E-Commerce
Email and SMS Retention Marketing for E-Commerce
Retention marketing is a consent business before it is a creative business. CAN-SPAM sets hard requirements for every promotional email, and the FCC requires written consent for commercial texts with revocation honored in any reasonable manner. Build the consent and suppression architecture first, then layer flows and campaigns on top.
The compliance spine: email
Commercial email must not use false or misleading header information or deceptive subject lines, must be identified clearly as an advertisement, and must include a valid physical postal address. [FTC, CAN-SPAM Act compliance guide]
Opt-out mechanisms must work for at least 30 days after sending, and requests must be honored within 10 business days without fees or extra steps beyond a reply or a single web page. [FTC]
Store owners often discover these issues only after a platform migration or a theme change disrupts something that was quietly working before, which argues for treating this checklist as a recurring audit rather than a one-time launch task.
- Each separate email in violation of CAN-SPAM is subject to penalties of up to $53,088, and more than one party can be liable. [FTC]
- Hiring an email vendor does not contract away legal responsibility; both the promoted company and the sender may be held responsible. [FTC]
The compliance spine: SMS
For commercial texts, consent must be in writing, and consent for autodialed or prerecorded calls and texts to wireless numbers is required with limited exceptions. [FCC, Stop unwanted robocalls and texts]
Consumers may revoke consent at any time and in any reasonable manner, so your opt-out flow needs to accept more than one channel of request. [FCC]
The common thread across every documented case study in this space is that the underlying fix was structural, not cosmetic, which should reset expectations for how much effort a genuine improvement actually requires.
- For non-commercial informational texts, such as school closings or non-profit messages, consent may be oral. [FCC]
The flow stack that earns its keep
Prioritize welcome and consent confirmation, browse and cart recovery, and post-purchase or replenishment flows before investing heavily in one-off campaigns.
These flows tend to outperform one-off campaigns on a per-message basis because they are triggered by an action the customer just took, which means the message arrives while intent is still fresh rather than competing for attention days or weeks later.
Small teams should resist running every workstream at once. Sequencing the work, one loop at a time, produces cleaner before-and-after data than trying to change acquisition, conversion, and retention simultaneously.
Segmentation without sensitive inference
Build segments on purchase behavior and stated preference, not inferred sensitive categories, and keep that discipline even where the platform technically allows more granular targeting.
A useful discipline for a lean e-commerce team is to timebox each improvement sprint and measure the specific metric it targeted before moving to the next workstream, rather than letting several initiatives blur together in the reporting.
Creative and offer testing
Test subject lines, send times, and offer structure deliberately, and give each test a large enough audience before drawing conclusions.
Vendors and platforms will keep shipping new features framed as growth levers. Weigh each one against the documented fundamentals in this article before adopting it, since novelty is not the same as proven impact.
Measurement
Never pass personally identifiable information into analytics, including in campaign parameters such as utm_source and utm_campaign. [Google Analytics Help, Best practices to avoid sending PII]
Attribute revenue to flows and campaigns consistently, using the same definitions across email and SMS, since comparing the two channels on different measurement standards produces a false picture of which one is actually driving results.
Revisit this checklist whenever a major platform update ships, since Shopify, Meta, and Google all continue to update their own documentation, and a policy or feature referenced here can change on their timeline, not yours.
Quarterly audit checklist
Every quarter, re-verify opt-out processing time, postal address accuracy, SMS consent records, and that no PII has leaked into analytics parameters.
Treat this audit as non-negotiable even during busy sales periods, since the cost of a single overlooked violation is far higher than the modest time the audit takes to run properly.
- Keep a dated record of every consent audit, since a documented history of compliance diligence is itself a useful asset if a dispute or inquiry ever arises.
Frequently asked questions
How fast must I process unsubscribes?
Within 10 business days (FTC, https://www.ftc.gov/business-guidance/resources/can-spam-act-compliance-guide-business).
Do I need written consent for marketing texts?
Yes, for commercial texts (FCC, https://www.fcc.gov/consumers/guides/stop-unwanted-robocalls-and-texts).
Can customers opt out however they like?
Yes, they may revoke consent at any time in any reasonable manner (FCC, https://www.fcc.gov/consumers/guides/stop-unwanted-robocalls-and-texts).
Can I put an email address in a UTM parameter?
No. Never send personally identifiable information to analytics (Google, https://support.google.com/analytics/answer/6366371).
What is a benchmark email revenue share?
Not confirmed from a primary source in this research; measure against your own historical baseline.
Primary sources
Policy and statistical claims in this guide are grounded in the sources below. Access dates and policy details can change, so verify regulated guidance before acting.