Why WhatsApp apps get your number banned: linked device vs API
Why linked-device WhatsApp apps for Shopify disconnect, stop sending order confirmations and get numbers restricted, and what the Cloud API changes.
A WhatsApp Business account banned because of a Shopify app is one of the most expensive things that can happen to a store that sells on WhatsApp: you lose the number your customers already saved, every open conversation, and the order confirmations that were quietly holding your cash-on-delivery return rate down. Merchants usually notice it in stages. First the app shows as disconnected and order confirmations stop sending. Then the number has to be re-paired every few days. Then one morning WhatsApp Business displays a restriction notice and nothing goes out at all. This article explains why that sequence happens, which kind of integration causes it, how to check what your current app is doing, and how Beacon Messenger avoids the failure mode entirely by sending only through Meta's WhatsApp Cloud API.
What merchants report
The clearest public record is in the low-star reviews of apps that connect to WhatsApp by pairing a phone. In the 1- and 2-star reviews of WhatFlow, 18 of the 30 reviews scraped on 28 September 2026 mention bans, restrictions, blocks or disconnections. One merchant wrote on 2 May 2026 that they "got our WhatsApp Business account restricted by Meta after a few months of use" while only sending order confirmations and shipping updates, and pointed at the fact that the app "connects via 'link a device' instead of the official" API. Another, on 30 March 2026, said their account had been "banned twice for using an unauthorized API". A third, on 1 July 2026, summarised the day-to-day experience as "Disconnects more than it connects!". The developer's public replies on the same page attribute the problem to "legacy web-pairing sessions" and say a separate "Official Meta API platform" has since been built, which is the strongest confirmation you will find that the pairing method itself was the cause.
SuperLemon's 1- and 2-star reviews show the second half of the same story: messages that stop going out without the merchant noticing. One undated review reports a "Massive drop in abandoned cart recovery from 15% to 3 & 5%" and concludes that "none of the messages are being sent". Its listing, as of the same date, still offers a Chrome extension that works inside WhatsApp Web for merchants on a personal number. These are merchant reports, not audits, but they describe exactly the behaviour that the two connection methods predict.
Why a linked-device session breaks and gets numbers restricted
WhatsApp offers two very different ways for software to touch an account. The first is the consumer feature that lets you scan a QR code or type a pairing code so a laptop can mirror your phone. It exists so a human can chat from a second screen. When an app uses it, the app's server pretends to be that laptop: it holds a WhatsApp Web session open around the clock, reads the message stream and injects outgoing messages as if you were typing them. Nothing about that is designed for automation, which is why it fails in three predictable ways.
- Sessions expire. WhatsApp Web sessions are tied to a phone that must stay online and periodically re-authenticate. When the phone loses signal, updates, or WhatsApp rotates its security parameters, the server-side session drops and every automation that depended on it goes silent until someone scans the QR code again. That is the "disconnected" state merchants describe.
- The protocol is unofficial. WhatsApp's own help centre is explicit: using unofficial apps or linking your account to unofficial versions "violates our Terms of Service", and "your WhatsApp account might also be temporarily or permanently banned, or it could lead to restrictions on your account, including the ability to link devices" (About unofficial apps). A server that emulates the web client is, from WhatsApp's side, an unofficial client.
- Volume looks like spam. A consumer number sending hundreds of near-identical order confirmations per day, with no approved template and no opt-in signal, matches the pattern WhatsApp's anti-abuse systems are trained to stop. That is why several reviewers report that problems started when order volume grew.
The second way is the WhatsApp Business Platform, where a business registers a phone number with Meta, submits message templates for approval, and sends through the Cloud API over HTTPS. Here automation is the intended use. Meta publishes messaging limits that start at 250 unique customers in a rolling 24 hours for a new business portfolio and grow with quality, publishes per-message pricing by template category and country, and returns a delivery status for every message. Because sends are attributed to a verified business, a burst of order confirmations is not a red flag; it is the product working as designed.
How to tell which kind of app you have
- Look at the onboarding screen. If setup asked you to open WhatsApp on your phone, go to Linked devices and scan a QR code or enter a pairing code, the app is driving a WhatsApp Web session. Cloud API apps ask for a WhatsApp Business Account ID, a phone number ID and an access token from Meta Business Manager, or hand you to Meta's embedded signup.
- Check the App Store listing. Listings that say "link a device", "no API approval needed" or "works with your existing number in minutes" are describing the pairing method. WhatFlow's listing, for example, still advertised connecting "using WhatsApp link-a-device" on 28 September 2026.
- Look for templates. The Cloud API can only start a conversation with a customer using a template that Meta has approved, so a Cloud API app will show you a template list with statuses such as Approved, Pending or Rejected. If you can type any free text and blast it to new customers, the app is not using the Cloud API.
- Check for a webhook. Cloud API apps receive delivery receipts and replies through a callback URL registered in the Meta app. If the app cannot show you sent, delivered and read for each message, it has no way to get them.
What to do if your number is already restricted
Disconnect the app before you do anything else, then remove any linked devices you do not recognise from WhatsApp Business on the phone. Follow the appeal flow in the restriction notice; WhatsApp's help centre recommends removing unofficial apps before re-registering with the official app. Do not move the same number to another pairing-based tool, because the next restriction is more likely to be permanent. If the number is permanently banned, you will need a new number for the Business Platform anyway, so register it directly with Meta and only ever expose it to Cloud API integrations. Finally, tell customers on your order status page and in your email confirmations which number is now official, so nobody replies to the dead one.
How Beacon Messenger connects
Beacon Messenger has no QR code, no pairing code and no linked-device flow anywhere in the app. The WhatsApp setup page asks for four values from your Meta developer app: the WhatsApp Business Account ID, the phone number ID, a permanent system-user access token and the app secret. The token and secret are encrypted at rest and only ever used to call Meta's Graph API at graph.facebook.com. When you save the connection, the app calls Meta to read the number's display name, verified name and current quality rating, then loads the approved templates from your WhatsApp Business Account so you can map them to the order confirmation, shipping, cash-on-delivery and abandoned-checkout automations. Every automated message is a template send through the Cloud API; there is no code path that sends free-form text to a customer who has not written to you first, apart from the short acknowledgement after a customer taps Confirm or Cancel on a cash-on-delivery message, which happens inside the customer-service window Meta opens for that reply.
Because every send goes through Meta, Meta's status webhooks come back for every message and are written to the delivery log as sent, delivered, read or failed, with the error code and message when something goes wrong. A disconnected token shows up as failed entries with Meta's error, not as silence. If you want the setup walkthrough, the order notifications through the Cloud API guide covers creating the Meta app, verifying the number and getting a first template approved; the Beacon Messenger landing page lists what the plans include.
Frequently asked questions
Can Meta ban a number that only sends order confirmations?
Yes, if the messages are sent through an unofficial client. WhatsApp's help centre states that linking an account to unofficial apps violates its terms and can lead to temporary or permanent bans. The content of the messages does not make the connection method compliant.
Will switching to a Cloud API app fix a number that is already restricted?
Not by itself. A restriction is applied to the account; you need to complete the appeal in the WhatsApp Business app first. Once the number is back, registering it with the WhatsApp Business Platform and using only Cloud API integrations prevents the same cause from recurring.
Does the Cloud API cost more than a linked-device app?
Meta charges per delivered template message by category and destination country, billed to your own Meta account, whether your app is free or paid. Linked-device apps do not have that Meta fee, which is part of their appeal, but they carry the disconnect and ban risk described above. Beacon Messenger itself charges a flat monthly fee with a message cap and adds nothing per message.
Why does my linked-device app say connected but nothing is sending?
The connection indicator usually reflects the last successful handshake, not the current session. Sessions drop when the paired phone goes offline or WhatsApp changes its web client. Only an integration that receives delivery receipts from Meta can tell you whether a specific message actually arrived.
More guides
- How to add a WhatsApp chat button to your Shopify store (2026)
- How to send Shopify order confirmations and shipping updates over WhatsApp with the official Cloud API
- Cash on delivery on Shopify: confirm orders over WhatsApp before you ship
- Recovering abandoned checkouts on Shopify with WhatsApp, the compliant way
- How a "free" WhatsApp app for Shopify ends up charging you
- Por qué una app de WhatsApp "gratis" para Shopify te cobra
- Pushdaddy or SuperLemon alternative: WhatsApp apps compared
- How to verify Shopify WhatsApp notifications were delivered
- Chat button still on your store after uninstalling the app?