Industries

Order Tracking Without Exposing Data: Email OTP Explained

Customers ask your chatbot 'where's my order?' every day — but handing over tracking details without verification is a data protection risk. Here's how email-based one-time codes let customers self-serve safely, with nothing shown if verification fails.

By OrCube Team27 July 20269 min read
Order Tracking Without Exposing Data: Email OTP Explained - featured image

Quick Answer

OrCube AI provides AI-driven web chatbot customer support software with built-in email one-time code (OTP) verification for secure order tracking and account lookups, ensuring no customer data is revealed if verification fails. The platform aligns with Cyber Essentials and ISO/IEC 27001 information security principles and is registered in England and Wales under Code Melodies Ltd. Businesses can start a 14-day free trial to test verified order-lookup automation on their own website chatbot.

A customer types "where's my order?" into your website chatbot at 9pm on a Tuesday. Your support team is offline. The obvious answer is to have the bot pull up the order and show the tracking status immediately — except that means anyone who knows or guesses an order number, from a delivery text left on a shared phone or a screenshot in a group chat, can see someone else's name, address, and delivery status. That's not a hypothetical. It's the exact gap that email one-time code (OTP) verification is built to close.

This matters more in 2026 than it did a few years ago, because the regulatory and threat environment around customer data has shifted. The UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 govern how personal data belonging to individuals in the UK must be collected, processed, stored, and protected, and order details — name, address, delivery status — count as personal data under both. A chatbot that reveals this information to whoever types in an order number, without confirming that person actually has a legitimate claim to it, sits on shaky ground.

Key takeaways
  • Order number alone doesn't verify identity — it's often visible on packing slips and shared messages, so OrCube AI ties the OTP to the email address on the order record instead.
  • If OTP verification fails, no order or customer data is revealed at any point — the chatbot doesn't confirm an order exists or hint at any details.
  • UK GDPR, the Data Protection Act 2018, and the Online Safety Act 2023 all reinforce the need for verified, secure disclosure of personal data like delivery status and addresses.
  • Managed IT support for UK SMEs typically costs £50–£150 per user/month, while a cybersecurity audit to validate a custom-built lookup system runs £3,000–£20,000 over 10–30 days.
  • Complex cases — lost parcels, disputes, locked email accounts — should hand over to a live agent inside the same chat window, not force endless automated retries.

Why order number alone isn't verification

An order number tells you which order someone is asking about. It doesn't tell you whether the person asking is the customer, a curious sibling who found a receipt on the kitchen table, or someone running through a list of sequential order IDs to see what comes up. Order numbers are often visible on packing slips, delivery texts, and shared inboxes — none of which prove identity.

Email OTP verification solves this by adding a second factor tied specifically to that order. When a customer asks OrCube AI's chatbot for their order status, the system sends a one-time code to the email address recorded against that specific order — not to a phone number, not via WhatsApp, and not to any address the customer types in on the spot. The code only reaches an inbox the real customer already controls.

How the verification flow actually works

The process is deliberately simple from the customer's side, because complexity is where people abandon a support interaction and call instead. The customer stays on the website the entire time — they never leave the chat window, never open an app, never get redirected to WhatsApp.

  • Step 1 — the request: the customer asks the chatbot about a specific order, either by order number or by describing what they bought.
  • Step 2 — the code is sent: OrCube AI's system generates a one-time code and emails it to the address stored against that order.
  • Step 3 — confirmation inside the chatbot: the customer copies the code from their inbox and types it directly into the chatbot interface — there's no separate login page or app switch.
  • Step 4 — access granted or denied: if the code matches, tracking details are shown immediately. If it doesn't match, or the customer never enters one, no order or customer data is revealed at any point.

That last step is the part businesses tend to underestimate. Failure has to fail silently. A chatbot that says "sorry, that code was wrong — did you mean order #48213 for Sarah Jones?" has already leaked more than the code itself would have protected.

What the law actually expects here

Businesses sometimes assume data protection law only cares about big breaches — a hacked database, a leaked spreadsheet. In practice, UK GDPR and the Data Protection Act 2018 apply just as much to small, everyday disclosures: showing the wrong person a delivery address counts as an unauthorised disclosure of personal data, even if nobody ever finds out.

The Online Safety Act 2023 adds a separate but related layer. It imposes duties of care on online service providers to protect users interacting through their platforms — reinforcing that secure, verified interactions aren't just good practice, they're part of a wider expectation that online services take reasonable steps to protect the people using them. A chatbot that hands out delivery information on request, with no verification step at all, sits awkwardly against that duty of care.

There's also a security angle beyond data protection specifically. The Network and Information Systems Regulations 2018, as amended by the NIS (Amendment) Regulations 2024, sets expectations around the security of digital infrastructure for certain categories of digital service providers. While the direct scope of NIS is narrower than general e-commerce, the broader principle — that customer-facing digital systems should be built with security as a default, not an afterthought — applies across the board. Exact applicability depends on the size and category of the business; check current guidance or consult a data protection professional if you're unsure whether NIS obligations apply to your specific operation.

Why email, not SMS or WhatsApp

It's worth being specific about why the OTP goes to email rather than a messaging app. Some businesses assume WhatsApp verification would feel more modern, but for order tracking, email has a structural advantage: the email address is already tied to the order at checkout, which means the OTP destination is fixed by the order record itself — nobody can redirect it by typing in a different phone number. Customers never need to open WhatsApp or download anything; they stay entirely within the website chat window from question to answer.

This also keeps the process fast. The UK's digital infrastructure — including its role as a major hub for global connectivity, with over 50 active subsea fibre optic cables carrying data in and out of the country — means email delivery and chatbot response times for OTP flows are typically near-instant rather than something the customer has to wait around for. A code that takes thirty seconds to arrive still feels faster than being told to email support and wait until Thursday.

What this costs to get right

Building this kind of verified lookup flow in-house isn't free, and it isn't just a chatbot problem — it touches infrastructure, security testing, and ongoing maintenance. For context, managed IT support for small and medium-sized e-commerce operations in the UK typically runs £50–£150 per user/month, with the exact figure driven by the number of users, infrastructure complexity, and the service level agreement in place — proactive monitoring and predictive maintenance sit at the higher end of that range. A cybersecurity audit and penetration test to validate that an order-lookup system doesn't leak data typically costs £3,000–£20,000 per engagement and takes 10–30 days, combining automated vulnerability scanning with manual ethical hacking to catch the kind of subtle flaw — like an OTP failure message that reveals a name — that automated tools alone tend to miss.

For businesses building or migrating their order systems rather than maintaining what they have, cloud migration projects for SaaS or PaaS platforms generally run £5,000–£50,000 per project over 20–90 days, and custom development work — building a bespoke verification flow from scratch — typically costs £250–£1,000 per day, with a functional MVP usually taking 60–180 days depending on scope. Buying into an existing platform with this already built in is, for most operations, considerably cheaper than any of these paths individually.

ServiceTypical CostInstall/Delivery Time
Managed IT Support (SME)£50–£150 per user/month5–15 days to onboard
Cloud Migration (SaaS/PaaS)£5,000–£50,000 per project20–90 days
Cybersecurity Audit & Pen Testing£3,000–£20,000 per engagement10–30 days
Custom Software Development£250–£1,000 per day60–180 days for MVP

Where automation should hand off to a human

OTP verification handles the routine case well — the customer wants a tracking number and nothing else. It's less suited to the messier situations: a parcel marked delivered that never arrived, a customer disputing a charge, or someone who's locked out of the email address tied to their order entirely. In those cases, the chatbot shouldn't keep trying to force a self-service answer.

This is where live handover matters. If a support agent is at their desk, the conversation gets flagged in their OrCube dashboard and they take over inside the same chat window the customer has been using the whole time — no app switch, no repeating themselves. If nobody's at a desk and the business has WhatsApp handover enabled, that request goes to the agent's own WhatsApp instead, purely so they can respond from their phone. The customer never sees or touches WhatsApp themselves; they stay on the website chatbot from start to finish.

Businesses evaluating whether to build this themselves or adopt a platform already built for it might also want to compare notes with the 200ms feedback rule article on why chatbot response speed matters just as much as the verification logic itself — a secure system that feels sluggish still drives customers to pick up the phone.

Getting this right without over-engineering it

Not every business needs bank-grade multi-factor authentication for a delivery status lookup. The goal is proportionate friction: enough verification that a stranger can't pull up someone else's address, not so much that a genuine customer gives up and emails support instead. Email OTP tied to the order record hits that balance for most e-commerce operations — it's fast enough not to frustrate a legitimate customer, and specific enough that a failed attempt reveals nothing at all.

OrCube AI builds this verification step directly into its chatbot for order and account lookups: a one-time code goes to the email address tied to the order, the customer confirms it inside the chat, and if the code doesn't match, no order or customer information is shown — full stop. The platform runs on Cyber Essentials-aligned practices and is built with ISO/IEC 27001 information security principles in mind, registered in England and Wales under Code Melodies Ltd. If you're currently answering "where's my order" manually, or your existing chatbot hands out tracking details with no verification at all, it's worth testing a platform that's already solved this. Start a 14-day free trial and see how it handles your first order lookup.

Expert Takeaway

The most common mistake in DIY order-lookup chatbots is matching only on order number — anyone who intercepts a delivery confirmation email or guesses a sequential order ID can pull up someone else's tracking details. Tying the OTP to the email address on file, rather than the order number alone, closes that gap because the code is only ever sent to an inbox the real customer controls.

Frequently Asked Questions

Does UK GDPR require order verification before sharing tracking details?

UK GDPR and the Data Protection Act 2018 require that personal data — which includes delivery addresses and order status — is only disclosed to the person it belongs to, or someone authorised to see it. While the law doesn't prescribe a specific technical method, verifying identity before disclosure (such as with an email OTP) is a practical way to meet that obligation and reduce the risk of unauthorised disclosure.

What happens if a customer enters the wrong OTP code?

If the OTP verification fails, no order or customer data is revealed at all — the chatbot won't confirm or deny that an order exists, and won't hint at a name, address, or status. This prevents someone from guessing their way toward information through repeated failed attempts.

How does the email OTP order-tracking process actually work?

The customer asks the website chatbot about their order. A one-time code is sent to the email address tied to that specific order, and the customer types the code directly into the chatbot interface — never leaving the website or opening a separate app. If the code matches, tracking details appear immediately in the chat.

Why does OTP verification matter more for e-commerce chatbots now?

Data privacy expectations under UK GDPR and duties of care under the Online Safety Act 2023 have raised the bar for how online services handle personal information, while automated chatbots make it easier than ever for an unverified lookup request to run at scale. Building verification in from the start reduces the risk of unauthorised disclosure rather than relying on manual review to catch mistakes after the fact.

See OrCube AI in action

Answer customer questions instantly, hand off to your team on WhatsApp, and book appointments — all in one AI-powered chat.

Start Free Trial
Order Tracking Without Data Exposure: Email OTP Explained | OrCube AI