Build or Buy Marketing Consent and Opt-In Records on Shopify?
Marketing consent and opt-in compliance records is a CUSTOMIZE on Shopify: the record already exists. Shopify stores a consent timestamp, opt-in level, current state and collection source for both email and SMS, and surfaces none of it as a report. Dataships starts at $500/month with no free plan (verified Sep 2026). Build the report; buy the capture.
Your profile — see how the verdict shifts
- Confidence
- High — Read Shopify's Admin GraphQL customer consent objects. Email consent state carries consentUpdatedAt for when the customer consented, marketingOptInLevel described against M3AAWG best-practice guidelines, marketingState for the current state, and sourceLocation for where consent was given. The SMS equivalent carries the same fields plus consentCollectedFrom. Shopify's own customer-management help page surfaces only editable Accepts email marketing, Accepts SMS marketing and Accepts WhatsApp marketing flags, and documents no timestamp, opt-in level or audit retrieval in the admin. Searched Marketing and conversion for checkout and email marketing, plus Store management security, and found only terms-checkbox apps and mainstream email platforms. Dataships is a near-singular specialist at 5.0★ across 72 reviews, no free plan, from $500/month (verified Sep 2026). The data exists; the retrieval is the gap.
- Reference scenario
- $20M–$100M GMV · SMS and email to 200,000+ contacts · US plus EU or UK buyers · consent also collected in store and by SMS keyword · agency dev bench
- As of
- September 2026
Decision at a Glance
| Your profile | Verdict | Why |
|---|---|---|
| Email only, consent captured at Shopify checkout | WAIT | The native fields already hold the timestamp, opt-in level, state and source for every contact. Write the export when someone first asks for it, and pay nothing until then. |
| SMS at scale, US buyers only | CUSTOMIZE | Per-message statutory exposure changes the stakes, and the data you need is already in the API. Build the ledger and the audit export rather than paying a subscription to read your own fields. |
| US plus EU or UK buyers | BUY | Region-aware opt-in language at checkout is genuinely hard and is exactly what Dataships sells, from $500/month with no free plan (verified Sep 2026). Capture is worth more than storage here. |
| Consent also collected in store, at events or by SMS keyword | BUILD | Reconciling off-platform opt-ins into one record per contact is nobody's product. Own the ledger, because the contacts most likely to trigger a complaint are the ones that never passed through checkout. |
What Marketing consent and opt-in compliance records Actually Drives
| Outcome | Impact | How it works |
|---|---|---|
| Revenue — indirect | High | Statutory damages on unconsented messages attach per message, so one bad list segment multiplies across every send instead of costing a single penalty. |
| Retention & LTV | Medium | Region-aware opt-in language collects more valid consent at checkout, which grows the list you are actually permitted to message rather than the one you hold. |
| Operational efficiency | Medium | An export that answers when, where and at what level a contact consented turns a legal request from a week of database work into a report someone runs. |
| Data & insight | Medium | Consent source and collection location show which acquisition channels produce contacts that survive scrutiny, and which ones quietly create exposure. |
Spend ceiling: Size the spend to message volume and exposure rather than contact count. US statutory damages on unconsented messages have historically reached $1,500 per message (verify against current law with your counsel), which makes every number on this page small. Start with the export, because the underlying data already sits in Shopify.
What buying enables (top apps)
- + Consent forms and SMS intake that adapt to the visitor's location and the privacy law that applies there
- + Detailed audit logs tracking consent status, maintained by a vendor whose business is keeping that language current
- + More consented contacts collected at checkout, which is why the pricing is structured around incremental contacts
- + A dedicated success manager on the Plus tier and above, useful when counsel is asking questions you cannot answer
What building additionally unlocks
- + An append-only history of consent changes, which the customer record alone does not preserve
- + Reconciliation of SMS keyword, in-store and event opt-ins into one record per contact, which no product on the App Store does
- + An audit export shaped to what your counsel actually asks for, generated the same day a demand arrives
Find Your Verdict in 3 Questions
Do you send SMS marketing as well as email?
Yes: Go to question 2.
No: Your verdict: WAIT — the native consent fields already carry timestamp, opt-in level, state and source for email; write the export when someone first asks.
Is any consent collected outside Shopify checkout, such as SMS keyword, in store or at events?
Yes: Go to question 3.
No: Your verdict: CUSTOMIZE — build the ledger and audit export from the native fields ($12,000–$35,000, Deploi estimate, illustrative).
Do you also need region-aware opt-in language for EU or UK buyers, not just the record?
Yes: Your verdict: BUY — region-aware capture is what Dataships is built for, from $500/month with no free plan (verified Sep 2026).
No: Your verdict: BUILD — reconciling off-platform consent into one record per contact is nobody's product; own the ledger and the export.
The TCC Scorecard — 12 Dimensions
TCC — Total Cost of Capability: what it actually costs to have this capability over three years, whichever way you get it. Each dimension is scored 0–5 for both paths. How we score →
| Dimension | Buy | Build | Why |
|---|---|---|---|
| Cost | |||
| Acquisition & implementation | Dataships installs and starts adapting forms quickly on a 5-day trial; the ledger and audit export are an estimated 3–7 weeks (Deploi estimate, illustrative). | ||
| Recurring fees | Pricing runs $500–$3,500/month with no free plan and per-contact overage from $1.50 to $2 (verified Sep 2026); a ledger reading native fields carries no subscription. | ||
| Maintenance & upgrades | The vendor tracks changing regional privacy language for you, which is real work; your own ledger needs its export format revisited when counsel asks for something new. | ||
| Switching & exit | Consent state stays on the Shopify customer record either way, and what leaves with the vendor is the audit log and the region-specific wording history. | ||
| Risk | |||
| Vendor risk | Dataships is strong at 5.0★ across 72 reviews and carries no Built for Shopify badge, and the deeper risk is concentration: a search of three App Store categories found no comparable specialist. | ||
| Security & compliance surface | Any consent tool holds contact identifiers and the evidence behind them, so an owned ledger keeps that evidence inside systems you already have to secure. | ||
| Platform-deprecation exposure | The consent objects are first-class Admin API types, and a ledger pinned to one API version needs moving before that version sunsets on the 12-month window. | ||
| Value | |||
| Fit to requirement | Dataships fits the capture problem precisely; only an owned ledger reconciles SMS keyword, in-store and event opt-ins into one record per contact. | ||
| Time to market | Region-aware forms go live in days, while a ledger and a defensible export take most of a sprint cycle before anyone can read a report. | ||
| Performance & scale | Both lanes scale fine on data volume, and the buy lane's cost scales with incremental contacts while the build lane's does not. | ||
| Data ownership & AI-readiness | The decisive dimension: an append-only consent ledger is the evidence you produce in a dispute, and it belongs beside your customer data rather than in a vendor's log. | ||
| Focus & opportunity cost | Nobody should write regional privacy language from scratch, and reading four fields your own store already stores is a small, well-bounded project. | ||
The App Landscape
| App | Status | Pricing | Best for |
|---|---|---|---|
| Shopify customer marketing consent | Native — First-party Shopify data model. Email consent carries consentUpdatedAt, marketingOptInLevel described against M3AAWG best-practice guidelines, marketingState and sourceLocation. The SMS equivalent carries the same fields plus consentCollectedFrom. The admin screen exposes only editable Accepts email marketing, Accepts SMS marketing and Accepts WhatsApp marketing flags, with no timestamp, opt-in level or audit retrieval on screen. | Included on every Shopify plan (verified Sep 2026) | Holding the raw consent evidence you already have, one API call away from a report |
| Dataships Checkout Opt-in | Live — 5.0★, 72 reviews; no Built for Shopify badge; 5-day free trial and no free plan. Adapts consent forms and SMS intake to a visitor's location and regional privacy law, and tracks consent status with detailed audit logs. Priced by incremental contacts, which tells you it is sold as a list-growth product as much as a compliance one. | Starter $500/month with 200 incremental contacts and $2 per additional contact; Plus $1,500/month with 1,000 and $1.75; Pro $3,000/month with 2,000 and $1.50; Custom $3,500/month above 2,000 (verified Sep 2026) | Region-aware consent capture at checkout when growing a consented list is the actual goal |
| Terms-and-conditions checkbox apps | Category — What a search for consent tooling mostly returns, and not the same capability. These listings add a checkbox and record whether it was ticked. They do not vary language by region, reconcile consent captured outside Shopify, or produce an audit report, and a ticked box with no timestamp, level or source is not a consent record. | Monthly subscriptions vary by listing; confirm on the current listing before comparing | A checkout agreement checkbox, which is a separate job from proving marketing consent |
| Consent ledger and audit report (custom) | Build lane — An append-only ledger built from the native consent fields, plus reconciliation of opt-ins captured outside Shopify and a per-contact export showing when, where, at what opt-in level and under what wording a contact consented. | $12,000–$35,000 one-time, plus upkeep (Deploi estimate, illustrative) | Merchants who already capture consent well and cannot produce the evidence on demand |
The Build Path
- Consent ledger from the native fields: A scheduled read of consentUpdatedAt, marketingOptInLevel, marketingState and sourceLocation, plus consentCollectedFrom for SMS, written into an append-only ledger. The customer record carries the current consent state, so the ledger is what preserves the trail of every change, including the ones a customer later reverses.
- Off-platform consent reconciliation: SMS keyword opt-ins, in-store signups and event lists never pass through checkout, and they are the contacts most likely to attract a complaint. Each one needs a source, a timestamp, an opt-in level and the exact language shown, written back onto the customer record so one record answers for the contact.
- Audit-ready export: A per-contact report your counsel can read without a developer: when consent was given, where, at what level, under what wording, and what was sent afterwards. The report is the actual deliverable, and it is the part that takes a week of database work when nobody built it in advance.
- Effort band
- $12,000–$35,000 for the ledger, off-platform reconciliation and the audit export — Deploi estimate (illustrative); lands in the $10–25K contact-form band, or $25–75K when several off-Shopify capture points are in scope
- Typical timeline
- 3–7 weeks, with off-platform reconciliation adding most of the range (Deploi estimate, illustrative)
- Maintenance, honestly
- ~15–20% of build cost per year (Deploi estimate): roughly $1,800–$7,000/yr (Deploi estimate, illustrative) to follow Admin API version changes on the 12-month cycle, add new capture points as marketing adds channels, and adjust the export when counsel asks for a different cut.
- What you own — and what you take on
- You own: the consent history, the reconciliation of every capture point, and an export you can hand to counsel the same day a demand arrives. You take on: keeping new capture points wired in, since a channel added by marketing without a consent path is exactly the gap the ledger was built to close.
3-Year Total Cost of Capability
| Buy (app path) | Build (custom path) | |
|---|---|---|
| Year 0 (setup) | $500–$3,500 (first month) | $12,000–$35,000 |
| Years 1–3 (recurring) | $18,000–$126,000 | $5,400–$21,000 (upkeep) |
| 3-year total | ≈$18,500–$129,500 | ≈$17,400–$56,000 |
- † All figures illustrative samples for the reference scenario — not quotes, not verified pricing.
- † Buy column: Dataships Starter at $500/month at the low end and Custom at $3,500/month at the high end (verified Sep 2026); per-contact overage excluded because it depends on list growth.
- † Build column: consent ledger, off-platform reconciliation and audit export built once; three-year horizon.
What the Sticker Price Hides
On the buy path
- — Per-contact overage sits on top of the plan, from $1.50 to $2 per additional contact depending on tier (verified Sep 2026)
- — There is no free plan and the trial runs 5 days, which is short for evaluating a compliance record
- — Pricing by incremental contacts means a good quarter of list growth raises the bill
- — The audit log lives with the vendor, so export terms matter more here than in most categories
On the build path
- — The customer record carries the current consent state, so without a ledger the history of changes is not preserved
- — Off-platform capture points get added by marketing without warning, and an unwired channel is an invisible gap
- — Region-specific opt-in language is a legal question rather than an engineering one; get it drafted, do not improvise it
- — ~$1,800–$7,000/yr upkeep (Deploi estimate, illustrative)
What Merchants Say
Marketing leads describe the same request landing on the wrong desk: a legal demand asks when and how one specific number opted in, and the answer takes a week of database work because nobody built the export.
The recurring blind spot is off-platform capture: keyword opt-ins, in-store signups and event lists that never touched checkout, sitting in the same send as fully consented contacts.
If You Change Your Mind Later
If you bought and outgrow it
Consent state itself stays on the Shopify customer record, so the contacts and their current status are never stranded. What leaves with the vendor is the detailed audit log and the history of which regional wording each visitor saw, which is precisely the evidence a dispute turns on. Export both on a schedule and confirm the retention terms before you sign, not at cancellation.
If you built and want out
Nothing strands, because the ledger is your own append-only table built from Shopify's own fields and the export is a report you generate. If you later buy region-aware capture, the ledger keeps working underneath it and becomes the historical record for everything collected before the vendor arrived.
When This Answer Changes
We're watching for:
- ▸ Shopify surfacing consent timestamp, opt-in level and source in the admin rather than only through the API
- ▸ A second dedicated consent-record listing appearing in the App Store, which would end the current single-specialist position
- ▸ Dataships moving away from incremental-contact pricing, which is what makes it a growth product as much as a compliance one
Verdict change log:
No changes since first publication (September 2026).
Common Questions
Does Shopify store marketing consent records?
Shopify stores marketing consent as structured data. Email consent carries a consent timestamp, an opt-in level described against M3AAWG best-practice guidelines, the current marketing state and the source location. SMS consent carries the same fields plus where consent was collected from (verified Sep 2026). The admin screen shows only editable Accepts email marketing, Accepts SMS marketing and Accepts WhatsApp marketing flags.
What does Dataships cost, and what does it actually do?
Dataships starts at $500/month for 200 incremental contacts and $2 per contact beyond that, rising to $3,500/month above 2,000 contacts, with no free plan and a 5-day trial (verified Sep 2026). The app adapts consent forms and SMS intake to a visitor's location and regional privacy law, and tracks consent status with detailed audit logs. Pricing by incremental contacts means it is sold as list growth.
What does a consent audit trail need that Shopify does not keep?
A consent audit trail needs three things Shopify does not keep. History, because the customer record carries the current consent state rather than every change to it. Off-platform consent, since SMS keyword opt-ins, in-store signups and event lists never pass through checkout. And the exact wording shown at the moment of opt-in. Expect $12,000 to $35,000 to build all three (Deploi estimate, illustrative).
Your Next Steps
If you're going with CUSTOMIZE(matches your selected profile)
- Pull consentUpdatedAt, marketingOptInLevel, marketingState and sourceLocation for a sample of contacts and see what you already have
- List every place consent is captured today, including the ones marketing added without telling anyone
- Build the append-only ledger first, since the customer record keeps only the current state
- Have counsel specify the export they would actually want, then build that report rather than a dashboard
- Wire off-platform capture points in one at a time, starting with SMS keyword opt-ins
If you're going with BUY
- Use the 5-day trial deliberately, since there is no free plan to fall back on (verified Sep 2026)
- Measure consented contacts gained, because incremental contacts are what you are being charged for
- Model overage at $1.50 to $2 per additional contact against your expected list growth (verified Sep 2026)
- Confirm export terms for the audit log and the regional wording history before signing
- Keep reading the native consent fields in parallel, so the record survives a vendor change
Official Docs & Sources
- Customer email marketing consent state (Admin API) — shopify.dev
- Admin GraphQL API — shopify.dev
- Customer privacy settings — Shopify Help Center
Official documentation linked for verification — our verdicts and estimates are our own.
Related Decisions
Build or Buy an Admin Activity Audit Log on Shopify?
Shopify records who signed in, never who changed a price. No app provides a field-level admin audit log, which makes this a build or nothing at all.
Build or Buy API and Webhook Deprecation Tracking on Shopify?
Shopify warns the whole world when an API version sunsets. Nothing tells you which of your own integrations still depends on it, and no app fills that gap.
Build or Buy API Rate-Limit and Throttling Management on Shopify?
No app manages Shopify Admin API rate limits across the apps on a store. Each app gets its own plan-sized bucket; your integrations need a rate-aware queue you own.
Build or Buy Checkout Extension and Theme App Conflict Debugging?
No app detects two Shopify apps fighting over the same extension point or cart drawer. The fix is a bisect runbook, an app register and a synthetic monitor you own.
Build or Buy Performance Monitoring & App Audits on Shopify?
Measurement is free on Shopify; storefront speed comes from an audit-and-remediation program, not a speed app.
Turn consent data you already have into evidence
Shopify records when, where and at what level every contact opted in. Nothing turns that into a report, keeps the history when consent changes, or accounts for the keyword and in-store signups that never touched checkout. We build the ledger and the export, so a legal request takes an afternoon.
Contact us todayVerdict scored for the reference scenario above. Estimates are not quotes; app pricing carries its verification date and gets re-verified quarterly. Full scoring anchors: see the TCC methodology.
Read how we score these decisions (the TCC Framework). No affiliate links, no paid placement — no app vendor pays to appear here.