The Checkout Flow That Was Never Meant to Deceive Anyone

Nobody on this brand's small team ever sat down and decided to deceive a customer. Every element of their checkout flow had been added, one at a time, by a genuinely well-meaning product team optimising for completed purchases. And yet, run against the CCPA's own guidelines, three separate elements of that checkout flow ticked boxes the company had never even heard of.

A growing direct-to-consumer skincare brand, selling primarily through its own website, had spent the better part of a year refining its checkout experience the way most e-commerce teams do — watching drop-off rates at each step, testing small changes, and keeping whatever moved the needle. By most conventional product-management standards, the checkout was working well: conversion rates were healthy, and the team had no reason to think there was anything to fix.

What a Proper Audit Actually Found

Prompted by news coverage of the CCPA's August 2026 enforcement disclosures — the same wave of penalties that named several considerably larger platforms — the brand's founders decided to run their own checkout through the CCPA's 2023 dark-patterns guidelines directly, rather than assuming their much smaller scale made this irrelevant to them. The exercise surfaced three specific issues, none of which had been built with any deceptive intent. A "protection plan" add-on, priced modestly, was pre-selected by default at checkout, requiring the customer to actively uncheck it rather than actively choose it — a textbook example of what the guidelines specifically define as basket sneaking. A shipping charge, genuinely modest but not shown anywhere earlier in the flow, appeared for the first time only on the final payment screen — squarely within the guidelines' definition of drip pricing. And a "only 2 left in stock!" message displayed on every single product page, regardless of actual inventory levels, which the guidelines classify as false urgency when the claim doesn't reflect real, current stock data.

The Uncomfortable Realisation

None of these had been added with any intent to mislead — each had simply performed well in isolated A/B testing at some point and been kept without anyone stepping back to evaluate it against a consumer-protection framework rather than a pure conversion metric. That's precisely the trap the CCPA's own June 2025 advisory seems aimed at: these aren't unusual, malicious tactics confined to a handful of bad actors — they're common, almost default product decisions across a huge share of Indian e-commerce, adopted for entirely ordinary commercial reasons.

What Actually Changed, and What It Cost

The fix here was genuinely inexpensive: the protection plan add-on was switched to an active opt-in rather than a pre-selected default; the shipping charge was disclosed clearly at the point a customer first adds an item to their cart rather than buried until final payment; and the stock-level messaging was either connected to genuine, real-time inventory data or removed where that wasn't feasible to implement quickly. Conversion rates dipped very slightly in the weeks immediately following the change — an entirely expected, modest trade-off — but the business avoided what could easily have become a public enforcement notice and penalty, along with the reputational cost that comes with being named in a regulatory action, for a UX decision nobody involved had ever intended as deceptive.

Why This Case Is Worth Sharing

The genuinely useful lesson here isn't about this one brand — it's that dark-patterns compliance risk scales down to businesses far smaller than the ones that make headlines when they're fined. A checkout flow built entirely in good faith, by a team with zero intent to deceive anyone, can still tick several of the CCPA's specific categories simply because those categories describe extremely common product decisions across the industry. Running your own checkout against the guidelines directly — rather than assuming your scale or your good intentions exempt you — is a low-cost exercise that, in our experience, nearly always surfaces at least one thing worth fixing, regardless of how careful and well-meaning the original design process was.


Have a question about this update? Submit a query to our team.