Is my order confirmation email considered marketing? Shopify's rules are confusing me

Order confirmations and marketing blasts run on completely different consent rules — here's how Shopify actually draws the line, and how to document it so you stop guessing.

emailcomplianceGDPRCASLconsent

What's going on

A merchant asks: is my order confirmation email marketing? What about a shipping update with a discount code in it, or an abandoned-checkout reminder? Shopify sends some emails automatically to every customer no matter what, and gates others behind a subscription status, but nothing in the admin clearly explains which rule applies to which email, or what happens the moment you add promotional content to a transactional template.

This matters because transactional and marketing emails run on entirely different legal bases. A transactional email, like an order confirmation, shipping notice, or refund receipt, is justified because the customer initiated the transaction it relates to, so no separate opt-in is required. A marketing email, like a sale announcement, back-in-stock alert, or re-engagement campaign, requires the customer to have actively consented, and that consent has to be revocable through an unsubscribe link. Get the classification wrong and you're either annoying customers with unwanted promotional email, or exposing the store to a CASL, GDPR, or CAN-SPAM complaint.

The practical confusion usually shows up in three places: merchants adding upsell content to built-in transactional templates, automations sending to customers without checking their actual consent status first, and stores never writing down anywhere which message types rely on which legal basis, so every new automation reopens the same debate.

Why it happens

Shopify architecturally separates the two: system notifications are configured in your store's notification settings and fire based on order and fulfillment events regardless of marketing consent, while marketing sends through Shopify Email, Flow, or most apps check a per-customer consent field (subscribed, not subscribed, pending, or unsubscribed) before sending. The split exists in the platform, but it isn't surfaced as a single compliance explainer anywhere merchants naturally find it.

The ambiguity gets worse the moment content is mixed. Regulators generally look at how much of a message is promotional, so a shipping-confirmation email with a discount banner can lose its transactional exemption entirely, even though it started as an order-lifecycle email.

Consent itself is also jurisdiction-dependent: CAN-SPAM in the U.S. doesn't require opt-in for marketing email, just clear sender information and an unsubscribe link, while GDPR and CASL both require unambiguous, unchecked-by-default opt-in. A merchant selling internationally is effectively running two different consent regimes on the same checkout, which is where a lot of the 'why is this checkbox even here' confusion actually comes from.

5 ways to fix it

1

Leave order-lifecycle emails alone — don't dress them up with marketing content

Shopify's system notifications (order confirmation, shipping and delivery updates, refund receipts, and similar order-lifecycle emails) are managed under your store's notification settings and go out to every customer regardless of their marketing consent, because they're required to complete a transaction the customer already started. The simplest fix for most of the confusion is to keep promotional banners, discount codes, and upsell content out of these templates entirely. Once you mix marketing content into a transactional email, regulators and most email service providers will treat the whole message as marketing, which then needs the same opt-in and unsubscribe handling as any promotional send.

2

Check the customer's actual consent status before sending anything borderline

Every customer record in Shopify carries an email marketing consent state (subscribed, not subscribed, pending, or unsubscribed) along with a timestamp for when it last changed. Before sending anything that isn't a strict order-lifecycle email — a back-in-stock alert, a review request, a post-purchase upsell, an abandoned-checkout reminder — check this field rather than assuming a completed purchase implies marketing consent. It's also the record to pull if you ever need to show a regulator or payment processor what your consent basis was for a given customer.

3

Default any checkout marketing opt-in to unchecked

Shopify lets you add a marketing opt-in checkbox to checkout and customize its text. If you sell to customers in the EU/UK or Canada, that checkbox needs to start unchecked — pre-checking it does not count as valid consent under GDPR or CASL, even though U.S. CAN-SPAM rules are more permissive on this point. Set your default based on the strictest regime your customer base falls under, not your home market's rules.

4

Don't assume your automations are consent-aware by default

If you use Shopify Flow, Shopify Email, or a third-party app to send anything beyond core order notifications — restock alerts, win-back campaigns, custom status nudges — verify that the tool is actually checking each customer's consent before sending, rather than assuming it happens automatically. A lot of the 'why didn't this customer get my email' complaints come from automations that quietly skip or fail on unsubscribed customers, or worse, ones that don't check consent at all. Build an explicit consent check into any automation you set up rather than trusting it to happen behind the scenes.

5

Write down your consent basis once, per message type, and reuse it

The recurring frustration here isn't really a Shopify bug — it's that most merchants never write down, in one place, which of their message types are transactional (consent equals the transaction itself) versus marketing (consent equals opt-in), and what they're relying on for each. A short internal reference — sender name, message type, legal basis, which setting or field enforces it — resolves the ambiguity for good and is the kind of artifact a regulator or payment processor will actually ask to see during a review.

Bottom line

This is less a Shopify settings problem than a documentation gap: Shopify already separates transactional notifications, which send regardless of consent, from marketing sends, which are gated by each customer's marketing consent status, but it doesn't hand you a compliance memo explaining which is which for your specific message types. Write that memo once — sender, purpose, legal basis, enforcing setting — and the "is this marketing or transactional" question stops coming up. No app fixes this by itself; it's a policy and process decision, so if you're evaluating tools here, look at your email service provider's consent-management features rather than expecting a Shopify app to make the call for you.

Still Stuck?

Browse the rest of the problem library, run a free storefront scan to catch issues like this automatically, or email us and we'll work out a custom solution for it.