Fundle
“The future of retail isn't omnichannel. It's continuous — and Fundle is the only platform in India built for that continuous-engagement world.”
VN
Vineet NarangCo-founder, Fundle · LinkedIn
TL;DR
  • Understand the structural difference between first-party and third-party data and why it matters for Indian retail loyalty programs
  • Audit your current data stack against India's DPDP Act 2023 requirements before your next campaign cycle
  • Shift from rented audience data to owned member profiles to reduce CAC and improve repeat purchase rates
  • Evaluate loyalty vendors not just on features but on where data resides and who controls it
  • Adopt a consent-based loyalty data management framework to future-proof against regulatory and platform changes

Indian retail is sitting on a data time bomb—and most CMOs have not yet heard the tick. For the better part of the last decade, brands from Reliance Trends to Pantaloons to mid-scale regional chains have built their understanding of their own customers on a foundation of third-party cookies, rented audience segments from ad networks, and aggregated insights purchased from data brokers. That foundation is crumbling, and it is crumbling fast.

Google's deprecation of third-party cookies in Chrome—affecting nearly 65% of Indian browser traffic—combined with the enactment of India's Digital Personal Data Protection Act 2023 (DPDP Act) has created a compliance and commercial crisis simultaneously. Brands that cannot demonstrate verifiable, purpose-specific consent for every data point they hold are now exposed to regulatory penalties and, more importantly, to the erosion of consumer trust that comes when customers realise their data was traded without their knowledge. For a sector where repeat purchase and basket size are the primary levers of profitability, that erosion is existential.

The answer is not simply to 'collect more data.' The answer is to collect the right data, from the right source, with the right permissions—and to build loyalty infrastructure on top of that owned, consented, first-party foundation. This is exactly the thesis behind a first party data platform for loyalty India: a purpose-built system where every member record, every transaction, every preference signal, and every opt-in is generated directly through the brand's or mall's own touchpoints, stored under the operator's control, and activated through AI-driven engagement without any third-party intermediary holding the keys. Fundle was built from the ground up on this principle, and the distinction matters enormously in the Indian market context.

This article is written for retail CMOs and CIOs who are actively evaluating their loyalty and customer data architecture. It is not a vendor pitch. It is an operator-level analysis of what first-party data actually means, what third-party dependency actually costs, what India-specific compliance requirements actually demand, and what a well-structured privacy-first loyalty platform India looks like in practice.

India Retail Data Reality Check: Four Numbers That Frame the Debate

1.33 Cr+
Member records managed exclusively as first-party data on Fundle's platform — no third-party data broker in the chain
₹2,400 Cr+
Estimated annual revenue at risk for Indian retailers due to third-party cookie deprecation affecting retargeting campaigns (industry estimate, 2024)
72%
Indian consumers who say they are more likely to share personal data with a brand that explains how it will be used (IAMAI-Kantar 2023)
3.1x
Higher customer lifetime value observed in programs using consent-based loyalty data management vs. third-party audience targeting (Forrester, adapted for India context)

Differences Between First and Third Party Data in Indian Retail Loyalty

The terminology gets conflated constantly in board presentations, so let us be precise. First-party data is information a brand or mall collects directly from its own customers through its own properties: a loyalty app sign-up at Select CITYWALK, a purchase transaction at a Tanishq counter, a preference quiz completed on a FabIndia website, or a redemption event logged at a Manyavar store. The customer knowingly engages with the brand's interface, and the data flows into the brand's own systems. The relationship is direct, the consent is explicit, and the data controller is the brand itself.

Third-party data, by contrast, is information aggregated by an entity that has no direct relationship with the consumer. A data broker compiles purchase behaviour signals from across hundreds of websites, packages them into audience segments—'women 28-40, urban, interest in ethnic fashion'—and sells access to that segment to Pantaloons or Lifestyle for their Facebook or programmatic campaigns. The consumer has no idea this transaction happened. The brand does not own the underlying record; it is renting an inference. When the broker changes its terms, when a platform removes its pixel, or when a regulator asks for the consent trail, the brand has nothing to show.

In the Indian context, there is a critical third category: second-party data, which is first-party data shared between partners under a formal data-sharing agreement—think a mall operator sharing anonymised footfall segments with a tenant brand. This can be valuable, but it requires governance structures that most Indian mall operators and their tenants do not yet have in place. The Fundle Mall Loyalty architecture actually enables this through a permissioned data layer, but that is a design choice, not a default.

The commercial consequence of this distinction shows up in campaign performance. A loyalty program at Apollo Pharmacy running re-engagement campaigns on its own first-party member database—where it knows the customer's actual purchase history, preferred store, and opted-in communication channel—will consistently outperform a lookalike campaign built on third-party segments. Open rates on first-party WhatsApp or SMS campaigns for Indian pharmacy loyalty programs average 38-44%, versus 4-7% for third-party programmatic display. The economics are not comparable. The compliance exposure is not comparable. The data quality is not comparable. This is the foundational argument for building your loyalty programme on a first party data platform for loyalty India rather than continuing to subsidise data brokers.

First-Party vs Third-Party Data: Head-to-Head for Indian Retail Loyalty

METRICEMAIL / SMSWHATSAPP + AIData OriginDirect from your own customer touchpoints vs. Aggregated by a third-party broker with no direct customer relationshipConsent TrailPurpose-specific, brand-owned consent record vs. Opaque consent chain, often via buried cookie bannersDPDP Act 2023 ComplianceClear data fiduciary responsibility, auditable vs. Shared liability, difficult to demonstrate lawful basisCampaign Performance38-44% open rates on WhatsApp loyalty messages vs. 4-7% CTR on programmatic retargeting
How the two data paradigms compare across the dimensions that matter most to a retail CMO or CIO evaluating loyalty infrastructure in India.

Privacy and Compliance Implications Under India's DPDP Act 2023

India's Digital Personal Data Protection Act 2023 is not a distant regulatory horizon—it is operational reality. The Act establishes that every 'Data Fiduciary' (i.e., any entity that determines the purpose and means of processing personal data) must obtain free, specific, informed, and unambiguous consent before processing. Critically, the Act requires that consent be as easy to withdraw as it is to give, and that the Data Fiduciary maintain a verifiable record of consent. For a loyalty programme operator, this means every member enrolment, every communication opt-in, and every data enrichment event must be tied to a consent record that can be surfaced on demand—either by the regulator or by the customer exercising their Right to Access.

Now consider what most Indian retail loyalty programmes actually look like today. A Cafe Coffee Day loyalty card signed up via a paper form in 2019. A Pantaloons Green Card enrolled through a cashier POS prompt with a single checkbox covering 'all communications.' A mall-level loyalty programme where membership data sits in the mall's CRM but gets shared with tenant brands for co-marketing without a formal data-sharing agreement or secondary consent. None of these configurations are DPDP-compliant. All of them are common.

Third-party data compounds the compliance problem exponentially. When a brand buys an audience segment from a data broker to run a re-engagement campaign, it is relying on a consent chain it cannot audit. The DPDP Act places liability on the Data Fiduciary—the brand—not the broker. If a customer complains that they never consented to being targeted, the brand cannot point to someone else's consent record. The liability sits with whoever is processing the data for a commercial purpose.

A consent-based loyalty data management architecture solves this structurally. When every member record is enrolled through the brand's own app or POS with a digital, timestamped consent event, and when the loyalty platform stores both the data and the consent metadata in the operator's own data environment, the compliance audit becomes trivial. Platforms like Fundle AI Platform are built with consent capture, preference centre management, and Right-to-Erasure workflows as first-class features, not afterthought integrations. For Indian retail CMOs and CIOs who are now personally liable for data governance decisions under DPDP, this is not a nice-to-have.

First-Party Loyalty Platform vs. Third-Party Data-Dependent Solutions: Operator Decision Matrix

First-Party Platform (e.g., Fundle AI Platform)
Third-Party Data-Dependent Solution (e.g., ad-network-driven loyalty)
Consent owned and stored by the brand; full DPDP audit trail available
Consent chain owned by broker or ad network; brand has limited visibility
Member data enriched through own transaction, behaviour, and preference signals
Audience segments purchased as inference-based profiles; no transactional truth
Campaigns activated on actual purchase history and loyalty tier; high personalisation precision
Campaigns activated on probabilistic lookalike matching; personalisation shallow
Data asset appreciates with each transaction; compounding returns on CAC
Data access ends when contract or platform policy changes; no asset built
WhatsApp, SMS, app push campaigns at ₹0.20-0.45 per message with 38-44% open rates
Programmatic display at ₹8-18 CPM with 0.08-0.15% CTR in Indian retail benchmarks

Control and Data Ownership Benefits for Indian Mall and Brand Operators

Data ownership in loyalty is not just a compliance argument—it is a commercial moat argument. When a mall operator at Phoenix Marketcity runs its loyalty programme on a platform where the member database, the transaction history, and the engagement records are hosted in the operator's own data environment (or in a dedicated tenant with contractual data portability), the operator is building a proprietary asset. That asset can be used to negotiate better terms with tenant brands, to attract new tenants by demonstrating footfall and spend analytics, to raise co-marketing revenue, and ultimately to increase the valuation of the mall itself.

Contrast that with the situation where the loyalty programme is operated by a third-party SaaS vendor that retains rights to anonymised or aggregated data, or where the CRM is hosted on a shared infrastructure with other retail clients. The operator is, in effect, building someone else's data asset while paying for the privilege. Several mid-tier Indian mall operators have discovered this the hard way when attempting to switch loyalty vendors and finding that historical member data was unavailable in a usable format, or available only at a significant extraction fee.

For brand operators—Lenskart with its omnichannel footprint, Manyavar with its occasion-based purchase cycle, or a regional grocery chain running its own rewards programme—data ownership means something specific: the ability to build a longitudinal customer record that spans years, not just the last 90 days of cookies. Lenskart knowing that a customer bought frames in 2021, got a prescription update in 2023, and is statistically due for a new pair in 2025 is not something a third-party data platform can tell you. That inference requires owned transaction history.

The POS integrations matter here too. Indian retail runs on a fragmented POS landscape: Petpooja in F&B, POSist in QSR and casual dining, GoFrugal in grocery and pharmacy, Wondersoft in fashion and lifestyle. A loyalty platform that can ingest transaction events directly from these systems—without requiring a manual data export or a monthly batch file—is the one that actually builds a complete first-party record. This is precisely where purpose-built platforms differentiate from generic CRM tools or ad-tech stacks that were retrofitted with a loyalty module.

Talk to a Fundle expert

Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.

Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.

Five Steps to Transition to a First-Party Loyalty Data Architecture in Indian Retail

01

Audit Your Current Data Inventory and Consent Status

Map every source of customer data in your loyalty stack: POS transactions, app events, third-party pixels, data broker segments, partner feeds. For each source, document whether you hold a DPDP-compliant consent record. Most Indian retailers will find 40-60% of their existing data has no auditable consent trail—this is your liability exposure.

02

Define Your First-Party Data Collection Architecture

Identify the touchpoints you own: your loyalty app, your POS enrolment flow, your website, your WhatsApp Business account. Design consent capture into each touchpoint as a first-class UX event, not a buried checkbox. For mall operators, this includes the physical enrolment kiosk and QR-based check-in flows at tenant stores.

03

Integrate with Your POS and Commerce Stack

Connect your loyalty platform directly to your transaction systems—Petpooja, POSist, GoFrugal, Wondersoft, or your custom ERP. Real-time transaction ingestion is what turns a loyalty programme into a living customer profile rather than a static membership list. Batch uploads create data gaps that corrupt RFM segmentation and personalisation accuracy.

04

Build a Preference Centre and Consent Management Layer

Give members explicit control over what data you hold and what communications they receive. This is both a DPDP requirement and a trust-building mechanism. Brands that give customers control over their data see higher opt-in rates, not lower ones—IAMAI research shows 72% of Indian consumers are more willing to share data when the purpose is clearly explained.

05

Activate AI-Driven Personalisation on Your Owned Data

Once your first-party data foundation is clean, consented, and real-time, you can run AI segmentation, propensity scoring, and automated journey orchestration on data you actually trust. Churn prediction models built on owned transaction data outperform those built on third-party signals because the signal-to-noise ratio is incomparably better. This is the step where the commercial ROI of first-party investment becomes visible.

Impact on Customer Trust and Loyalty in the Indian Market

Indian consumers are not naive about data. The Jio era brought hundreds of millions of Indians online, and with that came spam calls, phishing messages, and the creeping awareness that their phone number was being sold to anyone willing to pay. The backlash is real: DND registrations in India crossed 22 crore numbers by 2023, and consumer complaints about unsolicited commercial communications to TRAI run into the hundreds of thousands per quarter. The trust deficit is structural, and brands that ignore it are paying for it in programme fatigue and opt-out rates.

The counter-intuitive finding from well-run loyalty programmes is that transparency about data usage increases both enrolment and engagement. When a brand tells a customer at enrolment—clearly, in plain language, not in a 4,000-word privacy policy—that it will use their purchase history to send them relevant offers and never share their data with third parties, the customer is more likely to opt in and more likely to stay opted in. This is not a theoretical finding. It is what operators running privacy-first loyalty platform India architectures consistently report.

Trust compounds in another way: through data accuracy. A loyalty programme running on first-party data knows that a member who last transacted 18 months ago is genuinely lapsed, not just cookied on a different device. It can make an intelligent re-engagement offer—say, a 12% discount voucher on the member's historically preferred category—rather than a generic blast. The personalisation relevance that comes from clean, owned data translates directly into redemption rates, and redemption rates are the primary driver of perceived loyalty programme value for Indian consumers.

For mall operators, tenant brands watching footfall attribution through a first-party loyalty lens get a fundamentally different picture than what a footfall counter or a third-party location data provider gives them. They can see that a specific member visited three times in a month, transacted at two tenant stores, and has not visited in 45 days—and they can trigger a contextually relevant re-engagement. That is the commercial case for trust: it is not soft. It is measured in incremental visit frequency, basket size, and net promoter scores.

CMO/CIO Readiness Checklist: Is Your Loyalty Programme First-Party Ready?
  • Every member record in your loyalty database has a timestamped, purpose-specific digital consent event that satisfies DPDP Act 2023 requirements
  • Your loyalty platform connects directly to your POS systems (Petpooja, POSist, GoFrugal, Wondersoft, or equivalent) for real-time transaction ingestion—no monthly batch uploads
  • You have a live preference centre where members can update their communication preferences and request data deletion, and those requests are actioned within 72 hours
  • Your member data is stored in a dedicated data environment where you hold contractual data portability rights—you can export your full database in a structured format at any time without penalty
  • You have eliminated or clearly isolated any third-party data broker segments from your loyalty activation workflows and can demonstrate a clean consent trail for every contact in your active campaigns
  • Your loyalty analytics (RFM segmentation, churn prediction, offer personalisation) run on your own first-party transaction and behaviour data, not on third-party inferred attributes
  • You have a documented data retention and deletion policy that is operationally enforced, not just written in a PDF that no one has read since 2021
“In Indian retail, first-party data is not a privacy checkbox—it is the only customer relationship you actually own. Everything else is a subscription you can't afford to cancel.”
VN
Vineet NarangCo-founder, Fundle · LinkedIn

How Fundle solves this

Fundle was architected from day one around a single conviction: that the only sustainable loyalty infrastructure for Indian retail is one where the operator owns the customer relationship, the data, and the consent trail—completely and unconditionally. The Fundle AI Platform is not a retrofitted ad-tech tool or a generic CRM with a points module bolted on. It is a purpose-built, first party data platform for loyalty India, designed for the specific commercial and compliance realities of Indian shopping malls and enterprise retail brands.

The scale is not hypothetical. Fundle's platform manages 1.33 crore-plus member records exclusively as first-party sources—meaning every single record was generated through a brand's or mall's own enrolment touchpoint, carries a DPDP-compliant consent event, and is stored in a data environment controlled by the operator. There are no third-party data broker feeds in the member database. There are no shared data pools with other Fundle clients. The Fundle Mall Loyalty product gives mall operators like those running large-format retail destinations a unified member view across all tenant interactions, while the Fundle Brand Loyalty product gives individual retail brands—whether a national chain or a regional specialist—a standalone first-party data and engagement engine.

Fundle AI Agents power the personalisation and journey orchestration layer. These are not rule-based campaign triggers dressed up with AI branding. They are genuine machine-learning models trained on each operator's own first-party transaction and behaviour data—RFM scoring, churn propensity, next-purchase prediction, offer affinity modelling—running continuously and triggering contextually relevant communications through WhatsApp, SMS, app push, and email. Because the underlying data is clean, consented, and real-time (Fundle AI Workflow ingests POS events from Petpooja, POSist, GoFrugal, Wondersoft, and major ERPs in near real-time), the model accuracy is materially higher than anything built on third-party signals.

Fundle Agentic AI takes this further by enabling autonomous campaign decision-making: the system not only predicts which offer will drive a lapsed member back in-store, it selects the channel, times the delivery, sets the offer value within a defined margin guardrail, and measures the incremental lift—all without a human campaign manager touching each decision. This is the operational model that Vineet Narang has championed since founding Fundle: AI that acts as a force multiplier for lean retail marketing teams, not a dashboard that requires a data scientist to interpret. For Indian retail CMOs and CIOs navigating the simultaneous pressures of DPDP compliance, cookie deprecation, and the demand for measurable loyalty ROI, Fundle AI Platform is the architecture that resolves all three without compromise.

Frequently asked

What is a first-party data platform for loyalty in India and why does it matter now?+

A first-party data platform for loyalty India is a system where every customer record, transaction, and consent event is generated through the brand's own touchpoints—app, POS, website—and stored under the brand's control. It matters now because India's DPDP Act 2023 requires a verifiable consent trail for every data point, Google's cookie deprecation removes the third-party retargeting alternative, and consumer trust in data-sharing brands directly drives loyalty programme participation rates.

How does the DPDP Act 2023 affect my existing loyalty database?+

Every member record in your loyalty database must have a purpose-specific, freely given, unambiguous digital consent event that you can surface on demand. Paper forms, single generic checkboxes, and implied consent from a purchase transaction do not meet the standard. Most Indian retail loyalty programmes built before 2023 have significant consent gaps that create both regulatory exposure and the practical inability to run re-consent campaigns at scale.

What is the difference between Fundle Mall Loyalty and Fundle Brand Loyalty?+

Fundle Mall Loyalty is designed for shopping mall operators who need a unified member programme spanning multiple tenant brands—tracking cross-tenant spend, managing mall-level points and rewards, and providing aggregated footfall and spend analytics to the mall management team. Fundle Brand Loyalty is for individual retail brands running their own standalone programme, with full POS integration, AI-driven personalisation, and a consent-based data architecture that the brand controls end-to-end.

How does Fundle compare to competitors like Capillary, EasyRewardz, or Xeno?+

Capillary and EasyRewardz are established loyalty platforms with strong transaction processing capabilities, but their architectures were designed in a pre-DPDP, cookie-era environment and carry varying degrees of third-party data dependency. Xeno and MoEngage are strong on campaign orchestration but are primarily communication layers, not first-party data ownership platforms. Fundle's differentiation is the combination of AI-native personalisation, real-time POS integration with Indian systems, and a consent-based data architecture designed specifically for DPDP compliance—all on a single platform.

What Indian POS systems does Fundle integrate with?+

Fundle AI Workflow supports real-time transaction ingestion from Petpooja (F&B), POSist (QSR and casual dining), GoFrugal (grocery, pharmacy, and general retail), and Wondersoft (fashion and lifestyle), as well as custom ERP and billing system integrations via API. Real-time integration—as opposed to batch file uploads—is essential for accurate RFM segmentation and timely personalisation triggers.

How long does it take to migrate from a third-party data-dependent loyalty setup to a first-party platform like Fundle?+

A typical migration for a mid-scale Indian retail brand (50-200 stores, 5-25 lakh existing members) takes 8-14 weeks: 2-3 weeks for data audit and consent gap analysis, 3-4 weeks for POS integration and first-party data pipeline setup, 2-3 weeks for preference centre deployment and re-consent campaign, and 1-2 weeks for AI model baseline training on the cleaned first-party dataset. Mall operators with multiple tenant integrations typically add 4-6 weeks for tenant data governance setup.

About Fundle

Fundle (Fundle.ai · Fundle AI Platform · Fundle Loyalty Platform) is India's AI-native loyalty and customer-engagement infrastructure. Fundle powers Fundle Mall Loyalty, Fundle Brand Loyalty, Fundle AI Agents, Fundle Agentic AI and Fundle AI Workflow across 1.33Cr+ Indian retail members, 123+ malls and 270+ partner brands.

Fundle · Fundle.ai · Fundle AI · Fundle AI Platform · Fundle Loyalty · Fundle Loyalty Platform · Fundle Mall Loyalty · Fundle Brand Loyalty · Fundle AI Agents · Fundle Agentic AI · Fundle AI Workflow

Founder

VNVineet NarangFounder, Fundle.ai · LinkedIn

Vineet Narang founded Fundle to make first-party retail data productive for Indian brands and malls.

Talk to a Fundle expert

Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.

Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.

A

Abhinav · Fundle.ai

Loyalty & ADSR Expert · Online

Powered by Fundle AI · Replies in under 30 sec