CAN-SPAM and CartStack
Last updated September 15, 2026
The CAN-SPAM Act is the United States law governing commercial email. It applies to every commercial message sent to a US recipient, including business-to-business email, and it applies per message rather than per campaign. If you send recovery email through CartStack, it applies to you.
This page covers what the law requires, which obligations CartStack handles automatically, which ones stay with you, and how abandonment recovery messages are classified. It is written for our customers and for anyone evaluating whether recovery email is something they can send safely.
This is a plain explanation, not legal advice. It doesn't replace our Terms of Service or Privacy Policy.
Sending outside the US? See our GDPR page. GDPR and CAN-SPAM work on opposite consent models, and complying with one does not put you in compliance with the other.
Who carries the obligation
CAN-SPAM assigns responsibility to the business whose product or service is being promoted, and also to the party that actually transmits the message. Both can be held liable for the same email. Using a platform to send does not move the obligation off the business behind the message.
You, the sender
The recovery emails CartStack sends carry your brand, your offer, your from-address, and your customer relationship. You are the sender under the law. You decide who gets messaged, what the message says, and what offer it carries. Your physical address goes in the footer. Your opt-out is the one recipients act on.
CartStack, the platform
We transmit the messages on your instruction, and we build the required elements into the sending infrastructure so they're present by default rather than dependent on someone remembering. What we can't do is vet your list sources, write your subject lines, or decide what your business is allowed to promote.
The practical version: we make the compliant thing the default and the wrong thing hard to do by accident, but responsibility for the message is yours, and no platform can contract that away from you.
The requirements, in plain terms
1. Accurate header information. The from-name, from-address, reply-to, and routing data must honestly identify who sent the message.
2. Honest subject lines. The subject has to reflect what's actually inside. No bait and switch.
3. Identify the message as an advertisement. Required where the message is commercial, though the law allows flexibility in how the disclosure is made.
4. A valid physical postal address. A current street address, a registered post office box, or a private mailbox registered with a commercial mail receiving agency.
5. A clear way to opt out. Visible, easy to find, and functional for at least 30 days after the message was sent.
6. Honor opt-outs within 10 business days. You cannot charge a fee, require the recipient to log in, or ask for anything beyond an email address and their opt-out preferences.
7. Monitor what's sent on your behalf. Delegating the send does not delegate the liability.
Notably absent from that list: prior consent. CAN-SPAM is an opt-out regime. It does not require a recipient to have subscribed before you send them a commercial message, which is the single largest structural difference between US and EU email law.
How abandonment emails are classified
This is the question we get most often, and the honest answer is that cart, booking, and checkout recovery emails should be treated as commercial messages, not transactional ones.
CAN-SPAM recognizes a transactional or relationship category that's exempt from most requirements, covering things like order confirmations, shipping updates, and account notices. An abandoned cart is not a completed transaction. The message exists to prompt a purchase that hasn't happened yet, which is promotional in purpose even when it's genuinely useful to the person receiving it.
Where a message mixes both, the test is primary purpose, judged on the overall impression the message creates: subject line, layout, tone, and what gets the emphasis. Dressing a promotional message in transactional clothing is a well-worn enforcement target rather than a loophole.
The practical consequence is straightforward. Treat every recovery message as commercial, include the full set of required elements, and the classification question stops mattering.
This includes Send My Cart and Send My Stay. Those messages are triggered by a visitor asking to receive their cart or booking details, and the reminder sequence that follows is promotional in purpose. We treat the entire flow as commercial and include the full required elements throughout. It is the safer position, and it costs nothing to take.
What the platform handles
- Unsubscribe in every commercial template. Present by default across email campaigns.
- Physical address in message footers. Captured at account setup and merged into the footer of outgoing campaigns.
- Automatic suppression. An opt-out removes the address from future campaigns for that account.
- Authenticated sending. SPF, DKIM, and DMARC alignment on customer sending domains, which supports accurate header information and deliverability at the same time.
- Opt-out links that stay live. Unsubscribe URLs remain functional well beyond the 30 day minimum.
What stays with you
- Where your list came from. CartStack captures addresses from activity on your own site. If you import addresses from another source, their provenance is yours to stand behind.
- What your messages say. Subject lines, offers, and claims are yours. A deceptive subject line sent through compliant infrastructure is still a violation.
- Keeping your address current. A physical address that's no longer valid fails the requirement as surely as a missing one.
- Honoring opt-outs everywhere. If someone unsubscribes from your CartStack campaigns, continuing to message them from another platform is still a problem. Suppression needs to be shared across your stack, not siloed per tool.
- State law. CAN-SPAM preempts most state email statutes, but not provisions addressing falsity or deception, and a number of states maintain their own requirements. Where you send matters as well as what you send.
SMS and push notifications
CAN-SPAM covers email. It does not govern text message marketing, which falls under the Telephone Consumer Protection Act. The TCPA works on an opt-in model, with meaningfully different rules and a private right of action that CAN-SPAM largely lacks.
If you're running SMS recovery through CartStack, CAN-SPAM compliance does not cover you for those messages. Consent for SMS has to be collected and documented separately.
Browser push notifications sit outside both frameworks. They're governed by the browser's own permission model, which requires the visitor to have granted permission before anything can be sent.
Identified visitors and list building
CAN-SPAM does not require prior consent before sending a commercial email. A visitor identified on your site who never subscribed to anything can be sent a commercial message without that alone constituting a federal violation, provided the message meets the requirements above.
That is the legal floor, and it isn't the whole picture. Three things sit on top of it.
State provisions addressing deception are not preempted, and they apply regardless of how the address was obtained. Mailbox providers make their own filtering decisions based on engagement and complaint rates, which means a technically lawful send to an unengaged list can still damage your sending reputation in ways the law has nothing to say about. And if any portion of your audience is in the EEA or UK, a different framework applies entirely. See our GDPR page.
Our position is that what's permitted and what's advisable are different questions, and we'd rather you know where the line between them sits.
Email we send
The same rules apply to us. Our commercial email carries accurate headers, subject lines that match the contents, our physical address, and a working unsubscribe link. Opt-out requests are honored promptly, and we don't follow an unsubscribe with a promotional "sorry to see you go" message, which is itself a common violation.
To stop receiving commercial email from CartStack, use the unsubscribe link in any message or write to us at the address below. Opting out of marketing email does not stop transactional messages about an active account, such as billing notices or service alerts.
What non-compliance costs
CAN-SPAM is enforced by the Federal Trade Commission, with additional authority held by state attorneys general and internet service providers. Penalties attach per message rather than per campaign, so a single non-compliant send to a large list carries exposure that scales with the size of that list.
The statutory maximum is adjusted annually for inflation and currently exceeds $50,000 per violating email.
Aggravated conduct, including address harvesting, dictionary attacks, and falsified header information, carries additional penalties and can reach criminal liability.
Questions
Compliance contact: support@cartstack.com
Physical address: CartStack LLC, 1705 Southcross Dr W., Suite 107, Burnsville, MN 55306
Unsubscribe from CartStack marketing: use the link in any message, or contact us at the address above.
Changes to this page
We update this page as our practices and the law change. The last reviewed date appears at the top.