You are standing at the register with a pair of running shoes. The cashier beeps them through, stuffs them into a bag, and while you are still fishing around in your pocket for your card, the screen on the terminal asks if you want the receipt sent to your email. You type it in because four people are waiting behind you and the whole interaction will take longer if you do not, and somewhere around lunchtime the next day a promotional email from the same store is already sitting in your inbox, subject line about some sale you had zero interest in hearing about.
That three second exchange at the counter, the one where your email address went from your fingertips into a corporate database, was not a spur of the moment thing from a talkative employee. It was engineered into the checkout sequence on purpose, rehearsed into the cashier's routine, and for a surprising number of retailers, the email you just typed in will generate more long term revenue through the marketing funnel than the profit margin on the shoes you walked out with.
What follows is a breakdown of what the store actually does with your contact information after you leave, how much of the arrangement works in your favour versus theirs, what three federal and state laws say about the boundaries, and how to decline at the register without turning a five second interaction into an awkward standoff.
The five reasons stores ask
Not every store is collecting your information for the same reason, but the reasons tend to fall into the same five categories, and most stores are doing at least two of them at once.
Loyalty program identification. The plastic keychain card most people used to carry has been replaced, in almost every grocery chain and pharmacy, by a phone number typed into the register. You say the digits, the system pulls up your rewards balance and whatever coupons are loaded to your account, and the cashier applies them without you needing to present anything physical. Most shoppers already know this is why the question gets asked at the grocery store, though they do not always realise the same number is feeding a purchase history profile on the back end.
Digital receipt delivery. The store emails or texts you the receipt instead of printing it. For the customer, this means one less piece of thermal paper to lose. For the store, it means an email address in the database that can be used for other things.
Purchase history tracking. The moment a phone number or email gets stapled to your transactions, the store's software begins piecing together a buying profile, what categories you gravitate toward, how many times a month you walk in, which of the chain's locations you prefer, roughly how much you are willing to spend per visit. After enough data points accumulate, the system starts generating the personalised coupon emails and the "items you might like" recommendations that seem to know a little too much about your shopping habits.
Mailing address lookup. A phone number, on its own, can be run through a commercial data broker's database and matched to a physical mailing address, which is how some customers end up receiving catalogues and printed coupon mailers from stores they never gave a street address to. The store only collected a phone number at checkout, but the broker connected it to everything else.
Marketing list growth. The email address you gave for a receipt goes into the store's marketing database. From that point forward, you receive promotional emails until you unsubscribe, and unsubscribing does not always remove you from the database, it just moves you to a different list.
A woman buys a candle at a home goods store. The cashier asks for her email "for the receipt." She gives it. Over the next month, she receives four promotional emails from the store, none of which she signed up for. As far as the store's system was concerned, handing over her email for that receipt was the same thing as signing up for the mailing list.
What happens to your data after you leave the store
The information does not sit in a single place. A phone number or email that enters the store's point of sale system at 2:14 on a Tuesday afternoon can be sitting inside the company's customer relationship management software by 2:15, queued up in a marketing automation platform that will send the first promotional email within 48 hours, and in some cases already on its way to a third party data partner whose job is to flesh the profile out with information you never volunteered.
From where you are standing, as the person who typed the email into the terminal, the chain works like this.
The CRM attaches your email or phone number to a customer profile, and that profile picks up a new data point every time you shop. Give it a few visits and the system has mapped out enough of your purchasing pattern to start generating targeted offers on its own, the kind of email that knows you bought dog food three weeks ago and figures you might be running low, or the kind that flags your account as inactive after 90 days of silence and fires off a "come back" coupon.
When a retailer works with a third party data broker, the email or phone number you gave at the register can get matched against outside databases that tack on demographic information the store never asked you for, things like estimated household income, whether you rent or own your home, and what age bracket the broker thinks you fall into. The store did not ask you for your income bracket at the point of sale, but the data broker filled it in.
A lot of retailers do keep customer data locked inside their own systems, and their privacy policies will say as much in plain language. The problem is that privacy policies are not permanent documents. They get revised when leadership changes, they get thrown out entirely when the company is acquired by a chain with a different data philosophy, and they become irrelevant the moment someone breaches the database from the outside. The real question is not what the policy says this quarter, but whether you are comfortable with that information living inside a system you cannot see into and have no ability to manage.
A man gives his phone number at checkout to get the loyalty discount at a hardware store. He has never given the store his home address. Six weeks later, a printed catalogue from the store arrives in his mailbox.
The legal framework you probably did not know about
Three laws in the United States directly govern what a store can do with the contact information it collects at checkout, and two of them carry penalties that are large enough to make the question worth paying attention to.
CAN-SPAM Act
The CAN-SPAM Act is the federal law that sets the rules for commercial email in the United States. The part that surprises most people is that CAN-SPAM does not actually require the store to ask for your permission before it starts emailing you promotions. What it does require is that every single one of those emails contain a functioning unsubscribe link, the company's real physical mailing address, and something that makes it obvious the message is an advertisement rather than a personal correspondence. Noncompliant emails carry a fine of up to $53,088 each, a number the FTC adjusts for inflation, and the penalty stacks per message rather than per campaign. [2]
What this means in practice is that the store is legally allowed to email you after you give your address at checkout, even if you only gave it for a receipt, as long as the emails comply with the formatting and opt out requirements. CAN-SPAM is an opt out law, not an opt in law.
Telephone Consumer Protection Act (TCPA)
The TCPA governs calls and text messages and operates on a stricter standard than CAN-SPAM. A store that sends you marketing texts needs your prior express written consent before it sends them using an autodialer or prerecorded message. The penalties range from $500 to $1,500 per unsolicited text or call, and unlike CAN-SPAM, the TCPA allows individuals to file private lawsuits, which is why TCPA class action filings have been running at roughly 2,500 per year. [3]
A clothing store grabs a customer's phone number at the register during a loyalty signup. Four weeks go by, and then a text message lands on the customer's phone advertising a weekend clearance event. If that customer never agreed to receive marketing texts, the store just created $500 to $1,500 worth of liability with a single message under the TCPA.
California Consumer Privacy Act (CCPA)
The CCPA went through a round of expanded regulations that took effect on January 1, 2026, and in its current form the law gives anyone living in California the right to find out exactly what personal data a business has collected on them, to ask for that data to be deleted, to correct anything in it that is wrong, and to tell the company to stop selling or sharing it. The law applies to for profit businesses that meet certain revenue or data volume thresholds, and it covers any personal information collected at the point of sale, including email addresses and phone numbers. [4]
Outside California, a growing number of states have enacted their own consumer privacy laws with similar rights, though the specifics vary.
How to decline without making it awkward
You do not have to give a reason, and you do not need to apologise. The cashier is following a script, and most of them hear "no thanks" several times an hour.
A few approaches that work without slowing the line down.
"No thanks, just the receipt." This works at stores that ask for email for receipt delivery. The register can almost always print a paper copy instead, and the cashier just taps a different button on the screen to make that happen.
"I'll skip the rewards for now." Covers the situation where the phone number request is wrapped into a loyalty program, since it turns down both pieces at once and saves the cashier from having to figure out which half of the question you are saying no to.
"I'd rather not." Short, clear, and it does not invite follow up questions. If the cashier circles back to the question a second time, just repeat yourself. That usually ends it.
Some stores phrase the request so that it sounds like a requirement. "And what's your email?" is phrased as though it is part of the transaction, not a request. It is always a request. No U.S. retailer requires an email address or phone number to process a payment.
A teenager buying a pair of headphones at an electronics store is asked for an email address by the cashier. The teenager says "no thanks." The cashier taps something on the screen, and a paper receipt comes out of the printer instead. Same price on the headphones, same return window, same everything.
What a small shop owner should know about asking
If you are on the other side of the counter, the one running a small shop and trying to decide whether collecting customer emails or phone numbers at checkout is worth the effort, everything described above applies to your business in exactly the same way, and the rule that matters most is also the one that takes the least effort to follow.
Be upfront about what you plan to do with the information before you ask for it.
There is a meaningful difference between collecting an email so you can send someone a digital receipt and quietly adding that same email to your promotional mailing list without ever mentioning it. The second you send a marketing message to an address that a customer gave you strictly for a receipt, CAN-SPAM kicks in, and from that point on every email you send to that person needs an unsubscribe link, your physical business address, and a clear label identifying it as advertising.
Texting is where the rules tighten up considerably. The TCPA requires documented written consent before you send even one marketing text, and somebody nodding along at the counter while you are ringing them up does not count. That consent has to be captured in writing, which is the whole reason most small businesses that do text marketing collect it through a dedicated signup form or a consent checkbox wired into the point of sale terminal.
A mailing list with 200 people on it who all actively chose to be there will outperform a list of 2,000 that was built by collecting addresses under the pretence of receipt delivery. The people who opted in voluntarily open more of your emails, actually click through to whatever you are promoting, and virtually never report you as spam, which is the exact opposite of what happens when somebody realises they got added to a list without being told.
And if you would rather not collect contact details at all, a printed or PDF receipt built from a simple business receipt or a POS receipt template gives every customer a complete record of the sale without adding anyone to a list.
5 checkout data collection mistakes that cost stores more than they gain
1. Asking for an email "for the receipt" and then using it for marketing without disclosure
Customer trust does not survive this one, and it is the scenario behind most of the CAN-SPAM complaints that small retailers end up dealing with. The person handed you their email because you said it was for a receipt. When the first promotional message shows up in their inbox two days later, they do not see it as marketing. They see it as a lie.
2. Collecting phone numbers without understanding the TCPA
The consent bar under the TCPA is higher than most small business owners think it is, and finding out the hard way costs real money. A single promotional text fired off to a phone number you grabbed at checkout, sent without documented prior express written consent, puts you on the hook for $500 to $1,500 in statutory damages.
3. Making the request sound mandatory
There is a big difference between "would you like an email receipt?" and "and your email?" The second version sounds like it is part of the transaction, as though the sale cannot go through without it. Shoppers who feel like they got backed into giving up their email tend to be the first ones to unsubscribe, leave a one star review, or report the account as spam.
4. Keeping data indefinitely with no retention policy
A database full of customer records that nobody has reviewed or cleaned out in years is not an asset. It is a breach waiting to happen. And when the breach does happen, because small businesses get hit too, the exposed data includes every email and phone number from people who came in once years ago and have not been back since. Knowing how long to keep different types of records applies to customer data just as much as it does to receipts.
5. Not honouring unsubscribe requests within the required window
CAN-SPAM gives you 10 business days to process an opt out request. [2] Sending another promotional email to somebody who has already clicked unsubscribe counts as a fresh violation, and since the fine is assessed per message, a handful of ignored opt outs can add up to a number that gets uncomfortable fast.
Frequently asked questions
Can a store refuse to sell me something if I will not give my email or phone number?
No. There is no retailer in the United States that can hold up your purchase because you declined to share an email address or a phone number. The payment side of the transaction and the data collection side are two completely separate things, even when the store's checkout screen makes them look like they are part of the same step.
Is giving my phone number at checkout the same as consenting to marketing texts?
Not on its own. The TCPA requires prior express written consent before a business can send you marketing texts through an autodialer. [3] Saying your phone number out loud at the register so the cashier can look up your loyalty points does not clear that bar, although some loyalty program signup forms bury text message consent in the terms and conditions.
What should I do if I start getting marketing emails I did not sign up for?
Unsubscribe using the link at the bottom of the email. Under CAN-SPAM, every commercial email must include a working opt out mechanism, and the sender must process your request within 10 business days. [2] If the emails continue after you have unsubscribed, you can file a complaint with the FTC.
Does the store sell my information to other companies?
It depends on the retailer. Some stores share customer data with third party data brokers or advertising partners. Others publish privacy policies that say they keep everything in house and do not share it externally. Under the CCPA, California residents have the right to opt out of the sale or sharing of their personal information, and businesses must honour that request. [4]
Can I ask a store to delete the data it collected from me at checkout?
Under the CCPA, California residents have the right to request deletion of their personal information. [4] Similar rights exist under privacy laws in Colorado, Connecticut, Virginia, and several other states. Outside these jurisdictions, deletion rights depend on the store's own privacy policy.
The Bottom Line
The question at the register, "Can I get your email?" is not about the receipt. It is about connecting your purchase to a profile that the store can market to, and in most cases the receipt is just the reason the cashier gives for asking.
That does not make every store that asks for your email a bad actor. Loyalty programs with real discounts, personalised coupon codes that actually save money, and digital receipts that spare you from dealing with fading thermal paper are all legitimate services that plenty of shoppers use on purpose and would miss if they disappeared. What gets lost in the three second exchange at the register is that the arrangement is a swap, not a gift, and the thing you are putting up on your side of the counter is your contact information along with whatever additional data the store's partners decide to bolt onto it afterward.
The simplest protection is also the most effective. If you want the digital receipt but not the marketing, say so at the register. If you do not want to give your information at all, say "no thanks." The transaction will go through either way.