Skip to main content

Industries · Ecommerce

Website compliance for ecommerce

Ecommerce sites stack every category of website legal risk at once: advertising trackers and session-replay on every page (CCPA, CIPA), subscription programs under auto-renewal laws, marketing SMS and email under TCPA and CAN-SPAM, checkout flows under dark-pattern and drip-pricing rules, and the whole storefront under the ADA. Complidar's 22 checks were assembled around exactly this surface: one scan reads the store the way a plaintiff's firm would.

Where stores actually get hit

The enforcement record maps the risk. Sephora's $1.2M CCPA settlement was about ad trackers and an ignored Global Privacy Control signal (standard ecommerce telemetry). Javier v. Assurance IQ made session-replay recording a wiretap theory, and replay tools are near-universal on conversion-optimized stores. U.S. v. Adobe ($150M DOJ settlement, 2026) targeted hidden cancellation friction in subscriptions under ROSCA. While the FTC's 2024 Click-to-Cancel rule was vacated on procedural grounds in 2025, ROSCA and state auto-renewal laws still regulate the same mechanics. Tubi's $19.99M VPPA settlement shows what video-plus-pixel costs. None of these required a data breach, just default tooling, observable from outside.

The accessibility baseline

Retail consistently leads ADA web-filing counts by sector: product grids without alt text, filters and carts that don't work by keyboard, and checkout forms without labels are the standard citations. An inaccessible checkout is both a lawsuit and a conversion leak: the rare compliance fix that pays for itself in revenue.

If you run on Shopify or a similar platform, theme and app choices determine most of this, and a scan of your actual rendered store is the only way to know what shipped.

What the scan checks for ecommerce

  • Every tracker and pixel across product, cart, and checkout pages, with pre-consent firing flagged
  • Global Privacy Control honoring and consent dark patterns (the Sephora pattern)
  • Session-replay vendors recording browsing and form entry (the Javier/CIPA pattern)
  • Auto-renewal and cancellation-flow mechanics against ROSCA and state auto-renewal requirements
  • Drip pricing and dark patterns in the purchase flow; TCPA/CAN-SPAM marketing mechanics
  • Full WCAG/axe-core accessibility pass across the storefront, cart, and checkout

Common questions

We just use standard Shopify apps and Meta/Google pixels. Is that really exposure?

Standard tooling is what the cited settlements were about: Sephora ran ordinary ad trackers. Defaults aren't a defense; configuration is what matters (when pixels fire, whether opt-outs work). The scan shows your store's actual behavior, which is the only honest answer to 'are we fine?'

Do auto-renewal rules apply to my subscription box?

Subscription commerce sits squarely under ROSCA and state auto-renewal laws like California's ARL: clear pre-purchase disclosure, consent to recurring charges, and cancellation as simple as signup. Complidar's cancellation-flow check walks the path a customer would.

How long does a store scan take?

Minutes: up to 120 pages with a real browser, which covers the systemic issues on most small-to-mid stores since trackers and templates are site-wide. Monitoring re-scans every two weeks, which matters in ecommerce because every new app or theme update can change your exposure.

Check your site free

All 22 checks · up to 120 pages · no card

Last updated 2026-06-11 · Informational, not legal advice: how to read this