“Segmentation done by humans is 12 cohorts. Segmentation done by Fundle Brain is 1,200 cohorts, each with its own offer, channel and send-time.”
VN
Vineet NarangCo-founder, Fundle · LinkedIn
TL;DR
  • Understand why the DPDP Act fundamentally changes how Indian retailers must collect, store, and use customer data
  • Audit your current consent architecture before your next campaign goes live
  • Build a zero-party and first-party data stack that replaces third-party cookie dependence
  • Measure trust as a business KPI — not just a compliance checkbox
  • Deploy AI-powered engagement that personalises without profiling customers without consent

India's retail sector is sitting on a data time bomb — and most marketing heads haven't heard the tick yet. The Digital Personal Data Protection Act, 2023 (DPDP Act) is not a future concern. It is law. With rules expected to be notified in 2024-2025, every brand operating a loyalty programme, CRM, or customer engagement platform in India must now treat consumer consent as a hard business requirement, not a legal afterthought tucked into a privacy policy PDF that nobody reads.

The stakes are real. India has over 900 million smartphone users and retail e-commerce alone crossed ₹1.7 lakh crore in FY24. Organised retail — malls, hypermarkets, fashion chains, QSR aggregators — is growing at 12-14% annually. Every one of these transactions generates a data footprint: purchase history, location, payment preference, browsing behaviour, loyalty point redemption. The brands and mall operators who harvest this data without explicit, informed, granular consent are now exposed to penalties up to ₹250 crore per violation under the DPDP Act. That is not a rounding error. That is a board-level crisis.

Yet the instinct of most retail marketing heads is still to collect everything and sort it out later. Third-party data brokers, harvested mobile numbers from bill prints, email scraping from competition databases — these are still commonplace. The irony is that this approach produces worse business outcomes anyway. Studies consistently show that consumers who opt in voluntarily and understand how their data is used have 2-3x higher lifetime value compared to passively acquired contacts. Privacy is not the enemy of personalisation. Done right, it is the engine of it.

This is precisely the problem that a modern customer engagement platform with data privacy compliance is designed to solve. Fundle was built from the ground up with this thesis: that in India's mobile-first, trust-scarce consumer market, brands that earn explicit consent and honour it consistently will outperform brands that extract data covertly. The following analysis unpacks why privacy-first engagement is now a strategic imperative, what good looks like in practice, and how the right platform can make compliance a competitive advantage rather than a cost centre.

India Retail Data Privacy: The Numbers That Matter

₹250 Cr
Maximum penalty per violation under India's DPDP Act, 2023 — a board-level financial risk for non-compliant retail brands
270+
Indian retail clients for whom Fundle processes and stores consumer data with strict DPDP compliance, enhancing brand trust
67%
Indian consumers who say they are more likely to buy from a brand that clearly explains how their data is used (IAMAI, 2023)
2.8x
Higher email open rates observed when consent is explicitly captured at enrolment vs. passively harvested contact lists

Consumer Privacy Concerns in Indian Retail Are No Longer Fringe

Walk into any Phoenix Marketcity or Select CITYWALK and you will see loyalty enrolment happening at every POS counter. The cashier asks for a mobile number. The customer gives it. Nobody explains what happens next — whether that number gets shared with a data broker, sold to a partner brand, or used to push WhatsApp messages at 11pm. This is the current standard operating procedure for a significant chunk of Indian organised retail, and it is about to become legally untenable.

The DPDP Act introduces four non-negotiable pillars that every customer engagement software for retail must now accommodate: purpose limitation (data collected for one reason cannot be used for another without fresh consent), storage limitation (data must be deleted when the purpose is fulfilled), data principal rights (consumers can access, correct, and erase their data on request), and consent manager architecture (consent must be granular, revocable, and auditable). None of these are optional. None of them can be satisfied by a generic 'I agree to terms and conditions' checkbox.

The consumer anxiety is real and measurable. A 2023 LocalCircles survey found that 74% of Indian urban consumers had received marketing communications from brands they never directly interacted with — a clear signal of data being shared without consent across retail ecosystems. Brands like Tanishq, FabIndia, and Manyavar have built decades of consumer trust on product authenticity and cultural resonance. That trust is now being tested at the data layer. A single WhatsApp spam incident traced back to a loyalty programme data leak can undo years of brand equity investment.

Mall operators face a compounded version of this problem. A mall like Phoenix Marketcity Mumbai hosts 200+ brand tenants. Each of those brands may have its own loyalty stack — Capillary for one, EasyRewardz for another, a homegrown SQL database for a third. The consumer's data exists in fragmented silos across all of them. When a mall wants to run a unified engagement campaign — say, a Diwali points multiplier across all tenants — whose consent covers that cross-brand data share? Nobody has a clean answer today. That gap is exactly where regulatory exposure lives.

The Consent-First Engagement Funnel in Indian Retail

Anonymous Footfall — 100% of visitorsSoft Touchpoint (Wi-Fi login, QR scan) — 42% capturedLoyalty Enrolment with Granular Consent — 28% enrolledActive Consented Engagers (email + WhatsApp + push) — 18% active
Converting anonymous footfall into consented, high-value loyalty members requires a deliberate, privacy-safe data collection architecture at every stage.

Strategies for Privacy-First Engagement That Actually Drive Revenue

Privacy-first does not mean engagement-light. The brands getting this right are seeing higher engagement rates, not lower ones, because they are talking to people who actually want to hear from them. Here is what the playbook looks like in India's retail context.

Zero-party data collection is the starting point. Zero-party data is what a consumer intentionally and proactively shares — preferences, wishlist items, lifestyle choices, upcoming occasions. A Lifestyle or Pantaloons store can capture this through a well-designed onboarding quiz at enrolment: 'Are you shopping for yourself or gifting?', 'Which categories interest you most?', 'Do you want to be notified about sales or new arrivals?' Each answer is a consent signal and a personalisation input simultaneously. No inference required. No third-party enrichment needed. The data is clean, consented, and immediately actionable.

Granular consent management is the second pillar. A single consent checkbox is legally insufficient and commercially counterproductive. The right architecture gives consumers separate toggles for transactional communications (receipts, order confirmations), promotional communications (offers, sales), personalised recommendations, and third-party partner communications. This is not just a compliance feature — it is a trust signal that converts browsers into buyers. Apollo Pharmacy, for instance, operates in a category where health data sensitivity is acute. A consent screen that explicitly says 'Your purchase history will only be used to suggest relevant health products and will never be shared with insurance partners without your separate permission' is worth more than any discount offer.

First-party data activation through owned channels is the third leg. With third-party cookies effectively dead and telecom data sharing under scrutiny, brands must build direct relationships. This means investing in branded apps, WhatsApp Business API integrations with proper opt-in flows, and loyalty programme touchpoints that create value exchange — points, early access, personalised offers — in return for explicit data sharing. Cafe Coffee Day's loyalty ecosystem, for example, could generate significant incremental revenue if each app interaction was tied to a consented preference profile rather than a generic broadcast campaign.

Finally, data minimisation discipline is non-negotiable. The instinct to collect everything 'just in case' is expensive in three ways: storage costs, security exposure, and regulatory liability. Brands should audit their current data collection against actual use cases. If a fashion retailer like Reliance Trends is collecting date of birth but never actually triggering a birthday campaign, that field is pure liability with zero return. Pruning unused data fields and implementing automatic deletion schedules for inactive customer records is both a compliance act and an engineering efficiency.

Privacy-First Engagement vs. Conventional Data Extraction: Business Outcomes

Conventional Data Extraction Approach
Privacy-First Engagement Approach
Bulk mobile number harvesting from bill prints; no explicit consent captured
Granular opt-in at enrolment with channel-specific consent toggles; fully auditable
Unsubscribe rates of 18-25% on broadcast campaigns; high spam complaints
Unsubscribe rates below 6% on permission-based campaigns; 2.4x higher open rates
Single monolithic consent assumed for all marketing uses across partner brands
Separate consent for own-brand vs. partner communications; consumer controls each toggle
Data retained indefinitely; no deletion policy; high breach exposure surface
Automated retention schedules; deletion workflows triggered at consent withdrawal or account dormancy
Regulatory fine exposure up to ₹250 crore per violation under DPDP Act
Documented consent audit trail; Data Protection Officer workflow; near-zero regulatory exposure

How Fundle Ensures Consent and Transparency at Every Touchpoint

A customer engagement platform with data privacy compliance is not built by adding a consent checkbox to an existing CRM. It requires consent architecture to be load-bearing infrastructure — present at every data collection point, queryable at any time, and reversible in real time. This is not a feature. It is a design philosophy.

Fundle's approach begins at the identity layer. When a consumer enrolls in a Fundle-powered loyalty programme — whether at a mall kiosk, a brand app, or a WhatsApp chatbot — the system captures structured consent against each data category and each communication channel. These consent records are stored immutably with timestamps, channel identifiers, and consent version numbers. When the DPDP Act's data principal access rights kick in, a brand using Fundle can respond to a consumer data access request in under 72 hours — not 30 days of manual data archaeology.

The platform's consent manager architecture allows brands to present consumers with a transparent data dashboard: what data is held, how it is being used, which partners (if any) have access, and a one-tap option to revoke any or all consents. This is not a compliance page buried in settings. In a well-implemented Fundle deployment, it is surfaced proactively — in post-purchase confirmation messages, in quarterly 'your privacy summary' push notifications, and in loyalty tier upgrade communications. The philosophy is that transparency, when it is visible and proactive rather than hidden and reactive, converts consumers from passive data subjects into active brand advocates.

For mall operators running unified loyalty programmes across multiple tenant brands, Fundle Mall Loyalty provides a federated consent model. A consumer enrolling in the mall's master loyalty programme sees exactly which tenant brands will receive their engagement data and for what purposes. They can opt into the mall-wide programme while excluding specific tenants. This level of granularity was previously architecturally impossible on legacy platforms like older Capillary or EasyRewardz deployments, which treated mall-wide consent as a binary on/off switch. The result for mall operators is a consent database they can actually use for cross-tenant campaigns without legal exposure — and consumer trust scores that show up in Net Promoter Score improvements of 12-18 points within 12 months of a Fundle implementation.

Examples of Trust Building via Compliance in Indian Retail

Theory is useful. Proof is better. Across Fundle's client base, a consistent pattern emerges: brands that invest in consent infrastructure and communicate that investment to consumers see measurable trust and commercial payoffs within 6-18 months.

Consider the fashion jewellery category, where Tanishq has long set the benchmark for aspirational trust. Jewellery purchases are deeply personal — tied to occasions, family milestones, financial planning. A consumer who receives a WhatsApp message about a Dhanteras offer and knows with certainty that their purchase history was used only to determine offer relevance — not shared with a gold loan provider or insurance aggregator — is far more likely to engage. The consent architecture is invisible to the consumer in the best possible way: they just feel respected. Brands operating in categories with high emotional stakes — healthcare (Apollo Pharmacy), personal finance (insurance riders embedded in Manyavar packages), or child products — see the trust dividend most sharply.

For mall operators, trust building via compliance shows up in membership renewal rates. A consumer who receives an annual 'here is what we did with your data this year' summary — X personalised offers sent, Y redeemed, your data was not shared with any external party — is significantly more likely to renew an annual premium loyalty membership. This is a learnable lesson from banking and fintech, where HDFC Bank and Zerodha have built data transparency into their consumer communication calendars. Mall retail is 3-4 years behind fintech on this curve, but the adoption path is clear.

POS software partners — GoFrugal, POSist, Petpooja, Wondersoft — are increasingly being asked by brand clients to embed consent capture at the billing stage. A consumer checking out at a Pantaloons store can now, via a Fundle-connected POS integration, receive a consent prompt on the payment terminal screen: 'Join our loyalty programme and get 2% cashback — here is exactly what we will and will not do with your data.' The click-through rate on this consent-transparent prompt is 34% higher than a generic 'join our loyalty programme' CTA in pilot deployments. Transparency converts.

Talk to a Fundle expert

Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.

Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.

5-Step Playbook: Building a Privacy-First Customer Engagement Programme in Indian Retail

01

Consent Architecture Audit

Map every current data collection point — POS, app, web, WhatsApp, third-party data buys — against DPDP Act requirements. Identify gaps in consent granularity, storage limitation policies, and data principal rights workflows. This audit typically takes 3-4 weeks and should involve both legal and engineering stakeholders. Output: a data inventory with risk ratings.

02

Zero-Party Data Collection Design

Replace passive data harvesting with intentional value exchange. Design enrolment flows that ask customers what they want — preferences, occasion calendars, communication channel choices — in return for loyalty points, personalised benefits, or exclusive access. Each question is a consent act and a personalisation input. Pilot with one brand or one mall zone before full rollout.

03

Consent Manager Integration

Implement a consent management layer that stores structured, versioned, revocable consent records for every customer. Integrate this with your CRM, marketing automation, and POS systems so that communication suppression is automatic when consent is withdrawn. Platforms like Fundle AI Platform have this built in; legacy platforms will need custom middleware.

04

Consumer-Facing Transparency Dashboard

Build or activate a self-service privacy portal where consumers can view their data, see how it has been used, adjust consent toggles, and request deletion. Surface this dashboard proactively in post-purchase communications and loyalty app onboarding — not just in a footer link. Brands that do this proactively see a 40% reduction in consumer privacy complaints and a measurable NPS lift.

05

Ongoing Compliance Monitoring and Consent Refresh

Consent is not a one-time event. Implement a consent refresh workflow that re-engages dormant members every 12-18 months with a transparent reminder of their data choices and an opportunity to update preferences. Track consent health metrics — active consent rate, channel opt-in mix, withdrawal rate — as first-class KPIs alongside campaign metrics. Annual data deletion sweeps for non-consented records.

KPIs to Track for a Privacy-First Customer Engagement Platform in India

If privacy is a strategic investment and not just a compliance cost, it needs to be measured like one. Most retail marketing dashboards track open rates, conversion rates, and ROAS. Almost none track consent health, data quality scores, or trust-correlated retention metrics. That needs to change.

The primary KPI tier should include: Active Consent Rate (what percentage of your database has valid, current, channel-specific consent), Consent Withdrawal Rate (the canary in the coal mine — a rising withdrawal rate signals that consumers feel their data is being misused), and Data Quality Score (what percentage of your customer records have complete, verified, consented data fields versus inferred or stale data). These are health metrics for your engagement engine.

The secondary KPI tier links consent to commercial outcomes: Consented Segment vs. Non-Consented Segment ARPU comparison (this gap should widen over time as you invest in consent-based personalisation), Campaign Performance by Consent Channel (WhatsApp opted-in vs. SMS opted-in vs. email opted-in — each channel will show different engagement economics), and Loyalty Programme Renewal Rate segmented by consumers who have accessed their privacy dashboard versus those who have not. Brands that can show their board a chart where privacy transparency correlates with renewal rate have an easy business case for continued compliance investment.

Long-term, the most important metric is Trust-Adjusted Lifetime Value — an approximation of LTV that weights heavily for customers who have voluntarily deepened their consent over time (for example, adding a new channel opt-in or completing a preference update). These are your highest-intention customers. In Fundle deployments across Indian retail and mall clients, this segment consistently shows 2.5-3x LTV compared to minimally consented members. That number alone justifies the entire privacy infrastructure investment.

Pre-Launch Privacy Compliance Checklist for Indian Retail Engagement Programmes
  • Conduct a full data inventory mapping every collection point to its DPDP Act consent and purpose limitation requirement
  • Implement granular, channel-specific consent capture at all enrolment touchpoints including POS, app, web, and WhatsApp
  • Integrate a consent management layer that automatically suppresses communications when consent is withdrawn or expires
  • Build and activate a consumer-facing privacy dashboard accessible within 2 taps from the loyalty app home screen
  • Establish a Data Protection Officer (DPO) workflow with documented SLAs for consumer data access and deletion requests
  • Implement automated data deletion schedules for inactive records and for data categories whose purpose has been fulfilled
  • Define and track consent health KPIs — active consent rate, withdrawal rate, consent refresh completion rate — on your marketing dashboard
“In India, the brands that will win the next decade are not those with the biggest data lakes — they are the ones consumers actually trust to hold their data. Consent is the new currency of retail growth.”
VN
Vineet NarangCo-founder, Fundle · LinkedIn

How Fundle solves this

Fundle was purpose-built for exactly this inflection point in Indian retail: the moment when personalisation ambitions collide with privacy obligations and brands need an AI platform that handles both without compromise. The Fundle AI Platform is not a legacy CRM retrofitted with a consent checkbox. It is a ground-up architecture where consent is the primary key around which every customer data record is organised.

Fundle Loyalty — deployed across both standalone retail brands and mall ecosystems — ships with a built-in consent manager that supports granular, channel-level, purpose-specific consent capture. Every data field has an associated consent record. Every communication trigger checks consent validity before dispatch. This is not a manual compliance workflow. It is an automated, auditable system that operates at the speed of modern retail — processing millions of transactions and consent events daily without human intervention. Fundle processes and stores consumer data with strict DPDP compliance, enhancing brand trust across 270+ Indian clients — from fashion retailers and jewellery brands to QSR chains and mall operators.

For mall operators running complex multi-tenant loyalty ecosystems, Fundle Mall Loyalty provides the federated consent architecture described earlier in this article: consumer-level control over which tenant brands receive engagement data, with full auditability for the mall operator. For individual retail brands, Fundle Brand Loyalty delivers the same consent infrastructure with category-specific personalisation models — different consent and data use logic for a healthcare brand like Apollo Pharmacy versus a fashion brand like Lifestyle or a café chain like Cafe Coffee Day.

The intelligence layer — Fundle AI Agents and Fundle Agentic AI — operates strictly within consented data boundaries. When a Fundle AI Agent generates a personalised offer or a next-best-action recommendation, it references only data fields for which the consumer has given active, current consent. There is no shadow inference from non-consented behavioural signals. The Fundle AI Workflow engine automates consent refresh campaigns, suppression list management, and deletion request processing — turning what would be a manual compliance burden into a zero-touch operational system. Vineet Narang's founding vision was simple: that in India's consumer market, the brands that respect people's data will earn their business for life. Every product decision at Fundle is built backward from that principle.

Frequently asked

What is the DPDP Act and how does it affect Indian retail loyalty programmes?+

The Digital Personal Data Protection Act, 2023 is India's primary data privacy legislation. It requires brands to collect explicit, granular, revocable consent before processing personal data, limit data use to stated purposes, honour consumer rights to access and delete their data, and implement technical safeguards. Retail loyalty programmes that collect mobile numbers, purchase history, and behavioural data without documented consent face penalties up to ₹250 crore per violation. Any loyalty or CRM platform used in India must now be DPDP-compliant by design.

How is a customer engagement platform with data privacy compliance different from a standard CRM?+

A standard CRM is optimised for data storage and campaign execution. A customer engagement platform with data privacy compliance — like Fundle — has consent management as load-bearing infrastructure: every data record is linked to a structured consent record, every communication checks consent validity before dispatch, consumer data access and deletion requests are automated, and the system maintains an immutable audit trail for regulatory review. These are architectural differences, not configuration options.

Can a privacy-first approach actually improve campaign performance, or does it reduce reach?+

It improves performance materially. Consented segments consistently show 2-3x higher open rates, lower unsubscribe rates, and higher conversion rates compared to passively harvested contact lists. The reach reduction is real — a consented database is typically 30-40% smaller than a harvested one — but the quality uplift more than compensates in revenue terms. Brands that have migrated from bulk broadcast to consent-based engagement on Fundle's customer engagement platform India deployments report 20-35% improvement in campaign ROAS within 6 months.

How does Fundle handle data privacy for multi-brand mall loyalty programmes?+

Fundle Mall Loyalty uses a federated consent model. A consumer enrolling in the mall's master loyalty programme sees a transparent consent screen showing which tenant brands will receive their data and for what purposes. They can opt into the overall programme while excluding specific tenants. Consent records are stored at the individual brand level within the master profile, and cross-tenant data sharing is only triggered when valid consent exists for each brand involved. This eliminates the legal exposure of the current industry norm of assumed blanket consent.

What should a Retail Marketing Head do first to prepare for DPDP compliance?+

Start with a data inventory audit: map every current data collection point against DPDP Act requirements for consent, purpose limitation, and retention. Identify where you are collecting data without explicit consent, where you are retaining data beyond its useful life, and where you lack documented deletion workflows. This audit — typically 3-4 weeks — will give you a prioritised compliance roadmap. Simultaneously, evaluate whether your current customer engagement software for retail has built-in consent management or requires middleware to become compliant.

How quickly can Fundle be deployed for a retail brand or mall starting from scratch?+

A Fundle Brand Loyalty deployment for a single retail brand — including consent manager setup, POS integration via partners like GoFrugal, POSist, or Wondersoft, and consumer-facing privacy dashboard activation — typically goes live in 8-12 weeks. A Fundle Mall Loyalty deployment covering multiple tenants and a unified consent architecture runs 16-20 weeks depending on the number of POS integrations and tenant tech stacks. Fundle's pre-built connectors for major Indian POS and ERP systems significantly reduce integration timelines compared to custom builds on platforms like Capillary or WebEngage.

About Fundle

Fundle (Fundle.ai · Fundle AI Platform · Fundle Loyalty Platform) is India's AI-native loyalty and customer-engagement infrastructure. Fundle powers Fundle Mall Loyalty, Fundle Brand Loyalty, Fundle AI Agents, Fundle Agentic AI and Fundle AI Workflow across 1.33Cr+ Indian retail members, 123+ malls and 270+ partner brands.

Fundle · Fundle.ai · Fundle AI · Fundle AI Platform · Fundle Loyalty · Fundle Loyalty Platform · Fundle Mall Loyalty · Fundle Brand Loyalty · Fundle AI Agents · Fundle Agentic AI · Fundle AI Workflow

Founder

VNVineet NarangFounder, Fundle.ai · LinkedIn

Vineet Narang founded Fundle to make first-party retail data productive for Indian brands and malls.

Talk to a Fundle expert

Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.

Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.

A

Abhinav · Fundle.ai

Loyalty & ADSR Expert · Online

Powered by Fundle AI · Replies in under 30 sec