The postscript marketing setup that works on a $3M–$30M Shopify store is short on clever tactics and long on plumbing. Most of the damage is done before the first message goes out, in how consent is captured, how it’s labelled, and which system owns which trigger. This page is for operators on Shopify Plus or another paid platform who already run email and are adding SMS.
This guide is not for a store still deciding whether text belongs in the mix, or for a brand under the $3M floor that would be better off fixing its email first. If that’s you, the guide to SMS marketing for ecommerce is the right starting point.
What this page adds that the setup guides don’t: the step most teams get wrong is consent, and the cost shows up months later as double-texted shoppers and a subscriber list nobody can defend.
What do you need before you start postscript marketing?
Postscript marketing needs four things settled before anyone opens the app: a decision on which platform owns which trigger, a named person responsible for compliance sign-off, a consent wording draft, and a baseline of your current email flows. Skipping any of these is how a two-day install becomes a two-month cleanup.
The ownership decision matters most. If Klaviyo already sends your abandoned cart and welcome emails, you’re not replacing them. You’re adding a second channel to the same triggers, and the two systems don’t know about each other unless you make them. The comparison in Klaviyo vs Postscript covers the tool choice. This page assumes you’ve made it.
Gather these before you begin:
- Admin access to Shopify with permission to install apps and edit checkout settings.
- A copy of your current sign-up forms, so you can see what wording people have already agreed to.
- Your current abandoned cart and welcome email flows, printed or screenshotted, with their delays and exit rules.
- A contact at your legal or compliance function. Texting rules in the US sit under the TCPA and carrier requirements, and you should confirm specifics with counsel rather than with a blog post.
- The current pricing model from Postscript. It’s usage-shaped and changes, so read Postscript pricing for the structure and then check the vendor’s page for the number.
How do you set up Postscript marketing on Shopify, step by step?
Setting up Postscript marketing takes seven ordered steps. The order is deliberate: consent and source tagging come before any flow, because a flow built on numbers you can’t trace has to be rebuilt when someone asks where a number came from.
Labels in the Postscript admin move around between releases. The setting names in this guide describe what to look for, so if a menu is called something slightly different in your account, match on function.
Step 1: Connect Postscript to Shopify and audit what syncs
Install the app from the Shopify App Store and approve the permissions it requests. Read that list. It tells you what data Postscript will hold: customers, orders, products, and the marketing consent status Shopify stores per customer.
Then check three things before building anything.
First, does existing Shopify SMS consent flow across? Shopify keeps its own record of whether a customer agreed to marketing texts. If you’ve used Shopify’s own forms or checkout opt-in in the past, those customers may carry a consent flag that Postscript reads, ignores, or treats differently depending on configuration. Don’t assume. Open five customers you know opted in and five you know didn’t, and compare what each system shows.
Second, does order data arrive with product and discount detail? Your flows will branch on it later.
Third, note what does not sync. Postscript doesn’t reach into Klaviyo to read your email consent, and it doesn’t reach back into Shopify to overwrite your customer profiles with its own sources. Two consent records that both claim to be the truth is the seed of the problem in Step 3.
Verify by taking one test customer through a Shopify order and confirming the order shows in Postscript’s customer record with correct line items.
Step 2: Capture consent with wording you can defend
Consent capture is the step that gets the wrong kind of attention. Teams spend a week on the pop-up design and ten minutes on the disclosure text underneath it.
A defensible SMS opt-in has a few properties. The person types their own number. The wording says plainly that they’re agreeing to receive marketing texts from your brand. It states that message frequency varies, that message and data rates may apply, and how to stop and get help. It links to your terms and privacy policy. It doesn’t pre-tick a box, and it doesn’t bury the agreement inside a general terms checkbox.
The exact required language depends on your counsel’s reading and on carrier rules that change. Take Postscript’s suggested wording as a draft, send it to whoever signs off on compliance, and keep the approved version in a document with a date. When a regulator, carrier or plaintiff’s lawyer asks what a shopper agreed to on a given day, that document is the answer.
Set up the collection points you’ll actually use:
- Pop-up or embedded form. One field for the phone number, one line of disclosure directly under it, one button. A second field for email is fine if you want both, but each channel needs its own consent language.
- Checkout opt-in. Shopify Plus stores can place an SMS marketing checkbox in checkout. It’s a strong source of consent because the customer is already typing a phone number, but the checkbox must be unticked by default and worded to match your form. See Shopify checkout extensibility for what you can and can’t change there.
- Keyword opt-in. A short keyword texted to your number, promoted on packaging, social or in email. The reply message must carry the same disclosure.
Verify by joining through each path from a personal phone and screenshotting the exact screen you saw. Those screenshots are evidence.
Step 3: Tag every subscriber with a source
Most teams get this step wrong, or skip it entirely. It is the single change on this page that pays for itself.
Every subscriber record should carry, at minimum, where the number came from (pop-up, checkout, keyword, import, in-store), the date, and which version of the disclosure was showing. Postscript lets you segment and tag by sign-up source. Use that to keep the source explicit rather than inferring it later.
Why it matters. Consent isn’t one thing. A person who ticked the checkout box has agreed to something different from a person who was imported from a spreadsheet three years ago. When you’re deciding whom to include in a promotion, whom to keep out of a flow, or whom to defend in a dispute, the source is the only thing that tells you.
The failure mode looks like this. A brand imports a large batch of numbers from an old loyalty programme because they were in a CSV and marked “subscribed.” Nobody records that the loyalty terms only mentioned email. Six months on, complaints arrive, and there’s no way to separate the clean subscribers from the risky ones without deleting everyone. The number metric to confirm for your own list is: what share of current subscribers have a recorded source and disclosure version? Work it out from an export. If it’s not close to all of them, fix that before you scale sending.
Do not import a list unless you hold consent that plainly covers marketing texts from your brand. If you’re unsure, leave it out. A smaller clean list beats a larger one you can’t explain.
Verify by exporting subscribers and confirming the source field is populated for records created in the last 30 days, then for the whole list.
Step 4: Build the welcome flow
The welcome flow is triggered when someone becomes a subscriber. Keep it small.
The first text a new subscriber receives is a confirmation: who you are, that they’re signed up, how to stop, and how to get help. Many compliance programmes require it, and it doubles as the moment you set expectations for frequency. Send it immediately.
After that, the choice is whether to send a second text. If the sign-up incentive was a discount, the second message delivers the code. If there wasn’t one, a second message is optional and you should be more sceptical of it than the vendor’s templates suggest. A newcomer who gets three texts on day one is one of the fastest routes to an opt-out.
Two settings decide whether the flow behaves:
- Exit on purchase. Someone who buys after subscribing shouldn’t keep getting “still thinking it over?” nudges. Set the flow to end when an order is placed.
- Branch on existing customers. A person joining through checkout has already bought. Give them a different, shorter path from a first-time visitor who joined via a pop-up.
The welcome email automation guide has the logic for the email side. Mirror its branching, but shorten everything. A text is not a small email.
Verify by joining with a test number, buying, and checking the flow ends. Then join with a second test number and don’t buy, and check the follow-up arrives once.
Step 5: Build the cart flow without doubling up on email
The most common defect in a store running both email and SMS is a shopper who leaves a cart and gets an email and a text within a few minutes of each other. Both platforms fire on the same event. Neither knows the other exists.
Decide the pattern in advance. There are three workable ones:
- Text first, email second. SMS goes out at a short delay, email follows later for anyone who hasn’t returned. It works when the phone subscriber base is healthy.
- Email first, text second. The email goes out, and the text is a later reminder for people who haven’t opened or returned.
- Split by consent. People with a phone consent get the text path, everyone else gets email only.
I’d choose the third for most teams. It’s the only one that can be verified cleanly: a person is in exactly one branch, and if they show up in two, that’s a bug rather than a design choice. The delays inside each branch are yours to set by testing. Don’t copy a delay from a benchmark or a template. Your own order data, specifically the distribution of time between cart creation and purchase, tells you where the natural break falls. Work it out from a Shopify export of abandoned checkouts that later converted.
Whichever pattern you pick, the exit rules are non-negotiable. The flow ends on purchase, and it ends on a link click into a recovered checkout. Also check what happens when a cart is created on one device and paid on another, or through a wallet like Shop Pay. Those purchases can attach to a different customer record, and the flow keeps running.
For the email side of this, see Klaviyo abandoned cart flow, and for the text copy itself, abandoned cart text. One more caution: a cart text should contain a direct link back to the checkout and nothing else that needs explaining.
Verify by abandoning a cart with a test customer who has both email and phone consent. You should see one message path fire, not two.
Step 6: Set quiet hours, frequency and keywords
Three configuration areas protect the list.
Quiet hours. Set a window when no message sends, based on the recipient’s time zone rather than yours. A store based in one time zone that texts everyone at its own noon will hit some customers in the early morning. Whether the platform applies quiet hours automatically to flows and to campaigns, or only to one of them, is something to test rather than assume. Legal expectations on timing exist in the US and elsewhere, so put the window past your counsel too.
Frequency. Postscript and every comparable tool will let you send as often as you like. Set your own ceiling on campaigns per week and write it into the disclosure if you state one. Then count flow messages too: a subscriber who gets a welcome text, a cart text and a campaign in the same day has been sent three messages by three different owners, none of whom saw the others.
Keywords. Confirm that STOP-style replies opt a person out immediately and that HELP returns a message with your contact details. Test both from a real phone. Then decide who reads inbound replies. Text is a conversational channel, and shoppers reply with questions, complaints, and order problems. If those land in an inbox nobody watches, you’ve built a support channel by accident. Route anything about an order or a refund to a person; an automated reply on those is where a wrong answer costs more than a human minute. Your helpdesk setup, covered in helpdesk for Shopify, is the natural home.
Step 7: Test end to end before the first campaign
Run one full pass on a real phone before you send anything to the list.
- Join through each consent path and confirm the confirmation message fires once.
- Place a test order and confirm the welcome flow ends.
- Abandon a cart and confirm only the intended channel messages you.
- Click every link and confirm the destination, the tracking parameters, and that the order attributes correctly in Shopify and in your analytics.
- Reply STOP, confirm the opt-out, then check the record in both Postscript and Shopify.
- Reply HELP and read what comes back.
Only then send a first campaign, and send it to a small slice. Look at delivery, opt-outs, and replies before widening.
What is the step most teams get wrong?
Consent and source tagging, and it fails for a boring reason: nothing breaks on day one. A form with weak wording still collects numbers. An unlabelled import still sends. The cost arrives later and lands on someone who wasn’t there when the decision was made.
There’s a second, related failure that belongs here. Two platforms end up holding different versions of a person’s consent. A customer unsubscribes from texts in Postscript. Your email platform still shows them as subscribed to SMS, or a sync overwrites the flag on the next import. Whether that happens depends on how each tool is connected, so check it by test: opt out a test number in Postscript, wait through a full sync cycle, and read the flag in Shopify and in Klaviyo. Where the flags disagree, the more permissive record is the one that gets a person texted when they said stop.
The fix is procedural. Name one system as the record of SMS consent, and have every other system read from it. Write that down. Review it whenever you add an app.
How do you know Postscript marketing is working?
Measure it against a holdout, not against the platform’s own attribution. Platform-reported revenue counts every order placed after a text was sent, including the ones that would have happened anyway. On a store with strong returning-customer behaviour, that can be most of them.
Build the holdout before launch. Take a random slice of new subscribers, exclude them from campaigns (not from compliance messages), and compare revenue per subscriber between the two groups over the same period. The size of the holdout and the length of the test depend on your volume, so metric to confirm for your store: how many orders per month come through subscribers? If the answer is small, the test needs a longer window to say anything.
Put the result in context. Klaviyo reports that 41% of email revenue across its 183,000+ brands comes from automated flows (vendor-reported), which is a reminder that the always-on flows tend to matter more than the campaign calendar. The same logic is worth testing for text on your own account rather than assuming it transfers. The flow revenue calculator is a way to size what your flows might be worth from your own inputs.
Watch the other side of the ledger too: opt-out rate per message, complaints, and replies that need a human. A channel that lifts revenue and burns the list has a cost that doesn’t show in the dashboard.
What breaks as volume grows?
Three things tend to break when a store scales its texting.
Throughput and registration. A sending number that’s fine for a modest list can throttle on a large campaign, so a message meant to land at once spreads over a long window. Ask Postscript how sending is paced on your account, and stagger big sends accordingly.
Overlap between systems. Every new flow, app or integration is another thing that can text or email the same shopper. Keep a single sheet listing each trigger, its owning platform and its exit rules. Review it at every launch.
List hygiene. Numbers get recycled, customers change carriers, and people stop engaging. A sunset rule for unengaged subscribers protects deliverability and cost, since Postscript pricing is usage-shaped. The email equivalent is in sunset flow in Klaviyo.
Who should not run Postscript marketing?
Three groups should wait.
Brands without an email programme worth protecting. Text is a poor substitute for a weak welcome and cart flow in email, because the same underlying problems (wrong triggers, no exit rules) follow you.
Brands with no one to own compliance. A channel with legal exposure and nobody accountable is a risk, not a growth lever.
Brands whose customers don’t give a phone number willingly. If your audience is B2B buyers ordering through a purchasing team, the person at checkout isn’t the person you’d text, and the channel adds little.
If you’re weighing alternatives before committing, best SMS marketing app for Shopify and Klaviyo SMS marketing cover the field without repeating this setup.
Is this a tool problem or a lifecycle flows problem?
Postscript marketing is a lifecycle flows problem wearing a tool’s clothes. The app is the easy part. What decides the result is whether consent is captured cleanly, whether each trigger has one owner, whether exit rules are honoured across email and SMS, and whether anyone measures against a holdout. That work sits across platforms, which is why teams that treat it as an app install end up with two channels contradicting each other. Pointerflow’s lifecycle flows service is built for exactly that cross-channel layer.
Sources
- Klaviyo, 183,000+ brands: 41% of email revenue comes from automated flows (vendor-reported). No other external figures are quoted; the setup steps are written from how Postscript and Shopify are documented to work, and specific labels, limits and prices should be checked in each vendor’s current admin and pricing pages.