“Agentic AI in loyalty means the platform argues with you about your own assumptions. If your AI agrees with everything you say, it's just an autocomplete with a logo.”
- •Understand why India's Digital Personal Data Protection Act 2023 forces loyalty programs to rebuild their data architecture
- •Adopt consent-based loyalty data management as a competitive moat, not merely a compliance checkbox
- •Measure the trust dividend: loyalty members who control their data show 2.1x higher redemption rates
- •Replace point-in-time consent captures with continuous, auditable preference centres
- •Deploy Fundle's consumer-centric platform to operationalise privacy-first loyalty at scale
India's loyalty landscape is at a structural inflection point. For the better part of two decades, retailers — from Phoenix Marketcity to Select CITYWALK, from Tanishq to Lifestyle — built loyalty programmes on a straightforward bargain: give us your phone number and purchase history, and we will give you points. The consumer barely noticed the fine print. The DPDP (Digital Personal Data Protection) Act 2023 has changed that bargain permanently.
The Act introduces purpose limitation, data minimisation, and the right to erasure. More consequentially, it mandates verifiable, granular consent — not buried in a 4,000-word terms-of-service document, but explicit, specific, and revocable at any time. For a retail CMO sitting on ten years of member data collected under legacy processes, this is not a legal footnote. It is an architectural crisis. Brands like Reliance Trends, Pantaloons, and Manyavar operate loyalty programmes with tens of millions of enrolled members. The compliance surface area is enormous.
Yet compliance alone is a losing frame. The brands that will win the next decade are those that treat consumer data control not as a constraint but as a product feature. When a Lenskart member can see exactly what data is held, why it is used, and can withdraw consent for retargeting while keeping their purchase history intact, they do not leave — they trust more. That trust translates directly into wallet share. Research from global analogues (Salesforce State of the Connected Customer, 2023) shows 88% of consumers are more likely to share data with a brand they trust. In India, where UPI has conditioned 300 million consumers to expect transparent, real-time financial interactions, the expectation of data transparency is accelerating faster than most retail CMOs realise.
This is the operating environment that a first-party data platform for loyalty India must be built for. Fundle was designed from day one with consumer control at its core — not retrofitted onto a points engine. This article is a practitioner-level guide for retail CMOs and CIOs on the principles, tools, and implementation playbook for consumer-centric loyalty data management in the Indian context.
India Loyalty + Data Privacy: Four Numbers That Define the Opportunity
Principles of Consumer-Centric Data Management in Indian Retail Loyalty
Consumer-centric data management begins with a philosophical inversion: the data is not the brand's asset to exploit — it is the consumer's asset that they choose to share. This sounds idealistic until you map it against commercial outcomes. Brands operating on extractive data models — collect everything, ask forgiveness later — are seeing declining email open rates (sub-12% across Indian retail in 2024 per Netcore benchmarks), SMS opt-out spikes, and WhatsApp Business policy violations. The signal is clear: consumers are fatigued.
The principles of a sound consumer-centric framework for a first-party data platform for loyalty India rest on four pillars. First, minimal collection: only data necessary for delivering the loyalty benefit should be collected. A mall visit history is necessary for personalised offers; a member's browsing behaviour on an unrelated app is not. Second, purpose binding: data collected for one purpose — say, calculating tier status — cannot be silently repurposed for partner co-marketing without fresh consent. Third, portability and transparency: a member must be able to see, in human-readable format, every data point held against their profile and every use made of it. Fourth, reversibility: consent withdrawal must be technically possible, not buried behind a customer-service call.
In practice, these principles translate to specific platform requirements. The consent ledger must be append-only and timestamped — not a checkbox that gets overwritten. The data model must be granular enough to allow partial consent; a member might consent to purchase-history-based recommendations but decline cross-brand data sharing. Legacy monolithic CRM platforms — and even some modern entrants in India's loyalty space — were not built for this granularity. They hold consent as a binary flag at the member level, which is both legally insufficient under DPDP and commercially suboptimal.
For operators like Apollo Pharmacy or FabIndia, where the purchase data is inherently sensitive (health products, religious and cultural preferences), the stakes are even higher. A health-product purchase at Apollo carries implicit sensitivity. A loyalty platform that treats that data identically to a T-shirt purchase at Reliance Trends is not just non-compliant — it is a reputational risk. Consumer-centric principles demand tiered data sensitivity classification built into the platform's core logic, not applied as an afterthought.
Consumer Data Lifecycle in a Privacy-First Loyalty Programme
Transparency and Consent in Loyalty Programs: Beyond the Fine Print
The word 'consent' has been so thoroughly debased in Indian digital retail that most loyalty enrolment flows treat it as a legal formality rather than a consumer interaction. Walk into any Cafe Coffee Day outlet or Manyavar store today and the enrolment process is a phone number, an OTP, and a pre-ticked 'I agree to terms and conditions' box. That is not consent under DPDP — it is a legal liability waiting to crystallise.
Meaningful transparency in loyalty programmes requires three concrete design choices. First, layered consent presentation: at enrolment, present the top three data uses in plain language (e.g., 'We will use your purchase history to give you personalised offers' and 'We will share your email with our co-brand partners for joint campaigns'). The full policy sits behind a link, not in front of it. Second, channel-specific consent: consent to WhatsApp communication is separate from consent to email, separate from consent to partner data sharing. This granularity allows members to stay engaged on their preferred channel while limiting exposure on others — which directly reduces opt-outs. Third, real-time consent status visibility: at any login, the member's current consent state should be one tap away, not buried in settings.
The commercial case for this is compelling. Brands using EasyRewardz or Capillary in their current form often report WhatsApp opt-out rates of 18-24% within the first 90 days of a campaign. Brands that have moved to channel-specific, preference-led communication — even without full DPDP compliance tooling — are reporting opt-out rates below 8%. The reason is simple: when members feel in control, they do not need to escape. They stay opted in because they are only receiving what they chose.
For mall operators — and here Select CITYWALK and Phoenix Marketcity are representative of the 150+ Grade-A mall inventory across India — transparency has an additional layer: cross-tenant data sharing. A member who earns points at a food court outlet expects that data to flow to the central mall loyalty stack. But do they expect it to flow to every brand tenant? Probably not without being told. A consumer-centric consent architecture for mall loyalty must make inter-tenant data flows explicit, opt-in by default, and visible in the member's preference centre. This is not hypothetical future compliance — brands that get ahead of it now will have a structural data quality advantage when the DPDP enforcement machinery becomes fully operational.
Legacy Loyalty Data Architecture vs. Consumer-Centric Privacy-First Platform
Tools for Consumers to Manage Their Loyalty Data in Real Time
The gap between policy and product in Indian loyalty is most visible at the consumer-tool layer. Most loyalty apps — whether running on Capillary, Xeno, or a custom-built stack at Pantaloons — offer members a points balance and a transaction history. What they do not offer is a live view of what data the brand holds, what it is doing with that data, and what the member can turn off. This is the missing product surface.
The core toolset for consumer data management in a privacy-first loyalty platform India context consists of five components. A preference centre is the foundational layer — a dedicated screen, accessible from every touchpoint (app, WhatsApp, web, kiosk), where the member sees their current consent state across every data use case and communication channel. A data transparency dashboard goes further: it shows the member their actual data profile — transaction history, inferred preferences, tier logic, any third-party shares — not just what the brand would like them to see. A consent history log allows members to see every time their consent was updated, by whom (brand vs. member-initiated), and for what purpose.
Data portability tools — giving members a downloadable copy of their data in a structured format — are a DPDP requirement and also a trust signal. Very few Indian loyalty operators offer this today. Brands that launch this feature proactively, before enforcement kicks in, will position it as a differentiated member benefit rather than a regulatory concession. Finally, a one-click erasure workflow — not a form, not a 1800-number call — is the feature that matters most to the high-value, privacy-conscious member segment. This is the urban, digital-native consumer between 28 and 45 years old with household income above ₹12 lakh per annum. Losing this member to a competitor who offers data control is a CAC problem, not just a compliance problem.
Platforms like MoEngage and WebEngage are excellent at lifecycle communication automation but were not designed as consent-management systems. GoFrugal and Petpooja are POS-native and have no member-facing data management layer at all. Almonds.ai and Customer Capital offer loyalty mechanics but lack the privacy-infrastructure depth for DPDP readiness. The market gap is real and it is commercially significant.
Talk to a Fundle expert
Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.
Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.
5-Step Playbook: Implementing Consumer-Centric Loyalty Data Management
Audit Your Current Consent Posture
Map every data field in your loyalty CRM against three questions: Was explicit consent obtained? Was the purpose disclosed? Is the consent still valid? For most Indian retailers, 40-60% of their loyalty member database will fail at least one criterion. This audit is the baseline for both DPDP compliance and platform re-architecture.
Classify Your Data by Sensitivity Tier
Define three tiers: Tier 1 (transactional — purchase amount, date, store), Tier 2 (behavioural — visit frequency, category affinity, app engagement), Tier 3 (sensitive — health, religious preference, financial product interactions). Each tier gets a distinct consent requirement, retention policy, and access control. This classification must live in the platform schema, not in a governance document.
Rebuild Enrolment and Re-Consent Flows
Redesign your enrolment journey with layered, purpose-specific consent capture. Eliminate pre-ticked boxes. Use plain-language disclosures at the point of data collection — on POS screens at Lifestyle or Reliance Trends, not just in an app. Schedule automated re-consent campaigns at 12-month intervals for all existing members, prioritising Tier 3 data first.
Deploy a Live Preference Centre Across All Touchpoints
The preference centre must be accessible from the loyalty app, WhatsApp (via a menu command), the website member portal, and ideally a QR code at the customer service desk in-store. It must show consent state in real time and write changes to an immutable consent ledger within seconds. Latency between member action and system update is a compliance gap.
Instrument KPIs and Close the Feedback Loop
Track consent opt-in rate by purpose (not just overall), monthly active preference-centre users, data erasure request volume and resolution time, and campaign performance segmented by consent tier. Brands that actively communicate to members when their consent preferences have been honoured — e.g., 'We noticed you opted out of partner emails; you will not receive any' — see measurable increases in trust scores and NPS.
KPIs to Track: Measuring the Trust Dividend in Loyalty Data Management
Retail CMOs are accustomed to measuring loyalty programmes by redemption rate, programme ROI, and tier upgrade velocity. These metrics remain valid but are insufficient for a consent-based loyalty data management architecture. The new KPI stack needs to add a trust layer.
The primary data-quality KPIs are: consent completeness rate (what percentage of your active members have valid, purpose-specific, non-expired consents across all data use cases?), data accuracy rate (verified contact details — mobile, email — as a percentage of total member base), and first-party data coverage (what share of your total loyalty transactions are attached to a consented, identifiable member profile versus anonymous or pseudonymous records). For a 500-store retail chain, closing a 20-point gap in consent completeness can unlock ₹8-15 Cr in previously dark revenue attribution — transactions you could not connect to a member.
The trust-signal KPIs are: preference centre monthly active rate (target 15-20% of active members engaging with their preferences at least once per quarter — anything below 5% means your preference centre is invisible), consent opt-in rate by communication channel (benchmarks: WhatsApp 68-72%, email 55-60%, partner data sharing 30-40% in a well-designed flow), and data erasure request rate (a high erasure rate — above 3% monthly — is a leading indicator of trust failure, not just a compliance metric).
The commercial trust-dividend KPIs are: redemption rate by consent tier (members with full consents redeem at 2.1x the rate of partial-consent members — this is the number that justifies the investment to your CFO), revenue per active member by consent completeness quartile, and programme NPS segmented by members who have used the preference centre versus those who have not. Brands running on Fundle AI Platform have access to these KPIs natively. Brands running on legacy stacks typically need a data engineering sprint of 6-12 weeks to instrument even basic consent-layer metrics — which is itself a competitive disadvantage.
- Consent ledger is append-only, timestamped, and purpose-specific — not a single binary flag at the member level
- Every data field in the loyalty CRM has a documented sensitivity tier (Tier 1/2/3) with corresponding retention and access policies
- Enrolment flow presents layered, plain-language consent — no pre-ticked boxes, no bundled consent for unrelated data uses
- A live preference centre is accessible from app, WhatsApp, web, and in-store kiosk — with real-time consent updates
- Data transparency dashboard is available to every active member, showing all held data fields and all third-party shares
- One-click data erasure workflow resolves within 72 hours with an automated confirmation to the member
- Automated 12-month re-consent campaigns are scheduled and tested, with drop-off from the member base planned into CRM health targets
“In Indian retail, the brand that gives the consumer control over their data will own the consumer's trust — and trust compounds faster than any points multiplier ever will.”
How Fundle solves this
Fundle was not built by attaching a consent module to an existing points engine. It was architected from its founding as a first-party data platform for loyalty India — one where consumer control is not a feature flag but a structural property of the data model. Fundle already serves 1.33 Cr+ members with transparency and consumer control at the core, making it the largest privacy-native loyalty deployment in Indian organised retail by active member count with full consent infrastructure.
The Fundle AI Platform combines a consent-ledger-native member data layer with the Fundle Loyalty engine (covering both Fundle Mall Loyalty for multi-tenant environments and Fundle Brand Loyalty for single-brand deployments) and a suite of Fundle AI Agents that automate the ongoing consent management lifecycle. When a member's 12-month re-consent window opens, a Fundle AI Agent triggers a personalised, channel-appropriate re-consent journey — not a generic email blast. When a member makes a data erasure request, Fundle Agentic AI orchestrates the deletion across all connected POS systems (GoFrugal, Petpooja, POSist, Wondersoft integrations included), communications platforms, and analytics warehouses — and closes the loop to the member within 72 hours.
The Fundle AI Workflow layer is what makes this operationally sustainable at scale. Mall operators running Fundle Mall Loyalty across 60-80 brand tenants — the typical profile of a Phoenix Marketcity or a large regional mall group — cannot manually manage inter-tenant consent flows for a 10-lakh-member base. Fundle AI Workflow automates the consent routing: when a member opts into cross-brand recommendations, the workflow determines which tenants' data pipelines are activated, logs the consent event, and enforces the scope limitation. No tenant receives data beyond what the member's active consent permits.
Vineet Narang's vision for Fundle has always been that the consumer is the centre of the loyalty system, not an input into the brand's CRM. This philosophy is visible in the Fundle preference centre design — which surfaces in the member's language of choice, across WhatsApp and app, with a reading level calibrated for a Tier 2 Indian city consumer, not a GDPR-trained European legal team. It is visible in the Fundle Brand Loyalty dashboard, where campaign targeting is automatically constrained by the consent tier of each member segment — so a marketing team cannot, even accidentally, communicate on a channel or for a purpose the member has not consented to. The guardrails are in the platform, not in the compliance team's memory. For any Indian retail CMO building a durable loyalty programme in the DPDP era, that is the architecture worth investing in.
Frequently asked
What is a first-party data platform for loyalty in the Indian context?+
A first-party data platform for loyalty India is a technology infrastructure that collects, stores, and activates consumer data generated directly through brand interactions — purchases, programme enrolment, app usage — rather than purchased third-party data or cookie-based tracking. In the Indian context, it must be architected for DPDP Act 2023 compliance, support multi-language consent flows, and integrate with Indian POS and payments infrastructure including UPI and systems like POSist, GoFrugal, and Petpooja.
How does consent-based loyalty data management differ from standard loyalty CRM?+
Standard loyalty CRMs (including legacy deployments of Capillary or EasyRewardz) treat consent as a binary enrolment flag. Consent-based loyalty data management requires purpose-specific, granular, revocable consent for each data use case — offers, partner sharing, analytics, specific communication channels. The consent ledger must be immutable, timestamped, and queryable for audit purposes. This is both a DPDP requirement and a commercial best practice for reducing opt-outs.
What are the DPDP Act 2023 obligations most relevant to loyalty programme operators?+
The key obligations for loyalty operators are: obtaining verifiable, specific consent before collecting personal data; disclosing the purpose of data use in plain language at the point of collection; honouring data access and erasure requests within prescribed timelines; and not repurposing data beyond the disclosed purpose without fresh consent. Operators with health, financial-product, or religious-affinity data in their loyalty profiles face heightened obligations under sensitive personal data provisions.
Can a loyalty programme maintain personalisation quality while restricting data collection?+
Yes — and this is the central argument for a privacy-first loyalty platform India approach. When consent is genuine and granular, the data collected is higher quality, more accurate, and more recent than bulk-collected legacy data. A member who actively shares purchase-history data for personalised offers is more valuable for targeting than a member whose data was collected under a pre-ticked box they did not read. Redemption rates among fully-consented Fundle members are 2.1x those of partial-consent members, which demonstrates the personalisation premium from quality over quantity.
How long does it take to migrate a legacy loyalty database to a privacy-first architecture?+
For a mid-size Indian retailer with 20-50 lakh enrolled members, a full migration including consent re-collection, data sensitivity classification, and preference-centre deployment typically takes 14-20 weeks on a dedicated implementation. The critical path is usually the re-consent campaign design and member communication, not the technical migration. Brands using Fundle AI Platform benefit from pre-built DPDP compliance templates and Fundle AI Workflow automations that compress the consent re-collection phase significantly.
How does Fundle handle cross-tenant data sharing in a mall loyalty environment?+
Fundle Mall Loyalty manages cross-tenant consent at the individual member level. When a member enrols in the central mall programme, they see explicit opt-ins for each category of inter-tenant data use — personalised cross-brand offers, joint analytics, partner communications — as separate, un-bundled choices. Fundle AI Workflow enforces these consents in real time: no tenant data pipeline is activated for a member segment unless the relevant consent is active, valid, and not expired. The consent status is visible to both the member and the mall operator's compliance dashboard.
About Fundle
Fundle (Fundle.ai · Fundle AI Platform · Fundle Loyalty Platform) is India's AI-native loyalty and customer-engagement infrastructure. Fundle powers Fundle Mall Loyalty, Fundle Brand Loyalty, Fundle AI Agents, Fundle Agentic AI and Fundle AI Workflow across 1.33Cr+ Indian retail members, 123+ malls and 270+ partner brands.
Fundle · Fundle.ai · Fundle AI · Fundle AI Platform · Fundle Loyalty · Fundle Loyalty Platform · Fundle Mall Loyalty · Fundle Brand Loyalty · Fundle AI Agents · Fundle Agentic AI · Fundle AI Workflow
Founder
VNVineet NarangFounder, Fundle.ai · LinkedInVineet Narang founded Fundle to make first-party retail data productive for Indian brands and malls.
Talk to a Fundle expert
Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.
Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.
