TCPA claims and eCommerce sites: how text message lawsuits actually start
Most TCPA claims against online stores do not begin with a rogue campaign. They begin with a checkout checkbox, a spin-to-win popup, or a scheduled send that landed at 9:04 p.m. on the East Coast. Here is what a TCPA claim is, why storefronts are targeted, the defects plaintiffs' firms screen for, and the ten steps that close the exposure.

Key takeaways
- A TCPA claim is a private lawsuit over a marketing call or text sent without valid prior express written consent. No financial harm needs to be proven.
- eCommerce storefronts are targeted because the defective opt-in is public and reproducible — an attorney can screenshot your checkout in a browser.
- Damages are per message, so a single misconfigured flow across a mid-size list scales into six- and seven-figure demands.
- You must prove consent, and a subscriber row is not proof. Timestamp, source URL, IP, and the exact disclosure version are.
- Compliance is not a one-time fix — theme updates and new apps silently break a compliant opt-in, which is why drift monitoring matters more than an annual audit.
What is a TCPA claim?
The Telephone Consumer Protection Act, codified at 47 U.S.C. § 227, restricts marketing calls and text messages sent using automated technology. A TCPA claim is the private lawsuit the statute lets a consumer bring when they receive such a message without valid consent. Three features make it unusually dangerous for online retailers.
First, damages are statutory: $500 per negligent violation, up to $1,500 where the violation was willful or knowing. The plaintiff does not have to show they lost money, missed work, or suffered distress. Second, each message can be counted separately, so exposure is a function of list size multiplied by send frequency rather than of actual harm. Third, the burden of proving consent sits with the sender, not the recipient — an inversion of the usual litigation posture.
Claims arrive in three shapes: an individual demand letter seeking a nuisance-value settlement, a putative class action covering everyone who received the same defective flow, and a state attorney general or FCC enforcement inquiry. The demand letter is the most common first contact, and it is usually a probe to see whether you can produce consent records at all.
Why eCommerce sites attract TCPA claims
Plaintiffs' firms do not audit your ESP. They audit your storefront, because the storefront is public. A paralegal can load your checkout, complete a popup, and capture the exact opt-in language rendered on a given date. If that language is missing a required element, the case is largely made before a single subpoena issues.
Online retailers also concentrate risk in ways other businesses do not. Phone capture happens on many surfaces at once — checkout, cart abandonment, giveaways, quizzes, loyalty enrollment, and third-party lead pages — and each surface is often owned by a different team or a different app. Themes and apps update independently, so a disclosure that was compliant in January can be truncated by a template change in March with nobody noticing. Meanwhile the SMS list keeps sending, and every send after the regression is a fresh violation.
Add high send frequency (winbacks, flash sales, back-in-stock alerts) and nationwide scheduling, and the arithmetic turns hostile fast. A 40,000-number list receiving four campaigns a month produces 160,000 messages — the statutory ceiling on that alone is well past anything a mid-market brand wants in a complaint caption.
The eight opt-in defects that generate claims
These are the failures we see most often when scanning live storefronts, ordered by how directly they support a claim.
01Consent bundled with a discount
Critical"Enter your phone to unlock 15% off" with no separate SMS agreement makes consent a condition of the offer. Plaintiffs argue the consumer was buying a discount, not agreeing to recurring marketing.
02Pre-checked or implied opt-in at checkout
CriticalA phone field with an implicit "by continuing you agree to receive texts" line, or a checkbox already ticked, fails the affirmative-consent requirement almost per se.
03Missing required disclosures
HighThe opt-in must name the seller, state that messages are recurring marketing, say that consent is not a condition of purchase, disclose message frequency, and note that message and data rates may apply. Omitting frequency is the single most common defect we detect.
04One consent, many senders
HighLead-gen and affiliate forms that pass a single checkbox to a list of "marketing partners" no longer work under the one-to-one consent expectation. Each seller needs its own consent.
05Revocation not honored across programs
HighA STOP on the loyalty campaign must suppress that number across every marketing program. Numbers that keep receiving winback flows after opting out generate willful-violation exposure at $1,500 per message.
06Consent evidence you cannot produce
MediumMost brands can show a subscriber row. Few can show the timestamp, IP, source URL, and the exact disclosure version rendered on that date. Without the version history, the record proves nothing about what the consumer agreed to.
07Imported, purchased, or enriched numbers
MediumPhone numbers appended by a data vendor and labeled "opt-in" carry no transferable consent. Consent runs to the seller that collected it.
08Nationwide sends ignoring local time
MediumScheduling by a single account time zone rather than the recipient's local time produces quiet-hours violations across an entire region in one send.
How the damages math works
Exposure is not measured by the number of complaints you received. It is measured by the number of messages sent to numbers whose consent you cannot prove.
| Scenario | Messages | At $500 | At $1,500 |
|---|---|---|---|
| Single recipient, 6 messages | 6 | $3,000 | $9,000 |
| 1,000 numbers, 1 campaign | 1,000 | $500,000 | $1.5M |
| 10,000 numbers, 4 campaigns | 40,000 | $20M | $60M |
Real settlements land far below the theoretical ceiling, but the ceiling is what drives class certification pressure and what your insurer sees first. Reducing the count of unprovable-consent numbers is the single highest-leverage action available.
A ten-step plan to close TCPA exposure
01Inventory every phone-collection surface
Checkout, popups, footer signups, quizzes, giveaways, in-store tablets, landing pages, and every third-party lead form. You cannot defend a surface you did not know existed.
02Screenshot the live opt-in as a consumer sees it
Capture the rendered disclosure, not the code. This becomes your evidence exhibit and your baseline for drift detection.
03Unbundle consent from incentives
Discount capture and SMS consent become two distinct, separately actionable elements. State plainly that consent is not a condition of purchase.
04Rewrite disclosures to the full five elements
Seller name, recurring marketing messages, frequency, message and data rates, and the not-a-condition line — plus links to terms and privacy policy.
05Add double opt-in to the highest-risk surfaces
Checkout and giveaway forms produce the most disputed consent. A confirmation reply loop creates a second, consumer-initiated evidence point.
06Version your disclosure text
Store a hash and effective date for each disclosure variant, and link every consent record to the version the consumer actually saw.
07Log revocation as rigorously as consent
Accept STOP and free-form revocation on any channel, suppress within the required window, and record the timestamp and source channel.
08Enforce recipient-local quiet hours
Schedule by recipient local time with area-code fallback, and honor stricter state windows where they apply.
09Segregate transactional from marketing
Never attach a promotion to a shipping or order alert. Route the two through separate templates and separate consent states.
10Retain evidence for four years and monitor for drift
A theme update, an app install, or a new popup can silently break a compliant opt-in. Continuous scanning catches the regression before a demand letter does.
For the disclosure language and record-retention specifics, see our definitive TCPA compliance checklist.
What to do in the first 72 hours after a demand letter
- Preserve everything. Issue a litigation hold on consent logs, ESP exports, theme version history, and popup app configurations before anything auto-purges.
- Freeze the flow, not the evidence. Suppress the claimant's number immediately, but do not edit the live opt-in before it is captured — a quiet fix after notice reads as spoliation.
- Pull the consent record for that number. Timestamp, source URL, IP, user agent, and the disclosure version rendered that day.
- Scope the cohort. Identify every other number collected through the same surface during the same period. That set defines your class-exposure ceiling.
- Route to counsel. Statutory-damages exposure scales with message volume; a fast, evidence-backed response materially changes the negotiating posture.
Frequently asked questions about TCPA claims
What is a TCPA claim?
A TCPA claim is a private lawsuit brought under the Telephone Consumer Protection Act (47 U.S.C. § 227) by a person who received a marketing call or text without valid prior express written consent, after revoking consent, outside permitted hours, or without required identification. The statute gives consumers a private right of action with fixed statutory damages, so no proof of financial harm is required.
Why do eCommerce sites get TCPA claims specifically?
eCommerce brands collect phone numbers at high volume through checkout fields, spin-to-win popups, abandoned-cart flows, and SMS list-growth widgets. Those surfaces are the ones most likely to bundle SMS consent with a discount, pre-check the box, or omit the required disclosures — the precise defects plaintiffs' firms screen for. The storefront is also public, so an attorney can reproduce the defective opt-in flow in a browser and screenshot it as evidence.
What are TCPA statutory damages?
$500 per negligent violation and up to $1,500 per willful or knowing violation. Each individual message can count as a separate violation, which is why claims involving a modest list quickly reach six or seven figures on paper.
What is the statute of limitations for a TCPA claim?
Four years under the federal catch-all limitations period, 28 U.S.C. § 1658. That is why consent and revocation records must be retained for at least four years after the last message you sent to a number.
Who has the burden of proving consent?
The sender. In TCPA litigation the defendant must produce evidence that valid prior express written consent existed at the time each message was sent. A row in an ESP marked "subscribed" is generally not sufficient — courts look for the timestamp, the source, and the exact disclosure text the consumer saw.
Do TCPA rules apply to transactional order and shipping texts?
Order confirmations, shipping notifications, and delivery updates are generally treated as transactional rather than marketing, and do not require prior express written consent. Risk appears when a transactional message includes promotional content — a discount code appended to a shipping alert can reclassify the message as marketing.
Does an unsubscribe link protect me from a TCPA claim?
No. Opt-out mechanics matter, but liability attaches at the moment of sending without valid consent. An easy STOP flow reduces future violations; it does not cure messages already sent to a number that never gave express written consent.
Are quiet-hours violations really a claim theory?
Yes, and it is a growing one. Marketing calls and texts must land between 8:00 a.m. and 9:00 p.m. in the recipient's local time. Sending a nationwide 6:00 p.m. Pacific campaign puts every East Coast recipient at 9:00 p.m. or later, creating a clean, provable, list-wide violation from a single send.
See how your storefront's opt-ins would look to a plaintiff's firm
ConsentTensor scans every phone-capture surface on your site, flags missing disclosures, and monitors for drift after theme and app updates.
Run a free compliance scanConsentTensor provides compliance monitoring and guidance, not legal advice. Findings are surfaced with regulatory context for review by qualified counsel.