← All posts

The compliance guide to calling and texting abandoned checkouts

September 11, 2026 · ArquenGroup · 8 min read

Calling or texting someone about a cart they abandoned sits in a regulated space: it's outreach to a person who gave you their number but didn't complete a transaction. Done right, it's a service contact about the customer's own order. Done wrong, it's telemarketing without consent — and in the US that carries statutory damages per call or text.

This is a practical orientation, not legal advice. Rules change and vary by state and country; for a real program, confirm with counsel in your markets.

The mental model: whose number, what message, which channel

Almost every rule reduces to three questions:

  1. How did you get the number? A number typed into your own checkout by the customer is the strongest position — it's tied to a transaction they initiated.
  2. Is the message transactional or marketing? "You left items in checkout, need help finishing?" leans service. "Here's 10% off!" is marketing. Marketing needs more consent, everywhere.
  3. Which channel? Texts and auto-dialed or prerecorded/AI-voiced calls are regulated more strictly than a human manually dialing.

United States: TCPA and friends

SMS has its own second layer: carriers

Even with legal consent, US carriers separately require A2P 10DLC registration — your business (brand) and your use case (campaign) must be registered and approved before application-to-person texts will deliver reliably. Campaign reviews check for things regulators don't spell out:

We went through this registration ourselves, including rejections, before our SMS delivery went live — our published opt-in disclosure is what an approved flow looks like in practice.

Europe and the UK: GDPR + ePrivacy

Everywhere: the rules that never hurt you

  1. Call only your own checkout abandoners. Never purchased lists, never lookalikes. The transaction relationship is the foundation of every defensible program.
  2. Contact fast and few. One call, within hours, plus a capped number of messages. Frequency caps are both a legal safety margin and better marketing.
  3. Quiet hours in the customer's timezone, always.
  4. One no means no, forever. Instant, permanent, cross-channel do-not-contact.
  5. Get SMS consent explicitly, even mid-call. "Want me to text you the code? Message and data rates may apply, reply STOP to opt out" — then send exactly one message.
  6. Log everything. Consent source, call time, outcome, transcript, opt-outs. If you can't prove it, it didn't happen.
  7. Delete on schedule. Retention limits on transcripts and personal data, and honor platform deletion webhooks (Shopify's customer-redaction flow, for example) automatically.
The biggest practical risk isn't a regulator — it's your tooling. Most violations happen because software called at 10pm in the customer's timezone, retried an opted-out number, or texted without registered campaigns. Whatever stack you use, verify that quiet hours, DNC lists, attempt caps, and opt-out handling are enforced by the system, not by policy documents.

Checklist before your first recovery call

Compliance is the product, not an upsell.
Arquen Checkout Recall ships with quiet hours, do-not-call, one-decline rules, consent-gated SMS, retention limits, and GDPR webhooks enforced in software — on every plan, including the free one.
View on the Shopify App Store