Industries · Ecommerce
Website compliance for ecommerce
Ecommerce sites stack every category of website legal risk at once: advertising trackers and session-replay on every page (CCPA, CIPA), subscription programs under auto-renewal laws, marketing SMS and email under TCPA and CAN-SPAM, checkout flows under dark-pattern and drip-pricing rules, and the whole storefront under the ADA. Complidar's 22 checks were assembled around exactly this surface: one scan reads the store the way a plaintiff's firm would.
Where stores actually get hit
The enforcement record maps the risk. Sephora's $1.2M CCPA settlement was about ad trackers and an ignored Global Privacy Control signal (standard ecommerce telemetry). Javier v. Assurance IQ made session-replay recording a wiretap theory, and replay tools are near-universal on conversion-optimized stores. U.S. v. Adobe ($150M DOJ settlement, 2026) targeted hidden cancellation friction in subscriptions under ROSCA. While the FTC's 2024 Click-to-Cancel rule was vacated on procedural grounds in 2025, ROSCA and state auto-renewal laws still regulate the same mechanics. Tubi's $19.99M VPPA settlement shows what video-plus-pixel costs. None of these required a data breach, just default tooling, observable from outside.
The accessibility baseline
Retail consistently leads ADA web-filing counts by sector: product grids without alt text, filters and carts that don't work by keyboard, and checkout forms without labels are the standard citations. An inaccessible checkout is both a lawsuit and a conversion leak: the rare compliance fix that pays for itself in revenue.
If you run on Shopify or a similar platform, theme and app choices determine most of this, and a scan of your actual rendered store is the only way to know what shipped.
What the scan checks for ecommerce
- Every tracker and pixel across product, cart, and checkout pages, with pre-consent firing flagged
- Global Privacy Control honoring and consent dark patterns (the Sephora pattern)
- Session-replay vendors recording browsing and form entry (the Javier/CIPA pattern)
- Auto-renewal and cancellation-flow mechanics against ROSCA and state auto-renewal requirements
- Drip pricing and dark patterns in the purchase flow; TCPA/CAN-SPAM marketing mechanics
- Full WCAG/axe-core accessibility pass across the storefront, cart, and checkout
Common questions
We just use standard Shopify apps and Meta/Google pixels. Is that really exposure?
Standard tooling is what the cited settlements were about: Sephora ran ordinary ad trackers. Defaults aren't a defense; configuration is what matters (when pixels fire, whether opt-outs work). The scan shows your store's actual behavior, which is the only honest answer to 'are we fine?'
Do auto-renewal rules apply to my subscription box?
Subscription commerce sits squarely under ROSCA and state auto-renewal laws like California's ARL: clear pre-purchase disclosure, consent to recurring charges, and cancellation as simple as signup. Complidar's cancellation-flow check walks the path a customer would.
How long does a store scan take?
Minutes: up to 120 pages with a real browser, which covers the systemic issues on most small-to-mid stores since trackers and templates are site-wide. Monitoring re-scans every two weeks, which matters in ecommerce because every new app or theme update can change your exposure.
All 22 checks · up to 120 pages · no card
Last updated 2026-06-11 · Informational, not legal advice: how to read this