Free Shopify store auditSpeed, SEO and conversion leaks — no cost, no obligation.
Claim it
Thriftizer Solutions LLPShopify Select Partner
Book a Growth Audit
Shopify Oct 3, 2026 9 min read

WhatsApp Consent at Shopify Checkout: Setup and Opt-In Copy for India

Shopify now collects WhatsApp marketing consent natively at checkout. Here's how to enable it, what the opt-in text must say under DPDP, and why COD confirmations sit outside it.

WhatsApp Consent at Shopify Checkout: Setup and Opt-In Copy for India

Switch the field on in your checkout settings, write one line of opt-in text that names your brand and says what you'll actually send, and keep order confirmations and COD verification out of the marketing bucket entirely. That's the whole job. Shopify made WhatsApp marketing consent collection available at checkout on 10 September 2026, which means the tick box now lives on the customer record alongside email and SMS consent instead of being injected by whichever app you installed last. If you run an Indian store, that change is worth twenty minutes of your attention, because the way most Shopify stores in India have been collecting WhatsApp opt-ins until now would not survive a serious look under the DPDP Act.

Where the setting lives and what it actually records

You'll find it under Settings → Checkout, in the same block that controls whether customers can sign up for email and SMS marketing during checkout. Shopify moves labels around, so don't hunt for an exact string. Look for the customer contact and marketing sign-up options.

What matters more than the toggle is what gets stored. When a shopper ticks the box, Shopify writes a marketing consent state against the customer's phone number with a timestamp and a source. That record is the thing you show a regulator, and it's the thing your WhatsApp app should read before it sends anything promotional. If your current setup stores consent inside a third-party app's own database and nowhere on the Shopify customer, you have two lists that will drift apart within a quarter. We've cleaned up that mess often enough to say it bluntly: pick the native field as the source of truth and make the app sync to it, not the other way round.

One practical detail that catches people. Indian checkouts usually collect a ten-digit mobile number, and WhatsApp needs E.164 with the country code. If your theme or app normalises to +91 only on order creation, abandoned-checkout records will carry raw ten-digit numbers and your cart recovery flow will silently fail on a chunk of them. Check this before you blame the copy.

What the opt-in has to say under Indian rules

Two sets of rules apply at once. The Digital Personal Data Protection Act requires consent that is free, specific, informed and given by a clear affirmative action, with a notice that tells the person what you're collecting and why, and a withdrawal route that's no harder than the sign-up was. Meta's own business messaging policy requires that the person understands they are agreeing to receive messages from your business on WhatsApp, specifically.

Translated into checkout reality:

  • No pre-ticked box. Ever. An unticked box that the shopper chooses to tick is the affirmative action.
  • Name the business. "Get updates on WhatsApp" is not enough. Updates from whom?
  • Say WhatsApp explicitly. Consent to SMS is not consent to WhatsApp, and consent to "messaging" is a lawyer's problem waiting to happen.
  • Describe the content category honestly. Offers and launches are marketing. Say so.
  • Give the exit. One clause is enough.
  • Don't make it a condition of purchase. A COD order cannot require a marketing opt-in.

That last point is where a lot of Indian stores quietly fail. Several WhatsApp apps ship with a flow that asks the buyer to confirm a COD order on WhatsApp and treats that confirmation as blanket consent for promotions. It isn't. Confirming an order is not consenting to a Diwali sale broadcast.

Opt-in copy you can use

Short version, which is what we put on most stores:

Send me offers and order updates from [Brand] on WhatsApp. Reply STOP anytime.

Slightly fuller, for categories where repeat purchase is the whole model — supplements, coffee, skincare, pet food:

Yes, message me on WhatsApp. [Brand] will send restock reminders, new launches and occasional offers to this number. Opt out anytime by replying STOP.

And for jewellery, electronics or anything with a long consideration window, where the honest promise is less frequent:

Keep me posted on WhatsApp. [Brand] will send a few messages a month about new collections and price drops. Reply STOP to stop.

Notice what's missing. No "exclusive VIP access". No emoji. The tick rate goes up when the promise is small and credible, and more importantly the block rate stays down, which is the number that actually decides whether this channel is worth running in eighteen months.

COD confirmations are a separate category, and getting this wrong is expensive

Meta sorts template messages into marketing, utility and authentication, and prices them differently. Order confirmations, shipping updates from Shiprocket or Delhivery, delivery attempt alerts and COD address verification are utility. They do not need marketing consent, because they relate to a transaction the customer initiated. Promotions, cart recovery and festive broadcasts are marketing, and they do.

So you can keep sending COD confirmation messages to customers who did not tick the box. You should. Here's the arithmetic, using your own numbers in place of these.

Say a store ships 3,000 COD orders a month and sees 26% RTO. That's 780 parcels coming back, each carrying forward and reverse freight plus handling. At ₹160 all-in per RTO, that's ₹124,800 a month burnt. Now suppose a WhatsApp confirmation template with confirm/cancel buttons reaches 80% of those buyers, 8% of the responders cancel or correct an address before dispatch, and RTO on the remainder drops by a fifth. 3,000 × 0.80 × 0.08 = 192 orders never shipped, saving 192 × ₹160 if those would have bounced. On the 2,208 confirmed orders, a 26% to 21% shift is about 110 fewer returns, another ₹17,600. Rough, but the shape holds: the utility flow pays for itself long before the marketing flow does.

Which is the argument for separating them in your head. Utility messaging is operations. Marketing consent is a list you are building for later. Mixing the two produces a list full of people who ticked a box to find out where their parcel was.

Abandoned cart recovery needs the marketing tick

Cart and checkout abandonment templates fall under marketing in Meta's categorisation, not utility. The person didn't buy, so there's no transaction to service. If you send a recovery message to someone who never consented, you're relying on them not reporting it, and WhatsApp's quality rating is unforgiving about that.

The useful thing about the native checkout field is timing. The consent box sits at the contact step, before payment. So a shopper who enters a phone number, ticks the box, and then bails at the UPI screen has already given you permission. Shopify holds that on the abandoned checkout record. Build your recovery flow to read it and you recover a meaningful slice of drop-offs legitimately. Build it to ignore consent and you'll get volume for about six weeks, then a quality rating downgrade that throttles your festive sends in October. Bad trade.

Why WhatsApp opt-in beats SMS in India, and why the gap isn't really about the channel

People ask us to compare opt-in rates between WhatsApp and SMS as if they're competing for the same checkbox. The difference that matters is downstream. Promotional SMS in India runs through TRAI's TCCCPR framework: DLT registration, approved headers, approved content templates, and a DND preference register that blocks promotional traffic to a very large share of Indian mobile numbers regardless of what the customer ticked on your checkout. You can collect SMS consent beautifully and still not reach the person.

WhatsApp sits outside DND. Delivery is governed by Meta's policy and your template approvals instead. Open rates are also structurally different, because the message lands in the same app the buyer uses for everything else, with a profile picture and a verified name attached.

The counterweight, since nobody mentions it: WhatsApp costs money per message and SMS to an already-consenting non-DND number sometimes costs less. For a one-line "your order shipped" to a price-sensitive buyer, SMS is still fine. Use WhatsApp where the conversation or the media earns its rate.

Choosing an app, now that the checkbox isn't the differentiator

Until this change, half the pitch from WhatsApp marketing apps built for the Indian market was that they could get a consent checkbox onto your checkout. That's now native, so judge them on the things that are harder:

  • Does it write opt-outs back to the Shopify customer record when someone replies STOP or taps the block button? Many don't, and that's the compliance hole that actually bites.
  • Does it hold your own WhatsApp Business Account and phone number, or does it rent you a shared one? You want to own the number and the green tick.
  • Template approval turnaround, and whether support speaks to Meta on your behalf when a template gets rejected two days before a sale.
  • Does it handle Razorpay or Cashfree payment links inside a message cleanly, for the COD-to-prepaid conversion nudge?
  • Per-conversation markup over Meta's rate card, stated plainly.

If you're on checkout extensibility and want the consent line worded differently from Shopify's default, or you want it to appear only for Indian addresses, that's a checkout UI extension rather than an app setting. We build those as part of Plus checkout work, and it's a small job when it's scoped properly. Syncing consent state in both directions between Shopify and a messaging platform is usually a custom app, not a setting.

What the first thirty days of a new subscriber should look like

Don't put fresh checkout opt-ins into a broadcast list. The order of flows matters more than the content.

  1. Order confirmation and COD verification on the same day, as utility. This teaches the buyer that your number is useful.
  2. Shipping and delivery updates from the carrier webhook. Still utility. Still free of marketing consent requirements.
  3. Delivery + 3 days: a single review or usage message. One. Not a sequence.
  4. Day 10 onwards: the first marketing template, and only to people who ticked. Make it a restock reminder or a category they've already bought from, not a sitewide coupon.
  5. Abandoned checkout recovery runs in parallel for consented non-buyers, one message at around 60 minutes and at most one follow-up the next day.

Cap marketing sends at roughly four a month outside the festive window, and make the festive exception deliberate rather than accidental. The stores that get throttled in late October are almost always the ones that quietly went from four to twelve in the first week of the sale.

Three things that break

The buyer's checkout phone isn't their WhatsApp number. Common with COD, where the number given is a building watchman or a family member. There's no clean fix. Track undelivered templates by cohort and stop paying to retry them.

Guest checkout creates a second customer record. Same person, different email, consent on one record and not the other. Your segment counts will disagree with your platform's. Dedupe on normalised phone, not email.

Opt-outs made in WhatsApp don't always come back. If a customer blocks your number, Shopify may never know, and your consented count stays inflated. Reconcile monthly against the platform's delivery failures. We get this wrong on the first pass more often than we'd like, usually because the app's webhook for opt-out events was never subscribed.

Questions we keep getting

Do I need separate consent for WhatsApp if the customer already opted into SMS? Yes. Different channel, different expectation, and Meta's policy is specific about the person knowing they'll hear from you on WhatsApp.

Can I import an old list collected through a chat widget? Only if you can produce the record of what the person agreed to, when, and from which business. A list of numbers who once messaged your support line is not a marketing list.

Should the box be ticked by default to grow the list faster? No, and the DPDP Act is the smaller reason. A list built from people who didn't notice they joined has a block rate that eventually costs you the channel.

Go into your checkout settings, enable the field, and spend ten minutes writing the opt-in line yourself rather than accepting the default. Then check one thing: pull up a customer who opted in last week and confirm the consent state is visible on the Shopify record, not just inside your messaging app. If it isn't, that's the first fix. If you want a second pair of eyes on how your consent, COD confirmation and recovery flows fit together, our store audit covers it.

Previous postNext post

Ready to scale your D2C brand profitably?

Let's build a growth engine that drives more traffic, more conversions and more profit.

Book a Growth Audit
📅 Free Audit💬 WhatsApp