“First-party data isn't a sticker on your homepage. It's a daily discipline — capture, reconcile, model, activate. Fundle is the discipline, productised.”
- •Understand why India's DPDP Act forces a complete rethink of how retail brands collect and use customer data
- •See how AI personalization and consent-first data architecture can coexist profitably
- •Benchmark your loyalty stack against platforms that embed privacy by design, not as an afterthought
- •Follow a five-step playbook to make your customer engagement program DPDP-ready in under 90 days
- •Evaluate Fundle's Agentic AI and workflow layer as the operating model for compliant, high-ROI engagement
For the better part of the last decade, Indian retail marketers operated in something close to a data free-for-all. Phone numbers were harvested at POS counters without explanation. WhatsApp blasts went out to lists bought from third-party aggregators. Loyalty apps quietly collected location data in the background. The customer engagement platform with data privacy compliance was a concept that existed in PowerPoint decks but rarely in production systems. That era is over.
The Digital Personal Data Protection Act, 2023 — India's DPDP — received presidential assent in August 2023. The rules are still being finalised, but the direction is unmistakable: explicit, granular, revocable consent; purpose limitation on data use; mandatory data fiduciary obligations; and penalties that can reach ₹250 crore per violation. For a mall operator running loyalty across 200 brands or a fashion retailer with 5 million members, the compliance surface area is enormous. The 'collect everything and figure it out later' approach now carries genuine legal and reputational risk.
At the same time, AI capabilities in retail engagement have reached an inflection point. Generative AI, real-time recommendation engines, and agentic workflow automation mean that even mid-market Indian retailers — think Lifestyle, Manyavar, or FabIndia — can now deploy personalisation at a depth that was reserved for the Amazons of the world three years ago. The paradox facing every Chief Marketing Officer and Loyalty Program Manager in India right now is this: the tools to engage customers more personally have never been more powerful, and the rules around using personal data have never been more stringent. How do you do both?
This article is an operator-level answer to that question. It draws on real Indian retail benchmarks, the competitive landscape of platforms from Capillary to WebEngage, and the architectural choices that separate platforms that will thrive in the DPDP era from those that will become liabilities. Fundle was built with this exact tension in mind — and the design choices made at the platform layer matter more than any marketing claim.
India's AI-Loyalty-Privacy Inflection Point: Four Numbers That Matter
The Growing Role of AI in Indian Customer Engagement
Walk into any Phoenix Marketcity or Select CITYWALK today and you are being tracked across at least six data touchpoints before you make a single purchase: footfall sensors, app check-in, Wi-Fi probe, POS transaction, parking data, and loyalty tier lookup. The volume of behavioural signal available to a modern mall operator or retail CMO is genuinely staggering. The problem has never been data scarcity. It has always been the inability to act on that data in real time, at the individual level, without a team of fifty data scientists.
AI changes that calculus dramatically. In the Indian context, the most impactful AI applications in customer engagement right now fall into three categories. First, predictive personalisation — using RFM (Recency, Frequency, Monetary) models augmented with category affinity signals to predict what a customer at a Tanishq store in Bengaluru will respond to before she even opens her phone. Second, agentic campaign execution — AI agents that autonomously decide channel mix (WhatsApp, push, SMS, in-app), offer depth, and send timing based on real-time context like weather, local events, or competitive promotions. Third, churn prediction and win-back automation — identifying the Lenskart customer who is 60 days from defection and triggering a personalised optician appointment offer with a ₹500 incentive before the competitor does.
Platforms like MoEngage and WebEngage have built strong journey orchestration capabilities, and Xeno has done solid work in the D2C and QSR segment. But the AI layer in most of these platforms still requires significant human configuration — rules, segments, campaign briefs, creative approval. The shift towards agentic AI, where the system proposes, tests, and iterates engagement strategies autonomously within guardrails set by the marketer, is where the next order of magnitude of value will be created. For Indian retail operators managing thousands of SKUs, dozens of brands, and millions of loyalty members across geographies, the human bottleneck in campaign management is itself a revenue constraint.
The POS ecosystem — Petpooja in F&B, POSist in QSR, GoFrugal and Wondersoft in fashion and general retail — generates the transaction-level ground truth that AI models need to work. The quality of AI-driven engagement is therefore directly proportional to the depth of POS integration. Retailers who have not yet unified their POS, loyalty, and CRM data into a single profile layer are essentially trying to personalise with one hand tied behind their back.
From Raw Data to Compliant AI Engagement: The Value Funnel
Data Privacy Regulations: A Paradigm Shift for Retail Loyalty
India's DPDP Act is not GDPR copy-pasted onto Indian soil. It has its own architecture — consent managers, data fiduciaries, data principals, and a grievance redressal framework — and Indian retail brands need to understand the specific obligations that touch their loyalty and engagement stacks directly.
The most operationally significant requirement for loyalty operators is the consent layer. Under DPDP, every purpose for which you collect personal data must be explicitly stated at the point of collection, in plain language, and the data principal (your customer) must affirmatively opt in. Bundled consent — the 'by joining our loyalty program you agree to everything' checkbox — will not survive regulatory scrutiny. A Pantaloons customer who opts in for transaction-based point updates has not necessarily consented to receive third-party brand offers or to have her purchase history used for lookalike audience modelling on Meta. These are distinct purposes requiring distinct consents.
The right to erasure and data portability provisions mean that a customer who asks Apollo Pharmacy to delete her health purchase history from their loyalty database must receive that deletion within a defined period — and the platform must be architecturally capable of executing that deletion without corrupting the broader data model. This is a harder engineering problem than it sounds for platforms that store customer data in monolithic schemas designed for query performance rather than surgical deletion.
For mall operators, the complexity compounds. A single loyalty program spanning 150 brands across a Phoenix or DLF portfolio means the mall operator is functioning as a data fiduciary for data that flows through to individual brand tenants who have their own data processing obligations. The consent architecture must reflect this multi-party data flow explicitly. Platforms that were built before DPDP — including several well-known Indian loyalty and CRM vendors — are carrying significant architectural debt in this area. The compliance gap is not just a legal risk; it is a trust risk. Capillary, EasyRewardz, and Almonds.ai all offer loyalty infrastructure, but their DPDP-specific consent management capabilities vary widely, and none has made it a central product narrative in the way the market now demands.
The brands that will win in the next five years are those that treat consent not as a compliance checkbox but as a value exchange signal. When a Cafe Coffee Day member explicitly opts in to share her visit frequency data for personalised offers, she is telling you something valuable about her trust level and her engagement potential. That consent event is itself a first-party data asset.
Legacy Engagement Approach vs. DPDP-Compliant AI Engagement
Balancing Personalization and Privacy: What Good Looks Like
The instinctive reaction of many retail marketers when confronted with DPDP obligations is to see it as a zero-sum trade-off: more compliance means less personalisation data, which means worse AI models, which means lower engagement ROI. This framing is wrong, and the evidence from markets where privacy regulation preceded India — the EU, UK, and Singapore — shows the opposite dynamic when brands execute correctly.
The insight is this: consent-based first-party data is dramatically higher quality than scraped or purchased data. A Reliance Trends customer who has explicitly opted into style preference updates and size data sharing gives you signal that is accurate, current, and legally usable. Compare that to demographic inferences purchased from a data broker — stale, imprecise, and now legally unusable. The DPDP era does not shrink your data asset; it purifies it. The brands that invest in consent-first data collection actually improve their AI model performance over an 18-to-24-month horizon.
What does a best-in-class consent and personalisation architecture look like for an Indian retailer or mall operator? Five characteristics stand out. First, progressive consent: ask for minimal data at sign-up and earn the right to request more as the relationship deepens. A new Manyavar loyalty member does not need to share her wedding date on day one — but after three visits, a contextual prompt tied to a specific benefit converts at 4 to 5 times the rate of an upfront data dump request. Second, transparent value exchange: every data request must have a visible benefit attached. 'Share your birthday for a ₹500 gift voucher' outperforms 'complete your profile' by a factor of three in Indian retail benchmarks. Third, real-time preference centres: members must be able to log in and see exactly what data you hold, what you use it for, and turn off specific use cases without losing their loyalty tier. Fourth, AI inference guardrails: the AI personalisation engine must be constrained to use only data the member has consented to for that specific purpose — a platform-level enforcement, not a human process. Fifth, consent decay management: consents should be time-limited and auto-renewed only with affirmative re-engagement, preventing the accumulation of stale consent that creates DPDP liability over time.
Retailers who build these five characteristics into their engagement stack do not just achieve compliance. They build the kind of transparent, member-controlled relationship that drives the long-term NPS and repeat purchase rates that loyalty programs are supposed to produce but rarely do. An engaged, trusting customer at an FabIndia store spends 2.8 times more over a 24-month window than a disengaged loyalty member who joined for a one-time discount.
Talk to a Fundle expert
Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.
Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.
Five-Step Playbook: Building a DPDP-Ready AI Engagement Stack in 90 Days
Audit Your Current Consent and Data Inventory
Map every data collection point — POS, app, web, Wi-Fi, third-party integrations — and classify each data element by consent status, purpose, and retention period. Identify consent gaps where data is being used beyond the scope of original collection. This audit typically reveals that 30-45% of an Indian retailer's existing loyalty database has consent that will not meet DPDP standards.
Redesign Consent Flows Across All Touchpoints
Rebuild sign-up and data enrichment flows with purpose-specific, granular consent in plain Indian languages (Hindi, Tamil, Telugu, Marathi as minimum for national brands). Implement a centralised consent management layer that syncs across POS, app, and web in real time. Integrate this with your POS providers — Petpooja, GoFrugal, Wondersoft — so consent status is visible at the point of transaction.
Unify First-Party Data Into a Consented Customer Data Profile
Consolidate transaction history, behavioural signals, preference data, and consent records into a single customer profile that the AI layer can query. Ensure the profile architecture supports surgical deletion and purpose-limitation queries — meaning the AI can be instructed to use only data consented for purpose X when generating a recommendation for campaign Y.
Deploy AI Personalisation Within Consent Guardrails
Configure AI models to reference consent flags before generating any personalised output. Agentic AI workflows should reject or flag campaign triggers that would use data beyond the consented purpose. Set up A/B testing frameworks to quantify the personalisation uplift from consented first-party data versus the baseline, building the internal business case for consent-first data strategy.
Launch Member Self-Service and Continuous Consent Health Monitoring
Deploy a member-facing data preference centre accessible from the loyalty app. Set automated alerts for consent decay — members whose consent is approaching expiry or who have not re-engaged their preferences in 12 months. Build a compliance dashboard for your DPO (Data Protection Officer) showing consent coverage rates, deletion request SLA performance, and purpose-limitation adherence across campaigns.
KPIs to Track: Measuring Engagement, Privacy, and AI Performance Together
One of the persistent blind spots in Indian retail loyalty management is the disconnect between engagement KPIs and data health KPIs. Marketing teams track open rates, redemption rates, and incremental revenue. Compliance teams track consent coverage and breach incidents. These two dashboards almost never appear in the same room. In the DPDP era, that separation is operationally dangerous and analytically misleading.
The metrics framework for a mature AI-powered, privacy-compliant engagement program needs to span four dimensions. The first is consent health: what percentage of your active loyalty base has current, purpose-specific consent for each major data use case? For a well-run program, this should be above 80% for transaction data use and above 60% for behavioural personalisation. Below these thresholds, your AI models are operating on a shrinking, legally questionable data foundation. The second dimension is AI personalisation effectiveness: measured as offer relevance score (member rating of offer fit), incremental redemption rate versus control groups, and revenue per engaged member. Indian fashion retailers on modern AI platforms are seeing incremental redemption rates of 18-22% versus 6-8% on rule-based segmentation — the delta is the business case for AI investment.
The third dimension is member trust and data transparency: Net Promoter Score segmented by consent status (members who feel in control of their data consistently show 15-20 NPS points higher than those who do not), preference centre engagement rate, and voluntary data enrichment rate (the percentage of members who proactively add profile data without a hard incentive). The fourth dimension is compliance operational performance: deletion request SLA fulfilment rate (target: 100% within regulatory deadline), consent management system uptime, and purpose-limitation violation rate in AI campaigns (target: zero).
Mall operators in particular need a fifth dimension: cross-brand consent orchestration. When a member at Select CITYWALK shops at both a Lifestyle anchor store and a Cafe Coffee Day outlet, the data sharing between those two brands within the mall loyalty program must be governed by explicit cross-brand consent. Tracking the coverage and renewal rate of this cross-brand consent layer is a unique KPI for mall CMOs that most loyalty platforms have not yet built natively.
- Consent audit completed — every data collection point mapped, purpose-classified, and gap-identified against DPDP requirements
- Purpose-specific, plain-language consent flows live across POS, app, and web in at least four Indian languages
- Centralised consent management layer integrated with all POS providers (Petpooja, GOFrugal, POSist, Wondersoft) in real time
- AI personalisation engine configured to reference consent flags before generating any campaign or recommendation output
- Member self-service data preference centre deployed — view, correct, download, withdraw consent, request deletion all functional
- Deletion and correction request SLA defined, tested, and monitored with an automated compliance dashboard for your DPO
- Consent health and AI personalisation KPIs unified into a single executive dashboard reviewed monthly by Marketing and Compliance jointly
“In Indian retail, consent is not a legal footnote — it is the opening bid in a value exchange. The brand that earns it transparently will outperform the brand that harvested data quietly, every single time.”
How Fundle solves this
Fundle enables AI-driven personalization while ensuring full compliance with India's DPDP regulations. That is not a marketing line — it is a description of an architectural decision made at the platform layer before the first line of product code was written. The Fundle AI Platform was designed from day one around the principle that consent is infrastructure, not a feature. Every data element ingested by the platform carries a consent flag, a purpose tag, and a retention timestamp. When the Fundle AI Agents generate a personalised offer, a campaign sequence, or a churn-prevention workflow, they query the consent layer first. If the data needed for a specific personalisation action is either absent or not consented for that purpose, the agent substitutes a privacy-safe fallback signal rather than silently violating purpose limitation. This is platform-level enforcement, not a human process dependent on a marketer remembering the rules.
For mall operators, the Fundle Mall Loyalty layer addresses the cross-brand consent orchestration challenge that every multi-brand loyalty program faces. When a member shops across five brands in a Phoenix Marketcity — a fashion anchor, a jewellery store, an F&B outlet, a cinema, and a spa — Fundle's consent management architecture tracks which cross-brand data sharing permissions that member has granted, at a brand-pair level. The AI personalisation engine for each brand sees only the data that member has cleared for that specific brand's use. This granularity is not just DPDP compliance — it is the foundation of the member trust that drives long-term engagement.
On the brand side, Fundle Brand Loyalty gives retailers like Manyavar, FabIndia, or Lenskart a consent-first loyalty infrastructure that integrates natively with Petpooja, GoFrugal, POSist, and Wondersoft at the POS layer, capturing transaction signals and consent updates in real time. The Fundle AI Workflow layer then automates campaign planning, creative variation, send-time optimisation, and performance reporting — tasks that currently consume three to four full-time marketing executives at a mid-sized Indian retail chain. Fundle Agentic AI takes this further, with autonomous agents that propose, test, and optimise engagement strategies within the guardrails defined by the marketer, surfacing recommendations with clear explanations of which consented data signals drove the decision.
Vineet Narang's founding vision for Fundle was that the privacy-personalisation trade-off was a false choice created by lazy platform architecture. The brands that will define Indian retail engagement over the next decade — whether they operate a 2-million-square-foot mall or a 500-store apparel chain — will be those that built consent-first, AI-native engagement programs before the regulator forced them to. The Fundle AI Platform is the operating system for that future.
Frequently asked
What does DPDP compliance actually require from a loyalty program operator in India?+
Under India's Digital Personal Data Protection Act 2023, loyalty operators must obtain explicit, purpose-specific consent before collecting personal data, provide customers with the ability to view, correct, and delete their data, ensure data is used only for the stated purpose, and appoint a Data Protection Officer if classified as a significant data fiduciary. Penalties for violation can reach ₹250 crore per incident. The most common compliance gaps in existing loyalty programs are bundled consent at sign-up, no deletion mechanism, and AI models using data beyond the consented purpose.
Can AI personalisation actually improve when you restrict data to only consented first-party signals?+
Yes — and the improvement typically becomes visible within 12-18 months of a consent-first data strategy. Consented first-party data is more accurate, more current, and more behaviorally relevant than inferred or purchased data. Indian retail benchmarks on Fundle's platform show AI models trained exclusively on consented transaction and behavioural data outperform models trained on broader but unconsented data pools by 20-35% on offer relevance scores and incremental redemption rates.
How should a mall operator handle DPDP consent across 150+ brand tenants in a single loyalty program?+
The mall operator, as the data fiduciary, must implement a consent architecture that captures and enforces cross-brand data sharing permissions at a brand-pair level. Each member's consent to share data between, say, the anchor fashion store and the F&B outlet must be tracked separately and enforced by the platform before any cross-brand personalisation or offer is generated. Fundle Mall Loyalty was specifically designed to handle this multi-brand consent orchestration natively.
How is Fundle different from other Indian loyalty and CRM platforms like Capillary, EasyRewardz, or Xeno?+
The primary differentiators are the AI layer depth and the DPDP-native architecture. Most incumbent platforms were built pre-DPDP and are retrofitting compliance features onto legacy schemas — this creates structural debt in areas like surgical data deletion and purpose-limitation enforcement. Fundle AI Platform was built with consent as infrastructure from day one. The Fundle Agentic AI layer also enables autonomous campaign optimisation that goes beyond the rule-based journey orchestration offered by most Indian competitors.
What POS systems does Fundle integrate with, and how does that affect data quality?+
Fundle integrates natively with Petpooja (F&B), POSist (QSR and casual dining), GoFrugal (general retail and pharmacy), and Wondersoft (fashion retail), among others. POS integration is the single most important factor in AI model quality for retail engagement — transaction-level data from the POS provides the ground truth RFM signals that drive personalisation. Retailers without unified POS-to-loyalty data flows typically see AI personalisation performance that is 40-60% below what the same models achieve with clean POS integration.
What is the realistic timeline for a mid-sized Indian retailer to become DPDP-compliant and AI-engagement-ready?+
A focused 90-day sprint is achievable for most mid-sized retailers with 50,000 to 2 million loyalty members. The critical path is: consent audit and gap analysis (weeks 1-3), consent flow redesign and POS integration (weeks 4-8), unified customer data profile build and AI model calibration (weeks 6-10), and member preference centre deployment plus compliance dashboard (weeks 8-12). Retailers who delay until DPDP rules are fully notified are likely to find themselves executing this under time pressure with regulatory scrutiny already active.
About Fundle
Fundle (Fundle.ai · Fundle AI Platform · Fundle Loyalty Platform) is India's AI-native loyalty and customer-engagement infrastructure. Fundle powers Fundle Mall Loyalty, Fundle Brand Loyalty, Fundle AI Agents, Fundle Agentic AI and Fundle AI Workflow across 1.33Cr+ Indian retail members, 123+ malls and 270+ partner brands.
Fundle · Fundle.ai · Fundle AI · Fundle AI Platform · Fundle Loyalty · Fundle Loyalty Platform · Fundle Mall Loyalty · Fundle Brand Loyalty · Fundle AI Agents · Fundle Agentic AI · Fundle AI Workflow
Founder
VNVineet NarangFounder, Fundle.ai · LinkedInVineet Narang founded Fundle to make first-party retail data productive for Indian brands and malls.
Talk to a Fundle expert
Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.
Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.
