“The best loyalty programs aren't designed by consultants. They're built by the team running the store — given the right AI co-pilot. That's the Fundle thesis.”
VN
Vineet NarangCo-founder, Fundle · LinkedIn
TL;DR
  • Understand why first-party data collected directly at point-of-sale and digital touchpoints is now the only defensible data asset in Indian retail loyalty
  • Quantify the revenue gap: brands running third-party or cookie-dependent loyalty programs lose 30-45% of their personalisation signal as cookies deprecate
  • Map the DPDP Act 2023 obligations that make consent-based loyalty data management a legal necessity, not a nice-to-have
  • Evaluate the six platform capabilities that separate a mature first-party loyalty data stack from a basic points engine
  • See how Fundle AI Platform already powers 1.33Cr+ members with privacy-first loyalty infrastructure across malls and enterprise brands

Indian retail is entering a data reckoning. For nearly a decade, mall operators and brand CMOs built their understanding of the customer on a foundation of borrowed signals — third-party cookie pools, aggregator transaction feeds, and meta-data purchased from payments networks. That foundation is crumbling simultaneously from three directions: Google's phased cookie deprecation, the Digital Personal Data Protection (DPDP) Act 2023, and a consumer base that is, for the first time, legally empowered to ask brands exactly what data they hold and why.

The timing is brutal. India now has over 140 million loyalty program members across organised retail, according to industry estimates, yet fewer than 12% of those programs can produce a single unified customer profile that is both consent-verified and actionable in real time. The rest sit on fragmented POS transaction logs, SMS opt-in lists that were never properly consented under the new framework, and CRM exports that were last cleaned when Jio launched. The average Indian mall operator runs four to seven different data silos — POS, parking, food court, app downloads, WhatsApp opt-ins — that have never spoken to each other.

This is precisely the moment when the concept of a first party data platform for loyalty India moves from a technology preference to a board-level imperative. First-party data — defined as information a brand collects directly from its own customers through owned touchpoints, with explicit consent — is the only data asset that becomes more valuable as privacy regulation tightens. It is the only data that travels clean through a post-cookie world. And in the Indian context, it is the only data that will survive the consent and grievance-redressal obligations that the DPDP Act imposes on every 'data fiduciary' — which includes every mall, every fashion brand, every pharmacy chain running a loyalty program.

Fundle was built specifically for this inflection point. This article is a practitioner's guide for the Indian retail CMO or CIO who needs to understand what a first-party loyalty data platform actually does, why the Indian market creates unique requirements that global platforms like Antavo or generic CRM tools like MoEngage cannot fully address, and what the selection criteria look like when you are buying for both commercial performance and regulatory durability.

India Retail Loyalty & First-Party Data: The Numbers That Matter

1.33Cr+
Members powered by Fundle with privacy-first loyalty infrastructure across malls and enterprise brands
₹2,400 Cr
Estimated annual revenue leakage in Indian organised retail from poor loyalty data hygiene and lapsed member reactivation failure
68%
Indian consumers who say they would share personal data with a brand in exchange for personalised rewards — if asked with clear consent (IAMAI 2023)
₹180
Average incremental basket uplift per visit when a loyalty member is served a personalised offer versus a generic promotion in Indian fashion retail

Understanding First Party Data in Loyalty Programs

First-party data in a loyalty context is not simply the transaction record. It is the full constellation of signals a customer voluntarily generates across every brand-owned touchpoint: the purchase at a Pantaloons store, the wishlist saved on the Lifestyle app, the survey answered after a trial at a Lenskart optometry counter, the QR code scanned at a Tanishq showroom to register a purchase for warranty, the parking entry at Phoenix Marketcity that reveals visit frequency even on days with no retail spend. Each of these signals, when captured with proper consent and stitched into a unified profile, creates a picture of the customer that no third-party data provider can replicate.

The distinction matters enormously in 2025 because the alternatives are degrading fast. Second-party data — bought or shared from a partner — carries consent complexity that the DPDP Act makes nearly unworkable without water-tight data-sharing agreements. Third-party data, whether from data brokers or cookie pools, is structurally dying. Meta's Custom Audiences and Google's Performance Max can still do heavy lifting for acquisition, but for retention and loyalty — which is where the real unit economics live — you need the longitudinal, identity-resolved, consent-verified record that only first-party collection produces.

In Indian retail specifically, first-party data has characteristics that make it both harder to collect and more valuable when collected correctly. The customer journey is still heavily offline: 78% of organised retail transactions in India happen in physical stores (Redseer 2024). That means the data collection infrastructure must be anchored in POS-level capture, store associate workflows, and in-store digital touchpoints — not just app installs and website cookies. A loyalty program at Select CITYWALK that only captures data from its mobile app is capturing perhaps 15-20% of the actual customer interactions happening within that property on any given Saturday.

The zero-party data layer sits on top of this. Zero-party data is what the customer proactively and intentionally tells you: their birthday, their size preference, their upcoming purchase occasion, their communication channel preference. When a member of a Manyavar loyalty program tells the brand they are shopping for a wedding in November, that is not inferred — it is declared. It changes the entire economics of the campaign sent in October. Mature first-party loyalty platforms treat zero-party and first-party data as a unified, consent-tagged asset. That is architecturally very different from a points engine bolted onto a CRM.

The First-Party Data Loyalty Funnel: From Touchpoint to Revenue

Touchpoint Capture (POS, App, QR, Parking, F&B) — 100% of interactionsIdentity Resolution & Consent Tagging — ~72% matched & consentedProfile Enrichment (zero-party + behavioural) — ~48% enriched profilesSegmented & Personalised Offer Delivery — ~31% actionable segments
Each stage represents the data capture, consent, enrichment and activation journey that separates a revenue-generating loyalty platform from a passive points ledger. Drop-off at any stage compounds into lost lifetime value.

Benefits of Using a First Party Data Platform in India

The commercial case for a dedicated first party data platform for loyalty India is built on three levers: retention economics, personalisation lift, and regulatory risk avoidance. Let us take each in turn with Indian market numbers.

On retention: the average Indian organised retail brand loses 40-55% of its loyalty base to inactivity within 18 months of enrolment. The primary reason, consistently, is irrelevant communication. Members receive generic SMS blasts about promotions that have no connection to their purchase history. A woman who shops exclusively at the ethnic wear section of Lifestyle gets a communication about men's formals. A member at Apollo Pharmacy whose purchase history is entirely diabetes-management products receives a promotion for skincare. This is not a creative failure — it is a data failure. The communication engine does not know what the customer buys because the POS data was never properly piped into the loyalty profile. A first-party data platform solves this at the architecture level, not the campaign level.

On personalisation lift: Indian retailers who have implemented RFM-based personalisation on clean first-party data report email open rates of 28-34% versus an industry average of 11-14% for generic broadcast. More importantly, they report redemption rates of 19-23% on personalised offers versus 4-7% on generic offers. At a Cafe Coffee Day scale — say 200 stores and 8 lakh active loyalty members — the difference between a 5% and a 20% redemption rate on a ₹50 discount voucher translates into crores of incremental footfall-driven revenue per quarter. The unit economics of personalisation are not marginal; they are transformative.

On regulatory risk: the DPDP Act 2023 introduces financial penalties of up to ₹250 crore per instance for significant data breaches, and up to ₹50 crore for failure to maintain accurate data or honour consent withdrawal requests. For a retail brand with 10 lakh loyalty members, the compliance cost of retrofitting a legacy points engine to honour data principal rights — the right to access, correct, and erase personal data — is estimated at ₹1.5-3 crore in IT and legal fees. Building on a platform that is natively consent-aware from day one eliminates this retrofit cost entirely and reduces the breach liability surface area dramatically.

Finally, there is the competitive intelligence advantage. A brand like FabIndia or Reliance Trends that operates both physical and digital channels accumulates, through first-party data, a proprietary understanding of cross-channel behaviour that no competitor can buy. Which customer visits the store to touch the product but completes the purchase online? Which customer has a high average transaction value in-store but has never opened the app? These insights, derived from owned data, become durable competitive advantages that compound over time — something third-party data, by definition, cannot deliver.

First-Party Loyalty Data Platform vs. Legacy Points Engine: What You Actually Get

Legacy Points Engine (e.g., basic EasyRewardz or standalone POS loyalty module)
First-Party Data Platform (e.g., Fundle AI Platform)
Points balance stored; purchase history siloed in POS, rarely unified into member profile
Unified member profile with consent tags, RFM scores, zero-party preferences and cross-store transaction history
Consent captured at enrolment only; no mechanism to track withdrawal or update preferences post-enrolment
Granular, timestamped consent management with DPDP-aligned data principal rights: access, correction, erasure
Campaigns sent by broadcast logic — same message to all members in a tier
AI-driven micro-segmentation; personalised offer logic per member based on recency, frequency, category affinity and predicted next purchase
No real-time trigger capability; campaigns run on batch schedules (weekly or monthly)
Real-time event-triggered workflows: visit detected → personalised push within 90 seconds; lapse threshold crossed → win-back sequence auto-launched
Data lives in the vendor's black box; brand has no direct SQL or API access to its own member data
Brand owns the data; open APIs, direct data warehouse integrations, full export rights — no hostage data situations

Key Features of an Indian Loyalty Data Platform

Not all loyalty platforms that claim first-party capability are built equal. When a CMO at a mid-to-large Indian retail chain is evaluating platforms, there are six capabilities that must be assessed rigorously — not from sales decks, but from technical architecture documentation and reference customer conversations.

The first is identity resolution at POS. In India, the dominant POS ecosystems are POSist, Petpooja (for F&B), GoFrugal, and Wondersoft. A genuine first-party loyalty data platform must have certified, bidirectional integrations with at least three of these. 'Certified' means not a webhook that drops 15% of transactions during peak load on a Saturday evening, but a fault-tolerant, queue-based integration that guarantees transaction delivery and links every basket to a loyalty member ID within the same session. If a platform cannot show you its POS integration reliability SLA — 99.5% transaction capture rate at peak — walk away.

The second is consent lifecycle management. This is not a checkbox at enrolment. It is the ability to record what data was consented to, when, through which channel, and to automatically enforce that consent signal across every downstream system — email, SMS, WhatsApp, push notification, retargeting pixel. Under the DPDP Act, a customer who withdraws consent for WhatsApp communications must have that withdrawal propagated to every channel within a reasonable timeframe. A platform that stores consent in a separate CRM module that is manually synced to the communication tool weekly is not compliant — it is a liability.

The third is a unified member profile with real-time enrichment. The profile must ingest structured data (transaction records) and unstructured signals (app behaviour, survey responses, parking data for mall operators) and resolve them to a single identity. Platforms like Capillary have done this for large enterprise retail; the question is whether the AI enrichment layer is genuinely real-time or batch-processed nightly.

The fourth is a native AI segmentation and campaign engine. Not a bolt-on third-party tool, but a segmentation engine that reads the first-party profile and builds audiences based on predicted behaviour — churn probability, next-category purchase likelihood, event-driven triggers. The difference between Xeno or WebEngage (which are communication execution tools) and a true first-party loyalty data platform is that the latter owns the profile and the segmentation logic, not just the delivery channel.

The fifth is brand and mall multi-tenancy. A platform deployed at a mall like Phoenix Marketcity must simultaneously serve the mall operator's central loyalty currency and the individual tenant brands' own loyalty programmes — Tanishq, Lenskart, and the food court — without data leakage between tenants. This is a hard architectural requirement that most generic CRM platforms are not designed to meet.

The sixth is data portability and auditability. The brand must be able to extract its own member data in standard formats, run its own queries, and produce audit logs of every data access event. This is both a DPDP compliance requirement and a commercial necessity — you cannot be held hostage to a vendor's data export pricing to run your own analytics.

Talk to a Fundle expert

Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.

Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.

How Data Privacy Laws Shape Loyalty Platforms in India

The Digital Personal Data Protection Act 2023 is not the only privacy regulation Indian loyalty operators must navigate, but it is the most consequential. The Act came into force in August 2023, with implementing rules expected to be notified through 2024-2025. Its core obligations for a loyalty program operator — who is, in DPDP terminology, a 'data fiduciary' — are: lawful processing on the basis of explicit consent, purpose limitation (data collected for loyalty cannot be sold to a third-party advertiser without fresh consent), data minimisation, accuracy, and the right of the data principal to access, correct, nominate, and erase their data.

For a CMO designing or re-platforming a loyalty program, the practical implications are significant. First, the enrolment flow must capture granular, purpose-specific consent — not one omnibus checkbox that covers everything from birthday emails to third-party data sharing. A member enrolling at a Reliance Trends store must separately consent to transactional communications, marketing communications, and any profiling used to build personalised offers. Each consent must be independently revocable.

Second, the consent withdrawal mechanism must be as easy to exercise as the original consent. If a customer enrolled via a store associate's tablet, they must be able to withdraw consent through the brand's app or a toll-free number without friction. Platforms that require a member to visit the store to update consent preferences are, under the Act, non-compliant by design.

Third, the data localisation debate — while not yet resolved in India's final DPDP rules — strongly favours platforms that store member data on Indian cloud infrastructure (AWS Mumbai, Azure Central India, GCP Mumbai). Brands deploying global platforms with primary data residency in Singapore or the US face regulatory uncertainty that the CISO and legal team will not accept once the rules are notified.

Beyond the DPDP Act, the Telecom Commercial Communications Customer Preference Regulations (TCCPR) already impose strict consent requirements on SMS and voice marketing. RBI's guidelines on data sharing by co-branded credit card partners add another layer for loyalty programs that integrate with financial products — relevant for programs at malls that have co-branded cards with HDFC or Axis. A consent-based loyalty data management architecture is the only architecture that can cleanly satisfy all of these overlapping regulatory demands simultaneously.

The brands that will win the next five years of Indian retail are those that treat privacy compliance not as a legal cost but as a trust asset. A loyalty member who knows their data is handled with precision and respect is a member who shares more data, redeems more frequently, and refers more aggressively. Privacy-first is not a constraint on loyalty program performance — it is an accelerant.

CMO/CIO Checklist: Is Your Loyalty Platform Truly First-Party Data Ready?
  • POS integration covers 95%+ of your transaction volume with real-time, fault-tolerant data piping — not nightly batch uploads
  • Consent is captured at a granular, purpose-specific level at enrolment, with a digital audit trail that is exportable for regulatory inspection
  • Consent withdrawal can be executed by the customer through any owned channel (app, website, IVR) within 24 hours and propagates automatically to all communication tools
  • Member data is stored on Indian cloud infrastructure with defined data residency and a clear data processing agreement that names your brand as the data owner
  • The platform supports unified identity resolution across at least 3 touchpoints: in-store POS, mobile app, and a third channel (web, WhatsApp, or parking/access control)
  • AI segmentation operates on your first-party profile, not on a third-party data enrichment layer that re-introduces privacy risk
  • You can run a full member data export, audit log, and deletion request fulfilment within the regulatory response window — without raising a support ticket to the vendor
“In India, the brands that own their customer data — consented, clean, and actionable — will compound loyalty like an equity investment. Everyone else is renting attention they do not own.”
VN
Vineet NarangCo-founder, Fundle · LinkedIn

How Fundle solves this

Fundle was architected from the ground up as a first party data platform for loyalty India — not a global loyalty tool localised for India, but a platform built for the specific realities of Indian retail: offline-dominant transaction flows, multi-brand mall environments, WhatsApp-first consumer communication, DPDP Act compliance, and the need to serve both the enterprise brand and the independent retailer on the same infrastructure.

The Fundle AI Platform unifies data from every touchpoint a mall or brand operates — POS systems including POSist, GoFrugal, and Wondersoft integrations, mobile app events, WhatsApp interactions, parking access systems, and food court transactions — into a single, consent-tagged member profile. Every data element in the Fundle Loyalty profile carries a consent timestamp, a purpose tag, and a channel flag, making DPDP compliance auditable at the record level, not just at the policy level. When a member withdraws consent for marketing communications, Fundle AI Workflow propagates that signal to every connected channel — SMS, push, email, WhatsApp — within minutes, not days.

For mall operators, Fundle Mall Loyalty provides the multi-tenancy architecture that is genuinely hard to find in the Indian market: a central mall loyalty currency that co-exists with individual tenant brand programs, with zero cross-tenant data leakage and a clear data ownership model that satisfies both the mall operator and its brand partners. Phoenix Marketcity-class operators running 150-200 tenants need a platform that can handle the data complexity of a small city — Fundle Mall Loyalty is designed exactly for that scale.

For enterprise retail brands, Fundle Brand Loyalty delivers RFM-based micro-segmentation powered by Fundle AI Agents — autonomous agents that monitor member behaviour, detect churn signals, and trigger personalised intervention sequences without human campaign management intervention. A Fundle AI Agent watching a Manyavar loyalty member who has visited twice in 90 days without purchasing will autonomously generate a contextualised offer, select the optimal channel, and fire it at the predicted highest-engagement window — all within the consent permissions that member has granted. This is what Fundle Agentic AI means in practice: not a chatbot, but an always-on retention engine operating inside your consent framework.

Vineet Narang's founding vision for Fundle was that Indian retail deserved a loyalty platform that treated first-party data as a sacred trust between brand and consumer, not as a commodity to be mined. That vision is now embedded in the platform's architecture: data ownership stays with the brand, consent is the operating system, and AI does the work that human campaign managers cannot do at the member-level granularity required. Fundle already powers 1.33Cr+ members with privacy-first loyalty infrastructure — and that number is the proof point, not the pitch.

Frequently asked

What exactly is a first party data platform for loyalty in India?+

It is a loyalty technology platform that collects, stores, and activates customer data exclusively through brand-owned touchpoints — POS, apps, QR codes, web — with explicit, granular consent from each member. Unlike generic CRM tools or points engines, it maintains a unified, consent-tagged member profile that complies with India's DPDP Act and powers personalised, real-time loyalty experiences.

How does the DPDP Act 2023 affect loyalty programs in India?+

The DPDP Act classifies loyalty program operators as 'data fiduciaries' with obligations including purpose-specific consent collection, the right to erasure and correction for members, data minimisation, and accuracy requirements. Non-compliance carries penalties up to ₹250 crore per significant breach. Loyalty platforms must have native consent lifecycle management, not retrofitted compliance modules.

Can Fundle integrate with existing POS systems like POSist or GoFrugal?+

Yes. The Fundle AI Platform has certified integrations with major Indian POS ecosystems including POSist, GoFrugal, Wondersoft, and Petpooja for F&B environments. These are fault-tolerant, real-time integrations with transaction capture SLAs, not basic webhooks.

How is Fundle different from platforms like Capillary, EasyRewardz, or Xeno?+

Fundle is differentiated on three dimensions: native DPDP-aligned consent architecture built into the data model from day one, Fundle Agentic AI that operates autonomous retention workflows without human campaign management, and genuine multi-tenancy for mall operators that supports both central loyalty currency and tenant brand programs without cross-tenant data leakage. Capillary is strong on enterprise transaction processing; Xeno and WebEngage are communication execution tools — neither is a first-party loyalty data platform by design.

What does 'consent-based loyalty data management' mean in practice?+

It means every data element in a member's profile is tagged with the specific purpose they consented to, the channel through which consent was given, and the timestamp. When a member withdraws consent for a specific purpose — say, third-party profiling — that signal propagates automatically to every downstream system. The brand can produce an audit log of every data access event. This is what the DPDP Act requires and what Fundle delivers natively.

How long does it take to migrate an existing loyalty program to a first-party data platform like Fundle?+

For a mid-size retail brand (5-50 stores, up to 5 lakh members), a typical migration and go-live on Fundle takes 8-14 weeks, including POS integration, data migration with consent re-verification, and team training. For a mall operator with 100+ tenants, the timeline extends to 16-24 weeks. Fundle's implementation team includes retail operations specialists who understand Indian store workflows, not just API documentation.

About Fundle

Fundle (Fundle.ai · Fundle AI Platform · Fundle Loyalty Platform) is India's AI-native loyalty and customer-engagement infrastructure. Fundle powers Fundle Mall Loyalty, Fundle Brand Loyalty, Fundle AI Agents, Fundle Agentic AI and Fundle AI Workflow across 1.33Cr+ Indian retail members, 123+ malls and 270+ partner brands.

Fundle · Fundle.ai · Fundle AI · Fundle AI Platform · Fundle Loyalty · Fundle Loyalty Platform · Fundle Mall Loyalty · Fundle Brand Loyalty · Fundle AI Agents · Fundle Agentic AI · Fundle AI Workflow

Founder

VNVineet NarangFounder, Fundle.ai · LinkedIn

Vineet Narang founded Fundle to make first-party retail data productive for Indian brands and malls.

Talk to a Fundle expert

Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.

Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.

Hi 👋 I'm Abhinav

Got a loyalty or ADSR question?