SMS Opt-In Policy
This page documents how shoppers opt in to text messages sent through Cartbeat Comebacks and related SMS features. Merchants using Cartbeat send messages on behalf of their own store; Cartbeat provides the platform, delivery, and compliance controls described here. Related privacy terms (including mobile data): Privacy Policy · SMS & mobile information.
Mobile information is not shared for third-party marketing
We do not share, sell, rent, or otherwise provide your mobile phone number or messaging consent information to any third parties or affiliates for marketing or promotional purposes.
Phone numbers and consent records are used only to deliver the merchant store’s opted-in messages, honor STOP/HELP, maintain suppression, and operate support/compliance. Twilio (or another configured SMS transport) processes numbers solely to send those messages · not to market other products to you.
Who may receive texts
Only past customers of a Shopify merchant who have explicitly opted in to SMS marketing may receive comeback (win-back) texts. Cartbeat does not text abandoned-checkout shoppers who never completed a purchase.
How opt-in is collected
Cartbeat records opt-in with a timestamp and source. A phone number captured at checkout alone does not constitute SMS consent · Cartbeat only records consent when Shopify reports an explicit SMS marketing opt-in.
- Shopify checkout SMS checkbox · when a shopper checks the store’s SMS marketing box at checkout, Cartbeat syncs
buyer_accepts_sms_marketingand the consent phone from Shopify webhooks (shopify_checkoutsource). - Shopify customer consent updates · order completion and
customers_marketing_consent/updatewebhooks keep Cartbeat aligned when consent is granted or revoked in Shopify Admin or checkout. - Checkout or account signup checkbox · unchecked by default, with clear SMS disclosure and links to the merchant’s terms and privacy policy.
- Marketing signup form · dedicated SMS consent language (not bundled silently with email-only signup).
- Merchant import · only for contacts who previously gave express written consent to receive SMS from that merchant; import source is logged.
- Verbal or paper consent · merchant must retain proof; Cartbeat stores the opt-in event when the merchant records it in their systems.
Live opt-in example (for verification)
Reviewers and merchants can view a merchant-branded sample checkout at cartbeat.app/sms-opt-in-example · it shows the Shopify checkout SMS marketing checkbox as shoppers see it from the store (North & Thread in the sample). Cartbeat does not inject this UI; Shopify renders it when SMS marketing is enabled. When a shopper checks the box, Shopify sends buyer_accepts_sms_marketing via webhooks and Cartbeat records consent before any comeback SMS is sent.
Recommended merchant disclosure (checkout / signup)
Merchants should display language substantially similar to the following adjacent to an unchecked SMS opt-in checkbox:
Sample opt-in copy for merchants
☐ By checking this box, you agree to receive recurring automated marketing text messages (e.g., comeback offers and promotional store updates) from [Store Name] at the mobile number provided. Msg & data rates may apply. Msg frequency varies. Consent is not a condition of purchase. Reply STOP to cancel, HELP for help. Privacy Policy · Terms of Service.
What messages are sent
- Comeback / win-back marketing SMS · infrequent promotional texts to lapsed buyers who opted in at checkout, with a tracked claim link (coupon, gift, or BOGO configured by the merchant). Typical frequency: at most one text per customer per 90-day window.
Cartbeat Comebacks does not send abandoned-cart SMS to shoppers who never completed a purchase. Email recovery handles abandoned checkouts separately.
Every marketing message includes opt-out instructions. Cartbeat appends Reply STOP to opt out. when the merchant template does not already include it.
Message frequency
Comeback texts are limited by merchant-configured rules: minimum days since last order, cooldown between texts, and monthly send caps. Typical frequency is at most one comeback text per customer per 90-day window, subject to merchant settings.
How to opt out
- Reply STOP (or STOPALL, UNSUBSCRIBE, CANCEL, END, QUIT) to any message · processed automatically; no further texts are sent to that number across Cartbeat-powered sends for that store.
- Reply HELP for assistance or contact the merchant’s support channel.
- Email info@cartbeat.app to request suppression or data deletion.
Technical enforcement
Cartbeat blocks sends when:
- No recorded
sms_opt_in_attimestamp (when explicit opt-in is required · default on). - Customer replied STOP or is otherwise suppressed.
- Customer has no valid phone number on file.
- Merchant has disabled Comebacks or the customer is outside eligibility rules.
Data & subprocessors
Phone numbers and consent timestamps are stored to honor opt-in/opt-out. SMS delivery is provided by Twilio as a message transport only. We do not sell or share mobile numbers or messaging consent with third parties or affiliates for marketing or promotional purposes. See our Privacy Policy (section SMS, mobile information & messaging consent) for retention, sharing limits, and GDPR webhooks.
Message frequency varies. Message and data rates may apply. Consent is not a condition of purchase. Reply STOP to opt out, HELP for help.
Contact
Questions about this policy: info@cartbeat.app
Cartbeat