The checkout piece just landed, and it completes the set
If you sell to Indian shoppers, WhatsApp is probably your best-read channel and your messiest one. Most D2C brands built their WhatsApp lists out of whatever they could find: phone numbers from old orders, numbers typed into a popup, a spreadsheet a founder exported two years ago. None of that is real consent, and it's why so many brands hit rate limits, get low quality ratings, and eventually watch their number get restricted.
Shopify spent 2026 fixing the root cause. On 10 September it turned on the ability to collect WhatsApp marketing consent at checkout, which was the last missing capture point. Now consent can be gathered natively at the three moments that matter, and it's stored where your other customer data already lives. This is less flashy than a new ad format, but for retention it's one of the more useful things to happen to Shopify this year.
Here's what actually shipped, and how to turn it into a list you can send to without flinching.
What Shopify built, in order
The consent capability arrived in three pieces across the year, and they stack.
The API foundation (June)
In June, WhatsApp marketing consent became available in the Admin API and the Customer Account API. Under the hood there's a customerWhatsAppMarketingConsentUpdate mutation to set a customer's consent for their default phone number, and a whatsAppMarketingConsent field on the phone number object so any connected tool can read the current status. This is the plumbing. It means consent is a proper, queryable property of the customer, not a tag someone remembered to add.
Shopify Forms (August)
On 6 August, Shopify Forms gained a WhatsApp consent option. When a shopper fills out a form on your store, a newsletter signup, an early-access list, a festive waitlist, they can opt in to WhatsApp at the same time. This is your top-of-funnel capture, the people who aren't buyers yet but want to hear from you.
Checkout (10 September)
The newest piece, live from Sep 10, lets you collect WhatsApp marketing consent at checkout. You enable it in your Checkout settings, and buyers can opt in as they pay. This is the highest-value capture point because these people are already handing you money and a phone number; asking for permission to message them is a small, natural step.
Why native consent beats what you were doing
The instinct is to shrug and say your popup app already collects numbers. The difference is what you can prove and where it lives.
| Approach | Real opt-in proof | DPDP-clean | Syncs to Shopify customer | Ongoing cost |
|---|---|---|---|---|
| Shopify native (checkout, forms, API) | Yes, timestamped against the customer | Yes, if box is unticked by default | Native, no sync needed | Included |
| Third-party popup app | Sometimes, lives in the app | Depends on how it's configured | Needs an integration | Monthly fee |
| Numbers from past orders | No consent at all | No | Already there, but unusable | Free and risky |
| Imported spreadsheet | No | No | Messy | Free and risky |
The last two rows are how most brands built their lists, and they're the reason for the quality problems. A phone number is not consent. When Shopify stores the opt-in as a first-party property with a timestamp, you have something that holds up if a customer complains, if Meta reviews your quality rating, or if a DPDP query ever lands on your desk.
Setting it up this week
You don't need a developer for the first two steps.
1. Turn on checkout consent
Go to your Checkout settings and enable WhatsApp marketing consent. Keep the checkbox unticked by default and write the label in plain language: something like "Send me order updates and offers on WhatsApp." Don't bundle it with your terms acceptance; it has to be a separate, deliberate action.
2. Add consent to your highest-traffic forms
In Shopify Forms, add the WhatsApp consent option to your newsletter and waitlist forms. If you run festive early-access lists, this is where a lot of pre-season opt-ins will come from.
3. Wire consent into your CRM through the API
If you use a messaging platform, make sure it reads the whatsAppMarketingConsent field rather than blasting every number on file. This is the step that protects your sender quality. Your tool should only include customers whose consent value is set, and should stop messaging anyone who opts out.
Making it hold up under DPDP and TRAI
Indian rules have caught up with the channel, so treat consent as a compliance asset, not a growth hack.
Consent under the DPDP framework has to be free, specific, informed and unambiguous. In practice that means the box is unticked by default, the purpose is stated ("marketing offers," not buried), and the customer can withdraw as easily as they gave it. The native Shopify capture makes the first two easy. For withdrawal, make sure an opt-out on WhatsApp writes back to the consent field so you actually stop.
There's also a reputational reason to get this right. Regulators have been fining brands for pre-ticked boxes and sneaky checkout patterns, and a WhatsApp opt-in slipped past a distracted buyer is exactly that kind of pattern. A clean, obvious opt-in is both safer and, counterintuitively, more valuable, because the people who tick it actually want to hear from you.
Keep the receipt
Consent isn't a one-time capture, it's a record you should be able to produce later. The native storage helps here because it keeps consent against the customer's phone number rather than in a disconnected app. When someone asks "why am I getting your messages," or when Meta reviews your account quality, the answer should be a specific opt-in event, not a shrug. Make sure your setup keeps three things: when they opted in, where (checkout, form, or a synced source), and what they agreed to. If you migrate messaging tools later, that record travels with the customer instead of getting lost in an export.
The flip side matters just as much. When someone opts out, whether they reply STOP on WhatsApp or ask your support team, that has to write back to the consent field the same day. A list where opt-outs don't actually stop is a list that will eventually get your number reported, and no amount of clever copy fixes a damaged sender reputation.
Turning opt-ins into revenue
A consented list is only worth building if you send to it well. The flows that earn their keep for Indian D2C:
- Order and COD confirmation: the most-opened message you'll ever send. Confirm the order, and for COD, ask for a quick reconfirmation to cut RTO.
- Abandoned checkout: a single, well-timed WhatsApp nudge with the exact items, sent to consented shoppers only.
- Delivery updates: shipping and out-for-delivery messages carry huge open rates and reduce "where is my order" support load.
- Replenishment and reorder: for consumables, a reminder timed to when the product runs out.
- Win-back: for lapsed buyers, a short offer that respects the frequency caps.
The point is that all of these depend on a consent record you can trust. There's an order to switch them on, too. Start with the transactional messages, order, COD and delivery, because they carry the highest open rates and the lowest complaint risk; nobody reports a message telling them their parcel is arriving. Once those are running cleanly and your quality rating is stable, layer in the promotional flows like abandoned cart and win-back. Founders who flip on heavy promotions before the transactional base is solid tend to torch their rating in the first month and then wonder why delivery dropped.
Frequency is the other lever people get wrong. WhatsApp isn't email; two or three thoughtful messages a week is plenty, and Meta's own marketing limits will throttle you if you push past what customers tolerate. A consented list that you message sparingly outperforms a bigger list you spam, every time. If you'd rather have someone design the whole opt-in-to-retention engine, the flows, the frequency logic and the CRM wiring, that's what our D2C CRM and automation service is built to run.
The five-minute check before you scale
Before you push spend into WhatsApp campaigns this festive season, confirm four things. Is checkout consent enabled and unticked by default? Do your key forms capture WhatsApp opt-in? Does your messaging tool read the consent field instead of your full contact list? And does an opt-out actually write back and stop future sends?
Get those right and the list you build from here is one you can scale without flinching. It's dull work, first-party, timestamped, provable, but it's the difference between a WhatsApp number that stays healthy for years and one that gets throttled the first time a few hundred people report a message they never asked for.
Frequently asked questions
Do I still need a separate WhatsApp opt-in app now?
Is a pre-ticked WhatsApp checkbox at checkout allowed?
Where does the consent go after checkout?
Will this replace my email list?
Ready to put this into action?
Digistex4u runs performance, CRM, CRO and growth as one engine for D2C brands. Book a free 20-minute call and we'll map your fastest path to scale.
Get the D2C growth playbook
One practical teardown a week — the Meta, Google, SEO, CRM and retention tactics we run on real D2C brands. No fluff, no spam.
