If we require an order number to use the withdrawal function, is this legal? What if the customer entered the wrong email and can’t look up their order?
Requiring an order number together with an email address is acceptable – some form of identification is necessary to locate the contract. The directive requires that exercising the right of withdrawal be no more difficult than entering the contract, so you need to ensure there is a workable fallback if a customer cannot locate their order by email.