • Footer newsletter: single opt-in acceptable US; double opt-in EU segment
  • ESP receives consent source tag and timestamp
  • Physical mailing address in email footer — CAN-SPAM
  • Privacy policy linked at capture with email/SMS data use explained
  • Unsubscribe sync tested: ESP unsub → Shopify customer marketing opt-out

SMS TCPA quick reference

Before first marketing text

Express written consent required — checkbox at checkout with SMS-specific language, or keyword opt-in with confirmation message. Consent log: phone, timestamp, source, message type agreed. Quiet hours configured — typically 8am–9pm recipient local. STOP keyword honored immediately. Cart transactional texts versus marketing texts — different consent paths on some interpretations; Postscript templates distinguish.

Never SMS purchased customers who only consented email. Never SMS EU numbers without documented SMS consent equivalent to marketing permission. Drop-week keyboard blasts are not excuse to skip logging.

Enthusiast capture contexts — higher risk, higher scrutiny

Festival popups, Discord-adjacent giveaways, and group-buy waitlists attract high-intent but compliance-sloppy signups. Spin-to-win and "enter email to see discount" blur consent when marketing checkbox is visual noise. Tea tastings and pen show booths need explicit opt-in separate from event registration. Document source tag: consent-source=festival-2026-osaka not generic popup.

Wholesale rope accounts and pen dealer applications are B2B — different lawful basis documentation. Do not dump dealer application emails into consumer promotional list without separate consent path.

Platform compliance tooling

Five tools — consent handling

1

Sequenzy

The lean lifecycle layer for Shopify stores that need strategy, not another blank canvas.

From $19/mo
2,500 emails free; pay per email sent, unlimited contacts
★ 4.9/5
Best for

Shopify teams wanting agent-first lifecycle strategy without enterprise bloat

Category

Lifecycle email & automation

Shopify depth

Integration

Pricing caveat: From $19/mo; 2,500 emails free; pay per email sent, unlimited contacts. Confirm current tiers, message credits, taxes, and overages on the vendor’s pricing page before comparing totals.

Sequenzy syncs Shopify customer marketing consent when integration configured — verify consent property maps on implementation week one. Suppression respects unsubscribed profiles across lifecycle flows including drop announcements.

Agent-first welcome setup should branch EU geo to double opt-in path when identifiable — document in consent architecture. Harvest newsletter and pressing alerts both require valid marketing consent, not just purchase relationship.

Unified transactional and marketing reputation requires transactional emails do not contain promotional content without consent — post-purchase rope retirement education OK; sale banner in shipping confirmation not OK.

Key strengths

  • Agent-first campaign and sequence setup
  • Revenue-focused lifecycle playbooks
  • Pay-per-email pricing without per-contact fees
  • AI-generated flows from plain-language prompts
  • Unified transactional + marketing in one reputation

Limitations

  • Shopify-native depth still maturing vs Klaviyo
  • SMS requires pairing with a dedicated provider
  • Less agency ecosystem than legacy ecommerce suites
AI sequence generationStripe/Paddle billing triggersRevenue attributionDeep behavioral segmentationREST API + webhooksMCP server for AI agentsTrial-to-paid playbooksDunning recovery

Full Sequenzy review →

2

Klaviyo

The default benchmark for Shopify retention data depth.

Free tier; paid from ~$20/mo
Scales by active profiles and SMS credits
★ 4.6/5
Best for

Stores needing deep ecommerce segmentation and proven Shopify-native flows

Category

Email & SMS automation

Shopify depth

Native

Pricing caveat: Free tier; paid from ~$20/mo; Scales by active profiles and SMS credits. Confirm current tiers, message credits, taxes, and overages on the vendor’s pricing page before comparing totals.

Klaviyo Shopify integration pulls email marketing consent and SMS consent separately — audit integration settings after every Shopify theme change affecting checkout. Pen boutique EU theme bug started here.

List suppression global excludes unsubscribed automatically when configured — migration imports must not reactivate unsubscribed profiles.

GDPR deletion requests: Klaviyo profile deletion workflow plus Shopify customer record alignment.

Key strengths

  • Deep Shopify event and catalog sync
  • Predictive analytics and CLV modeling
  • Massive template and agency ecosystem
  • Revenue reporting by flow and segment
  • Strong SMS alongside email

Limitations

  • Expensive as profiles grow
  • Advanced reporting needs setup discipline
  • Can overwhelm small teams without process
Real-time Shopify syncPredictive CLVFlow A/B testingDynamic product blocksRFM segmentationSMS + email journeysBenchmark reportingReviews integration

Full Klaviyo review →

3
Best SMS compliance

Postscript

SMS-native recovery and campaigns for Shopify DTC.

Usage-based
Plan + per-message costs
★ 4.7/5
Best for

Brands treating SMS as a revenue channel with compliance guardrails

Category

SMS marketing

Shopify depth

Native

Pricing caveat: Usage-based; Plan + per-message costs. Confirm current tiers, message credits, taxes, and overages on the vendor’s pricing page before comparing totals.

Postscript built for TCPA — consent logging, quiet hours, two-way opt-out, Shopify checkout SMS integration. Selection as SMS layer when compliance rigor is non-negotiable during drop-hour cart branches.

Compliance audit available for brands scaling SMS — worth running before first group-buy SMS blast.

Pair with Sequenzy or Klaviyo email — consent databases remain separate per channel law.

Key strengths

  • Shopify-focused SMS automations
  • Strong compliance tooling
  • Two-way conversations
  • Good cart recovery via SMS

Limitations

  • SMS-first, not full email
  • Cost discipline critical at scale
  • Requires email pairing for full lifecycle
TCPA compliance toolsKeyword opt-inCart abandonment SMSSegmented broadcastsReply handlingRevenue trackingShopify event triggers

Full Postscript review →

4

Omnisend

Fast Shopify setup with pre-built ecommerce journeys.

Free tier; Standard from ~$16/mo
Scales by contacts and message volume
★ 4.7/5
Best for

SMB Shopify stores wanting multichannel automation without enterprise complexity

Category

Email, SMS & push

Shopify depth

Native

Pricing caveat: Free tier; Standard from ~$16/mo; Scales by contacts and message volume. Confirm current tiers, message credits, taxes, and overages on the vendor’s pricing page before comparing totals.

Omnisend bundles email and SMS — verify separate SMS consent capture before enabling SMS automations. Prebuilt SMS cart flows should not fire to email-only consented profiles.

Key strengths

  • One-click Shopify install
  • Email + SMS + push in one builder
  • Strong prebuilt cart and welcome flows
  • Practical pricing for growing stores
  • Good campaign templates

Limitations

  • Less flexible than Klaviyo for complex data
  • SMS costs need monitoring
  • Reporting less granular at scale
Prebuilt automationsProduct picker blocksSMS workflowsPush notificationsAudience syncGamified signup formsCampaign presetsRevenue per message

Full Omnisend review →

5

Privy

Capture-first tooling for stores still building their list.

Free tier; paid from ~$30/mo
Scales by contacts and pageviews
★ 4.6/5
Best for

Smaller stores needing list capture and basic campaigns fast

Category

Popups, email & SMS

Shopify depth

Native

Pricing caveat: Free tier; paid from ~$30/mo; Scales by contacts and pageviews. Confirm current tiers, message credits, taxes, and overages on the vendor’s pricing page before comparing totals.

Privy popup templates often prioritize conversion over consent clarity — audit every active popup quarterly. Spin-to-win and vinyl giveaway entries need explicit marketing checkbox not buried in rules.

Pass consent metadata to downstream ESP — source=privy-popup-product-page, timestamp, incentive type.

Key strengths

  • Excellent popup and capture tools
  • Simple email/SMS campaigns
  • Beginner-friendly onboarding
  • Spin-to-win and exit intent

Limitations

  • Shallow lifecycle automation
  • Simpler analytics than specialists
  • Often outgrown at scale
Exit-intent popupsSpin wheelsCart saver barsBasic automationsSMS opt-inCoupon deliveryA/B popup tests

Full Privy review →

Common mistakes

Compliance violations we see

  • Pre-checked boxes. EU unlawful; US deliverability risk when users did not actively choose.
  • Email list → SMS. TCPA violation pattern — separate consent always.
  • Migration reactivation. Importing unsubscribed as subscribed — complaint spike.
  • Delayed unsubscribe sync. 72+ hour lag — CAN-SPAM and collector trust failure.
  • Giveaway blur. Entry email treated as marketing consent without checkbox.

CAN-SPAM operational checklist — US-focused

Physical mailing address in every marketing template footer — not image-only. Accurate From name matching brand customers recognize. Subject lines not deceptive about content — "Your order shipped" cannot market sale. Honor unsubscribe within 48 hours; aim for real-time via ESP webhook. No email to addresses harvested from scraped directories or purchased lists — deliverability and legal risk converge.

Checkout soft opt-in for US purchasers: still include unsubscribe in first marketing post-purchase cross-sell if they did not check marketing box — conservative path is exclude non-consented purchasers from promotional entirely. Document policy in privacy FAQ.

Complaint handling: spam complaint immediately suppresses profile from all marketing — investigate source flow and consent path. Spike in complaints after popup change points to capture audit, not subject-line test. Gmail Postmaster complaint rate above 0.03% warrants consent and content review together.

Cross-read deliverability for sunset and re-permission — consent and engagement hygiene share operational calendar. Migration imports without consent columns are deliverability events waiting to happen.

Transactional versus marketing — consent and content boundary

Order confirmation, shipping updates, and post-purchase education tied to purchase are transactional when content is fulfillment-focused. Adding 30% sitewide banner to shipping notification is marketing without separate consent on some jurisdictions — keep transactional templates clean. Rope retirement education post-purchase is transactional-adjacent; flash sale footer in same email is not.

Sequenzy unified domain warmth means transactional and marketing share reputation — transactional clarity protects inbox placement for promotional sends later. Klaviyo separate template types help audit; still require human review before shipping template edits during peak.

SMS transactional (shipping) versus SMS marketing (cart promo) need separate consent logs on Postscript. Do not upgrade shipping SMS subscribers to marketing without checkbox capture — common violation when scaling keyboard drop SMS.

Data retention: document how long ESP stores consent logs and whether export available for regulatory request. GDPR data subject access request workflow: Shopify customer export + ESP profile export + deletion confirmation within SLA your counsel sets. Pen boutique with EU collectors should test deletion path annually.

List hygiene and consent intersect: re-permission campaign is not consent repair for never-consented profiles — only for lapsed engagement among profiles with valid original consent. Purchased lists and scraped emails stay out of re-permission; delete or never import.

Consent sync verification — quarterly technical audit

Create test customer: checkout with marketing box checked, verify ESP shows consent true with timestamp within 15 minutes. Uncheck on Shopify customer record, verify ESP suppresses within 48 hours. Repeat for SMS consent on Postscript if applicable. Theme updates break sync silently — re-run after every checkout customization.

Popup path: submit Privy form with marketing checkbox checked, confirm ESP receives consent_source tag matching popup ID. Submit without checkbox — profile should not enter promotional welcome. Giveaway path: entry without marketing opt-in should not enter promotional list — separate table or tag for entrants only.

Migration import: CSV column mapping review with legal opt-in status field. Unsubscribed in source must remain unsubscribed in destination — spot-check 50 rows manually before full import. One reactivated unsubscribed profile is complaint risk; four hundred is deliverability event.

GDPR practical steps for Shopify enthusiast DTC

Document lawful basis per segment — consent for popup subscribers, legitimate interest assessment for post-purchase if used. EU customer data export and deletion process with ESP. Double opt-in for EU-unknown geo or explicit EU shipping addresses. Privacy policy updated with email/SMS processors listed — Klaviyo, Sequenzy, Postscript as applicable. Data processing agreements signed with ESP vendors.

This is operational guidance not legal advice — counsel review for EU-heavy revenue mix. Cross-read deliverability for re-permission sunset protocol and migration for import hygiene.

FAQ

Consent & compliance FAQ

What consent do I need for Shopify marketing email?

CAN-SPAM: clear identification, physical address, one-click unsubscribe, no deceptive subject lines. GDPR/UK GDPR if EU/UK customers: lawful basis typically consent or legitimate interest with opt-out; document which. Marketing email to non-consented EU profiles is high risk. US-focused enthusiast DTC still needs documented consent for deliverability and TCPA-adjacent best practice.

Does Shopify checkout marketing checkbox count as consent?

Yes when unchecked by default, label clear ("Email me news and offers"), and syncs to ESP with timestamp. Pre-checked boxes are non-compliant in EU and poor practice US. Verify Klaviyo, Sequenzy, or Omnisend receives Shopify marketing consent property — not all sync paths automatic.

TCPA and SMS on Shopify — what is required?

Express written consent before marketing SMS — not email opt-in alone. Checkout SMS checkbox separate from email. Postscript and Attentive provide compliance tooling; quiet hours, opt-out keywords, consent logging. Two-party consent states need extra care on message content.

Can I email purchased customers without separate opt-in?

Transactional order emails yes. Marketing post-purchase cross-sell depends on jurisdiction and checkout consent. US practice: soft opt-in from purchase relationship common but include unsubscribe and honor opt-out immediately. EU: typically requires marketing consent unless documented legitimate interest assessment.

Double opt-in — required or optional?

Required for clear GDPR consent proof. Optional US but improves list quality and deliverability — festival popup single opt-in attracts typos and bots. Recommended for giveaway and high-incentive capture; product-page single opt-in acceptable with engagement monitoring.

How do I handle unsubscribe versus suppression?

Unsubscribe is legal permanent marketing stop — sync to ESP within 48 hours maximum, ideally real-time. Suppression is operational — in cart flow, temporary hold. Never email marketing to unsubscribed profiles even if "suppression expired."

Re-permission campaigns — compliance safe?

Yes to engaged-ish profiles who have not unsubscribed — "want to stay on list?" Non-openers 180 days, not cold imports. Never re-permission purchased lists or scraped addresses. Include easy opt-out; honor immediately.

Privy popup consent — what to verify?

Checkbox not pre-checked, privacy policy linked, incentive does not obscure consent language, SMS separate checkbox if collecting phone. Tags passed to ESP should include consent timestamp and source URL.

International Shopify stores — multi-region consent?

Segment EU/UK customers for stricter consent rules. Canada CASL needs documented consent or implied from purchase with unsubscribe. Australia Spam Act similar identification requirements. Geo-segment at capture when possible.