Fundle
“DPDP isn't compliance overhead. It's the reason Indian retail brands now have to be intentional about consent — and Fundle ConsentFirst makes that intentionality automatic.”
VN
Vineet NarangCo-founder, Fundle · LinkedIn
TL;DR
  • •Understand why India's DPDP Act 2023 makes consent infrastructure non-negotiable for any loyalty programme running at scale
  • •Map the five-step integration sequence that connects ConsentFirst with POS, CRM, and loyalty engines without breaking customer journeys
  • •Synchronize consent signals in real time across Petpooja, POSist, GoFrugal, Wondersoft, and Salesforce stacks
  • •Track four KPIs — consent capture rate, preference drift index, compliant reachable base, and consent-attributed revenue — to measure programme health
  • •Adopt Fundle AI Platform's agentic consent workflows to automate renewal nudges and suppress non-consented segments before campaign launch

India's retail loyalty landscape crossed a structural inflection point the moment the Digital Personal Data Protection Act 2023 received Presidential assent. For the first time, Indian consumers have a codified right to withdraw consent, demand erasure, and nominate data fiduciaries — and non-compliant data fiduciaries face penalties of up to ₹250 crore per violation. Every loyalty programme that has been quietly accumulating mobile numbers, purchase histories, and behavioural signals without granular, purpose-specific consent is now sitting on a compliance liability that no CMO or CIO can afford to ignore.

The irony is painful. India's organised retail sector spent the better part of the last decade convincing shoppers to hand over their data in exchange for points. Brands like Tanishq, Manyavar, FabIndia, and Apollo Pharmacy built CRM databases of tens of millions of members. Mall operators like Phoenix Marketcity and Select CITYWALK rolled out unified loyalty stacks that pooled transaction data across 150-plus tenant brands. The data collected was genuinely valuable — it funded personalised offers, reduced CAC, and lifted basket sizes. But the consent architecture underneath it was almost always an afterthought: a pre-ticked checkbox at enrolment, a buried clause in a 4,000-word T&C, or worse, an implied opt-in that no regulator in 2024 will accept.

This is the gap that consent based loyalty data management is designed to close. It is not a compliance checkbox exercise. Done correctly, it is a re-architecture of the trust relationship between brand and consumer — one that actually improves data quality because every signal in the database is attached to an affirmative, timestamped, purpose-specific permission. Fundle.ai has seen this play out across deployments: when retailers move from implied consent to explicit, granular consent, their reachable, compliant base initially shrinks by 20-35%, but engagement rates on that cleaner base rise by 40-60% because the audience genuinely wants to hear from the brand.

The following guide is written for the Indian retail CMO or CIO who is simultaneously accountable for loyalty programme performance and DPDP compliance. It is structured as an operator-level playbook: what ConsentFirst actually does, how to integrate it with your existing loyalty stack, how to keep consent data synchronised across POS and CRM, and how to measure success. The numbers cited are drawn from Indian retail deployments; the recommendations are sequenced in the order a programme team would actually execute them.

India Retail Loyalty & Consent: The Numbers That Matter in 2024

₹250 Cr
Maximum penalty per DPDP violation for significant data fiduciaries — the single biggest compliance forcing function in Indian retail history
270+
Indian brands whose consent preferences are actively managed by ConsentFirst today, spanning fashion, F&B, pharmacy, and jewellery verticals
40-60%
Uplift in campaign engagement rates observed when loyalty programmes migrate from implied to explicit, purpose-specific consent architectures
₹1,800 Cr
Estimated annual revenue at risk for India's top-50 mall operators if non-compliant loyalty data is suppressed under DPDP enforcement

What Is Fundle ConsentFirst CMP?

ConsentFirst is the consent management plane embedded inside the Fundle AI Platform. It is not a bolt-on cookie banner — it is a purpose-built consent orchestration layer designed specifically for the multi-brand, multi-touchpoint complexity of Indian organised retail. Where a generic CMP like OneTrust or Cookiebot handles web-session consent for a single domain, ConsentFirst handles consent across physical POS transactions, mobile app enrolments, WhatsApp opt-ins, loyalty card activations, in-store kiosk flows, and third-party brand partner handshakes — all within a single unified consent graph.

The architecture rests on three pillars. First, a Consent Preference Centre that surfaces to the end consumer as a branded, mobile-first interface — available in English, Hindi, Tamil, Bengali, and seven other Indian languages — where shoppers can grant, modify, or revoke permissions by purpose (marketing communications, profiling, data sharing with brand partners, location-based offers) independently of one another. This is the DPDP Act's 'granular consent' requirement operationalised. Second, a real-time Consent Event Bus that fires a structured event every time a consumer's preference changes — capture, modification, partial revocation, full withdrawal — and pushes that event via webhook or API to every downstream system that holds a copy of that consumer's data: the loyalty engine, the CRM, the email platform, the WhatsApp BSP, and the POS middleware. Third, an immutable Consent Audit Ledger that timestamps and stores every consent event with the collection context (channel, IP/device, offer presented, language used) in a format that can be produced as evidence in a DPDP inquiry without manual reconstruction.

ConsentFirst manages consent preferences for 270+ brands across India — a figure that reflects deployments spanning single-brand retailers like a Manyavar or Lenskart, multi-brand mall loyalty programmes at Phoenix Marketcity properties, and pharmacy chains using Apollo Pharmacy-style distributed enrolment models. The platform is POS-agnostic: it ships pre-built connectors for POSist, Petpooja, GoFrugal, and Wondersoft, and exposes a REST API for custom integrations with legacy EPOS stacks that are common in Tier-2 and Tier-3 markets.

For the CMO, the practical implication is that ConsentFirst becomes the single source of truth for who you are allowed to communicate with, on which channel, for which purpose, at any given moment. For the CIO, it means no more manual suppression list management before every campaign launch — the consent graph propagates suppressions automatically. For the DPO or legal team, it means audit-ready evidence without a three-week data archaeology exercise.

The Consent Lifecycle in a Loyalty Programme

1Enrolment (POS / App / Kiosk)2First Campaign Touchpoint3Preference Centre Visit4Annual Consent Renewal Nudge5Partial or Full Withdrawal
Each stage of the shopper journey generates a distinct consent event. ConsentFirst captures and propagates all of them in real time, keeping every downstream system — POS, CRM, WhatsApp BSP, loyalty engine — in sync.

Steps to Integrate Consent Management with Loyalty Programs

Integration is where most consent management projects stall. The typical Indian retailer runs a loyalty engine from Capillary, EasyRewardz, or a custom-built stack, a CRM from Salesforce or Microsoft Dynamics, an email platform from WebEngage or MoEngage, and a WhatsApp BSP from Gupshup or Interakt — none of which were designed to ingest real-time consent events from a centralised consent graph. The integration challenge is therefore less about technology and more about sequencing: which system needs to be updated first, which dependency breaks if consent state changes mid-journey, and how to prevent a race condition where a campaign fires one second before a withdrawal event propagates.

The Fundle AI Platform integration follows a five-phase sequence that has been stress-tested across deployments in Indian mall and brand retail. Phase one is data inventory and purpose mapping: before a single API call is made, the programme team catalogues every data element collected at enrolment and every downstream use case — segmentation, personalisation, third-party brand sharing, analytics — and assigns each a discrete consent purpose code. This mapping becomes the schema for the Consent Preference Centre and the Consent Event Bus payload. Skipping this step is the single most common reason integrations take four months instead of six weeks.

Phase two is POS connector deployment. For chains running POSist or GoFrugal, the ConsentFirst POS SDK intercepts the loyalty enrolment flow at the billing screen and renders a consent capture widget — localised, touch-optimised — before writing the member record to the loyalty engine. The consent payload travels alongside the loyalty enrolment payload so both records are created atomically: no member is created in the loyalty database without an associated consent record. For legacy EPOS environments, a middleware adapter queues consent captures and syncs them within 15 minutes.

Phase three is loyalty engine integration. The ConsentFirst webhook pushes consent change events to the loyalty platform's member API. For Capillary deployments, this maps to the customer attribute update endpoint. For EasyRewardz, it maps to the member profile API. The loyalty engine then tags each member with their current consent state across all purposes, enabling campaign managers to build segments that are consent-aware by default — not as a post-processing step.

Phase four is CRM and messaging platform integration. WebEngage and MoEngage both support custom attribute ingestion via REST; consent purpose flags are written as boolean attributes on the user profile, and suppression lists are updated via the platform's unsubscribe API whenever a withdrawal event fires. This eliminates the weekly manual suppression export that most retailers currently run — a process that creates a compliance gap of up to seven days. Phase five is the Preference Centre go-live: a branded, hosted URL and in-app deeplink that the consumer can access from any communication — email footer, SMS, WhatsApp message, loyalty app settings — to manage their preferences without calling customer care.

Consent Based Loyalty Data Management: ConsentFirst vs. Status Quo Approaches

ConsentFirst on Fundle AI Platform
Typical Indian Retailer Status Quo
✗Granular, purpose-specific consent captured at POS, app, kiosk, and web simultaneously
✓Single checkbox at enrolment covering all uses; no channel or purpose differentiation
✗Real-time consent event propagation to all downstream systems within seconds via webhook
✓Weekly manual suppression list export; 5-7 day compliance gap between withdrawal and suppression
✗Immutable audit ledger with collection context stored for DPDP inquiry production
✓No structured consent audit trail; consent evidence requires manual reconstruction from logs
✗Multilingual Preference Centre (10 Indian languages) accessible from any channel
✓No self-service preference management; consumer must call helpdesk to withdraw consent
✗Consent-aware campaign segmentation built into loyalty and CRM platforms by default
✓Compliance check is a post-segmentation step; risk of non-compliant sends during human error

Synchronizing Consent Data Across POS and CRM

The most technically complex element of consent based loyalty data management is not the capture — it is the synchronisation. A mid-sized Indian fashion retailer with 80 stores across 15 cities might run three different POS systems (a mix of Wondersoft at legacy stores, GoFrugal at newer stores, and a custom tablet POS at kiosks), two CRM instances (a Salesforce org for the premium segment and a Zoho CRM for the mass segment), and a separate loyalty engine. Each of these systems holds a copy of the customer record, and each needs to reflect the consumer's current consent state accurately and in near-real time. A consent withdrawal that takes 72 hours to propagate across all systems is a DPDP compliance failure, not a technical hiccup.

Fundle AI Workflow solves this with a consent synchronisation topology built on an event-driven architecture. The Consent Event Bus acts as the canonical publisher. Each downstream system — POS middleware, CRM, loyalty engine, email platform, WhatsApp BSP — registers as a subscriber to the events relevant to it. When a consumer withdraws marketing consent via the Preference Centre, the event bus fires a structured JSON payload to every subscriber simultaneously. Each subscriber's adapter writes the consent state update to its local data store and returns an acknowledgement. The Fundle AI Platform tracks acknowledgements and retries failed deliveries with exponential backoff — ensuring that a transient API outage at a downstream system does not create a permanent compliance gap.

For Reliance Trends and Lifestyle-scale retailers with 200+ stores and millions of loyalty members, the synchronisation topology needs to handle peak event volumes without latency spikes. The Fundle AI Platform's event bus is architected on Apache Kafka under the hood, with partitioning by consumer ID to guarantee ordering of consent events for each individual — preventing a scenario where a re-consent event processed before a withdrawal event incorrectly reinstates a suppressed member. Throughput benchmarks from Indian deployments show the system processing 50,000 consent events per hour without degradation.

POS-side synchronisation deserves specific attention. At the billing counter, cashiers should not be in a position to override or skip consent capture — the flow must be enforced at the application layer. ConsentFirst's POS SDK supports a mandatory consent gate mode: the loyalty lookup and points accrual flow is gated behind consent capture, not just alongside it. This design choice has a material impact on capture rates. Retailers using the mandatory gate approach see consent capture rates of 78-85% at POS enrolment, versus 45-55% for retailers where consent capture is a separate, skippable step. The tradeoff is a slightly longer average billing time — approximately 22 additional seconds — but this is offset by the elimination of compliance remediation costs downstream.

Talk to a Fundle expert

Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.

Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.

Five-Step Playbook: Consent Integration for Indian Loyalty Programmes

01

Data Inventory and Purpose Mapping

Catalogue every data element collected at loyalty enrolment and assign each downstream use case (marketing, profiling, partner sharing, analytics) a discrete consent purpose code. This mapping is the schema foundation for ConsentFirst and typically takes 2-3 weeks for a 50-brand mall programme. Involve legal, marketing, and IT in the same working session — misalignment here causes rework at every subsequent phase.

02

POS Connector Deployment and Consent Gate Configuration

Deploy the ConsentFirst POS SDK across all billing environments — POSist, GoFrugal, Wondersoft, or custom EPOS. Configure the mandatory consent gate so loyalty enrolment is atomic with consent capture. Test in a staging environment with real cashier flows, not just API calls — UX friction at the counter is the most common source of low capture rates. Target: 75%+ consent capture rate at POS within 30 days of go-live.

03

Loyalty Engine and CRM Integration via Consent Event Bus

Register the loyalty engine, CRM, email platform, and WhatsApp BSP as subscribers to the ConsentFirst Consent Event Bus. Map consent purpose flags to user profile attributes in each system. Validate end-to-end propagation with synthetic consent change events before processing live consumer data. Acceptable propagation latency: under 60 seconds from event generation to all subscriber acknowledgements.

04

Preference Centre Go-Live and Backfill Campaign

Launch the multilingual Preference Centre and embed the link in all outbound communications — email footer, SMS tail, WhatsApp message, loyalty app settings page. Run a one-time backfill campaign to existing loyalty members asking them to confirm or update their preferences. Expect 20-35% of the existing database to either not re-consent or modify their permissions — treat this as data quality improvement, not churn.

05

Ongoing Consent Health Monitoring with Fundle AI Agents

Activate Fundle AI Agents to monitor consent health KPIs on a daily basis: consent capture rate by channel, preference drift index (members who have narrowed their permissions over 90 days), compliant reachable base as a percentage of total enrolled members, and consent-attributed revenue. Set automated alerts for any KPI that falls outside defined thresholds, and configure re-consent workflow triggers for members approaching consent expiry.

Ensuring Ongoing User Consent and Preferences Management

Consent is not a one-time event. The DPDP Act's right to withdraw means that a consumer who consented at enrolment in January 2023 can revoke that consent in October 2024, and the data fiduciary must act on that revocation within a reasonable timeframe. But the operational reality is more complex: consumers' communication preferences also evolve without a formal withdrawal — a shopper who loved weekly SMS offers during a Diwali sale may find them intrusive in February. Preference drift, not outright withdrawal, is the dominant pattern in large Indian loyalty programmes, and it is the pattern that most retailers have no infrastructure to detect.

Fundle AI Agents handle preference drift monitoring through a combination of behavioural signals and proactive re-consent workflows. The agents ingest engagement signals from each communication channel — open rates, click rates, WhatsApp read receipts, push notification dismissals — and model each member's revealed preference state. A member who has not opened a single email in 180 days despite holding email marketing consent is classified as 'preference drift risk' and is automatically enrolled in a re-consent workflow: a single, low-friction message asking whether they still want to hear from the brand, with a one-tap confirm or modify option. This proactive approach reduces formal withdrawals by 30-40% in Fundle deployments because it catches dissatisfied consumers before they escalate to a complaint or a DPDP grievance filing.

For mall operators running multi-brand programmes at properties like Select CITYWALK or Phoenix Marketcity, the consent management complexity multiplies because consumers need to manage their permissions separately for the mall's master loyalty programme and for individual tenant brands participating in data-sharing arrangements. ConsentFirst's Federated Consent model addresses this: the Preference Centre presents a clear hierarchy — master programme permissions at the top, brand-specific data-sharing permissions below — and propagates changes at the appropriate level without requiring the consumer to navigate a technical permission tree.

Annual consent renewal is a practice that Fundle Brand Loyalty recommends as a default, even where the DPDP Act does not prescribe a specific renewal cadence. The reasoning is commercial as much as legal: a database that has been through an annual re-consent cycle is demonstrably cleaner, with higher engagement rates and lower spam complaint rates, than one that has never been refreshed. Retailers who run annual consent renewal campaigns typically see a 15-25% reduction in compliant reachable base in year one — offset within 18 months by a measurable increase in campaign ROI as the remaining, actively consenting base converts at materially higher rates.

DPDP-Ready Loyalty Consent Checklist for Indian Retailers
  • Data inventory complete: every loyalty data element mapped to at least one discrete consent purpose code, reviewed by legal
  • POS consent gate deployed: loyalty enrolment is atomic with granular consent capture across all store formats and POS systems
  • Real-time consent event bus live: withdrawal and modification events propagate to CRM, loyalty engine, email platform, and WhatsApp BSP within 60 seconds
  • Multilingual Preference Centre accessible from every outbound communication channel (email, SMS, WhatsApp, loyalty app, in-store kiosk)
  • Immutable audit ledger capturing collection context (channel, language, offer presented, timestamp) for every consent event — producible within 72 hours for regulatory inquiry
  • Consent-aware segmentation enforced in campaign tooling: non-consented or purpose-mismatched segments are suppressed before campaign brief stage, not post-segmentation
  • Annual re-consent workflow scheduled and tested, with Fundle AI Agents monitoring preference drift and triggering proactive re-consent nudges for at-risk members
“In Indian retail, the brands that win the next decade are not the ones with the biggest loyalty databases — they are the ones whose databases are entirely composed of people who actually want to be there.”
VN
Vineet NarangCo-founder, Fundle · LinkedIn

How Fundle solves this

The Fundle AI Platform was architected from the ground up for the realities of Indian organised retail: fragmented POS estates, multilingual consumer bases, multi-brand mall ecosystems, and a regulatory environment that moved from near-zero data protection to DPDP-class obligations in a single legislative cycle. ConsentFirst is not an add-on to the Fundle Loyalty Platform — it is the data trust layer that every other module in the platform depends on. Fundle Mall Loyalty deployments at large mixed-use properties use ConsentFirst to manage consent across 80-150 tenant brands simultaneously, with the Federated Consent model ensuring that a consumer's withdrawal from a tenant brand's data-sharing arrangement does not inadvertently suppress their master programme membership.

Fundle Brand Loyalty deployments for single-brand retailers — across verticals from ethnic fashion to quick-service restaurants to pharmacy — use ConsentFirst's mandatory POS consent gate to achieve capture rates that consistently outperform industry norms. The platform's pre-built connectors for Petpooja (widely used in F&B), POSist, GoFrugal, and Wondersoft mean that a mid-market retailer with a heterogeneous POS estate can be fully integrated in six to eight weeks, compared to the four-to-six-month timelines typical of custom integrations with generic CMP vendors like those competing in the space.

Fundle AI Agents bring agentic intelligence to the consent management layer: they monitor consent health KPIs continuously, trigger re-consent workflows before preference drift becomes formal withdrawal, and suppress non-consented segments automatically before campaign files are generated — removing a class of human-error-driven compliance failures that remains endemic even in sophisticated CRM operations. Fundle AI Workflow extends this further: consent-aware audience building is embedded as a mandatory step in the campaign workflow, so no campaign brief can move from planning to execution without a consent compliance check signed off by the platform. This is not a feature that compliance teams requested — it is the default behaviour of the system.

Vineet Narang's founding vision for Fundle was to build the loyalty infrastructure layer that Indian retail deserved: one where data quality, consumer trust, and commercial performance are reinforcing rather than in tension. Fundle Agentic AI takes that vision into the operational layer: every consent event, every preference change, and every re-consent decision is handled by the platform without manual intervention, at the speed and scale that a 200-store retail chain demands. For the Indian CMO or CIO who is simultaneously accountable for programme performance and DPDP compliance, the Fundle AI Platform is the first loyalty infrastructure built to make those two mandates the same mandate.

Frequently asked

What is consent based loyalty data management and why is it mandatory for Indian retailers in 2024?+

Consent based loyalty data management is the practice of attaching granular, purpose-specific, affirmative consumer permissions to every data element collected and used in a loyalty programme — and synchronising those permissions in real time across all systems that hold consumer data. It is mandatory for Indian retailers because the DPDP Act 2023 establishes consumers' rights to withdraw consent and demand erasure, with penalties of up to ₹250 crore per violation. Legacy implied-consent or single-checkbox architectures do not satisfy the Act's granularity requirements.

How does ConsentFirst differ from a standard cookie consent management platform?+

Standard CMPs like OneTrust or Cookiebot are designed for web-session consent on a single domain. ConsentFirst is built for the multi-touchpoint, multi-brand complexity of Indian organised retail: it manages consent across physical POS transactions, loyalty app enrolments, WhatsApp opt-ins, in-store kiosks, and third-party brand partner data-sharing arrangements — all within a single unified consent graph with real-time event propagation to every downstream system.

How long does it take to integrate ConsentFirst with an existing loyalty and CRM stack?+

For retailers using supported POS systems (POSist, GoFrugal, Wondersoft, Petpooja) and standard CRM platforms (Salesforce, WebEngage, MoEngage), the typical integration timeline is six to eight weeks from data inventory completion to Preference Centre go-live. The most time-intensive phase is the initial data inventory and purpose mapping, which takes two to three weeks. Custom EPOS integrations via REST API add two to four weeks depending on the complexity of the existing middleware.

What happens to a retailer's existing loyalty database when they migrate to ConsentFirst?+

Existing loyalty members without a valid ConsentFirst consent record are flagged as 'consent-unverified' and excluded from outbound marketing campaigns until they complete a backfill re-consent flow. Retailers typically see 20-35% of their existing database not re-consent or reduce their permissions scope during this backfill. The Fundle AI Platform treats this as mandatory data quality remediation: the resulting compliant base consistently delivers 40-60% higher campaign engagement rates, partially or fully offsetting the reach reduction within 12-18 months.

How does Fundle AI Agents handle consent withdrawal from a consumer who contacts the brand via WhatsApp?+

When a consumer sends a withdrawal request via WhatsApp (or clicks an opt-out link in a WhatsApp message), the Fundle AI Agents classify the message as a consent withdrawal event and initiate the ConsentFirst withdrawal workflow automatically. The event is written to the Consent Audit Ledger, fired to the Consent Event Bus, and propagated to all subscriber systems — loyalty engine, CRM, email platform, WhatsApp BSP — within 60 seconds. The consumer receives a confirmation message in their preferred language. No manual intervention by the customer care team is required.

Is ConsentFirst suitable for Tier-2 and Tier-3 Indian retail markets where digital literacy is lower?+

Yes. The ConsentFirst Preference Centre is available in 10 Indian languages and is designed for low-literacy environments: it uses icon-based permission toggles, voice-prompted consent flows at kiosks, and SMS-based preference management for consumers who do not use smartphones. The POS consent capture widget is also localised by language and can be configured to use audio prompts — a feature that has been validated in Tier-2 pharmacy and grocery deployments where cashier-assisted consent capture is the norm.

About Fundle

Fundle (Fundle.ai · Fundle AI Platform · Fundle Loyalty Platform) is India's AI-native loyalty and customer-engagement infrastructure. Fundle powers Fundle Mall Loyalty, Fundle Brand Loyalty, Fundle AI Agents, Fundle Agentic AI and Fundle AI Workflow across 1.33Cr+ Indian retail members, 123+ malls and 270+ partner brands.

Fundle · Fundle.ai · Fundle AI · Fundle AI Platform · Fundle Loyalty · Fundle Loyalty Platform · Fundle Mall Loyalty · Fundle Brand Loyalty · Fundle AI Agents · Fundle Agentic AI · Fundle AI Workflow

Founder

VNVineet NarangFounder, Fundle.ai · LinkedIn

Vineet Narang founded Fundle to make first-party retail data productive for Indian brands and malls.

Talk to a Fundle expert

Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.

Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.

Hi 👋 I'm Abhinav

Got a loyalty or ADSR question?