|
/ Documentation /Cart Abandonment/ GDPR / Privacy Compliance for Cart Tracking (Cookie Consent, Data Retention)

GDPR / Privacy Compliance for Cart Tracking (Cookie Consent, Data Retention)

If you serve customers in the EU, UK, or other jurisdictions with strict privacy laws, you need to ensure your cart abandonment tracking is compliant with regulations like GDPR, UK-GDPR, CCPA, and similar frameworks.

This guide explains:

  • What data Cart Abandonment Recovery captures
  • How to enable the built-in GDPR consent feature
  • Best practices for data retention, privacy policies, and unsubscribe handling

What Data Does the Plugin Capture?

When a shopper starts a checkout, the plugin stores:

  • Email address (primary identifier)
  • First & last name (if entered)
  • Billing/shipping details (if entered)
  • Cart contents — products, quantities, prices
  • Date and time of abandonment
  • Tracking token (used for unsubscribe links)

This data is stored in your WordPress database (in custom tables created by the plugin).

Prerequisites

  • Cart Abandonment Recovery plugin installed and activated
  • WooCommerce checkout configured
  • A published Privacy Policy page on your site

Step-by-Step: Enabling the Built-In GDPR Consent

Step 1 — Open GDPR Settings

Go to WooCommerce → Cart Abandonment → Settings → GDPR.

GDPR Settings

Step 2 — Enable Email GDPR Integration

Toggle Enable Email GDPR Integration to ON.

Once enabled, a consent notice will appear below the email field on your checkout page, asking the customer to agree to data tracking before their cart is captured.

Step 4 — Customize the Consent Message

Edit the GDPR message field. Use clear, plain-language wording that:

  • Names your store
  • Explains what data you collect
  • Links to your Privacy Policy
  • States the purpose (abandoned cart recovery emails)

Example:

By entering your email, you agree that [Your Store] may send you a recovery email if you don’t complete your order. See our Privacy Policy for details. You can unsubscribe anytime.

Step 5 — Save Settings

Click Save Settings and verify the consent appears on your checkout page.

GDPR Text On Checkout

Pro Feature: Phone Number GDPR Consent

If you’re using the Pro version and capturing phone numbers for SMS recovery, you’ll see an additional Enable Phone GDPR Integration toggle on the same GDPR settings tab. Enable this to add a separate consent notice below the phone field on checkout.

Cart Abandonment Recovery GDPR Setting

Best Practices for Data Retention

1. Limit Retention Period

Don’t keep abandoned cart data forever. Configure a reasonable Abandoned cart lost time (e.g., 30 days) and delete older records regularly.

How:

  • Go to Reports, filter by Lost status and old date ranges
  • Use Bulk Delete

2. Honor Deletion Requests

When a customer requests their data be deleted:

1.   Search for their email in Reports

2.   Delete all matching records

3.   Also delete associated WooCommerce orders if requested

3. Update Your Privacy Policy

Your Privacy Policy should disclose:

  • That you use Cart Abandonment Recovery (or a similar tool)
  • What data is captured (email, name, cart contents)
  • How long it’s kept
  • The purpose (sending recovery emails)
  • The lawful basis (typically “legitimate interest” or “consent”)
  • How users can opt out or request deletion

4. Offer a Clear Unsubscribe

Every recovery email must include {{unsubscribe_link}} — this is legally required, not optional.

See: Unsubscribe / Opt-Out Handling for Recovery Emails.

Tips & Best Practices

  • Enable GDPR consent even if you’re outside the EU — it’s good practice and works as a trust signal.
  • Link to your Privacy Policy in the consent text, not just mention it.
  • Use plain language — don’t hide data practices behind legal jargon.

FAQs

Was this doc helpful?
What went wrong?

We don't respond to the article feedback, we use it to improve our support content.

Need help? Contact Support
Table of Contents