TCPA · By industry
TCPA compliance for ecommerce SMS marketing
TCPA compliance for an ecommerce store means the signup forms behind your SMS marketing, loyalty texts, and abandoned-cart messages capture prior express written consent before a single promotional text goes out, because the Telephone Consumer Protection Act prices every text at $500 to $1,500, with no cap. Complidar checks the consent language and disclosures on every phone-collecting form in your store, the same surface a plaintiff's firm screenshots first.
The exposure is per text, times your list
The number that matters is not a headline verdict, it is the multiplication. Statutory damages run $500 per negligent violation and up to $1,500 per willful one, with no cap, and every message sent on a defective consent is its own violation. A 25,000-subscriber SMS list texted twice a month is 600,000 sends a year, so a single consent defect in how that list was collected is theoretical exposure in the hundreds of millions before a class is even argued. That is why the store's signup form, not the texting platform, is where these cases are won and lost.
Class-action outcomes only show the ceiling that math reaches. As scale illustrations, not typical results, Wakefield v. ViSalus produced a $925M jury verdict on 1.8 million calls at statutory rates, and Birchmeier v. Caribbean Cruise settled at $76M. The realistic framing for a store is the per-text figure against your own list size, not those numbers. The point is that texting programs hit class size fast, because every message is a violation candidate.
Where stores collect consent wrong
Marketing texts require prior express written consent: a clear disclosure that the person agrees to receive automated marketing messages, that consent is not a condition of any purchase, with an affirmative act tied to that disclosure. Ecommerce stores break this in a small set of repeatable ways, and all of them are visible from outside the checkout:
- A pre-checked SMS opt-in box at signup or checkout, which is a dark pattern and a consent defect at once. Vergara v. Uber ($20M) and Hossfeld v. Compass Bank ($11M) both turned on consent that was not validly obtained
- Phone-number capture in a loyalty, rewards, or 'get 10% off' field with no disclosure that the number will be used for automated marketing texts
- SMS consent bundled into the purchase flow so it is not separable from the order, with no 'consent is not a condition of purchase' language
- Abandoned-cart and back-in-stock text programs firing to numbers collected for a different stated purpose, so the consent on file does not cover marketing use
- Missing the disclosures that belong at signup: the program name, message frequency, a 'msg & data rates may apply' note, and STOP/HELP instructions
What the scan checks here
- Every form that collects a phone number across product, cart, checkout, and loyalty pages, up to 120 pages
- Express-written-consent disclosure presence and proximity to the SMS opt-in field
- Pre-checked SMS consent boxes at signup and checkout (a dark pattern and a consent defect at once)
- 'Consent is not a condition of purchase' language where the opt-in is bundled into the buying flow
- Program name, message-frequency, 'msg & data rates', and STOP/HELP disclosures where a texting program is advertised
- Privacy-policy consistency: does the phone-number section match what loyalty and cart forms actually collect
Honest limits: A scan verifies the consent capture your store presents: what the SMS opt-in says, whether the box is pre-checked, which disclosures appear at signup. It cannot see your texting platform's send logs, your consent database, or whether STOP requests are honored downstream. Those are records questions for counsel. The scan settles what the form said when the number was collected, which is where most TCPA disputes start, and the report says so rather than implying a clean form equals a clean program.
Common questions
We use a Shopify SMS app like Postscript or Attentive. Doesn't it handle consent?
The app sends the messages and stores the opt-ins, but the consent itself is captured by the form on your store, and the demand letter names your store, not the app. If the opt-in box is pre-checked, or the disclosure is missing, or marketing consent is bundled into checkout, the defect is in your page. Complidar scans the forms your customers actually fill in, app-embedded widgets included.
What does a TCPA problem actually cost an online store?
Damages are $500 to $1,500 per text with no cap, so exposure scales with list size, not with any one verdict. A 25,000-person list texted twice a month is 600,000 violation candidates a year against one consent defect. Class-action outcomes show the ceiling that reaches (Wakefield v. ViSalus at $925M as a scale illustration), but the realistic small-store framing is the per-text figure against your own list, and most cases settle quietly on that cost asymmetry.
Is an SMS checkbox at checkout enough?
Only if it is unchecked by default and tied to a clear disclosure: automated marketing texts, not a condition of purchase, with program name, frequency, message-and-data-rates, and STOP/HELP noted. A pre-checked box, or consent bundled into the order so it cannot be declined separately, is not valid express written consent. Vergara v. Uber and Hossfeld v. Compass Bank both turned on consent that was not properly obtained. The scan checks the box state and the disclosure text together.
All 22 checks · up to 120 pages · no card
Last updated 2026-06-28 · Informational, not legal advice: how to read this