{
  "id": "MSG-264",
  "slug": "msg-264",
  "title": "An abandoned-cart message must not complete the purchase in the thread",
  "statement": "A cart reminder must not collect payment information, accept purchase approval by keyword reply, or otherwise complete the transaction — the recipient must finish the purchase through a direct URL.",
  "rationale": "A purchase confirmed by replying Y is a charge authorised by a single character, sent from a device somebody else may be holding, with no price, no total and no terms on screen at the moment of authorisation. T-Mobile and CTIA both refuse it, and the harm is not hypothetical: the dispute rate on keyword-confirmed purchases is what put the rule in the handbook. Merchants build it because it converts, and because the platform offering the feature does not mention that carriers refuse the campaign that uses it.",
  "layer": "MESSAGE_CONTENT",
  "layerSlug": "message-content",
  "object": "cart-reminder message body",
  "severity": "BLOCKING",
  "detectability": [
    "AI_FORM"
  ],
  "failureClass": "RETRY_FIELD",
  "authorities": [
    "T-Mobile",
    "CTIA"
  ],
  "applicabilityText": "Applies to every 10DLC registration.",
  "universal": true,
  "remediation": "Replace the keyword purchase step with a direct link to the checkout page for that basket, and take every request for card, billing or address detail out of the message body. Done when the only thing a reply can do is stop the messages, and every purchase completes on your own site with the total on screen.",
  "example": "Acme Coffee: your basket is still here — 2 bags of Ethiopia Guji, $34 total. Check out at https://acmecoffee.com/cart/4471 Reply STOP to opt out.",
  "pitfalls": [
    "A \"reply Y to confirm and we will charge your card on file\" flow is exactly the prohibited pattern, and it is the one most cart platforms offer as a headline feature."
  ],
  "notes": "Universal for the same reason as MSG-263: no registration fact declares a cart programme, so the condition lives in the criteria and opens with a PASS boundary.",
  "phase": "approval",
  "automated": true,
  "url": "https://ekas.io/rules/10dlc/message-content/msg-264/",
  "markdown": "https://ekas.io/rules/10dlc/message-content/msg-264.md",
  "registry": "https://ekas.io/rules/10dlc/",
  "updated": "2026-07-25",
  "licence": "CC BY 4.0 — https://creativecommons.org/licenses/by/4.0/"
}
