The Complete Guide to Age Verification for UK Wellness Ecommerce (CBD, Supplements & Beyond)

CBD/supplements store? Stop guessing. Pick the right age gate vs real verification - UK rules, payment risk, UX + WooCommerce setup.

#

Back to Home

March 27, 2026

i 3 Table Of Contents

If you run a UK wellness ecommerce store, age verification probably isn't the first thing you think about when it comes to compliance.

After all, you're not selling alcohol or cigarettes. You might be selling CBD products, mushroom supplements, functional drinks, libido support products, or sleep gummies made with ingredients like magnesium and lemon balm. These products sit in an awkward middle ground: they aren't always legally age-restricted in the same way as alcohol, but they often attract scrutiny from payment providers, advertising platforms, marketplaces, and other companies that decide whether your business can operate online.

That's usually when questions start to arise. A payment processor asks about your age-checking procedures. An advertising platform flags a landing page. A marketplace review mentions age-restricted goods. Suddenly, you're trying to work out whether your current setup is enough and what "age verification" actually means in practice.

This guide is designed to answer those questions. While it isn't legal advice, it provides a practical UK-focused overview of age verification for ecommerce websites, the situations that typically trigger compliance concerns, and the different ways wellness brands can implement age controls without creating unnecessary friction for customers.

We'll look at the difference between simple age gates and more robust verification methods, where age checks should appear within the customer journey, how to apply rules to specific products and categories, and the most practical implementation options for WordPress and WooCommerce stores.

Outcomes you want by the end:

  • Reduce legal and commercial risk (including account shutdowns).
  • Avoid nasty surprises with payment processors and ad platforms.
  • Improve audit readiness, even if nobody audits you today.
  • Keep friction low so you do not torch sales.

Why UK wellness ecommerce sites suddenly need age verification (and why it’s not just “for vape shops”)

A few years ago, age gates were mostly a vape shop thing. Or alcohol. Or adult content.

Now wellness brands get pulled into it for a simple reason: you sit in the overlap between “health adjacent” and “policy sensitive”. And the people who control your ability to trade online (platforms, PSPs, ad networks) tend to be cautious, sometimes overly so.

Here is what is happening in practice:

  • Platforms and marketplaces increasingly treat CBD, intimacy products, and certain “performance” supplements as age sensitive even when the underlying law is not crystal clear.
  • Payment providers want to see that you have controls that prevent sale to minors, because chargebacks, reputational risk, and regulatory scrutiny roll downhill.
  • Ad networks often require age targeting plus on-site gating for restricted categories. Sometimes they enforce it inconsistently, which is even more fun.
  • Local Trading Standards may look at whether you are preventing sales to minors where that matters, and whether your systems look competent.

And just to be clear on language.

When people say “age verification for a website”, they can mean two different things:

  • Age gating: the “Are you 18+?” prompt, tick box, enter DOB, click to proceed. Low friction, low assurance.
  • Age verification: a stronger check that gives you more confidence the person is the required age (ID checks, database checks, third party verification, age verified delivery, or a combination).

Most UK wellness stores do not need the heaviest option for every product. But most should have something, especially if you sell CBD, high caffeine products, intimacy products, or anything that triggers platform policy.

What counts as “age restricted” in the UK wellness space (CBD, supplements & beyond)

“Wellness” is a broad label. That’s part of the issue. Under the same Shopify theme you might have:

  • Standard vitamins.
  • Botanical blends with strong claims language on social.
  • CBD products.
  • Energy shots.
  • Intimate wellness items.
  • Sleep aids.
  • Nootropics.
  • Maybe even nicotine free vapes or “herbal inhalers”.

Age expectations differ. And age gating might be required for three different reasons:

  1. By law (product specific).
  2. By policy (payment providers, ad networks, platforms).
  3. By brand risk management (you want to be able to show you took reasonable steps).

Common categories that end up gated in practice:

  • Vaping and nicotine products: strict, legally sensitive.
  • Alcohol: strict.
  • Certain blades and chemicals: not “wellness”, but some stores cross sell things that fall here.
  • Intimate products: often policy driven, sometimes brand choice.
  • High caffeine energy products: increasingly treated cautiously, especially for marketing exposure.
  • Some herbal or nutraceutical products where claims, stimulants, or “adult positioning” pushes you into a riskier bucket.
  • CBD: often policy driven. CBD itself is not uniformly treated as age restricted by statute in the way alcohol is, but many partners behave as if it is 18+ and expect controls.

Also, there is a practical distinction that matters:

  • Access restriction: stopping underage users from viewing parts of the site or specific product pages.
  • Transaction restriction: preventing checkout and purchase.

A lot of stores implement the first and forget the second, or focus on checkout restrictions whilst leaving product access completely open. If you want something defensible, you usually need transaction restriction at minimum for restricted SKUs.

A good approach here is risk based gating.

Meaning:

  • Low risk catalogue: minimal friction.
  • Higher risk categories: stronger gate.
  • Checkout for restricted SKUs: hard enforcement.
  • If a partner requires stronger verification: escalate only where needed.

UK rules and compliance signals you should design around (without getting lost in legal jargon)

You can spend days reading guidance and still not have a clear answer because requirements come from multiple sources.

Think of it as layers:

  • UK law: product-specific restrictions (and general expectations around preventing sales to minors when that applies).
  • Regulator guidance: can shape what “reasonable steps” looks like.
  • Platform policies: Google, Meta, TikTok, marketplaces, affiliate networks.
  • Payment provider contracts: their underwriting rules can be stricter than the law.
  • Delivery partners: age-verified delivery options and proof of handover.

What “good” looks like, in signals:

  • Clear age warnings where relevant (product pages, cart, checkout).
  • A way of preventing sale to minors, not just a decorative popup.
  • Some form of evidence that the control exists and is enforced (settings, screenshots, logs, order notes, delivery method rules).
  • Consistent enforcement across channels (website, subscription checkout, bundles, social landing pages).

Also, the gate vs verification point again, because it matters in audits.

  • Age Gate: user self-declares. Easy. Weak.
  • Age Verification: stronger check. Harder. More defensible.

If you are unsure what applies to your exact products, you should confirm with a legal or compliance professional. But you can still implement best practice controls now because the basics are the same: warn, restrict, enforce, document.

Age gate vs full age verification: choose the right level of friction

Here are the common methods you will see in ecommerce, roughly from lightest to strongest:

  1. Checkbox or “I am 18+” button
  2. Enter date of birth
  3. Account based DOB (saved on profile)
  4. Checkout verification step (can be checkbox, DOB, or third party)
  5. Third party age verification (ID scan, document check, database checks)
  6. Delivery and hand off checks (age verified delivery at the door)

Pros and cons in a wellness ecommerce context:

Checkbox or enter DOB

  • Pro: fast, cheap, low drop off.
  • Con: easy to bypass, weak evidence.

Account based DOB

  • Pro: consistent per user, helps subscriptions.
  • Con: you are now storing personal data you might not need. Also minors can still lie.

Checkout only verification

  • Pro: lowest friction up top, protects the actual sale.
  • Con: may fail platform policy that expects users not to see restricted content. Also feels “late” and can annoy people who just invested time browsing.

Third party verification

  • Pro: strongest proof, best for high risk or where PSP demands it.
  • Con: cost, UX friction, more privacy obligations, failure cases when checks fail.

Age verified delivery

  • Pro: strong at handover.
  • Con: does not stop a minor ordering in the first place, and it is operationally messy.

A sensible recommendation for many UK wellness stores is tiered:

  • Start with a clear gate for restricted categories or site entry if the whole store is restricted.
  • Add mandatory checkout enforcement for restricted SKUs, so you can honestly say “minors cannot purchase”.
  • Escalate to third party verification only when required by a partner or when the product risk justifies it.

The phrase I use is defensible controls.

If you get questioned, can you show that a minor cannot easily purchase? Not “cannot ever”, because nothing is perfect. But you made it meaningfully difficult, consistent, and auditable.

What a good age verification system looks like (UX + compliance + performance)

A real system is not a popup. It is a small set of parts working together:

  • Age prompt UI: modal, page gate, or inline prompt.
  • Rules engine: who gets gated and when (site wide, category, SKU, checkout).
  • Session and cookie logic: remembers pass status for a period.
  • Checkout enforcement: blocks purchase of restricted SKUs without passing the check.
  • Logging or audit trail: not always necessary, but extremely helpful.
  • Admin controls: ability to adjust the age threshold, gate duration, categories, products, and messaging.

UX best practices that keep you compliant without annoying everyone:

  • Use plain English copy. No pseudo legal panic.
  • Keep it mobile first. Big buttons. Minimal typing.
  • Be accessible: keyboard navigation, readable contrast, no tiny click targets.
  • Do not do dark patterns like hiding “Exit” or trapping the user in an infinite loop.
  • Make mistakes recoverable. People enter the wrong DOB more often than you think.

Performance considerations, especially on WordPress:

  • Keep scripts lightweight.
  • Do not block page render if you can avoid it.
  • Make sure it works with caching and CDNs. A cached “passed gate” state that leaks between users is a nightmare scenario.
  • Test with your optimisation stack (minification, deferred JS, Cloudflare, LiteSpeed cache, whatever you use).

Edge cases to think through early:

  • Cookies disabled or private browsing.
  • Shared devices (family iPad).
  • Underage attempts (what does the user see).
  • Bots and scrapers.
  • International visitors if you ship abroad.

Where to place age verification on an ecommerce site (and what each option protects)

There is no perfect placement. There is only what you are trying to protect.

Option A: Site wide entry gate (before browsing)

Best for: stores that are clearly age restricted across the whole catalogue (vape, alcohol, CBD only stores that want to be conservative).

What it protects:

  • Limits exposure to restricted content.
  • Satisfies many platform policy expectations.
  • Creates a clear compliance story.

Trade off:

  • Highest friction, especially for new visitors from ads or social.

Option B: Product or category gate (restricted collections only)

Best for: mixed catalogues, like supplements plus CBD, or functional drinks plus intimacy products.

What it protects:

  • Keeps browsing smooth for non-restricted products.
  • Still restricts access to sensitive product pages.

Trade off:

  • Needs good rules mapping and tagging, or it will be inconsistent.
  • Users can still land directly on a restricted PDP from an ad, and then get gated. That is usually fine, but it needs to work cleanly.

Option C: Checkout only verification

Best for: when you want minimal friction and your main concern is “prevent sale to minors”.

What it protects:

  • The transaction itself, which is often the most important part.

Trade off:

  • Weak protection for content exposure.
  • Might not satisfy partners that expect age restriction earlier in the journey.

Combining approaches (usually the sweet spot)

Common setup for wellness:

  • Category or product gate for restricted areas
  • Plus mandatory checkout validation for restricted SKUs

This gives you both: a cleaner policy story and a harder stop at purchase.

How to set your rules: products, categories, and age thresholds

This is the bit most people skip, then regret.

You need a simple internal mapping that answers:

  • Which products require an age check?
  • What age threshold applies (usually 18+)?
  • Is it a browse restriction, purchase restriction, or both?

Operationally, in ecommerce terms, it helps to build this into how you manage products:

  • Create a product tag like age-restricted.
  • Or a category like 18-plus that you apply to any restricted product.
  • Ensure the rule is part of the new product checklist, so new SKUs do not slip through.

Content and notice placement matters more than you think:

  • Add a clear age notice on the PDP for restricted items.
  • Repeat it in the cart if a restricted product is present.
  • Make it obvious at checkout what the customer is agreeing to and what will happen if they cannot verify age.

International shipping note:

If you sell outside the UK, be careful about claiming you comply with every country’s rules. A practical approach is:

  • Apply UK rules by default.
  • If you have meaningful international volume, consider geo-based rules or separate storefront logic.
  • Be explicit in policies about where you ship and what restrictions apply.

WooCommerce age verification: practical implementation paths (from fastest to most robust)

WooCommerce brings its own realities:

  • You may have guest checkout.
  • Products may be variable, bundled, subscription-based.
  • Checkout can be classic or block-based.
  • Themes and caching plugins can break UI overlays.

So here are realistic paths.

Path 1 (fast): plugin-based age gate (site, category, product)

This is the quickest compliance uplift. You install an age gate plugin, configure it for 18+, decide where it shows, and set a cookie duration.

Good when:

  • You need to show “we have an age gate” quickly.
  • Your risk is more platform and PSP pressure than strict legal categorisation.

Limitations:

  • Often easy to bypass.
  • May not enforce checkout restriction for specific SKUs.
  • Logging is usually minimal.

Path 2 (stronger): gate + restricted product tags + checkout enforcement

This is where it starts to look like a system.

Core idea:

  • Tag restricted products.
  • Gate those products or categories.
  • At checkout, if the cart contains restricted items, require an explicit confirmation and block order submission if not completed.

This is typically done via a WooCommerce extension or a small custom snippet, depending on your stack. (If you go custom, get it reviewed. Checkout validation bugs are costly.)

Good when:

  • You sell a mix of products.
  • You want a defensible answer to “how do you prevent sales to minors?”

Path 3 (most robust): third party age verification integration

Use this when:

  • Your payment provider requires it.
  • Your ad platform account is at risk without stronger verification.
  • Your category risk is genuinely high.

In practice this might mean:

  • Redirect to a verification flow.
  • Verify with a third party provider.
  • Store only a token or “verified yes/no”, not the full DOB, where possible.
  • Enforce at checkout and maybe at account creation.

What to test in WooCommerce (do not skip this)

WooCommerce breaks in surprising places. Test at least:

  • Guest checkout vs logged in.
  • Restricted vs non restricted products.
  • Coupons and free shipping thresholds (can the user bypass the check by changing cart contents).
  • Subscriptions (first purchase and renewals).
  • Bundles and mixed carts.
  • Variable products (does the gate apply to the parent, the variation, or both).
  • Payment methods (some gateways render checkout differently).
  • Checkout blocks vs classic checkout.

WordPress age verification options (and how to avoid common plugin mistakes)

On WordPress, most age verification tools come in a few forms:

  • Modal popup gates
  • Full page redirect gates
  • Category restrictions
  • Cookie based “remember me” logic

The mistakes I see over and over:

  • Easy to bypass gates: a modal that only hides content visually, but the page is still accessible, or the “pass” cookie can be set trivially.
  • Blocking SEO crawling incorrectly: accidentally gating Googlebot and deindexing your product pages. That one hurts.
  • Caching conflicts: a cache plugin serving a “verified” page state to new visitors, or the gate never appearing because the cached page is served without the script.
  • Accessibility problems: modals without focus lock, tiny buttons, unreadable text.
  • Intrusive UX: a full screen gate on every page load, no remembering, on mobile. People bounce.

Selection criteria when choosing a plugin or approach:

  • Actively maintained, recent updates, decent support.
  • Performance: lightweight scripts, no heavy external dependencies unless necessary.
  • Granularity: site wide vs category vs product level rules.
  • Ability to enforce at checkout for restricted SKUs (or integrate with your checkout logic).
  • Customisable messaging and styling so it matches your brand.
  • Some form of logging or at least consistent settings export for audit readiness.
  • GDPR and UK privacy friendliness.

Deployment checklist (quick and boring, but it saves you):

  • Implement on staging first.
  • Have a rollback plan.
  • Test with caching on.
  • Test on mobile, Safari, Chrome, in private browsing.
  • Monitor after launch: gate views, bounce, checkout completion.

GDPR and UK privacy considerations: collect the minimum, store it safely

Age controls touch personal data surprisingly quickly, especially if you ask for date of birth.

A practical privacy principle here is data minimisation:

  • In many cases, you do not need to store DOB at all.
  • You can validate “18+” via a yes/no confirmation, or via third party verification that returns an “age verified” token.
  • If you do collect DOB, have a clear reason and retention approach. Do not keep it forever because it feels useful.

Cookies and session storage:

  • If you store a “passed age gate” cookie, disclose it in your cookie notice or policy.
  • Document what it stores (ideally a simple pass flag), how long it lasts, and why it is necessary.

If you use third party verification:

  • Do basic vendor due diligence.
  • Put a Data Processing Agreement in place.
  • Understand where data is processed and stored.
  • Update privacy policy wording to reflect it, clearly.

Security basics (yes, still relevant):

  • HTTPS everywhere.
  • Least-privilege admin accounts.
  • Keep plugins updated.
  • Know who can access logs and order notes.
  • Have a basic breach response plan, even if it is just “who do we call and what gets locked down”.

Keeping conversions healthy: how to reduce drop off while staying compliant

If you implement age checks badly, you will feel it in revenue.

A few things that consistently help:

Copy that works

People comply when they understand why. Keep it simple:

  • Why: “UK age restricted product”
  • What: “Please confirm you are 18 or over”
  • Privacy: “We do not store your date of birth” (only say this if it is true)

A decent baseline:

  • “Some products on this site are for customers aged 18+. Please confirm your age to continue.”

Design tips that avoid rage clicks

  • Avoid forcing the gate on every page view. Use a reasonable “remember me” duration.
  • Keep it fast. If the modal takes two seconds to load, you lose people.
  • Make buttons clear: “I am 18+” and “I am under 18”.
  • On under 18, show a polite message, not a dead end.

Offer alternate paths (where appropriate)

If your store is mixed catalogue, do not trap underage users.

If they fail a restricted product gate:

  • Suggest non-restricted categories.
  • Link to educational content that is not product salesy, if that fits your brand.
  • Or simply redirect them to the homepage with a notice.

Measure impact properly

Track:

  • Gate views
  • Pass rate vs fail rate
  • Bounce rate from gated pages
  • Checkout completion for carts containing restricted SKUs
  • Country and device splits

A lot of “conversion loss” is actually mobile UX breakage or caching conflicts, not the existence of the gate.

Operational checklist: testing, monitoring, and proving your controls work

You want to be able to answer, calmly, if someone asks: “How do you prevent minors purchasing?”

That means testing and documentation.

Pre-launch tests

Try to bypass your own system:

  • New session, refresh, open in incognito.
  • Cookies disabled if you can.
  • Logged in vs guest.
  • Add restricted product to basket, then remove it, then add again.
  • Try direct checkout URL access.
  • Try checkout with restricted products and a saved payment method.
  • Confirm what happens when the user fails the check.
  • Confirm what happens if a user enters the wrong DOB and needs to fix it.

Ongoing monitoring

Age verification is not “set and forget”.

Watch for:

  • Plugin updates and theme changes.
  • New product uploads that are missing the restricted tag.
  • Changes to checkout (new payment gateway, new checkout plugin).
  • Policy updates from PSPs and ad platforms.

Documentation that helps in real life

Keep a simple folder with:

  • Screenshots of the gate and checkout enforcement.
  • Plugin settings exports.
  • A one-page SOP: what products are restricted, how you tag them, what happens at checkout, what to do if something slips through.

Incident handling (because at some point, something will)

If a restricted order slips through:

  • Cancel or refund according to your policy and risk level.
  • Record what happened (order number, why it slipped).
  • Fix the rule that allowed it.
  • Add a prevention note to your SOP.

That last part is what makes you look competent if you are ever questioned.

Putting it all together for a UK wellness store (a simple recommended setup)

If you want a balanced baseline for a mixed UK wellness catalogue, here is a setup that usually works without killing conversion:

  1. Define rules: decide which categories and SKUs are 18+.
  2. Implement category or product gating for restricted items (not necessarily site wide).
  3. Mandatory checkout validation if restricted SKUs are in the basket.
  4. Clear notices on PDP, basket, and checkout.
  5. Tracking: measure gate views and checkout completion.
  6. Document SOP: keep it boring and short.

For CBD focused stores:

  • Consider a site wide gate plus checkout enforcement.
  • Be prepared to escalate to stronger verification if a payment provider or ad platform demands it.
  • Also consider age verified delivery options if it fits your logistics and category risk.

Implementation order for fastest ROI:

Define rules first, then gate, then checkout enforcement, then tracking, then documentation. In that order. Otherwise you end up with a nice looking popup and no actual control.

Age verification is a system. Rules, UX, enforcement, evidence. Not a single modal you install and forget.

FAQs

Do I legally need age verification to sell CBD in the UK?

It depends on the exact products, how they are positioned, and what rules your partners apply. Even when the law is not explicit in the way it is for alcohol, many payment providers, ad platforms, and risk teams treat CBD as 18+ and expect controls. A practical move is to implement at least product or category gating plus checkout enforcement for CBD SKUs.

Is an “I am 18+” checkbox enough?

Often it is enough for a basic age gate, but it is weak proof and easy to bypass. If you want defensible controls, add checkout enforcement for restricted products at minimum, and consider stronger verification where required.

Should I gate the whole site or only certain products?

If your entire catalogue is clearly restricted, a site-wide gate is simplest. If you sell a mix (supplements plus CBD, for example), category or product gating is usually better for conversion, as long as you still enforce checks at checkout for restricted SKUs.

Will an age gate hurt my SEO?

It can if implemented badly. Do not block search engine crawlers unintentionally, and avoid setups that require a cookie to access indexable content. Test with Search Console and make sure Googlebot can crawl your important pages as intended.

How do I do age verification in WooCommerce without custom code?

The quickest route is a reputable age gate plugin that supports WooCommerce and ideally product or category rules. For stronger checkout enforcement, you may need a WooCommerce-focused extension or light customisation. Always test checkout thoroughly before going live.

Do I need to store customers’ date of birth?

Usually no. Many setups can confirm age without storing DOB, or they can store only an “age verified” flag. If you do collect DOB, make sure you have a clear reason, disclose it properly, and protect it.

What should happen if someone says they are under 18?

Do not leave them at a dead end. Show a clear message that the product is restricted, and if your site has non-restricted items, guide them there. If your whole site is restricted, redirect away and keep the message polite and simple.

What if a payment provider asks for proof of age controls?

Be ready to provide screenshots of the gate, checkout enforcement, and a short explanation of your process. If you have logs or settings exports, even better. The goal is to show consistent enforcement and that you took reasonable steps to prevent sales to minors.

How often should I review my age verification setup?

At least quarterly, and any time you change theme, checkout, caching, payment gateways, or product range. Also review when ad platforms or PSP policies change, which happens more often than they admit.

Alex Hedges

As the CEO of FitPixels, I've had the privilege of guiding our agency to success for over a decade. With a passion for marketing innovation and a keen understanding of a variety of sectors including; telecoms, B2B, service based businesses and manufacturing, I've led our Manchester-based team to become a trusted partner for businesses looking for transformative strategies.