← All posts
The compliance guide to calling and texting abandoned checkouts
September 11, 2026 · ArquenGroup · 8 min read
Calling or texting someone about a cart they abandoned sits in a regulated space: it's outreach
to a person who gave you their number but didn't complete a transaction. Done right, it's a
service contact about the customer's own order. Done wrong, it's telemarketing without consent —
and in the US that carries statutory damages per call or text.
This is a practical orientation, not legal advice. Rules change and vary by state and
country; for a real program, confirm with counsel in your markets.
The mental model: whose number, what message, which channel
Almost every rule reduces to three questions:
- How did you get the number? A number typed into your own checkout by the
customer is the strongest position — it's tied to a transaction they initiated.
- Is the message transactional or marketing? "You left items in checkout,
need help finishing?" leans service. "Here's 10% off!" is marketing. Marketing needs more
consent, everywhere.
- Which channel? Texts and auto-dialed or prerecorded/AI-voiced calls are
regulated more strictly than a human manually dialing.
United States: TCPA and friends
- TCPA (Telephone Consumer Protection Act) is the statute that matters. Calls
using an artificial or prerecorded voice — which includes AI voice agents — to mobile numbers
require prior express consent; if the call contains marketing, the bar is
prior express written consent. A checkout form where the customer enters their
own number, next to clear disclosure text, is how programs establish this. Damages run $500 per
violation and up to $1,500 for willful ones, and class actions are routine.
- Quiet hours: federally 8am–9pm in the recipient's local time;
several states are stricter. Some states also cap call attempts per number per day.
- Do-not-call: honor the national DNC registry where applicable, and keep your
own internal DNC list forever. One "don't call me again" must end all future contact.
- Disclosure: the caller must identify who is calling and on whose behalf.
An AI agent should say what it is when asked, and hang up gracefully on request.
SMS has its own second layer: carriers
Even with legal consent, US carriers separately require A2P 10DLC registration
— your business (brand) and your use case (campaign) must be registered and approved before
application-to-person texts will deliver reliably. Campaign reviews check for things regulators
don't spell out:
- A published privacy policy stating that mobile opt-in data is never sold or
shared with third parties for marketing.
- Public terms describing the SMS program: message frequency, "message and
data rates may apply," STOP to opt out, HELP for help.
- A documented opt-in flow (call-to-action) the reviewer can actually see —
for voice-initiated texts, that means publishing the exact consent script the agent uses.
- Working STOP/HELP keyword handling.
We went through this registration ourselves, including rejections, before our SMS delivery went
live — our published opt-in disclosure is what an approved flow looks
like in practice.
Europe and the UK: GDPR + ePrivacy
- GDPR governs the data: you need a lawful basis to process the customer's
name and number for recovery outreach, documented retention limits, and the ability to honor
access and deletion requests. Abandoned-cart outreach to your own checkout customers is commonly
run under legitimate interest — with the balancing test written down — but the analysis is the
merchant's to make.
- ePrivacy rules (country by country) govern the channel. Several EU states
effectively require opt-in for marketing calls; others run opt-out registers you must screen
against. The "soft opt-in" concept (existing customers, similar products, easy opt-out) helps for
email and sometimes SMS, but its application to calls varies by country.
- Automated-call rules are stricter: prerecorded/automated marketing calls
generally require explicit consent across the EU and UK.
Everywhere: the rules that never hurt you
- Call only your own checkout abandoners. Never purchased lists, never
lookalikes. The transaction relationship is the foundation of every defensible program.
- Contact fast and few. One call, within hours, plus a capped number of
messages. Frequency caps are both a legal safety margin and better marketing.
- Quiet hours in the customer's timezone, always.
- One no means no, forever. Instant, permanent, cross-channel do-not-contact.
- Get SMS consent explicitly, even mid-call. "Want me to text you the code?
Message and data rates may apply, reply STOP to opt out" — then send exactly one message.
- Log everything. Consent source, call time, outcome, transcript, opt-outs.
If you can't prove it, it didn't happen.
- Delete on schedule. Retention limits on transcripts and personal data, and
honor platform deletion webhooks (Shopify's customer-redaction flow, for example) automatically.
The biggest practical risk isn't a regulator — it's your tooling. Most violations
happen because software called at 10pm in the customer's timezone, retried an opted-out number, or
texted without registered campaigns. Whatever stack you use, verify that quiet hours, DNC lists,
attempt caps, and opt-out handling are enforced by the system, not by policy documents.
Checklist before your first recovery call
- Checkout disclosure text near the phone field reviewed by counsel
- Quiet hours + timezone enforcement on by default
- Internal do-not-call list, permanent and cross-channel
- A2P 10DLC brand + campaign approved (US texting)
- Privacy policy, SMS terms, and opt-in disclosure published
- Retention limits and deletion webhooks working
Compliance is the product, not an upsell.
Arquen Checkout Recall ships with quiet
hours, do-not-call, one-decline rules, consent-gated SMS, retention limits, and GDPR webhooks
enforced in software — on every plan, including the free one.
View on the Shopify App Store