Free Shopify store auditSpeed, SEO and conversion leaks — no cost, no obligation.
Claim it
Thriftizer Solutions LLPShopify Select Partner
Book a Growth Audit
Shopify Sep 29, 2026 10 min read

WhatsApp Consent at Shopify Checkout: Turning It On for Indian Stores

Shopify now collects WhatsApp marketing consent in Checkout settings. Where the opt-in lands, how it differs from an app-collected number, DPDP implications, and which flows to point at it first.

WhatsApp Consent at Shopify Checkout: Turning It On for Indian Stores

If you came here looking for the switch: it's in your Shopify admin under Settings → Checkout, in the block that controls customer contact and marketing consent, sitting next to the email and SMS options you already know. Turn on WhatsApp marketing consent and shoppers get a tick box at checkout asking whether they want WhatsApp updates from you. The answer gets stored against that customer's phone number as its own consent state, separate from SMS. Shopify shipped this on 10 September, and for an Indian store running WhatsApp as its main retention channel, it's the first time the opt-in has lived where it should have lived all along — inside checkout, not inside a third-party widget.

That's the five-second version. The rest of this is what changes downstream, because turning the toggle on is the easy part.

What the checkout toggle actually does, and what it doesn't

Enabling Shopify WhatsApp marketing consent at checkout does three things. It renders a consent control on the checkout contact step. It records a yes or no against the customer record, tied to the phone number the shopper entered. And it exposes that state to apps and to the customer admin, so anything reading consent properly can filter on it.

It does not send WhatsApp messages. Shopify is not a WhatsApp Business Solution Provider. You still need a BSP or a WhatsApp marketing app connected to a verified Meta Business account, with approved message templates, before a single message leaves. The toggle is plumbing for consent. The water comes from somewhere else.

It also does not retroactively fix your existing list. Every number you collected through a pop-up, a Razorpay-side field, or an app's own opt-in widget before September keeps whatever consent record that tool holds. Shopify won't backfill it.

One practical note from setting this up on live stores: if the control doesn't appear on your checkout, check that checkout is actually collecting a phone number in the first place. On stores where phone is optional and the shopper only gives an email, there's nothing for the consent to attach to.

Almost every Indian Shopify store already collects a mobile number at checkout. You have to. Delhivery, Blue Dart and every Shiprocket courier need it for the delivery call, and the COD confirmation call is often the only thing standing between you and a refused parcel.

So merchants look at a database of 40,000 verified mobile numbers and reason that they may as well message them. Meta's commerce and business messaging policies say otherwise: opt-in has to be given by the person, to your business, for the kind of messages you plan to send. A number harvested for shipping is not that. When you breach it, the penalty isn't a warning letter — it's a quality rating downgrade, then a messaging limit cut, then template rejections. We've watched a store go from 10,000 marketing messages a day to 1,000 in under two weeks because of complaint rates after a bulk send to a shipping list.

The checkout consent state is the clean version of that permission. It was given at the moment of purchase, by an identified customer, with the business name on screen. That's a far stronger record than a tick box in a floating widget the shopper barely registered.

They look like sibling checkboxes in the admin. Legally and operationally they aren't.

SMS in India runs under TRAI's commercial communications rules. Promotional SMS needs a registered sender ID, DLT-registered headers and templates, scrubbing against the DND registry, and it respects the 9pm-to-9am promotional blackout. WhatsApp is an over-the-top service, so DLT and DND don't apply to it. What applies is Meta's own policy plus Indian data protection law.

That has a few consequences worth planning around:

  • A customer can be opted in to WhatsApp and opted out of SMS, or the reverse. Treat them as two lists. If your app collapses them into one "phone marketing" audience, you have a problem.
  • WhatsApp opt-out is handled inside the conversation. Every marketing template carries a stop option, and when the customer taps it, Meta blocks your marketing templates to that number regardless of what your Shopify record says. Your consent sync needs to read that back, or you'll keep counting a dead contact as reachable.
  • SMS is still the better fallback for OTPs, COD verification on feature phones, and anyone whose WhatsApp isn't linked to the number they gave you. Don't retire it.

Is a WhatsApp marketing opt-in DPDP compliant?

Under the Digital Personal Data Protection Act, 2023, consent has to be free, specific, informed, unambiguous, and given by a clear affirmative action. It also has to be paired with a notice that tells the person what data you're processing and for what purpose, and withdrawal has to be as easy as giving it.

A checkout opt-in clears that bar if you set it up properly. Unchecked by default. Not bundled with order processing, so the customer can complete the purchase without agreeing. Wording that names your brand and says what they'll receive. A privacy policy link within reach.

What fails: a pre-ticked box. A single checkbox that covers email, SMS, WhatsApp and "partner offers" at once. Consent wording buried in terms and conditions. And the common one in India — treating the shipping number as implied permission because the customer bought something.

Rules under the Act are still being operationalised, so treat this as a compliance floor and get your own counsel to sign off on the final wording. But a clean, granular, checkout-level record is a materially better position than a spreadsheet of numbers with no provenance.

Which flows should use the checkout opt-in first

Not the broadcast campaign. Start with the flows that fire off a behaviour, because they perform without needing volume and they keep your template quality rating healthy.

Abandoned checkout is the obvious first. The shopper reached the contact step, gave a number, and ticked the box. Consent and intent in the same session. Fire at roughly 45 to 60 minutes, then once more at 22 hours if you must, and stop. Three chases on WhatsApp is how you get reported.

Back in stock is second, and underrated. Indian shoppers will wait for a restock on a size they want far more patiently than they'll wait for a discount, and WhatsApp read rates make the alert land within minutes.

Post-delivery review and replenishment comes third, gated on delivery status from your fulfilment feed rather than on order date, which matters when a Tier-3 delivery runs five days over.

Here's the awkward bit. Your highest-return WhatsApp use in India is probably COD order confirmation and address verification, and that doesn't need marketing consent at all. It's a utility-category template sent about a transaction the customer initiated. If you've been holding off on COD confirmation flows while you sorted out marketing opt-ins, you held off for no reason. Build that one first, independent of this toggle. It's the only WhatsApp flow we've seen reliably move the RTO rate.

The arithmetic on a WhatsApp abandoned cart flow

Plug your own numbers in, but the shape holds. Say a month looks like this:

  • 2,000 checkouts started, 640 completed. 1,360 abandoned.
  • Of the abandoners, 45% ticked the WhatsApp box — 612 reachable contacts.
  • Two-message sequence, so 1,224 marketing messages. At an assumed ₹0.90 per message billed by your BSP, that's ₹1,102. Check current Meta rates; the India marketing rate has changed more than once and moved to per-message billing.
  • Recovery at 7% of reachable contacts: 43 orders. At ₹1,400 AOV, ₹60,200 in recovered revenue.

Now the part most calculations skip. If 60% of those recovered orders are COD — 26 orders — and your COD refusal rate is 24%, six of them come back. Forward plus return freight at ₹130 a shipment is ₹780 of pure loss, plus packaging and the handling time. So the honest figure is closer to ₹59,400 gross revenue against ₹1,880 of messaging and RTO cost, before COGS.

Still an easy yes. But it tells you where the next lever is: prepaid nudging inside the recovery message. A ₹50 UPI discount on the abandoned cart link shifts some of those 26 COD orders to prepaid, and each one you shift saves the full RTO exposure on that order. Offer it in the first message, not the second.

Setting it up end to end for an Indian store

Order of operations, because doing this out of sequence wastes a week waiting on approvals:

  1. Meta Business verification. Business verification with matching GST and entity documents. This is the slow step. Start it before anything else.
  2. WhatsApp Business API through a BSP or a Shopify app. Pick the app first if you want the Shopify sync handled for you, since most of the WhatsApp apps on the App Store are BSP front-ends anyway.
  3. Dedicated number. Use a number that isn't already running on the WhatsApp Business mobile app. Migrating a number with live chat history is doable but fiddly, and you lose the app inbox on that number.
  4. Templates submitted and approved. Marketing category for cart recovery and campaigns, utility for order and delivery updates. Getting the category wrong is the most common rejection we see, and it changes what you're billed.
  5. Turn on checkout consent in Settings → Checkout and write the opt-in wording carefully.
  6. Verify the sync. Place a test order, tick the box, and confirm the consent state reaches your WhatsApp tool — not just that the phone number does. Then place a second test order without ticking, and confirm that customer is excluded from the flow. This second test is the one people skip, and it's the one that catches a broken integration.

If your app only reads phone numbers and has no concept of a WhatsApp consent field, you'll need a middleware step or a custom sync. That's a small piece of Shopify app work, usually a day or two, and it's worth doing before a festive campaign rather than during one.

Things that break

A few we've hit:

Duplicate messaging. A customer who opted in to email, SMS and WhatsApp gets three abandoned cart messages within the hour from three tools that don't know about each other. Pick a channel priority per flow and suppress the others. WhatsApp first for cart recovery, email first for anything with long content.

Country codes. Shopify stores the number as entered. If your checkout doesn't force +91 normalisation, you'll get ten-digit numbers that the WhatsApp API rejects silently. Check a sample of 50 records before you trust the list.

Draft orders and manual orders. Orders created in admin or over the phone never hit checkout, so they never generate a consent record. If a meaningful share of your revenue comes in that way, you need a separate opt-in path for it.

Existing subscribers. Numbers collected by an app widget before September sit in that app's own consent store, not Shopify's. You can import them if the provenance is documented. If it isn't, the cleaner move is to run a re-permission message to that list once, and let the non-responders go.

Short answers to the things people ask next

Do I need a separate app to collect a WhatsApp number at checkout? No. Shopify collects the phone number natively and the consent control attaches to it. You need an app to send.

Can I pre-tick the box to grow the list faster? You can. It fails DPDP's affirmative-action requirement and produces exactly the complaint rate that gets your templates throttled. Don't.

Does this replace SMS? No. Keep SMS for OTPs and COD confirmation fallback. WhatsApp costs more per message and reaches fewer people than a phone number does.

Will the opt-in rate be any good? On an unchecked box at an Indian checkout, we'd expect somewhere in the 35 to 50% range depending on wording and category. Beauty and food do better than electronics. It'll be lower than your email capture and higher than your SMS consent.

Is this a Shopify Plus feature? No. It's in Checkout settings on standard plans. Plus gives you more control over the checkout UI around it, which matters if you want custom wording placement, but the consent capability itself isn't gated.

What to do this week

Turn the setting on, write the opt-in line yourself instead of accepting the default, and run the two test orders described above. Then look at what your WhatsApp app is actually filtering on. If it's sending to every phone number on file rather than to consented contacts only, fix that before the next festive push, when volume is high enough for complaint rates to bite.

We're a Shopify Select Partner and a Meta Business Partner, and we set these up out of Bengaluru for stores across India and the Gulf. If you want a second pair of eyes on your retention stack before Diwali, a free audit will tell you where the consent records and the flows are out of step.

Previous postNext post

Ready to scale your D2C brand profitably?

Let's build a growth engine that drives more traffic, more conversions and more profit.

Book a Growth Audit
📅 Free Audit💬 WhatsApp