Executive Summary
US online retailers—including WooCommerce merchants, custom carts, and marketplace sellers who text from their own numbers—send application-to-person (A2P) SMS when order, shipping, or promo messages leave a plugin or ESP. Carriers expect that traffic on local long codes to use A2P 10DLC Brand and Campaign registration via a Campaign Service Provider (CSP) and The Campaign Registry (TCR). The core ecommerce packaging decision is separating delivery / order notifications from marketing (abandoned cart, flash sales, loyalty). Checkout opt-in must be clear, 1:1, and not buried in unrelated terms. TCPA rules still govern marketing consent. This guide covers use-case mapping, WooCommerce-specific pitfalls, sample messages, a decision framework, risks, and an implementation checklist.
Short answer: Online retailers—including WooCommerce, Shopify-style, and custom carts—that text US customers from a local 10-digit number need A2P 10DLC Brand + Campaign registration. Treat order confirmation, shipping, and delivery updates as operational / delivery-notification style programs, and treat abandoned-cart, flash sales, and loyalty offers as Marketing—usually with stronger consent and often a separate Campaign. Plugins do not create a WooCommerce exemption from TCR or TCPA rules.
Who This Is For / Who It Is Not For
Who this is for
- DTC brands and WooCommerce / Magento / custom-cart operators sending US SMS
- Grocery and specialty shops using SMS for order-ready and promos
- Marketing ops and developers wiring Twilio, Bandwidth, or other CSP plugins
- Agencies managing multi-store SMS programs for retail clients
Who this is not for
- Marketplaces where the platform (not you) is the registered sender of record
- Non-US domestic SMS with no US 10DLC leg
- Pure email-only lifecycle programs
- Anyone needing a guarantee of Campaign approval or TCPA outcomes
Definitions
| Term | Ecommerce meaning |
|---|---|
| 10DLC | Registered US 10-digit long code for A2P SMS/MMS |
| Brand | Legal merchant identity in TCR via CSP |
| Campaign | Declared program: use case, samples, opt-in/out/HELP |
| Delivery Notification | Common use-case framing for shipment/delivery updates (confirm with CSP) |
| Marketing Campaign | Promo, cart recovery, win-back, loyalty offers |
| Checkout opt-in | Consent captured at purchase—must disclose SMS program clearly |
| BOPIS | Buy online, pickup in store—often “order ready” SMS |
| CSP | Messaging provider submitting Brand/Campaign |
Why Ecommerce Hits 10DLC
Typical retail SMS programs:
- Order placed / payment received
- Shipped / out for delivery / delivered
- Pickup ready (BOPIS)
- Back-in-stock alerts
- Abandoned cart and win-back
- Flash sales and loyalty points
Per Twilio’s A2P 10DLC docs, anyone sending SMS/MMS over a 10DLC number from an application to the US must register. WooCommerce’s Twilio SMS Notifications documentation describes order-status triggers and opt-in configuration—useful product context, but plugin settings do not replace Brand + Campaign registration (WooCommerce Twilio SMS Notifications).
See also: MyTCRPlus ecommerce & retail solutions and WooCommerce registration guidance.
Use-Case Map for Retail Campaigns
| Message type | Typical Campaign framing | Consent posture |
|---|---|---|
| Order confirmation | Delivery Notification / Account Notification / Customer Care | Disclose at checkout for order updates |
| Shipping / tracking | Delivery Notification | Same program as order updates when described accurately |
| Delivered / pickup ready | Delivery Notification | Keep non-promotional |
| Payment failure / invoice | Account Notification | Avoid promo CTAs |
| Back-in-stock | Often Marketing or Mixed—confirm with CSP | Explicit alert opt-in recommended |
| Abandoned cart | Marketing | Marketing-grade consent |
| Flash sale / coupon | Marketing | Marketing-grade consent |
| Loyalty offers | Marketing | Marketing-grade consent |
Alignment rule: Campaign description, samples, and checkout language must match. Bandwidth’s best practices require descriptions that state who you are, who you reach, and why you message—and warn against inconsistent samples vs attributes (Bandwidth campaign best practices).
Brand and Website Packaging for Stores
- Legal name and EIN must match tax/business records used for Brand verification.
- Storefront URL must work; “coming soon” or password walls commonly fail review.
- Privacy policy should address SMS/mobile information sharing. See 10DLC privacy policy template.
- Terms/privacy URLs in Campaign fields must be publicly reachable.
- If you sell age-restricted or SHAFT-adjacent products, review carrier prohibited-content rules before submitting—website content can sink a Campaign even if SMS samples look clean.
Checkout Opt-In That Reviewers Can Verify
Bandwidth and CSP guidance emphasize 1:1 opt-in that is not implied and not hidden only inside long T&Cs.
Order-updates pattern (illustrative):
- Unchecked box: “Text me order and shipping updates from [Store].”
- Nearby disclosure: frequency, msg & data rates, STOP/HELP, privacy link.
Marketing pattern (illustrative):
- Separate unchecked box: “Also send me sales, cart reminders, and offers via SMS.”
- Do not force marketing SMS as a condition of purchase when alternatives exist—confirm TCPA/state rules with counsel.
Retain: timestamp, phone, cart/order ID, disclosure version, IP/user agent where available.
Sample Messages (Illustrative)
Operational
- [Store]: Order #[1234] confirmed. We’ll text tracking when it ships. Reply STOP to opt out, HELP for help. Msg&data rates may apply.
- [Store]: Order #[1234] shipped. Track: [link]. Reply STOP to opt out.
Marketing (separate consent/Campaign)
- [Store]: Your cart is waiting—checkout by midnight for free shipping. [link] Msg frequency varies. Reply STOP to opt out, HELP for help. Msg&data rates may apply.
Use brackets for variables in TCR samples per Twilio collect-business-info guidance.
Decision Framework: Plugin → Production
- Inventory every SMS trigger in WooCommerce/plugins/ESP.
- Tag each trigger operational vs marketing.
- Choose one Delivery/Customer-Care Campaign and, if needed, one Marketing Campaign.
- Rewrite checkout checkboxes to match Campaign descriptions.
- Publish privacy SMS section; capture screenshots for
message_flow. - Register Brand, then Campaigns, via your CSP (often Twilio Console for WooCommerce Twilio setups).
- Create Messaging Service; attach approved numbers; map plugin “From” to registered senders.
- Soak-test order updates on a real order before enabling cart recovery blasts.
- Sync STOP across plugin, ESP, and ESP suppression lists.
- Monitor error codes for unregistered/unassociated numbers.
Requirements Matrix
| Requirement | Order/shipping SMS | Promo / cart SMS | Notes |
|---|---|---|---|
| Brand registration | Yes | Yes | Same Brand typically |
| Campaign registration | Yes | Yes—often separate | Align use case |
| Checkout disclosure | Yes | Yes—separate box recommended | 1:1 opt-in |
| STOP / HELP | Yes | Yes | Honor across systems |
| Live privacy policy | Yes | Yes | Public URL |
| Embedded link attribute | Set accurately if tracking links used | Same | Mismatch → resubmit |
| WooCommerce plugin config | Map statuses | Map marketing flows | Does not replace TCR |
Risks and Failure Modes
| Risk | Impact | Mitigation |
|---|---|---|
| Cart promo samples on Delivery Campaign | Rejection / filtering | Split Campaigns |
| Pre-checked SMS boxes | Consent challenges | Unchecked, clear copy |
| Unregistered Twilio number in plugin | Blocks (e.g., 30034-class) | Register + associate |
| Shared agency Brand for many stores | Identity failures | Brand per merchant EIN |
| SHAFT content on store site | Denial | Remove or use approved paths only |
| STOP not synced to ESP | Complaints / TCPA risk | Central suppression |
| Buying more numbers for throughput | Does not multiply 10DLC capacity | Vetting / correct use case—confirm with CSP |
Implementation Checklist (Owner + Artifact)
| Step | Owner | Artifact |
|---|---|---|
| SMS trigger inventory | Dev / marketing ops | Spreadsheet |
| Use-case classification | Compliance | Signed map |
| Checkout UI update | Frontend | Staging screenshots |
| Privacy policy SMS section | Legal | Live URL |
| Brand + Campaign submit | Messaging admin | CSP IDs |
| Number → Messaging Service | Dev | Sender pool audit |
| Plugin From-number config | Dev | Config export |
| STOP sync test | Dev | Test thread log |
| Order soak test | Ops | Delivery metrics |
| Promo enablement gate | Marketing lead | Go-live ticket |
Soft CTA
Before you submit, validate Brand consistency, sample alignment, and disclosure pages with MyTCRPlus tools and, if you need public SMS policy pages, review compliance microsite options. These help packaging readiness; they do not guarantee approval.
FAQ
Does WooCommerce require 10DLC?
If you send US A2P SMS from a 10DLC number through a plugin or app, yes—you need Brand + Campaign registration. The platform name does not create an exemption.
Can order and promo texts share one Campaign?
Possible with Mixed / Low-Volume Mixed, but separating Marketing is cleaner for consent and approval. Confirm fees/throughput with your CSP.
Are shipping texts “transactional” so TCPA never applies?
Transactional framing helps Campaign packaging, but autodialed/marketing rules and state laws still matter. Do not add sale CTAs to shipping templates on a non-marketing Campaign. Ask counsel for edge cases.
What if we only text a few orders per day?
Low volume does not remove registration requirements for US 10DLC A2P. Low-Volume Campaign types may fit—confirm with CSP.
Do grocery shops follow the same rules?
Yes for US 10DLC A2P order-ready and promo texts.
How do we prove opt-in to reviewers?
Provide a live checkout URL or screenshots/video of the consent flow in the Campaign message-flow field, matching Bandwidth/Twilio expectations for verifiable opt-in.
What happens if we send unregistered?
Major CSPs block unregistered US 10DLC traffic; Twilio documents error 30034 and possible charges on blocked attempts. See the noncompliance guide.
Should we use toll-free for ecommerce?
Toll-free verification is a separate path some national brands prefer. Compare registration, branding, and throughput—not as a way to skip consent.
Can we use the same number for support chat and blasts?
Possible if Campaign scope and consent cover both; mixed programs need careful description. Many brands separate support vs marketing numbers/Campaigns.
Do we need double opt-in?
Not universally mandated for all ecommerce SMS, but double opt-in can strengthen proof for marketing programs. See single vs double opt-in.
Key Takeaways
- Ecommerce SMS on US 10DLC requires Brand + Campaign registration—plugins are not a loophole.
- Separate order/shipping programs from marketing when content and consent differ.
- Checkout opt-in must be clear, 1:1, and documented.
- Align samples, use case, and website disclosures before submit.
- Wire STOP across cart, ESP, and CSP.
- Test with real orders after number association.
- Use MyTCRPlus tools/microsite help for packaging—never claim guaranteed approval.
Disclaimer
This article is informational only and not legal advice. CSP fees, carrier filtering, Campaign outcomes, and TCPA exposure depend on your facts. Confirm requirements with your provider and qualified counsel before sending retail SMS. MyTCRPlus does not guarantee approval or deliverability.