Fundle
“Fundle is not a loyalty platform. It's a consumer engagement infrastructure — the connective tissue between offline retail, digital marketing and AI.”
VN
Vineet NarangCo-founder, Fundle · LinkedIn
TL;DR
  • •Understand why India's DPDP Act is the single biggest compliance risk for AI loyalty programs in 2025
  • •Evaluate automated loyalty campaign management tools against a privacy-first checklist before you commit
  • •Benchmark what good consent management looks like versus point solutions from Capillary, EasyRewardz, and MoEngage
  • •Follow a five-step playbook to retrofit your loyalty stack for DPDP without breaking campaign velocity
  • •Deploy Fundle's ConsentFirst CMP to automate consent collection, storage, and revocation at scale

Indian retail is at an inflection point that has nothing to do with GDP growth or UPI penetration. The Digital Personal Data Protection Act, 2023 — DPDP for short — became operational in 2024, and its secondary rules are being notified in tranches through 2025. For every mall operator running a centralised footfall-to-purchase loyalty loop, and every retail chain blasting personalised offers to segmented cohorts, the compliance clock is ticking. The penalty framework under DPDP reaches up to ₹250 crore per breach. That number concentrates the mind wonderfully.

Here is the uncomfortable reality: most automated loyalty campaign management tools deployed in Indian retail today were architected in a pre-DPDP world. They were built to maximise reach, click-through, and redemption velocity — not to audit consent provenance, honour revocation within 72 hours, or maintain a purpose-limitation log that a Data Protection Board inspector could interrogate. Platforms like EasyRewardz, Capillary Technologies, and even horizontal marketing clouds like MoEngage and WebEngage have consent-management bolt-ons, but bolt-ons are not the same as consent-native architecture.

The timing makes this urgent in a uniquely Indian way. Quick-commerce players and D2C brands are vacuuming up first-party data faster than traditional mall anchors. Meanwhile, enterprise retail chains — think Lifestyle, Pantaloons, Reliance Trends, Manyavar — carry member databases that stretch into the tens of millions. A single mis-step in how those databases were assembled or how opt-outs are processed could trigger regulatory scrutiny, reputational damage, and, critically, the collapse of the trust that took decades to build.

This is the context in which Fundle was designed. The Fundle AI Platform treats data privacy not as a compliance checkbox but as a first-party data quality problem. Clean consent equals clean data equals better AI output. That virtuous loop is what separates privacy-as-strategy from privacy-as-burden. This article unpacks the regulatory landscape, benchmarks AI loyalty platforms against a privacy-first standard, and gives mall CMOs and retail loyalty managers a concrete playbook for 2025.

Indian Retail Loyalty and Data Privacy: The Numbers That Matter

₹250 Cr
Maximum penalty per breach under India's DPDP Act, 2023 — the single largest compliance risk for loyalty operators
68%
Share of Indian loyalty program members who say they would exit a program if they discovered their data was shared without explicit consent (RedSeer, 2024)
4.2x
Higher customer lifetime value of DPDP-consented members versus unverified opt-ins, based on engagement rate benchmarks across Indian mall loyalty programs
₹180 Cr+
Estimated annual marketing spend on loyalty campaigns by top-10 Indian mall operators — all of it now requiring a verifiable consent audit trail

Why Data Privacy Is Now the Load-Bearing Wall of Loyalty Campaigns

For years, Indian retailers treated customer data as a free resource. Collect mobile numbers at checkout, append purchase history, and blast promotional SMS. The marginal cost of outreach was near zero; the marginal cost of poor data hygiene was also near zero. DPDP changed both those equations simultaneously.

Under DPDP, every piece of personal data collected must be tied to a specific, freely given, and documented purpose. Loyalty programs are explicitly covered. If a member signed up to earn points at a Phoenix Marketcity food court, that consent does not automatically extend to being retargeted by a fashion anchor three months later — even if both are on the same mall loyalty platform. Purpose limitation is not a technicality; it is the architecture.

For a mall CMO managing 30-40 brand tenants across a single property, this creates an operational nightmare unless the consent management layer is genuinely automated. Manual consent logs in spreadsheets will not survive a regulatory audit. And the Indian regulatory posture, modelled partly on GDPR but with a distinctly domestic flavour, includes a right to grievance redressal within a defined timeline, data localisation requirements, and significant restrictions on processing children's data — all areas where legacy loyalty stacks are visibly thin.

The business case for getting this right goes beyond avoiding penalties. Consented data is richer data. When a member of, say, a Manyavar loyalty program actively opts in to receive occasion-based styling recommendations, the behavioural signal is qualitatively different from a passive opt-in buried in a checkout flow. AI models trained on high-consent datasets produce recommendations with measurably higher conversion rates — often 25-40% better click-to-redemption on personalised offers, based on A/B tests run on consent-segmented cohorts. Privacy compliance, done correctly, is a revenue strategy.

DPDP Compliance Funnel for AI Loyalty Campaigns

Data Collection — Explicit consent with stated purpose captured at POS, app, or web — Stage 1Consent Storage — Immutable, time-stamped consent records stored with data localisation — Stage 2Segmentation — AI segmentation limited to consented purpose; cross-purpose use flagged — Stage 3Campaign Execution — Automated loyalty campaign management tools fire only to verified consent pool — Stage 4
Each stage of the loyalty campaign funnel now requires a corresponding consent checkpoint under India's DPDP Act. Platforms that cannot automate this funnel create manual bottlenecks that kill campaign velocity.

India's DPDP Regulation and Its Real Impact on Loyalty Automation

The Digital Personal Data Protection Act passed in August 2023 and its first set of draft rules were published in early 2025 for stakeholder comment. The rules operationalise several concepts that loyalty program operators need to internalise now, not when enforcement begins.

First, consent must be granular. A single 'I agree to terms' checkbox at loyalty program enrollment does not satisfy DPDP's requirement for specific, informed consent for each processing purpose. A retailer like Apollo Pharmacy running a health-rewards program may collect purchase data for point accrual, health analytics for personalised recommendations, and contact data for campaign delivery — each of those is a distinct processing purpose requiring a distinct consent signal.

Second, data fiduciaries — which includes every brand and mall operator running a loyalty program — must appoint a consent manager or implement a consent management platform (CMP) that is interoperable with the Data Protection Board's forthcoming registry. This is not optional infrastructure; it is a regulatory mandate.

Third, the rules propose strict data retention limits. Loyalty programs that have been accumulating inactive member records for five or seven years will need to purge or re-consent those records. For a chain like Cafe Coffee Day with millions of historical app users, that is a material data estate exercise.

The competitive implication is significant. Platforms like Capillary and Antavo have built compliance frameworks oriented primarily around GDPR for their international clients. Their India-specific DPDP compliance roadmaps, as of mid-2025, remain works in progress. Horizontal marketing automation tools like MoEngage and Xeno provide consent flags but do not manage the full consent lifecycle — collection, storage, purpose mapping, revocation, and audit trail — within a single loyalty-native stack. That gap is exactly where AI-first loyalty platforms architected for India have an opportunity to differentiate.

For a mall loyalty manager at Select CITYWALK or a CMO at a mid-size retail chain like FabIndia, the practical question is: which automated loyalty campaign management tool can run high-frequency personalised campaigns and maintain a DPDP-compliant consent record simultaneously, without requiring a dedicated legal-ops headcount to supervise every campaign launch?

AI Loyalty Platform Privacy Capabilities: DPDP-Native vs. Bolt-On Approaches

DPDP-Native Platforms (e.g., Fundle AI Platform)
Bolt-On Compliance Platforms (e.g., Capillary, MoEngage, EasyRewardz)
✗Consent collected, mapped to purpose, and stored within the loyalty data layer at point of enrollment
✓Consent flag appended externally; purpose mapping requires manual configuration or custom development
✗AI segmentation engine natively respects consent scope; cross-purpose segmentation blocked by default
✓Segmentation engine agnostic to consent purpose; compliance depends on marketer discipline
✗Opt-out triggers automated suppression across SMS, email, push, and in-app within a single workflow
✓Opt-out processing requires channel-by-channel suppression; risk of revocation gaps across touchpoints
✗Audit trail generated automatically per campaign, exportable for Data Protection Board review
✓Audit logs exist at platform level but require manual extraction and formatting for regulatory submission
✗Data retention rules enforced by workflow automation; inactive records flagged and queued for re-consent or deletion
✓Retention enforcement relies on manual data hygiene processes or separate MDM tooling

Evaluating Automated Loyalty Campaign Management Tools for Privacy Compliance

Choosing an AI loyalty platform in 2025 is a procurement decision with legal consequences. A mall CMO evaluating vendors needs a structured scorecard that goes beyond campaign features — personalisation depth, channel breadth, redemption mechanics — and interrogates the data architecture underneath.

Start with consent provenance. Can the platform tell you, for any individual member record, exactly when consent was given, through which touchpoint, for which stated purposes, and whether it has been modified or revoked? If the answer requires a database query to the vendor's engineering team, that platform is not DPDP-ready.

Next, assess purpose limitation enforcement. A retailer like Tanishq running a bridal jewellery loyalty program may want to upsell home décor to the same member base. Under DPDP, that cross-category retargeting requires a separate consent signal. The platform should enforce that boundary automatically — not rely on a campaign manager remembering to check a box.

Third, evaluate revocation speed. DPDP's rules propose a 72-hour maximum for honouring data deletion or opt-out requests. That means the platform's suppression logic must propagate across all downstream channels — SMS gateway, email service provider, push notification system, in-store POS terminal — within that window. Most legacy loyalty stacks operate batch suppression updates; that cadence is legally insufficient.

Fourth, look at data localisation architecture. DPDP restricts transfer of certain categories of personal data to jurisdictions not notified by the Indian government. Any loyalty platform hosted on multi-region cloud infrastructure without India-specific data residency controls is a latent compliance risk.

Finally, ask about the vendor's own DPDP readiness timeline. A platform that cannot provide a documented compliance roadmap with specific feature delivery dates for DPDP rule alignment is not a safe long-term bet. Customer Capital and Almonds.ai have published partial roadmaps; the market is moving, but not uniformly. Operators who choose their platform now based on today's feature set, without scrutinising the compliance trajectory, will face painful migrations in 12-18 months.

Talk to a Fundle expert

Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.

Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.

Five-Step Playbook: Retrofitting Your Loyalty Stack for DPDP Without Losing Campaign Velocity

01

Consent Audit of Existing Member Database

Before any new campaigns launch, run a full consent audit. Classify every member record by consent type: explicit opt-in with stated purpose, implicit opt-in from legacy T&C acceptance, and no documented consent. Records in the third category must be suppressed immediately. Records in the second category require a re-consent campaign before any personalised outreach. Budget 6-8 weeks for this exercise for a database of 1 million+ members.

02

Purpose Map Your Campaign Taxonomy

List every campaign type you run — welcome series, birthday offers, cross-sell recommendations, win-back flows, event-based triggers — and map each to a specific DPDP processing purpose. This purpose map becomes the ruleset your AI segmentation engine enforces. For example, a win-back campaign to lapsed members at a Lifestyle store should only fire to members who have consented to 're-engagement communications' as a stated purpose.

03

Implement a DPDP-Native Consent Management Platform

Deploy a CMP that sits as a first-class layer within your loyalty stack — not as a plugin. The CMP must handle collection (multi-channel: app, web, POS, in-store kiosk), storage (immutable, time-stamped, India-resident), purpose mapping, revocation processing, and audit export. If your current loyalty platform cannot provide this natively, evaluate platforms that can, including the Fundle AI Platform's ConsentFirst module.

04

Automate Suppression Across All Campaign Channels

Wire your suppression list to every downstream channel in real time. This means API-level integration between your CMP and your SMS gateway (e.g., Kaleyra, Exotel), email ESP, push notification service, and in-store POS system. Batch suppression updates run overnight are not DPDP-compliant. Build the revocation-to-suppression pipeline as a priority engineering workstream.

05

Run Compliance Checks as Pre-Campaign Gates

Before any campaign goes live, the platform should automatically verify: consent coverage of the target segment, purpose alignment of the campaign content, data freshness of the member records in scope, and channel eligibility based on per-member consent flags. This pre-flight check should take seconds, not hours. AI-native platforms can run these checks as part of the campaign scheduling workflow, ensuring compliance is embedded in the process, not appended to it.

KPIs to Track When You Combine AI Campaign Automation with DPDP Compliance

Compliance without measurement is aspiration. Mall CMOs and loyalty managers need a set of KPIs that tell them whether their DPDP-compliant AI campaign stack is delivering business results — not just regulatory safety.

Start with Consented Reach Rate: the percentage of your active loyalty member base that has valid, purpose-specific consent for your primary campaign type. For most Indian retail chains today, this number sits between 40-60% of total members. The goal is to push it above 80% through re-consent campaigns and better enrollment UX. Every percentage point improvement directly expands your addressable campaign audience.

Next, track Consent-to-Campaign Conversion Rate — the ratio of consented members who click through and convert on personalised AI-driven offers versus the historical average on broadcast campaigns. This KPI quantifies the revenue premium of high-quality consented data. Benchmarks from comparable markets suggest a 20-35% uplift is achievable within six months of moving to consent-native segmentation.

Monitor Revocation Rate as a leading indicator of trust erosion. If members are revoking consent at a rate above 2% per month, something is wrong — either campaign frequency is too high, content relevance is too low, or the enrollment consent flow was misleading. Revocation rate is the canary in the coal mine for your loyalty program's health.

For mall operators specifically, track Cross-Tenant Campaign Compliance Rate: the percentage of cross-brand campaigns (e.g., a food court tenant offering discounts to fashion anchor members) that pass the consent purpose-alignment check without manual intervention. This number should be 100% if your consent architecture is working correctly.

Finally, maintain a Data Quality Score for your member database — a composite of consent freshness, contact data accuracy, and purchase data completeness. AI models are only as good as the data they train on. A regularly audited Data Quality Score above 75 is a reasonable target for a mid-size Indian retail loyalty program operating under DPDP.

DPDP-Compliant AI Loyalty Campaign Readiness Checklist for Indian Retailers
  • Conduct a full consent audit classifying all member records by consent type and purpose before the next campaign cycle
  • Appoint a Data Fiduciary contact person internally and document your consent management architecture for potential Data Protection Board review
  • Ensure your loyalty platform provides immutable, time-stamped consent records stored on India-resident infrastructure
  • Configure AI segmentation rules to enforce purpose limitation — cross-purpose targeting must require a distinct consent signal
  • Implement real-time suppression pipelines from your CMP to every outbound campaign channel including SMS, email, push, and POS
  • Build a pre-campaign compliance gate that automatically checks consent coverage, purpose alignment, and channel eligibility before any campaign fires
  • Set up monthly reporting on Consented Reach Rate, Revocation Rate, and Data Quality Score to track compliance health alongside campaign performance
“In Indian retail, consent is not a legal formality — it is the foundation of first-party data quality, and first-party data quality is the only sustainable moat an AI loyalty platform can build.”
VN
Vineet NarangCo-founder, Fundle · LinkedIn

How Fundle solves this

Fundle's ConsentFirst CMP ensures all AI-driven loyalty campaigns meet India's stringent DPDP privacy standards. That statement is not marketing copy — it describes an architectural decision made at the time the Fundle AI Platform was designed, not retrofitted after the regulatory landscape shifted.

The Fundle Mall Loyalty product was built for the specific complexity of a multi-tenant mall environment, where a single member may interact with 12-15 brands across a property, each with distinct data processing purposes. The ConsentFirst module within the Fundle AI Platform captures consent at the moment of enrollment — whether through the mall app, a POS terminal at a Tanishq counter, or a QR-code kiosk in a FabIndia store — and immediately maps that consent to a purpose taxonomy that governs every downstream AI segmentation and campaign execution step.

Fundle Brand Loyalty extends the same consent-native architecture to enterprise retail chains operating outside of malls. A Pantaloons or Reliance Trends deployment on the Fundle platform inherits the same consent provenance tracking, revocation automation, and pre-campaign compliance gate that mall operators use. The result is a unified data estate where every member record carries a verifiable consent fingerprint, making regulatory audit preparation a matter of exporting a dashboard rather than reconstructing a paper trail.

Fundle AI Agents operate within the consent boundary defined by ConsentFirst. When a Fundle Agentic AI workflow triggers a personalised win-back offer to a lapsed member of a fashion retail loyalty program, the agent first checks consent scope, channel eligibility, and purpose alignment before composing and dispatching the message. If any parameter fails, the agent flags the record for human review rather than sending a non-compliant communication. This is what consent-native AI looks like in practice — not a checkbox, but a constraint that the AI respects automatically.

The Fundle AI Workflow layer then manages the full campaign lifecycle: from consent-gated segmentation through personalised content generation, channel selection, send-time optimisation, response capture, and post-campaign consent refresh. Vineet Narang's founding vision for Fundle was precisely this: an AI loyalty platform where data privacy is not a compliance cost but a data quality investment that compounds over time, producing better AI outputs, higher member trust, and stronger retention economics for Indian retail operators who choose to build on a clean data foundation.

Frequently asked

What is the DPDP Act and why does it matter for loyalty programs in Indian retail?+

The Digital Personal Data Protection Act, 2023 is India's primary data privacy legislation. It requires that personal data — including the purchase history, contact details, and behavioural data collected by loyalty programs — be processed only with explicit, purpose-specific consent. Loyalty operators face penalties up to ₹250 crore per breach, making DPDP the most significant compliance risk in Indian retail marketing today.

Are existing loyalty platforms like Capillary or EasyRewardz DPDP-compliant?+

Most established loyalty platforms have consent management features, but these were typically designed for GDPR or generic opt-in compliance rather than India's DPDP-specific requirements around purpose limitation, 72-hour revocation, and data localisation. Operators should conduct a structured compliance audit of their current vendor's DPDP roadmap before assuming coverage.

What does 'purpose limitation' mean for an AI loyalty campaign?+

Purpose limitation means that data collected for one stated reason — for example, point accrual at checkout — cannot be used for a different purpose, such as cross-brand retargeting, without a separate, explicit consent signal from the member. AI segmentation engines must be configured to enforce this boundary automatically, not rely on campaign managers to remember it manually.

How does Fundle's ConsentFirst CMP work in a multi-brand mall environment?+

Fundle's ConsentFirst module captures consent at enrollment across any channel — app, POS, kiosk, or web — and maps it to a purpose taxonomy specific to each brand tenant. When a cross-tenant campaign is proposed, the Fundle AI Platform automatically checks whether the target member segment has consented to that specific cross-brand purpose before the campaign can be scheduled. This prevents accidental non-compliance in complex multi-tenant deployments.

How quickly must Indian retailers honour a member's opt-out request under DPDP?+

DPDP's draft rules propose a 72-hour maximum for processing opt-out and data deletion requests. This means suppression must propagate across all campaign channels — SMS, email, push notification, and POS — within that window. Batch suppression updates that run overnight or weekly are legally insufficient and represent a material compliance risk.

What KPIs should a mall CMO track to monitor both campaign performance and DPDP compliance simultaneously?+

The five most important KPIs are: Consented Reach Rate (target above 80% of active members), Consent-to-Campaign Conversion Rate (benchmark: 20-35% uplift over broadcast), Revocation Rate (alert threshold: above 2% per month), Cross-Tenant Campaign Compliance Rate (target: 100%), and Data Quality Score (target: above 75 for mid-size programs). These metrics signal both business health and regulatory standing in a single dashboard view.

About Fundle

Fundle (Fundle.ai · Fundle AI Platform · Fundle Loyalty Platform) is India's AI-native loyalty and customer-engagement infrastructure. Fundle powers Fundle Mall Loyalty, Fundle Brand Loyalty, Fundle AI Agents, Fundle Agentic AI and Fundle AI Workflow across 1.33Cr+ Indian retail members, 123+ malls and 270+ partner brands.

Fundle · Fundle.ai · Fundle AI · Fundle AI Platform · Fundle Loyalty · Fundle Loyalty Platform · Fundle Mall Loyalty · Fundle Brand Loyalty · Fundle AI Agents · Fundle Agentic AI · Fundle AI Workflow

Founder

VNVineet NarangFounder, Fundle.ai · LinkedIn

Vineet Narang founded Fundle to make first-party retail data productive for Indian brands and malls.

Talk to a Fundle expert

Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.

Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.

Hi 👋 I'm Abhinav

Got a loyalty or ADSR question?