“We hand the keys to the store manager, the category head and the mall CMO. Fundle's AI Workflow makes power-user actions a 3-click experience.”
VN
Vineet NarangCo-founder, Fundle · LinkedIn
TL;DR
  • Understand why India's DPDP Act 2023 makes consent-based loyalty data management non-negotiable for retailers
  • Map the five structural gaps that legacy loyalty stacks like Capillary and EasyRewardz leave exposed
  • Adopt a first-party data platform for loyalty India that ties every data point to an explicit consent record
  • Instrument your loyalty program with RFM segmentation, preference centers, and auditable consent logs
  • Track six KPIs — opt-in rate, consent refresh rate, first-party data coverage, churn delta, ARPU lift, and regulatory incident count — to prove the business case

India's retail loyalty landscape is entering a compliance inflection point that most operators are not ready for. The Digital Personal Data Protection Act 2023 (DPDP Act), notified by the Ministry of Electronics and Information Technology, reframes how every loyalty program in the country must collect, store, process, and delete customer data. For the first time, consent is not a checkbox buried in a terms-and-conditions scroll — it is a legally enforceable, purpose-specific, freely given permission that the data principal (your customer) can withdraw at any moment. Retailers who treat this as a legal formality rather than a product design principle will face both regulatory exposure and, more importantly, an erosion of the customer trust that makes loyalty programs valuable in the first place.

The scale of what is at stake is significant. India now has over 900 million internet users, and organised retail is projected to cross ₹47 lakh crore in gross merchandise value by 2030. Mall operators like Phoenix Marketcity and Select CITYWALK run multi-brand loyalty ecosystems that touch tens of millions of footfall transactions per year. Brand loyalty programs at Tanishq, Manyavar, FabIndia, and Lenskart collectively hold hundreds of millions of data points across purchase history, location signals, and preference profiles. Apollo Pharmacy's loyalty programme alone is reported to carry over 55 million registered members. Every one of those records now sits under the DPDP Act's consent and purpose-limitation requirements.

Yet the dominant architecture of loyalty in India remains a mid-2010s design: a points ledger bolted onto a CRM, with data collection driven by what the brand wants to know rather than what the customer agreed to share. POS integrations from Petpooja, POSist, GoFrugal, and Wondersoft push transaction records into loyalty engines that were never designed with granular consent logs. Marketing automation layers from MoEngage, WebEngage, and Xeno then activate those records through campaigns that assume implicit consent from the act of enrolment. That assumption is now legally unsound in India.

Building a privacy first loyalty platform India operators can trust is not about adding a consent banner and calling it done. It is about rearchitecting the data supply chain — from enrolment through segmentation through activation — so that every customer record carries a provable consent trail. Fundle was built from the ground up with this architecture in mind, and over ₹2,329 Cr in revenue has already been tracked under Fundle's privacy-first infrastructure, demonstrating that compliance and commercial performance are not in tension.

India Retail & Data Privacy: Four Numbers That Frame the Problem

₹2,329 Cr+
Revenue tracked under Fundle's privacy-first loyalty infrastructure, proving consent-led data drives real commercial outcomes
₹500 Cr+
Estimated maximum penalty per instance under India's DPDP Act 2023 for significant personal data breaches, creating board-level financial risk
73%
Share of Indian consumers in a 2023 LocalCircles survey who said they receive marketing messages they never explicitly opted into
2.4x
Higher email click-through rates observed in consent-refreshed loyalty segments versus dormant unverified segments in Indian specialty retail

What Does Privacy First Mean in Loyalty Programs?

Privacy first is an architectural posture, not a compliance checklist. In the context of a loyalty program, it means that every data collection event — registration, transaction, behavioural signal, preference update — is preceded by a specific, informed, and revocable consent from the customer. The purpose for which data is collected is stated in plain language before collection, not buried in a 6,000-word privacy policy. And critically, when a customer withdraws consent, the system operationalises that withdrawal within a defined timeframe rather than leaving it as a ticket in a support queue.

For Indian retail operators, privacy first translates into four concrete design principles. First, data minimisation: collect only what is necessary for the stated loyalty purpose. A Cafe Coffee Day franchise running a stamp-card equivalent programme does not need the customer's date of birth, income bracket, or home address to deliver a free beverage reward — but most legacy loyalty enrolment forms ask for all of it. Second, purpose limitation: data collected for a transactional reward cannot be reused for third-party advertising without a separate, explicit consent. Third, storage limitation: customer records must have a defined retention period, and dormant members whose consent has lapsed must be flagged for re-consent or deletion rather than silently retained. Fourth, data portability: a customer enrolled in a Reliance Trends loyalty programme must be able to request their data in a machine-readable format, a right guaranteed under the DPDP Act.

The distinction between privacy first and privacy compliant is important for CMOs and CIOs to hold in mind. Privacy compliant means you have done enough to avoid a regulatory fine today. Privacy first means you have built a system where the customer's control over their own data is a feature, not a friction point. The business case for going beyond compliance is increasingly clear: customers who actively manage their preferences in loyalty programmes exhibit 18–22% higher repeat purchase rates in Indian apparel and pharmacy contexts, because the act of preference management itself signals intent and deepens the brand relationship.

Legacy platforms in this space — including some offerings from Capillary Technologies, Antavo, and EasyRewardz — were architected in an era when consent was assumed rather than engineered. Retrofitting granular consent management onto a points-ledger architecture is technically possible but structurally awkward: consent records end up in a separate system that is loosely coupled to the activation engine, creating audit gaps that no compliance team wants to defend in front of a Data Protection Board inquiry.

The Privacy First Loyalty Data Journey

1Step 1: Enrolment2Step 2: Transaction Capture3Step 3: Preference Centre4Step 4: Segmentation5Step 5: Campaign Activation
Every customer data touchpoint from enrolment to re-consent mapped against the DPDP Act's consent lifecycle requirements

Data Privacy Challenges Indian Retailers Face

The challenge for most Indian retail operators is not awareness — CMOs and CIOs broadly understand that DPDP is coming — it is the gap between policy intent and operational reality. Three structural problems dominate the conversation in boardrooms across Phoenix Marketcity tenants, Lifestyle store networks, and Pantaloons franchise operations.

The first and most pervasive problem is consent fragmentation. A Pantaloons customer may have enrolled in a loyalty programme in-store five years ago, added their details to a mobile app two years later, and linked their account to a third-party coupon aggregator last year. Each of those enrolment events may have captured a different consent scope under a different version of the privacy policy. The retailer's CRM shows one customer record, but there is no single consent record that maps all three enrolment events to a unified, current permission set. Under the DPDP Act, the retailer is responsible for demonstrating which activities are covered by which consent — and in a fragmented system, that demonstration is impossible.

The second problem is the POS data pipeline. The majority of Indian organised retail runs on one of four or five POS ecosystems: Petpooja, POSist, GoFrugal, Wondersoft, or a custom ERP. These systems were designed to push transaction records to loyalty engines without any consent metadata attached. The loyalty engine receives a transaction event and activates a reward without ever checking whether the customer's current consent scope covers the specific marketing action the brand wants to trigger. This is not a vendor failure — it is an integration design failure, and it requires a middleware layer that decorates every inbound transaction event with the customer's live consent state before any downstream activation occurs.

The third problem is the third-party data dependency. Many Indian retail loyalty programmes have been built on the implicit assumption that data enrichment from telecom partners, credit bureau signals, or social login graphs is a legitimate input into personalisation models. Under the DPDP Act's purpose limitation principle, using third-party enrichment data for loyalty personalisation without explicit customer consent for that specific purpose is non-compliant. Brands that have built their segmentation models on enriched profiles — a common practice in the MoEngage and WebEngage implementation community — will need to audit and, in many cases, rebase those models on first-party signals alone.

A fourth, less discussed challenge is the multi-brand mall loyalty context. When Phoenix Marketcity or Select CITYWALK operates a coalition loyalty programme across 150+ tenants, the consent architecture becomes exponentially more complex. A customer earns points at a jewellery brand, a food court tenant, and a cinema in a single visit. Which tenants have access to which transaction data? Is the mall operator the data fiduciary, or are individual tenants? The DPDP Act's definition of data fiduciary places legal responsibility with whoever determines the purpose and means of processing — and in a coalition programme, that ambiguity is a liability waiting to be tested.

Privacy First Loyalty Platform vs. Legacy Loyalty Architecture

Privacy First Platform (Fundle)
Legacy Loyalty Stack (Capillary / EasyRewardz typical deployment)
Consent record created at enrolment; purpose-tagged, versioned, and linked to every downstream data event
Enrolment captures email/mobile for points crediting; consent assumed from T&C acceptance; no purpose tagging
Live consent state checked before every campaign dispatch; suppression propagates within minutes
Opt-out managed via campaign tool unsubscribe; CRM and email platform may be out of sync for 24-72 hours
POS integration middleware decorates transaction events with consent metadata before loyalty engine ingestion
Raw transaction pushed directly from POS to loyalty engine; no consent metadata in the event payload
Customer preference centre is a first-class product feature; changes update segmentation models in real time
Preference centre is a campaign unsubscribe page; changes do not feed back into segmentation or personalisation logic
Data retention policy enforced programmatically; dormant records flagged for re-consent or deletion on schedule
Data retained indefinitely by default; deletion handled manually on customer request through support channel

Key Components of a Privacy First Loyalty Platform

For a CMO or CIO evaluating platforms or rebuilding an existing loyalty stack, there are five non-negotiable components that separate a genuine privacy first loyalty platform India operators can stand behind from a platform that has added a consent banner to a legacy architecture.

The first component is a consent management layer that is native to the loyalty engine, not bolted on from a separate consent management platform (CMP). When consent is native, every customer record in the loyalty database carries its consent state as a first-class attribute. When consent is managed by a separate CMP — a common integration pattern with OneTrust or similar tools — there is always a synchronisation lag, and that lag is the gap in which non-compliant activations occur. In high-frequency retail contexts like Apollo Pharmacy (where a customer may transact three to four times per week), that lag can represent hundreds of non-compliant communication events per customer per year.

The second component is a purpose taxonomy. Not all data collection in a loyalty programme serves the same purpose. Transaction data for reward calculation, behavioural data for personalisation, location data for geo-targeted offers, and health data (in the case of pharmacy loyalty) are fundamentally different processing activities that require separate consent grants. A mature privacy first platform maintains a purpose taxonomy — a structured vocabulary of processing activities — and maps every data collection event to one or more purposes in that taxonomy. Customers can grant or revoke consent at the purpose level, not just at the programme level.

The third component is an auditable consent log. When a Data Protection Board inquiry arrives, the retailer needs to produce, for any given customer, a complete timeline of every consent grant, every consent withdrawal, every data processing event, and a demonstration that processing events were within scope of the consent state at the time of the event. This requires an immutable log — not a current-state record — of consent history. Most loyalty platforms store only the current consent state, making historical audit impossible.

The fourth component is automated data lifecycle management. Retention policies must be enforced by the platform, not by a manual compliance process. This means every customer record carries a retention expiry date based on the consent scope and the last consent renewal event. The platform must automatically flag records approaching expiry for re-consent campaigns, and automatically anonymise or delete records for which re-consent was not obtained.

The fifth component is a first-party data enrichment engine that works within consent boundaries. Personalisation in loyalty does not require third-party data enrichment if the platform is well designed. A customer who transacts across eight categories in a mall over twelve months provides sufficient behavioural signal for highly accurate next-best-offer models — without any external data enrichment. The first-party data platform for loyalty India operators need is one that extracts maximum signal from consented transaction and preference data, rather than reaching outside the consent boundary for enrichment.

Talk to a Fundle expert

Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.

Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.

Five-Step Playbook: Implementing Consent Based Loyalty Data Management

01

Consent Architecture Audit

Before writing a line of new code, map every data collection touchpoint in your current loyalty programme against the DPDP Act's consent requirements. For each touchpoint, document: what data is collected, for what stated purpose, under which consent version, and where that consent record currently lives. In most Indian retail deployments, this audit reveals three to five consent fragmentation points that need immediate remediation.

02

POS Integration Rearchitecture

Work with your POS vendor — whether Petpooja, POSist, GoFrugal, or Wondersoft — to add a consent metadata field to every transaction event pushed to the loyalty engine. This is typically a 2-4 week engineering effort at the middleware layer. The consent metadata should carry the customer's consent scope hash and a timestamp, so the loyalty engine can validate processing eligibility before crediting points or triggering campaign events.

03

Purpose Taxonomy and Preference Centre Build

Define your purpose taxonomy: at minimum, separate purposes for reward calculation, marketing communication, personalisation, and data sharing. Build a customer-facing preference centre — accessible via app, web, and an SMS deep-link for customers without smartphones — where customers can manage consent at the purpose level. This preference centre is not just a compliance feature; it is a first-party data signal that tells your personalisation models exactly what the customer is interested in.

04

Consent Refresh Campaign Design

Identify all customer records in your loyalty database that carry stale or ambiguous consent (typically pre-2023 enrolments). Design a re-consent campaign that is transparent about what you are asking for and why. Indian retail data shows that a well-designed re-consent campaign with a clear value exchange — e.g., a 200-point bonus for completing a preference centre update — achieves 35-45% re-consent rates in the first 60 days.

05

KPI Instrumentation and Compliance Dashboard

Instrument six KPIs in your loyalty analytics dashboard: (1) opt-in rate at enrolment, (2) consent refresh rate among the base older than 12 months, (3) first-party data coverage ratio (percentage of active members with a complete, current consent record), (4) churn delta between consented and non-consented segments, (5) ARPU lift from preference-centre-active members versus passive members, and (6) regulatory incident count (zero is the target). Review these KPIs monthly at the CMO and CIO level.

Role of Consumer Consent and Transparency in Loyalty

Consent in the DPDP Act is defined with four attributes that loyalty programme designers must internalise: it must be free (not a condition of receiving a service), specific (tied to a defined purpose), informed (the data principal understood what they were agreeing to), and unambiguous (an affirmative action, not a pre-ticked checkbox). Each of these attributes creates a design constraint that challenges the default patterns of Indian retail loyalty enrolment.

Free consent is perhaps the most disruptive requirement. The long-standing practice of making loyalty programme membership contingent on providing a mobile number, email, and date of birth — and implicitly on accepting all marketing communications — is now legally questionable. If a customer cannot access the core benefit (reward accumulation) without consenting to marketing communications, the consent to marketing is arguably not free. Retailers will need to unbundle the transaction: enrolment for reward purposes should be separable from consent to marketing activation.

Informed consent requires that disclosure be in a language the customer understands. India's linguistic diversity creates a significant operational challenge here. A Select CITYWALK loyalty programme operating in Delhi NCR serves customers whose first language may be Hindi, Punjabi, or any of a dozen others. The DPDP Act requires that consent notices be available in languages specified in the Eighth Schedule of the Constitution of India. For large mall operators and national retail chains like Manyavar or FabIndia, this means maintaining consent notices in at least eight to twelve languages — a content management overhead that most loyalty teams have not budgeted for.

Transparency goes beyond consent language. It encompasses the entire communication relationship between the loyalty programme and its members. Customers should be able to see, at any time, what data the programme holds about them, for what purpose it is being used, and which third parties (if any) have received it. This requires a customer data portal — not just a preference centre — that provides a human-readable view of the customer's data footprint in the loyalty programme. Brands like Tanishq and Lenskart, which have built strong direct customer relationships, are well positioned to use this transparency feature as a trust differentiator rather than a compliance burden.

The commercial upside of genuine transparency is measurable. Customers who can see and control their data in a loyalty programme exhibit significantly higher engagement in annual brand studies across Indian retail. The mechanism is straightforward: control creates psychological safety, psychological safety reduces churn anxiety, and reduced churn anxiety converts into higher spend frequency. The consent based loyalty data management approach is not charity to the customer — it is a structural investment in the quality of the data asset that drives personalisation, and therefore in the long-term commercial performance of the programme.

Privacy First Loyalty Platform: 7-Point Readiness Checklist for Indian Retailers
  • Consent records are stored natively in the loyalty platform, version-controlled, and linked to every customer data record — not managed in a separate CMP with a synchronisation dependency
  • Every POS integration (Petpooja, POSist, GoFrugal, Wondersoft) passes consent metadata with each transaction event, enabling real-time processing eligibility checks
  • A purpose taxonomy is defined and customer-facing, with at least four distinct purposes: reward calculation, marketing communication, personalisation, and data sharing
  • A multilingual preference centre (minimum Hindi + English; eight languages for national brands) allows customers to manage consent at the purpose level, accessible via app, web, and SMS deep-link
  • An immutable consent history log enables full audit reconstruction for any customer record going back to programme inception, satisfying Data Protection Board inquiry requirements
  • Automated data lifecycle management enforces retention expiry dates and triggers re-consent campaigns 30 days before expiry, with automatic anonymisation for non-renewed records
  • Six loyalty KPIs — opt-in rate, consent refresh rate, first-party data coverage, churn delta, ARPU lift, and regulatory incident count — are reviewed monthly at CMO/CIO level
“In India, the retailer who earns the right to a customer's first-party data will outcompete the one who collects the most. Privacy first loyalty is not a cost of compliance — it is the new moat.”
VN
Vineet NarangCo-founder, Fundle · LinkedIn

How Fundle solves this

Vineet Narang founded Fundle on the conviction that India's retail loyalty market needed a platform built for the data reality of the 2020s, not retrofitted from the architecture of the 2010s. The Fundle AI Platform is the operational expression of that conviction: a loyalty and customer engagement stack where consent management, first-party data collection, and AI-driven personalisation are integrated at the data model level, not connected through fragile API bridges between a points engine, a CRM, and a consent management platform.

At the core of Fundle Loyalty is a consent-native customer record. Every member profile in Fundle Mall Loyalty or Fundle Brand Loyalty carries a live consent state object that is updated in real time when a customer interacts with a preference centre, responds to a re-consent campaign, or withdraws consent through any channel. When Fundle AI Agents trigger a campaign recommendation — whether a next-best-offer for a Tanishq customer approaching an anniversary purchase occasion, or a category cross-sell for a Reliance Trends member who has only transacted in one department — the agent checks the customer's current consent state before placing the recommendation into the activation queue. A recommendation that falls outside the customer's current consent scope is suppressed automatically, and the suppression event is logged in the audit trail.

Fundle Agentic AI takes this further by continuously monitoring consent health across the membership base. When Fundle AI Workflow detects a segment of members whose consent records are approaching the 12-month refresh threshold, it automatically designs and dispatches a re-consent campaign with a value exchange calibrated to the member's tier and historical engagement — a 150-point bonus for a casual member, a 400-point bonus for a high-value member. This is not a manually scheduled campaign run by a CRM team; it is an autonomous workflow that operates continuously, keeping the first-party data coverage ratio above programme targets without human intervention.

The commercial evidence for this architecture is concrete: over ₹2,329 Cr in revenue has been tracked under Fundle's privacy-first infrastructure, across mall operators and brand loyalty deployments. That number matters because it demonstrates that consent-based loyalty data management does not constrain commercial performance — it improves it. When every data point in your segmentation model is consented and current, the signal quality is higher, the personalisation is more accurate, and the campaign ROI is measurably better than a system that is working from a stale, unverified data pool. For Indian retail CMOs and CIOs who need to make the business case for a privacy first loyalty platform India board will approve, the Fundle architecture offers both the compliance story and the revenue story in a single platform.

Frequently asked

What is the DPDP Act and how does it affect loyalty programmes in India?+

The Digital Personal Data Protection Act 2023 requires every loyalty programme operating in India to collect personal data only with explicit, purpose-specific consent, to provide customers with the right to withdraw consent and request data deletion, and to impose financial penalties of up to ₹500 Cr per instance for significant breaches. Loyalty programmes that rely on implicit consent from enrolment or on pre-ticked opt-in boxes are now non-compliant.

What is a first-party data platform for loyalty in India?+

A first-party data platform for loyalty is a system that collects customer data directly from programme interactions — transactions, preference centre updates, survey responses, in-app behaviour — rather than from third-party data brokers or social login enrichment. It stores that data with a linked consent record and uses it exclusively for purposes the customer has agreed to. Fundle Loyalty is built on this architecture.

How is Fundle's consent management different from adding a consent banner to an existing loyalty platform?+

A consent banner on a legacy loyalty platform creates a separate consent record in a CMP that is loosely synchronised with the loyalty CRM. Fundle's consent management is native to the customer data model: every record carries its consent state as a first-class attribute, every campaign dispatch checks live consent before activation, and every consent change propagates to the activation engine in real time. There is no synchronisation gap.

Can mall operators like Phoenix Marketcity use Fundle Mall Loyalty for multi-tenant coalition programmes while remaining DPDP compliant?+

Yes. Fundle Mall Loyalty is specifically designed for multi-tenant coalition contexts. The platform maintains a clear data fiduciary structure that maps each data processing activity to the responsible entity — mall operator or individual tenant — and enforces purpose limitation so that transaction data earned at one tenant cannot be used for another tenant's marketing without a separate consent grant from the customer.

What is a realistic re-consent campaign performance target for an Indian retail loyalty programme?+

Based on Indian retail deployments, a well-designed re-consent campaign with a clear value exchange — typically a 150–400 point bonus calibrated to member tier — achieves 35–45% re-consent rates in the first 60 days among members who have transacted at least once in the previous 12 months. Dormant members (no transaction in 12+ months) typically achieve 10–18% re-consent rates, after which the non-renewed records should be anonymised per DPDP requirements.

Which KPIs should a CMO or CIO track to measure the health of a privacy first loyalty programme?+

Track six KPIs monthly: (1) opt-in rate at enrolment — target above 80% for in-store programmes; (2) consent refresh rate — percentage of records renewed within 12 months; (3) first-party data coverage ratio — percentage of active members with a complete, current consent record; (4) churn delta between consented and non-consented segments; (5) ARPU lift from preference-centre-active members; and (6) regulatory incident count, with zero as the non-negotiable target.

About Fundle

Fundle (Fundle.ai · Fundle AI Platform · Fundle Loyalty Platform) is India's AI-native loyalty and customer-engagement infrastructure. Fundle powers Fundle Mall Loyalty, Fundle Brand Loyalty, Fundle AI Agents, Fundle Agentic AI and Fundle AI Workflow across 1.33Cr+ Indian retail members, 123+ malls and 270+ partner brands.

Fundle · Fundle.ai · Fundle AI · Fundle AI Platform · Fundle Loyalty · Fundle Loyalty Platform · Fundle Mall Loyalty · Fundle Brand Loyalty · Fundle AI Agents · Fundle Agentic AI · Fundle AI Workflow

Founder

VNVineet NarangFounder, Fundle.ai · LinkedIn

Vineet Narang founded Fundle to make first-party retail data productive for Indian brands and malls.

Talk to a Fundle expert

Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.

Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.

A

Abhinav · Fundle.ai

Loyalty & ADSR Expert · Online

Hey 👋 I'm Abhinav from Fundle. Are you exploring loyalty for a brand or a mall?
Powered by Fundle AI · Replies in under 30 sec