If you’re about to switch on SMS in Klaviyo or Postscript, or you’ve already sent a few campaigns and are now wondering whether you’re doing it properly, the short answer is: yes, SMS marketing is legal in Australia. But it’s regulated, and the rules are stricter in practice than most Shopify merchants assume when they first tick the “enable SMS” box in an app’s settings.
The law that governs it is the Spam Act 2003 (Cth), enforced by the Australian Communications and Media Authority (ACMA). It treats commercial SMS essentially the same way it treats marketing email, same core obligations, same regulator, same exposure if you get it wrong. Most Shopify merchants have spent years thinking about email compliance and almost none thinking about SMS, simply because it’s a newer channel for most stores.
This guide walks through what the Spam Act actually requires for SMS marketing, how consent, unsubscribe and sender identification work in practice on a Shopify store, and how that maps onto the settings inside Klaviyo SMS or Postscript. None of this is legal advice for your specific situation, if you’re unsure how the Act applies to your business, it’s worth a conversation with a lawyer who specialises in privacy and marketing law. What follows is the general compliance framework every Shopify merchant sending SMS should understand before their next campaign goes out.
What the Spam Act 2003 Actually Covers
The Spam Act regulates “commercial electronic messages”, a category that includes marketing email, SMS, MMS and instant messages, provided the message has an Australian link. That link exists if the message is sent from Australia, sent to a phone number or address in Australia, or authorised by a business that carries on activities in Australia. For an Australian Shopify store texting its own customer list, that link is automatic.
It’s worth separating this from a piece of legislation merchants sometimes confuse it with: the Do Not Call Register Act 2006, which covers telemarketing calls and faxes, not SMS. SMS marketing sits squarely under the Spam Act, alongside email.
The Spam Act imposes three core obligations on anyone sending commercial electronic messages:
- Consent, you need permission to message the recipient, either express or inferred.
- Identification, the message must clearly identify who sent it and how to contact them.
- Unsubscribe, the message must include a functional way to opt out, and opt-out requests must be honoured.
Using a Shopify app like Klaviyo SMS or Postscript doesn’t change any of this. The app is the delivery mechanism; legal responsibility for compliant messaging sits with your business as the sender. An app’s default settings are a starting point, not a guarantee, most of the mistakes covered below happen inside apps that are perfectly capable of compliant sending, because a merchant configured (or didn’t configure) something incorrectly.
Is SMS Marketing Legal for Shopify Stores in Australia?
Yes, provided all three obligations above are genuinely met, not just technically present. A store can have an unsubscribe link in every message and still be non-compliant if it’s texting customers who never opted in to SMS marketing specifically, or if unsubscribe requests aren’t actually being processed. Having the right features in your SMS app doesn’t automatically mean you’re using them correctly. The rest of this guide covers where Shopify merchants most commonly go wrong.
Consent: The Foundation of Compliant SMS Marketing
Consent is where most SMS compliance problems start, largely because Shopify stores generally collect phone numbers for several different reasons, order confirmations, shipping updates, checkout, and it’s easy to conflate “we have this customer’s mobile number” with “we have permission to market to this customer via SMS.” Those are not the same thing under the Spam Act.
Express consent
Express consent is permission the customer has actively and knowingly given for marketing messages specifically. On a Shopify store, this typically looks like:
- A clearly labelled SMS marketing opt-in checkbox at checkout (separate from the email marketing checkbox, bundling the two together, or defaulting SMS to checked, undermines the “express” nature of the consent).
- A dedicated SMS signup form or popup, where the customer enters their number specifically to receive marketing texts.
- A keyword opt-in (texting a word like “JOIN” to a shortcode), common with Postscript and supported in Klaviyo SMS depending on your setup.
Express consent is the safest basis for SMS marketing, and it should be the default approach for anything beyond genuinely transactional messages. It’s unambiguous, it’s easy to document, and it holds up if a customer ever disputes having agreed to receive texts.
Inferred consent
The Spam Act also recognises inferred consent, situations where it’s reasonable to conclude someone consented, based on their conduct or an existing business relationship, even without an explicit opt-in action. In practice, inferred consent is a much narrower and riskier basis for SMS than it is for email, and it’s not something we’d recommend building an SMS program on for a direct-to-consumer Shopify store. Regulators have historically applied inferred consent conservatively, and SMS is a more personal, more intrusive channel than email, a fact that raises, rather than lowers, the bar for what counts as reasonable.
What doesn’t count as consent
The single most common mistake: a customer provides their phone number at checkout for order and shipping updates, and the store adds that number to its general marketing SMS list without a separate opt-in. Collecting a number for transactional purposes does not create consent to market to it. If your checkout only captures one phone number field with no distinct marketing opt-in, you need a separate, explicit consent mechanism before that number goes into marketing sends.
Unsubscribe Requirements: What “Functional” Actually Means
Every commercial SMS must include a way to opt out, and that mechanism needs to actually work, not just exist.
What a compliant unsubscribe mechanism looks like
- A reply keyword (typically “STOP”) that immediately removes the customer from future marketing texts, not just that specific campaign.
- The opt-out facility needs to remain functional for a reasonable period after the message is sent, in practice, this means it should always work, not just for the first day or two.
- Requests need to be processed promptly. Treat “promptly” as meaning as close to immediately as your systems allow, rather than banking unsubscribe requests to process in batches at the end of the week.
Common Shopify SMS unsubscribe mistakes
- Channel silos: a customer replies STOP to SMS and is removed from texts, but stays subscribed to email, or vice versa, which is fine as long as the customer only asked to leave one channel, but becomes a problem if your app’s default behaviour doesn’t match what the customer actually requested.
- Custom keywords that break STOP: some merchants set up promotional reply keywords (like texting a word to get a discount code) without testing that the standard STOP keyword still works cleanly alongside them.
- Manual processing gaps: if any part of opt-out handling relies on someone manually removing a customer from a list, delays and human error creep in. Klaviyo and Postscript both automate STOP handling by default, the risk shows up when a merchant layers custom automation or a separate list on top of that default without testing it.
Sender Identification Requirements
Every commercial SMS needs to make clear who sent it and how the recipient can contact that business, typically your business name and either a phone number, email address or website. This information needs to stay accurate and accessible for a reasonable period after the message is sent, not just at the moment it’s delivered.
SMS’s 160-character limit makes this genuinely harder than email, where you have a whole footer to work with. Most compliant Shopify SMS programs solve this by putting the brand name at the start of every message (many carriers and platforms do this automatically via the sender ID) and keeping a consistent, recognisable “From” identity across every send, rather than cramming a full business address into every message.
How This Plays Out in Klaviyo SMS and Postscript on Shopify
Both platforms give you the building blocks for compliant sending, but neither one makes you compliant automatically, that still depends on how you configure and use them.
- Consent capture points: both integrate with Shopify checkout consent fields and offer their own popups and signup forms. Check that your checkout’s SMS marketing consent field is genuinely separate from the email one, and that any popup form makes clear the customer is opting into marketing texts, not just “joining the list.”
- Consent syncing: Klaviyo and Postscript both sync SMS consent status against the Shopify customer profile, but if you’re also running SMS through a second tool, or you’ve migrated platforms recently, it’s worth auditing that consent status actually transferred correctly rather than assuming it did.
- Segmentation by consent status: build your sending segments off the platform’s actual SMS consent field, not off “has a phone number on file”, the latter will include people who never opted into marketing.
- STOP handling and quiet hours: both platforms handle opt-out keywords automatically and let you configure sending windows (avoiding very early morning or late evening sends), which is good practice even though quiet hours themselves aren’t a strict Spam Act requirement in the same way consent and unsubscribe are.
The practical risk with both tools isn’t the software, it’s historical data. Many stores turn on SMS marketing and message a phone number list collected years earlier for entirely different purposes, or import a list from a previous platform without checking consent status transferred cleanly.
A Practical Compliance Checklist for Shopify SMS Marketing
Before you send your next SMS campaign, confirm:
- [ ] Your Shopify checkout has a distinct SMS marketing opt-in, separate from email consent, and it’s not pre-checked
- [ ] Any SMS signup form or popup clearly states the customer is opting in to marketing texts
- [ ] Your SMS sending segment is built from actual SMS consent status, not just “has a phone number”
- [ ] Historical or imported phone number lists have been audited for genuine, documented consent before being used for marketing
- [ ] STOP (or your chosen opt-out keyword) is tested and confirmed working, including alongside any custom reply keywords
- [ ] Opt-out requests are processed automatically and promptly, not via manual review
- [ ] Every marketing SMS clearly identifies your business, either in the message itself or via a consistent, recognisable sender identity
- [ ] Transactional messages (order confirmations, shipping updates) are kept separate from marketing sends in your logic and reporting
When to Bring in a Specialist
Basic consent and unsubscribe hygiene is manageable in-house once you understand the rules. It gets genuinely harder at scale, merging historical customer data from a platform migration, reconciling consent across multiple apps, or building flows and automations that need to respect consent status at every step without manual checking.
This is exactly the kind of setup work a proper Klaviyo email marketing engagement is built to get right from the start, consent capture, list hygiene, segmentation and flow logic configured properly against your actual Shopify data, rather than left to an app’s defaults. If you’re also weighing up which platform to run SMS through in the first place, it’s worth understanding how Klaviyo connects to Shopify natively before adding a second, separate SMS tool on top.
FAQ
Do I need separate consent for SMS and email marketing on Shopify?
Yes. Consent under the Spam Act is generally understood to be channel-specific, a customer opting into marketing emails hasn’t automatically opted into marketing texts, and vice versa. Your Shopify checkout and signup forms should capture these as distinct choices, not a single combined toggle.
Can I text customers who abandoned their cart without explicit SMS marketing consent?
Not for an abandoned cart marketing message. If the customer has genuinely opted into SMS marketing, an abandoned cart text is a normal use of that consent. If they haven’t opted in to SMS specifically, even if they gave a phone number during checkout, sending a marketing-style cart recovery text would fall outside what the Spam Act treats as valid consent.
How quickly do I need to action an SMS unsubscribe request?
The Spam Act requires unsubscribe requests to be processed within a reasonable time, and the safest practice is to treat that as immediately or automatically. Klaviyo and Postscript both handle standard STOP replies this way by default, the main risk is anything that relies on manual processing or sits outside the platform’s automated opt-out handling.
Does the Spam Act apply to transactional SMS like order and shipping updates?
Purely transactional messages, order confirmations, shipping notifications, delivery updates, generally sit outside the Spam Act’s definition of a commercial message, because they’re not marketing. The distinction matters, though: if a transactional message also includes promotional content (a discount code, a cross-sell), it can be treated as a commercial message and pull in the full consent and unsubscribe requirements.
What happens if a Shopify store doesn’t comply with the Spam Act?
ACMA is the regulator responsible for investigating and enforcing Spam Act breaches, and non-compliance carries real regulatory and reputational risk. Beyond the legal exposure, non-compliant SMS sending tends to damage deliverability and customer trust well before it becomes a formal complaint, carriers and platforms both track complaint rates, and a pattern of unwanted texts affects your sender reputation over time.
Ready to Get Your SMS Program Set Up Properly?
If you’re setting up SMS marketing for the first time, or you’ve inherited a list you’re not confident is clean, it’s worth getting a second set of eyes on your consent capture, segmentation and unsubscribe handling before you scale up sending. Book a call with our team and we’ll talk through what a compliant, effective SMS setup looks like for your store.