WhatsApp Business for Ecommerce: Setup and Compliance
TL;DR. A WhatsApp Business programme rests on five things: the prior opt-in Meta requires before any contact, templates approved by Meta, their categorisation, which weighs on the price, the business portfolio messaging limits that climb in tiers, and the 24-hour customer service window that turns your response time into a cost line. A rollout that ignores one of them pays for it, in blocked volume or on the invoice.
Opening an account is the easy part. Whether the programme holds up depends on Meta's rules and on how they meet your organisation: who answers messages, how fast, and with what consent on file.
App or API: decide early
The WhatsApp Business app suits, in our agency view, a brand that handles its conversations by hand: its product page presents it for greeting people who start a conversation and replying to their messages, "even when you're away", and for one-to-one communication with customers throughout their purchase journey.
The Cloud API is the route for a programme driven from the CRM. In exchange, it requires Meta to approve every brand-initiated message sent outside the customer service window.
Make the choice early, because switching from one to the other mid-programme is a migration, with the work that implies on the contacts already in your database and on the scenarios already wired. We collect opt-in again on that occasion, as an agency precaution that Meta does not impose.
Templates and their categorisation
Any brand-initiated message sent outside the customer service window goes through a template submitted to Meta, categorised into one of three families:
Utility. Supports a transaction the customer initiated: order confirmation, dispatch, delivery, status update.
Authentication. One-time passcodes.
Marketing. Everything else: promotions, new arrivals, reactivation.
The category Meta keeps weighs on the rate, which Meta publishes in a separate table per market. This is the line where we see the most drift at scoping stage: slipping a promotional message into a utility template amounts to hoping for a utility rate on marketing, and Meta has closed that door.
Automatic recategorisation became the default behaviour on 9 April 2025, where it had previously been a property you enabled when creating the template. A template submitted as utility that Meta considers marketing is therefore approved, but as marketing, and billed at the marketing rate for the market concerned: it is the category kept at approval that sets the rate, to be read off Meta's table, category by category and market by market.
A utility template that adds "and enjoy 20% off" is no longer a utility template.
The customer service window
When a user messages or calls the brand, a 24-hour customer service window opens, and each new message or call from them resets it. During that period the exchange is free: no template to get approved before replying, and utility templates delivered inside an open window are not billed.
Once the window has closed, resuming contact means going back through a template, billed as soon as it is delivered.
The practical consequence is direct: your response time is a cost line. A brand that handles messages within the day replies inside the window the customer opened, where a brand that lets the window close has to buy the contact back with a template. This is why we get coverage hours and a response-time commitment agreed before any rollout.
Business portfolio messaging limits
Meta defines the messaging limit as the maximum number of unique WhatsApp user phone numbers your business can deliver messages to outside the customer service window, over a rolling 24-hour period. A tier is therefore counted in unique recipients reachable in 24 hours, not in message volume.
Meta calculates and sets that limit at the business portfolio level, and it is shared by every business phone number the portfolio contains: adding a number does not raise the limit, all numbers draw from it. The limit climbs in tiers, and the documentation mixes two mechanics that need separating before you build a ramp-up plan.
Moving from the entry tier to the next one happens through one of three routes, your choice: get your business verified, have it verified by a partner, or deliver messages outside the customer service window to distinct WhatsApp user phone numbers over a rolling 30-day period, using templates with a high quality rating, reaching the volume Meta publishes on the messaging limits page. These are three alternatives and not three cumulative conditions, and the volume criterion becomes the fallback route for anyone unwilling or unable to get verified.
Completing one of the three routes triggers Meta's analysis of your message quality. That analysis approves or denies your portfolio's eligibility, and the limit moves to the next tier only once the request is approved. The recipient count attached to each tier can be checked on that same page, which Meta can change: it is the mechanic you retain, the figure gets verified on the day you scope the project.
Beyond that, automatic tier increases rest on two cumulative criteria: sending quality messages across all your business phone numbers and templates, and having used at least half your current limit over the last seven days. The second is the more operational of the two, and the most often ignored: a spotless portfolio sitting well below its limit stays on its tier.
We roll out in phases for a separate reason: transactional only, long enough to build a clean history, then conversational opening, then targeted marketing. That is a quality precaution, distinct from the tier-increase mechanic, and the two pull in opposite directions: ramping up volume serves the usage criterion, opening cautiously works against it. Once the entry tier is cleared, the usage criterion is what sets the pace, and caution shifts onto template content and targeting rather than onto the volume sent.
Opt-in
We do not reuse an email or SMS consent to open WhatsApp. Meta requires prior opt-in: the WhatsApp Business policy conditions any contact on the person having given their mobile number and their permission. Meta's page on collecting that opt-in leaves the collection method to the business, but sets what that collection must state: the business must make clear to the person that they are consenting to receive communications from the business, and name the business whose messages they will receive. That same page does accept a general opt-in, not specific to WhatsApp: our refusal to reuse an email or SMS consent is therefore an agency requirement, not a rule set by Meta.
The WhatsApp Business policy goes further on how granular the collection should be: it recommends a separate opt-in per message category, and separate consent for calls. It frames both points as recommendations, not obligations. We treat them as rules for our clients: an undifferentiated opt-in leaves proof that is hard to produce the day someone disputes having accepted marketing.
The second framework is French. The CNIL guidance on commercial prospecting by electronic means (the CNIL is France's data protection authority) covers advertising sent through that channel and cites email, SMS-MMS and automated calling systems as examples, the list ending with "etc.". It names neither instant messaging, nor WhatsApp, nor social networks: the list is open, without that openness amounting to inclusion. Our agency reading: we treat a WhatsApp programme as electronic prospecting and stack both sets of requirements, Meta's and the guidance's, the second not replacing the first. The regulatory baseline common to electronic channels is covered in GDPR and email marketing.
The guidance separates two regimes. For prospecting addressed to a professional, it accepts a legitimate interest basis where the subject of the approach relates to the recipient's profession, with a right to object rather than prior consent. An ecommerce brand's WhatsApp programme addresses private individuals: the consent expected there is prior, freely given, specific, informed and unambiguous, collected through a positive action, pre-ticked boxes being excluded.
It provides an exception to that prior consent where the person contacted is already a customer of the business and the prospecting concerns similar products or services supplied by that same business, and it immediately sets the limit: the exception cannot be relied on where no sale or service has been carried out, including where the customer has created an online account.
Its formal requirement bears on the message sent, not on the form: every approach must allow the person to identify the organisation sending it, and to express a refusal by a simple means. A WhatsApp template must therefore identify the brand and open a simple route to opt out.
The guidance does not, on the other hand, take a position on how far a consent carries from one channel to another. We draw two agency precautions from that. First: a dedicated WhatsApp box at the collection point, separate from other channels, to keep the proof legible. Second: do not treat as open a channel that the wording the person accepted does not name, even where the number is already in your database, because the proof is fragile there under scrutiny.
As with SMS, keeping the number is not enough: it is the proof of consent that gets collected and archived, using the same method described in SMS and GDPR in France. What we have our clients timestamp and archive: the date, the collection point, the exact wording displayed at that moment, and the version of the text. A form rebuild that overwrites the old wording without archiving it leaves nothing to produce for contacts collected before.
What we refuse to do for our clients: import a database of numbers collected for SMS and treat the channel as open.
Integrating with the stack
A non-overlap rule, the one we set for our clients to stop the same person being contacted on two channels on the same day, only holds if email, SMS and WhatsApp read the same customer profile. That is the technical reason to plug WhatsApp into your CRM platform rather than running it alongside.
Without a shared profile, the scenario is predictable: the same customer receives the same offer by email, by SMS and on WhatsApp on the same day, because three tools hold three lists that do not talk to each other. The coordination logic is set out in Klaviyo omnichannel marketing.
Three things have to flow in both directions, and that is the criterion separating a useful integration from a plain connector: opt-in status per channel, recent-buyer exclusions, and suppression. An unsubscribe that does not make it back to the shared profile lets messages go out to someone who explicitly asked for them to stop, and no later correction undoes a message already delivered.
Check the direction of the sync too before you sign. We regularly come across connectors that push to WhatsApp without pulling conversation events back, which leaves you unable to segment on the behaviour of the channel you have just opened.
The cost model
WhatsApp bills template messages on delivery, at a rate that depends on the template category, the recipient's country calling code and, for utility and authentication templates, the monthly volume tier reached, with Meta publishing a separate table per market. Utility templates delivered inside an open customer service window, on the other hand, are not billed: a team that handles its conversations fast moves part of its transactional programme outside billing altogether.
Meta's table changes, and its billing unit has already changed, per-message billing being in force since 1 July 2025: build your budget on the rate read in Meta's documentation on the day you scope the project, rather than on a figure lifted from an article.
Three rules to keep it from drifting:
- model the cost per message and per market before rollout;
- set a monthly spend cap;
- calculate the basket threshold below which a marketing send is not profitable, and turn it into a segmentation rule.
The calculation logic is the same as for SMS: a unit cost per delivered message, weighed against average order value and margin.
FAQ
Can you use numbers already collected for SMS?
Our default rule is no: a number collected for SMS, or an address collected for the newsletter, was gathered under wording that does not mention WhatsApp, which leaves fragile proof under scrutiny. The CNIL guidance provides an exception to prior consent for prospecting addressed to someone who is already a customer of the business and concerning similar products or services supplied by that same business, an exception that falls away if no sale or service has been carried out, the mere creation of an online account not being enough. Outside that case, plan a dedicated collection point, and archive the exact wording displayed along with the date.
What is the difference between the app and the API?
The app is built for greeting people who start a conversation, replying to them even when you are away, and exchanging one to one with them throughout their purchase journey. A programme driven from the CRM goes through the Cloud API, which in exchange requires Meta to approve every brand-initiated message sent outside the customer service window. Make the choice before launch, because switching from one to the other afterwards is a migration, with the work that implies on the contacts already in your database and on the scenarios already wired.
Why can a template submitted as utility be billed as marketing?
Any brand-initiated message sent outside the customer service window goes through a template submitted to Meta and filed under one of three categories, utility, authentication or marketing. Since 9 April 2025, automatic recategorisation is the default behaviour: a template submitted as utility that Meta judges to be marketing is approved, but as marketing, and billed at the marketing rate for the market concerned. It is the category Meta keeps at approval that sets the rate, not the one you declared.
How long does the customer service window last?
Twenty-four hours, opened by the message or call the user sends to the business, and reset by each new message or call from them. During that period the exchange happens without a template, and utility templates delivered inside an open window are not billed. Once the window has closed, resuming contact requires a template, billed on delivery.
How do a business portfolio's messaging limits go up?
The limit is the maximum number of unique WhatsApp user phone numbers you can deliver messages to outside the customer service window over a rolling 24-hour period: it counts unique recipients, not messages. It is set at portfolio level and shared across every business phone number the portfolio contains. Moving from the entry tier to the next one comes through business verification, directly or via a partner, or failing that by delivering messages outside the customer service window to unique recipients over a rolling 30-day period, using templates with a high quality rating, reaching the volume Meta publishes on the messaging limits page; completing one of them triggers Meta's analysis of your message quality, that analysis approves or denies your portfolio's eligibility, and the limit moves to the next tier only once the request is approved. Beyond that, automatic increases ask for two things at once: quality messages across all your business phone numbers and templates, and use of at least half the current limit over the last seven days. The recipient count specific to each tier can be checked on that same page on the day you scope the project.
Going further
The sequences to launch once the setup is in place, and the order in which to open them, are covered in WhatsApp marketing strategy. Scoping a WhatsApp programme is set out on our WhatsApp marketing agency page, and plugging the channel into your email and SMS database is a conversation to have with our team.
Provenance and verification
The eight declared pages were reopened and re-read on 24 August 2026, and this translation carries the same claims as the French source article, with no figure of its own. Meta pricing page: per-message billing since 1 July 2025, triggered on delivery of a template message; rates vary by template category, by the recipient's country calling code and, for utility and authentication templates, by the monthly volume tier reached, the page publishing separate tables per market and stating no price ordering between categories nor any tier threshold, and the article carrying neither a rate hierarchy between categories, nor a threshold, nor an amount; 24-hour customer service window and no charge for utility templates delivered inside an open window. The templates section keeps only the effect of the category on the rate, the full list of factors being carried once, in the cost model section, so that neither passage reads as an exhaustive enumeration. Cloud API send-messages guide: this is the page that carries the opening of a 24-hour customer service window as soon as a WhatsApp user messages or calls the business, the counter resetting with each new message or call from them, and the fact that once the window closes only pre-approved template messages can be sent; the section 'The customer service window' and the FAQ answer on the length of the window rest on it. Template category guidelines page: approving a template submitted as utility under the marketing category is available through the allow_category_change property and became the default behaviour on 9 April 2025. Messaging limits page: the limit is defined as the maximum number of unique WhatsApp user phone numbers the business can deliver messages to outside the customer service window over a rolling 24-hour period, so a count of unique recipients and not a message volume; it is calculated and set at business portfolio level and shared by every business phone number the portfolio contains; moving from the entry tier to the next one comes through one of three routes the page presents as alternatives, getting the business verified, having it verified by a partner, or delivering messages outside the customer service window to unique recipients over a rolling 30-day period using templates with a high quality rating, completing one of them triggering Meta's analysis of the message quality, that analysis approving or denying the business portfolio's eligibility, and the limit moving to the next tier only once the request is approved; beyond that, automatic increases rest on two cumulative criteria, quality messaging across all business phone numbers and templates, and use of at least half the current limit, itself measured at portfolio level, over the last seven days. WhatsApp Business policy: prior opt-in required, the page conditioning any contact on the person having given their mobile number and their permission, and further recommending a separate opt-in per message category as well as separate consent for calls: the page frames both points as recommendations and not obligations, and the article reports them as such, without the rationale the policy attaches to them, not re-checked. Meta page on collecting opt-in: consent may be general and not WhatsApp-specific, and the business must make clear to the person that they are consenting to receive communications from the business, and name the business whose messages they will receive; the page also leaves the choice of collection method to the business, that freedom of form not cancelling the two content requirements, and the article reports both. Publisher product page for the WhatsApp Business app: it carries greeting people who start a conversation and replying to their messages, 'even when you're away', as well as one-to-one communication with customers throughout their purchase journey, and nothing on CRM integration, automation or device counts: the body and the FAQ describe the app on that content alone. CNIL guidance on commercial prospecting by electronic means: it covers advertising sent by electronic means and cites email, SMS-MMS and automated calling systems as examples, the bracket ending with 'etc.': the page names neither instant messaging, nor WhatsApp, nor social networks, and that open list does not amount to inclusion, the application of the regime to WhatsApp being given in the article as an agency reading and not as content of the guidance; it separates prospecting addressed to a professional, which may rest on the organisation's legitimate interest where the subject of the approach relates to the recipient's profession, with a right to object rather than prior consent, from prospecting addressed to a private individual, which requires prior consent that is freely given, specific, informed and unambiguous, collected through a positive action, pre-ticked boxes excluded; it finally carries an exception to that prior consent where the person is already a customer and the approach concerns similar products or services supplied by the same business, an exception that cannot be relied on where no sale or service has been carried out, including where the customer has created an online account; it finally requires every approach to let the person identify the organisation sending it and to express a refusal by a simple means, a formal requirement bearing on the message sent and reported as such in the article. The guidance sets prior consent that is freely given, specific, informed and unambiguous, collected through a positive action, without taking a position on how far a consent carries from one channel to another: the article therefore attributes no per-channel consent requirement to it. What no opened page carries is absent from the text: price ordering between template categories, quality rating assigned per number and the signals that move it, consequences of a degraded rating, recovery delay, phase durations. The numeric tiers of the messaging limit, and the 30-day volume attached to the fallback route, do appear on the messaging limits page re-read on 24 August 2026, but are deliberately left out of the text: a quota table goes stale, and the article sends the reader to Meta's page for the recipient count in force as well as for the fallback route's volume, keeping only the mechanic. The other retained values, the 24-hour window, the rolling 30-day period, the half-of-limit usage threshold over seven days, per-message billing since 1 July 2025 and default recategorisation since 9 April 2025, are those re-read on the declared pages during the same day's source check. Stated as agency precautions, with no figure or numbered sequence and without being attributed to Meta: keeping proof of consent, re-collecting opt-in when migrating between the app and the API, and phased rollout, which is kept separate from the limit-increase mechanic. Internal links were checked against the slugs declared in articles/en/ and landings/en/: gdpr-email-marketing-2026, sms-gdpr-france, klaviyo-omnichannel-marketing and whatsapp-marketing-strategy exist and are in status ready, whatsapp-marketing-agency exists as an English landing, and the four articles cited publish before this one's modification date. English URLs only for internal links, and the sole outbound links point to the Meta and CNIL pages declared as sources: no competing vendor is linked. Editorial pass of 29 August 2026, without reopening the sources, aligning this translation on the French source article: two long paragraphs split in the messaging limits section and two more in the templates and cost model sections; the notion of a quality rating to monitor removed from the Cloud API description in the body and in the FAQ, the counterpart of the Cloud API brought back to Meta's approval of brand-initiated messages sent outside the customer service window, which is the only obligation the declared pages carry; the rationale the policy attaches to per-category opt-in removed, not re-checked; the entry-tier mechanic corrected to match the messaging limits page, completing one of the three routes triggering Meta's quality analysis, that analysis approving or denying eligibility, and the limit moving to the next tier only once the request is approved; the non-overlap rule explicitly attributed to the agency. No figure was changed.
- Sources checked on
- Reviewed by
- Claude (local CLI) cross-check of Meta's official WhatsApp Business pages and of the CNIL guidance on the consent regime
- AI assistance
- Yes
- Sources
-
- developers.facebook.com/docs/whatsapp/pricing
- developers.facebook.com/docs/whatsapp/cloud-api/guides/send-messages
- developers.facebook.com/docs/whatsapp/updates-to-pricing/new-template-guidelines
- developers.facebook.com/docs/whatsapp/messaging-limits
- developers.facebook.com/docs/whatsapp/overview/getting-opt-in
- whatsappbusiness.com/policy
- whatsappbusiness.com/products/business-app
- www.cnil.fr/fr/la-prospection-commerciale-par-courrier-electronique
Want to apply this to your stack?
Spend 30 minutes with Charlotte to review your CRM setup, size the opportunity and leave with a practical action plan.
Book a 30-minute call →