“We didn't build Fundle to sell software. We built it to make first-party data productive — every campaign, every store, every shopper, every day.”
- •Understand why India's DPDP 2023 Act makes legacy loyalty data practices legally and commercially untenable
- •Discover how ConsentFirst, embedded inside Fundle's loyalty workflow, turns consent from a checkbox into a revenue signal
- •See how AI-powered loyalty automation software can personalise at scale without breaching data minimisation rules
- •Map the five-step playbook retail CMOs need to retrofit DPDP compliance into existing loyalty campaigns
- •Measure the KPIs that prove privacy-first automation grows wallet share, not just opt-in counts
Loyalty program automation tools India-wide have spent the last decade optimising for one thing: frequency. Send more, segment harder, retarget faster. The playbook worked when customer data flowed freely between POS systems, CRM databases, and marketing clouds with minimal regulatory friction. That era ended on August 11, 2023, the day India's Digital Personal Data Protection Act received Presidential assent. When the rules around how brands collect, store, and act on personal data change at the legislative level, the entire architecture of loyalty automation changes with them.
The stakes for retail CMOs are not abstract. A multi-brand mall running a shared loyalty programme across 120 tenant brands — think Phoenix Marketcity or Select CITYWALK — may be processing data on three to five million registered members. Under DPDP 2023, every one of those members is a 'Data Principal' with enforceable rights: the right to access their data, correct it, nominate a successor, and withdraw consent at any time. Non-compliance penalties can reach ₹250 crore per instance. For a loyalty programme built on mass-blast SMS campaigns and third-party data enrichment, that is not a compliance nuance — it is an existential risk.
The irony is that the same AI capabilities that make modern loyalty automation powerful — predictive churn models, next-best-offer engines, real-time personalisation — are precisely the capabilities that require the richest first-party data. The brands that win under DPDP are not the ones that collect less data; they are the ones that collect the right data with explicit, granular, auditable consent. This is where the architecture of loyalty platforms must evolve from a 'collect everything, ask later' model to a 'ConsentFirst, personalise intelligently' model. Fundle was built with that principle at its core, and its ConsentFirst module is the industry's clearest answer to the compliance-personalisation tension.
This article is written for retail CMOs and loyalty programme managers who operate at scale — across malls, large retail chains like Reliance Trends, Lifestyle, Pantaloons, or Manyavar, and F&B brands like Cafe Coffee Day. The goal is to give you a clear-eyed view of what DPDP demands, what good compliance looks like inside a loyalty workflow, and how AI-powered loyalty automation software can be structured to grow revenue while staying on the right side of the law.
India Loyalty + DPDP: The Numbers That Matter
Overview of India's DPDP 2023 Privacy Requirements
The Digital Personal Data Protection Act 2023 is not a GDPR clone, and retail operators who treat it as one will get the architecture wrong. GDPR allows six legal bases for processing; DPDP narrows this significantly for commercial entities. For a loyalty programme, the operative basis is 'consent' — freely given, specific, informed, and unambiguous. Legitimate interest, the GDPR loophole that powered most retargeting stacks in Europe, does not exist in the same form under DPDP. This means that the moment a Tanishq store manager captures a customer's mobile number at the point of sale and feeds it into a centralised CRM for campaign automation, that action requires prior, documented consent.
The Act introduces the concept of a 'Consent Manager' — a DPDP-registered entity through which individuals can give, manage, and withdraw consent across multiple Data Fiduciaries. For a mall with 80 to 150 tenant brands, this has profound structural implications. A member who joins the Phoenix Marketcity loyalty programme is not blanket-consenting to data sharing with every brand inside the mall. Each brand's use of that data — whether it is Apollo Pharmacy sending a personalised health promotion or FabIndia triggering a seasonal weave campaign — requires a distinct consent record tied to a specific purpose.
Data localisation under DPDP requires that personal data of Indian citizens be stored on servers within India, which immediately disqualifies several globally-hosted CRM and loyalty SaaS platforms that process data on shared international infrastructure. This is a procurement filter that retail CIOs need to apply rigorously when evaluating any loyalty automation vendor. Data Principal rights — access, correction, nomination, grievance, and erasure — must be honoured within timeframes the government will specify in rules, expected to be 30 to 72 hours for critical requests based on draft guidance.
For workflow automation for loyalty programmes, the most operationally complex requirement is purpose limitation. Data collected to award points at the point of sale cannot be silently repurposed to build a look-alike audience for a Facebook retargeting campaign without a fresh consent trigger. This breaks the assumption on which most loyalty CRM pipelines were built — that a single sign-up event creates a perpetual licence to market. Under DPDP, every new purpose needs a new consent layer, and every consent withdrawal must cascade through the entire martech stack in near-real time. That cascade is technically non-trivial; it is where most legacy platforms will fail at audit.
The DPDP Consent Funnel Inside a Loyalty Workflow
Role of ConsentFirst in Compliance and Consent Management
ConsentFirst is not a cookie banner. That distinction matters enormously for retail operators who have watched European e-commerce brands slap a consent pop-up on their homepage and call it compliance. In the context of loyalty programme automation, ConsentFirst is a structured consent management architecture that sits at the ingestion layer of every data touchpoint — POS terminal, mobile app, WhatsApp opt-in, in-store kiosk, and web portal — and creates a time-stamped, immutable consent record before any data enters the processing pipeline.
Fundle's ConsentFirst is India's only DPDP-compliant CMP integrated into loyalty workflows. That is not a marketing claim; it is a technical and regulatory distinction. Other loyalty platforms in the Indian market — Capillary, EasyRewardz, Customer Capital, Almonds.ai — offer consent capture as a feature bolt-on, typically a checkbox at enrolment. ConsentFirst integrates consent as a first-class data object that travels with every customer record through every workflow stage. When a campaign manager at a Lifestyle store builds an automation rule that says 'send a ₹500 voucher to members who have not purchased in 60 days,' ConsentFirst checks whether that member has active consent for promotional communications via the chosen channel — SMS, email, push notification — before the message enters the send queue. Members who have withdrawn consent are silently excluded without manual intervention.
For multi-brand mall operators, ConsentFirst addresses the tenant data-sharing problem that no other platform has solved cleanly. The mall entity — say, a Phoenix Marketcity management company — can configure ConsentFirst to maintain brand-level consent namespaces. A member's consent to receive offers from a food court brand does not propagate to jewellery brands unless that member has explicitly opted in to cross-category sharing. This is not a UX preference; it is a legal requirement under DPDP's purpose limitation principle, and ConsentFirst enforces it at the workflow engine level.
Consent withdrawal is equally important. When a member texts 'STOP' to a loyalty short code or toggles off notifications inside the mall app, ConsentFirst triggers a cascade that removes that member from active campaign queues, flags their record in the CDP, and logs the withdrawal with a timestamp for audit purposes — all within seconds. For brands integrating with POS systems like POSist, GoFrugal, Wondersoft, or Petpooja, ConsentFirst exposes a webhook that pushes consent status updates in real time, ensuring that even in-store staff using POS terminals cannot manually add a withdrawn-consent customer to a campaign list.
ConsentFirst Architecture vs. Bolt-On Consent Features: Side by Side
Integrating Privacy-First Automation in Loyalty Campaigns
The natural anxiety among loyalty programme managers when they first encounter DPDP is that compliance will throttle reach. If consent is required for every channel and every purpose, will campaigns simply die because opt-in rates are too low? The data from markets where privacy-first loyalty has been operating longer — the UK post-GDPR, South Korea under PIPA — suggests the opposite. Brands that build transparent, value-exchange-based consent journeys see higher opt-in quality, longer engagement tenure, and lower unsubscribe rates. The members who consent with full information are the ones who actually want to hear from you.
For Indian retail, the practical integration of privacy-first automation into loyalty campaigns starts at the enrolment moment. Instead of a 'register and agree to everything' flow, a well-designed ConsentFirst enrolment presents the member with a layered opt-in: points accrual (required for programme participation), personalised offers (optional, with a clear value proposition — 'Get offers matched to your style and spend'), cross-brand communications (optional, with specific brand categories listed), and research and profiling (optional, with explicit explanation). Each layer is stored as a distinct consent object. The AI personalisation engine then builds its recommendation model using only the data from consented categories.
AI-powered loyalty automation software that is consent-aware does not simply exclude non-consented members from campaigns. It actively uses consent patterns as a signal. A member who opts into personalised offers but not cross-brand communications is signalling high-intent loyalty to specific categories — that is valuable segmentation data in itself. Fundle's AI Agents can build RFM segments that factor in consent breadth as a proxy for engagement depth, allowing campaign managers to prioritise high-consent members for first-look offers and preview events, creating a genuine VIP tier without requiring demographic data at all.
Workflow automation for loyalty programmes must also handle consent at the trigger layer. When a Manyavar store's POS records a transaction above ₹15,000 and the automation workflow fires a 'thank you' message with a bonus points offer, the workflow must check consent status before sending. If the member consented to WhatsApp but not SMS, the message routes to WhatsApp. If all channels have been withdrawn, the points are credited silently and the message is suppressed — but the transaction is still logged for the member's benefit. This kind of consent-routing logic, which sounds complex, is handled natively inside Fundle AI Workflow's rule engine without any custom development from the brand's IT team.
Talk to a Fundle expert
Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.
Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.
5-Step Playbook: Retrofitting DPDP Compliance into Your Loyalty Automation Stack
Audit Your Existing Consent Records
Pull every member record from your current loyalty database and classify consent status: explicit opt-in with timestamp, implicit enrolment-only, or no consent record. For Indian retail chains with legacy POS integrations — GoFrugal, Wondersoft, POSist — this audit often reveals that 40-60% of the member base has no auditable consent record. These members must be re-permissioned before any automated campaign can touch them under DPDP.
Define Purpose-Specific Consent Layers
Map every way you currently use member data — points accrual, promotional messaging, personalisation, cross-brand sharing, third-party enrichment, analytics — and assign each a distinct consent category. Work with your legal team to write plain-language descriptions of each purpose that a Tier 2 or Tier 3 Indian city consumer can understand. DPDP requires that consent notices be available in languages specified by the government, so plan for regional language versions from day one.
Rebuild Enrolment Flows with ConsentFirst
Redesign your POS, app, and WhatsApp enrolment flows to capture granular consent at the point of registration. For kiosk and in-store enrolments, use QR-code-linked digital consent forms that are pre-integrated with ConsentFirst so the consent record is created before any data enters your CRM. This step requires coordination between your loyalty platform vendor, your POS provider, and your mobile app team — an integration Fundle handles through pre-built connectors.
Configure Consent-Gated Automation Rules
Inside your loyalty workflow engine, add a consent-check step as the first node in every campaign automation. Fundle AI Workflow allows loyalty managers to configure consent gates visually — no coding required. Set up automated re-permissioning journeys for members whose consent has expired or been partially withdrawn: a value-led 'here is what you are missing' message that invites them to re-opt in, sent through the one channel they still accept.
Implement Real-Time Consent Cascade and Audit Logging
Connect your consent management system to every downstream martech tool — your email service provider, SMS gateway, WhatsApp Business API, and push notification platform — via webhooks that push consent status changes in under 60 seconds. Maintain an immutable audit log of every consent event for a minimum of three years. In the event of a DPDP Data Protection Board inquiry, this log is your primary defence. Fundle's ConsentFirst generates this log automatically and exports it in formats accepted by Indian legal processes.
Balancing Personalization and User Privacy in Loyalty Programs
The personalisation-privacy tension is real but it is not zero-sum. The mistake most loyalty managers make is treating consent as a filter that reduces the addressable audience for personalisation. The more sophisticated framing is that consent is a signal that enriches personalisation accuracy. A member who has explicitly told you they want offers on ethnic wear, have opted into WhatsApp, and have consented to profiling based on their purchase history is a far higher-quality personalisation subject than a member whose preferences have been inferred from raw transaction data without any declared intent. You know less about the second member than you think, and your AI model's confidence intervals on their next-best offer are wider than your campaign reports suggest.
For large retail chains — Pantaloons running 400+ stores across India, or Apollo Pharmacy with its loyalty programme spanning pharmacy, diagnostics, and wellness — the personalisation stack needs to operate across product categories with very different consent sensitivities. A member's pharmaceutical purchase history is far more sensitive than their apparel transaction data. Under DPDP, brands like Apollo that collect health-adjacent data must treat it with heightened care, and their loyalty automation must enforce category-level consent gates that prevent health data from bleeding into general retail personalisation models.
The practical answer to the personalisation-privacy balance is progressive profiling. Instead of demanding maximum data at enrolment, well-designed loyalty workflows ask for incrementally more information as the member relationship deepens, each ask paired with a clear value exchange. After three purchases, invite the member to share their size and style preferences in exchange for early access to new collections. After six months, offer double points for completing a preference survey. Each micro-consent event builds the first-party data asset organically, with full documentation, and the result is a richer profile than any inferred dataset could provide — because the member built it themselves.
Fundle AI Agents are specifically designed to orchestrate this progressive profiling at scale, without manual campaign management. An AI Agent monitors each member's engagement cadence, identifies the optimal moment to introduce a preference-capture prompt, selects the right channel and message variant based on past interaction history, and logs the resulting consent update automatically. For a mall loyalty programme managing two million active members, this level of individualised progression is only possible through agentic AI — not rules-based automation or batch-processed segmentation.
- Every member record has a time-stamped, purpose-specific consent record stored as an auditable object — not a binary flag
- Enrolment flows across all channels (POS, app, WhatsApp, kiosk) capture layered consent before data enters the CRM
- Consent withdrawal triggers an automated cascade to all active campaign queues within 60 seconds
- All member personal data is stored on India-based servers; international data transfers are documented and justified
- Data Principal rights requests (access, correction, erasure) can be honoured within regulatory timeframes through a self-serve portal
- AI personalisation and segmentation models are consent-gated — no ineligible data enters model training or inference
- A minimum three-year immutable audit log of all consent events is maintained and exportable for regulatory review
“In India, the brands that treat consent as a growth mechanism — not a compliance cost — will own the next decade of customer loyalty. First-party data you earned is worth ten times the data you scraped.”
How Fundle solves this
The Fundle AI Platform was architected from inception around two non-negotiable constraints: that loyalty automation must be genuinely intelligent at the individual customer level, and that it must never require a brand to choose between personalisation and compliance. These are not competing priorities in Fundle's design — they are the same priority expressed at different layers of the stack. Vineet Narang's founding thesis was that India's retail sector would not get a second chance to build trust with its digital consumers; the architecture of loyalty had to earn that trust from the first interaction.
Fundle Loyalty and Fundle Mall Loyalty are the two primary deployment modes for organised retail. Fundle Mall Loyalty is purpose-built for the multi-tenant mall environment — it handles the brand-level consent namespacing that DPDP requires, the revenue attribution logic that determines which tenant brand 'owns' a given member interaction, and the cross-brand campaign governance that prevents one tenant's aggressive communication strategy from burning out a shared member base. For mall operators running programmes at the scale of Select CITYWALK or Phoenix Marketcity, this governance layer is not optional; it is what makes a shared loyalty programme legally and commercially viable.
Fundle Brand Loyalty serves large retail chains and F&B brands that operate their own independent loyalty ecosystems. Here, Fundle AI Agents power the core personalisation engine: predicting churn at the individual member level 30 to 45 days before it becomes visible in transaction data, triggering re-engagement workflows through consented channels, and dynamically adjusting reward structures based on each member's price sensitivity and category affinity. Fundle Agentic AI goes further — AI Agents can autonomously A/B test reward structures, identify emerging micro-segments within the member base, and escalate anomalies (a sudden drop in consent opt-in rates, for instance, often signals a UX problem in the enrolment flow) to human campaign managers before they become P&L problems.
Fundle AI Workflow is the operational layer where compliance and automation converge. Campaign managers at brands like Lenskart or Manyavar can build end-to-end loyalty journeys — from enrolment through to win-back — using a visual workflow builder that has ConsentFirst gates embedded as native nodes. There is no separate compliance step and no separate personalisation step; they are the same step, designed together. The result is that loyalty programme automation tools India-wide can finally operate at the speed and intelligence that modern retail demands, without accumulating the regulatory liability that has quietly been building under legacy CRM stacks for the past five years.
Frequently asked
What does DPDP 2023 specifically require from a loyalty programme operator in India?+
Under DPDP 2023, loyalty programme operators are classified as Data Fiduciaries and must collect explicit, purpose-specific consent before processing any personal data. They must honour Data Principal rights — access, correction, nomination, and erasure — within regulatory timeframes. They must store personal data on India-based servers, maintain auditable consent records, and ensure that consent withdrawal cascades across all downstream processing systems in near-real time. Penalties for non-compliance can reach ₹250 crore per instance.
How is Fundle's ConsentFirst different from a standard cookie consent banner?+
Fundle's ConsentFirst is a DPDP-native consent management architecture embedded inside the loyalty workflow engine, not a UI element added to a webpage. It captures purpose-specific consent at every data touchpoint — POS, app, WhatsApp, kiosk — stores each consent as an immutable, time-stamped object, and gates every downstream automation rule against live consent status. A cookie banner tells a website visitor what data will be collected; ConsentFirst governs what happens to that data at every stage of the loyalty automation lifecycle.
Can a mall with 100+ tenant brands realistically manage per-brand consent under DPDP?+
Yes, with the right architecture. Fundle Mall Loyalty's ConsentFirst module creates brand-level consent namespaces within the shared member database. A member's consent to receive offers from a food brand does not propagate to a jewellery brand or a pharmacy brand unless the member has explicitly opted into cross-category communications. The mall operator sets the governance rules; ConsentFirst enforces them automatically across all tenant campaign workflows.
Will DPDP compliance reduce the size of our addressable loyalty audience?+
In the short term, a consent audit will likely surface a portion of your member base that has no auditable consent record — often 40 to 60% in legacy programmes. Those members need re-permissioning before you can market to them. However, research from post-GDPR European markets and early Indian data consistently shows that a transparently permissioned member is three to four times more likely to redeem an offer than an inferred-consent member. Compliance shrinks the addressable list but dramatically improves its quality.
How does Fundle's AI personalisation work without breaching data minimisation principles?+
Fundle's AI personalisation engine is consent-gated: it only ingests data categories for which the member has active consent. Rather than treating this as a constraint, Fundle AI Agents treat consent breadth as a personalisation signal in itself — members with wide consent profiles receive richer personalisation, creating a genuine incentive for members to share more. Progressive profiling workflows, orchestrated by Fundle AI Agents, grow the consented data asset over the member lifecycle without requiring maximum disclosure at enrolment.
Does Fundle integrate with Indian POS systems and what does that mean for consent management?+
Fundle has pre-built integrations with major Indian POS and ERP platforms including POSist, GoFrugal, Wondersoft, and Petpooja. For consent management, these integrations include a real-time webhook that pushes consent status updates from ConsentFirst to the POS system, ensuring that even in-store staff cannot trigger a communication to a member who has withdrawn consent. Transaction data from POS systems flows into Fundle's loyalty engine only after consent eligibility is confirmed at the integration layer.
About Fundle
Fundle (Fundle.ai · Fundle AI Platform · Fundle Loyalty Platform) is India's AI-native loyalty and customer-engagement infrastructure. Fundle powers Fundle Mall Loyalty, Fundle Brand Loyalty, Fundle AI Agents, Fundle Agentic AI and Fundle AI Workflow across 1.33Cr+ Indian retail members, 123+ malls and 270+ partner brands.
Fundle · Fundle.ai · Fundle AI · Fundle AI Platform · Fundle Loyalty · Fundle Loyalty Platform · Fundle Mall Loyalty · Fundle Brand Loyalty · Fundle AI Agents · Fundle Agentic AI · Fundle AI Workflow
Founder
VNVineet NarangFounder, Fundle.ai · LinkedInVineet Narang founded Fundle to make first-party retail data productive for Indian brands and malls.
Talk to a Fundle expert
Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.
Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.
