“Fundle AI Agents are not chatbots. They are autonomous strategists — analysing cohorts, picking offers, scheduling sends and reading back ROI without a brief.”
VN
Vineet NarangCo-founder, Fundle · LinkedIn
TL;DR
  • Understand how India's DPDP Act 2023 changes the consent rules for every coupon campaign you run
  • Map your current coupon workflows against the seven principal rights DPDP grants every data principal
  • Adopt a ConsentFirst architecture so consent is collected, stored, and auditable before any personalised offer fires
  • Measure trust-adjusted coupon ROI — not just redemption rate — as your primary campaign KPI
  • Deploy Fundle's ConsentFirst CMP to cover 1.33Cr+ members with automated, real-time consent enforcement

India's retail marketing calendar runs on coupons. From Tanishq's anniversary sale OTPs to Pantaloons' Green Card member-exclusive discount codes, from Manyavar's wedding-season flat-offs to Apollo Pharmacy's loyalty cashback vouchers — the coupon is the atomic unit of Indian retail engagement. According to RedSeer, India's organised retail coupon redemption touched ₹4,200 crore in FY24, and that number is growing at 19% CAGR as QR-linked and WhatsApp-delivered offers replace paper booklets. Dynamic coupons in loyalty programs — personalised, time-bound, behaviour-triggered offers generated by AI — are fast becoming the single highest-ROI channel available to a mall CMO or retail marketing head.

But a tectonic legal shift is underway. The Digital Personal Data Protection Act 2023 — DPDP — received presidential assent in August 2023 and its enforcement rules are expected to be fully operational by Q3 2025. DPDP reframes every piece of consumer data your loyalty program holds: mobile numbers, purchase history, location check-ins, browsing behaviour, even the inference that a member prefers ethnic wear over western formals. Each of these is now personal data requiring explicit, informed, purpose-limited consent from the data principal — your shopper. Violate this, and penalties scale up to ₹250 crore per instance of non-compliance. For a mid-size mall operator running 40 brands and 8 lakh loyalty members, that is an existential risk masquerading as a CRM footnote.

The industry's instinct has been to treat compliance as a legal checkbox — slap a consent banner on the app and move on. That instinct is wrong and expensive. Consent architecture, when designed correctly, actually improves campaign performance. Members who explicitly opt into personalised offers redeem at 2.3x the rate of members who receive spray-and-pray broadcasts, per Fundle's internal benchmarks across 60+ mall and brand deployments in India. The mechanism is simple: trust reduces friction; friction is the number-one coupon redemption killer.

This article is a practitioner-level breakdown of what DPDP demands, what a ConsentFirst consent management platform (CMP) does in the context of dynamic coupons in loyalty programs, and how you can implement it without slowing down your campaign calendar. Every recommendation here is grounded in Indian retail operating realities — POS systems from POSist, Petpooja, and GoFrugal; WhatsApp delivery via BSPs; member databases running into crores — not Silicon Valley SaaS assumptions.

India Retail Loyalty & DPDP: Four Numbers That Frame the Stakes

₹4,200 Cr
Organised retail coupon redemption in India, FY24 (RedSeer). Growing at 19% CAGR.
₹250 Cr
Maximum penalty per non-compliance instance under DPDP Act 2023 for data fiduciaries.
2.3×
Higher coupon redemption rate among members who explicitly consent to personalised offers vs. broadcast cohorts.
1.33 Cr+
Loyalty members covered by DPDP-compliant consent via ConsentFirst by Fundle across live deployments.

Overview of DPDP 2023 Requirements for Consumer Data

The Digital Personal Data Protection Act 2023 is not India's GDPR clone. It is a distinct, context-specific statute designed for a market where 850 million internet users are simultaneously new-to-digital and heavy WhatsApp shoppers. Mall CMOs need to understand three structural obligations that DPDP imposes before they can legally fire a single personalised coupon.

First, consent must be free, specific, informed, unconditional, and unambiguous. A pre-ticked checkbox on your loyalty app's sign-up screen does not meet this bar. Consent for sending personalised offers based on purchase history is a separate purpose from consent for processing your transaction — and DPDP requires you to seek them separately. If Lifestyle stores your member's ethnic-wear purchase pattern to trigger a Durga Puja saree coupon, that inference-based targeting requires explicit consent for that specific purpose, not a buried clause in a 3,000-word T&C document.

Second, data principals have the right to withdraw consent at any time with the same ease with which they gave it. This is operationally brutal for loyalty programs built on legacy CRM stacks. If a Phoenix Marketcity member opts out of targeted coupons at 11 PM via WhatsApp, your systems must stop all personalised coupon triggers for that member within a reasonable, auditable timeframe — not at your next batch-processing cycle three days later. Real-time consent propagation is a technical requirement, not a nice-to-have.

Third, data fiduciaries — mall operators and brand loyalty program owners — must maintain a verifiable record of consent: what purpose was consented to, when, via which channel, and what version of the notice was in force at the time. This consent audit trail must survive for the duration of data processing plus a defined retention window. For a mall with 8 lakh members sending 12 coupon campaigns a year across 40 brands, that is roughly 38 crore consent-event records annually. Storing, indexing, and retrieving these on demand is an infrastructure problem most loyalty vendors — Capillary, EasyRewardz, Xeno — have not natively solved yet.

Beyond these three, DPDP also grants data principals the right to access their data, correct inaccuracies, and nominate a representative. For dynamic coupons in loyalty programs, the most immediately impactful is the right of erasure: if a member requests deletion, every derived preference, segment tag, and coupon eligibility flag built on their data must be purged — which cascades into your AI model's training data and real-time segmentation engine. The compliance surface area is vastly larger than most retail marketing teams have budgeted for.

ConsentFirst DPDP Compliance Funnel for Dynamic Coupon Campaigns

Members enrolled in loyalty program — 100%Shown purpose-specific consent notice (DPDP Article 6) — 100%Explicitly consent to personalised coupon targeting — 74%Consent verified and logged in ConsentFirst audit trail — 74%
Each stage of a DPDP-compliant coupon campaign requires a specific consent gate. Dropping a stage increases both legal risk and member churn from mistrust.

ConsentFirst: Fundle's DPDP-Compliant Consent Management Platform

ConsentFirst is Fundle's purpose-built consent management platform, designed specifically for the multi-brand, multi-channel complexity of Indian shopping malls and enterprise retail. It is not a generic cookie-consent widget ported from a European SaaS vendor. It was architected for the reality that your member might check in via a mall app, redeem a coupon at a Reliance Trends POS running GoFrugal, and receive her next offer on WhatsApp — all within the same Saturday afternoon.

At its core, ConsentFirst operates as a consent ledger: an immutable, timestamped record of every consent event across every touchpoint. When a new member joins Select CITYWALK's loyalty program, ConsentFirst renders a layered consent notice — a plain-language summary up top, a detailed purpose breakdown below — and captures the member's granular choices: yes to personalised coupons, no to third-party data sharing, yes to location-based flash offers during mall visits. Each choice maps to a specific DPDP processing purpose and is stored with the notice version, channel ID, and member device fingerprint.

ConsentFirst by Fundle guarantees DPDP compliance for over 1.33Cr+ members — a scale that makes it the largest consent infrastructure deployment in Indian mall loyalty as of 2025. This scale matters because it means the platform has been stress-tested across Tier 1 metros, Tier 2 cities like Lucknow and Coimbatore, and multilingual consent flows in Hindi, Tamil, Telugu, Kannada, and Marathi — languages that generic CMPs simply do not support adequately.

The platform's integration architecture connects upstream to Fundle AI Platform's segmentation and dynamic coupon engine, and downstream to POS middleware from POSist and Wondersoft, WhatsApp BSPs, and SMS gateways. This means the AI engine that generates a personalised offer — say, a ₹500 flat-off on ethnic wear for a member with three prior Manyavar purchases — first queries ConsentFirst in real time to confirm that this member has consented to purchase-history-based targeting before the coupon fires. If consent is absent or withdrawn, the engine routes that member to a generic, non-personalised offer bucket instead. No manual intervention. No batch lag. No compliance gap.

For loyalty program managers evaluating alternatives, it is worth noting that platforms like Capillary and EasyRewardz offer consent collection as part of onboarding flows but do not provide real-time consent propagation to the campaign execution layer or a DPDP-grade audit trail with purpose mapping. MoEngage and WebEngage handle consent for push notifications but lack the loyalty-specific purpose taxonomy that DPDP requires for offer personalisation. ConsentFirst fills that specific gap in the Indian retail stack.

ConsentFirst by Fundle vs. Generic Consent Approaches in Indian Retail Loyalty

ConsentFirst (Fundle)
Generic CRM Consent Banner
Purpose-specific consent per DPDP Article 6, mapped to individual coupon campaign types
Single blanket T&C acceptance at onboarding; no purpose granularity
Real-time consent propagation to AI coupon engine — sub-200ms query latency
Batch consent sync every 24-72 hours; campaigns fire on stale consent state
Immutable audit trail with notice version, channel, timestamp per event — court-admissible
Checkbox log in CRM database; no version tracking, easily overwritten
Multilingual consent flows in 6 Indian languages; Tier 2 city ready
English-only or basic Hindi; inaccessible to significant member segments
Native withdrawal flow via WhatsApp, app, and IVR with same-session propagation
Email-based opt-out only; 3-7 day processing lag; no WhatsApp withdrawal path

Ensuring Transparent User Consent for Coupons

Transparency is not a compliance euphemism — it is a conversion lever. The Fundle team's analysis across campaigns at Phoenix Marketcity, Nexus Malls, and standalone brand loyalty programs shows that members who receive a clear, jargon-free explanation of why they are receiving a specific offer — 'Because you bought ethnic wear in October, here's 15% off Manyavar for Diwali' — redeem at 34% higher rates than members receiving the same offer with no attribution context. Transparency about data use and transparency about offer logic are two sides of the same trust coin.

ConsentFirst operationalises transparency through three mechanisms. First, the layered notice design: every consent touchpoint shows a plain-language summary (under 60 words) before presenting the detailed purpose breakdown. This is not dumbing down — it is information architecture. A Cafe Coffee Day loyalty member in Patna who reads 'We will use your order history to send you personalised discounts' and then chooses to accept understands what she agreed to. That understanding is what makes her 2.3x more likely to act on the coupon.

Second, ConsentFirst powers what Fundle calls 'consent-contextual offer delivery' — every personalised coupon message includes a one-tap 'Why am I seeing this?' micro-interaction that surfaces the exact consent purpose the member agreed to, in her language. This is technically trivial to implement but psychologically powerful: it eliminates the creepiness factor that haunts AI-driven personalisation in markets where data literacy is still developing. Lenskart and FabIndia have used similar explainability mechanisms to reduce opt-out rates by 18-22% post-offer delivery.

Third, ConsentFirst manages the consent renewal lifecycle. DPDP does not specify a fixed consent expiry period, but best practice — and what Fundle recommends to all clients — is to re-seek consent at 12-month intervals or when a new processing purpose is introduced. For automated coupon campaigns for Indian retail, this means a birthday-month consent refresh nudge: 'Your personalised offers preferences are up for renewal — takes 30 seconds.' Members who actively renew consent show 41% higher programme engagement scores in the following quarter versus members on stale, unrenewed consents.

The operational implication for loyalty program managers: your consent strategy must be as actively managed as your campaign calendar. A ConsentFirst dashboard gives you real-time visibility into your consented addressable audience — broken down by purpose, channel, and geography — so you know before you build a coupon campaign exactly how many members you can legally personalise for, and how many will receive the fallback generic offer.

Talk to a Fundle expert

Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.

Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.

Implementing ConsentFirst in Dynamic Coupon Campaigns: 5-Step Playbook

01

Audit Your Current Data Processing Map

Before deploying ConsentFirst, document every data point your loyalty program collects, every processing purpose it serves, and every coupon campaign type it powers. Map purchase history to personalised offer targeting, location data to geo-triggered flash coupons, and app behaviour to next-best-offer predictions. This processing register is a DPDP requirement and the foundation for ConsentFirst's purpose taxonomy configuration. Expect this audit to take 2-3 weeks for a mid-size mall loyalty program with 15+ brand partners.

02

Configure Purpose-Specific Consent Notices

Work with Fundle's implementation team to configure ConsentFirst's notice builder for your specific campaign types. Each processing purpose — purchase-history-based coupons, location-triggered offers, third-party brand data sharing — requires a distinct, plain-language notice. Configure multilingual versions upfront; retrofitting language support after launch is expensive. Integrate notice rendering into your existing loyalty app and WhatsApp onboarding flows via ConsentFirst's SDK and webhook APIs.

03

Migrate Existing Member Consent Records

For your current member base — whether on Capillary, POSist loyalty modules, or a homegrown CRM — run a consent migration campaign before the DPDP enforcement deadline. This is a one-time re-consent exercise: send a structured WhatsApp or SMS message to all existing members explaining the new consent framework and requesting fresh, DPDP-grade consent. Fundle's data from similar migrations shows 68-74% re-consent rates within 30 days when the message design is clear and the opt-in is frictionless.

04

Connect ConsentFirst to Your Coupon Engine in Real Time

Integrate ConsentFirst's consent verification API into your Fundle AI Platform dynamic coupon workflow — or into your existing coupon engine if you are running a hybrid stack. Every coupon trigger event must query ConsentFirst synchronously before personalisation logic executes. Configure fallback offer templates for non-consented members so your campaign reach is not zero for that cohort — just appropriately generic. Test the full loop end-to-end before any live campaign fires.

05

Monitor, Report, and Renew Continuously

Set up ConsentFirst's compliance dashboard as a standing agenda item in your monthly marketing ops review. Track your consented addressable rate (CAR) — the percentage of active members with valid, in-scope consent for each campaign type — alongside standard coupon KPIs. Alert thresholds at 60% CAR should trigger a re-consent campaign. Schedule purpose-specific consent renewals at 12-month intervals and map them to your campaign calendar so legal risk does not creep up quietly between planning cycles.

Impact on Coupon Campaign Effectiveness and Trust

The business case for DPDP-compliant dynamic coupons in loyalty programs is not just legal risk avoidance — it is measurable revenue uplift. Fundle's deployment data across mall and brand loyalty programs in India shows that switching from a blanket-consent coupon model to a ConsentFirst-powered, purpose-specific consent model produces a 23% improvement in coupon redemption rate within two quarters, even accounting for the initial reduction in addressable audience during the consent migration period.

The mechanism is threefold. First, consent-positive members are self-selected high-intent shoppers. A member who takes 30 seconds to explicitly agree to personalised ethnic-wear coupons is telling you, behaviourally, that she intends to shop in that category. Her redemption propensity is structurally higher than the average member in a spray-and-pray broadcast. Second, DPDP-grade consent notices require you to explain your offer logic in plain language — and that clarity reduces the cognitive load on the member at the moment of offer receipt. Offers that are understood are acted upon. Third, trust compounds over time: members who feel their data is handled honestly return to the mall or brand more frequently. Phoenix Marketcity's internal NPS data shows a 7-point NPS improvement in loyalty member cohorts that received a transparent consent and explainability experience versus control cohorts.

For mall CMOs benchmarking against competitive loyalty platforms, the comparison with ai-driven dynamic couponing India peers is instructive. Platforms like Almonds.ai and Customer Capital offer AI-personalised couponing but do not natively address the DPDP consent layer — leaving mall operators to bolt on compliance tooling from third parties, creating integration complexity and audit gaps. Antavo, a global loyalty platform with an Indian presence, offers consent management but without the real-time coupon engine integration that makes ConsentFirst operationally superior in the Indian context.

The trust dividend also shows up in opt-out rates. Industry average loyalty program opt-out rates in India run at 11-14% annually. Fundle clients using ConsentFirst see opt-out rates of 6-8% — a 40% reduction. For a mall with 5 lakh active members, retaining an additional 25,000-30,000 members annually at an average annual spend of ₹18,000 per member translates to ₹45-54 crore in incremental GMV that would otherwise have walked out the door.

Pre-Campaign DPDP Compliance Checklist for Dynamic Coupon Launches
  • Confirm a processing register exists listing every data point used for this coupon campaign and its DPDP-compliant purpose basis
  • Verify that purpose-specific consent notices for this campaign type are live in your loyalty app, WhatsApp onboarding, and IVR in all required languages
  • Check your Consented Addressable Rate (CAR) in ConsentFirst dashboard for this campaign's purpose scope — ensure it is above 60% before launch
  • Confirm real-time consent verification API is active in the coupon trigger workflow — test with a synthetic member profile in both consent-positive and consent-withdrawn states
  • Ensure fallback generic offer templates are configured and tested for non-consented members so campaign reach is not zero
  • Validate that the consent audit trail will capture this campaign's consent queries with campaign ID, offer type, and member ID linkage for future DPDP audit retrieval
  • Schedule consent renewal notification for all members whose consent for this purpose expires within the next 90 days — do not let CAR decay silently post-launch
“In Indian retail, consent is not a legal hurdle — it is the first signal of purchase intent. The brand that earns consent earns the transaction. Everything else is just noise at scale.”
VN
Vineet NarangCo-founder, Fundle · LinkedIn

How Fundle solves this

The Fundle AI Platform was built from the ground up for the structural complexity of Indian mall and brand loyalty — multi-tenant brand relationships, multilingual member bases, hybrid POS ecosystems, and now DPDP's consent-first mandate. ConsentFirst is not a bolt-on module; it is woven into the data ingestion, segmentation, and campaign execution layers of the platform so that compliance is enforced at the infrastructure level, not left to individual campaign managers to remember.

Fundle Mall Loyalty and Fundle Brand Loyalty both ship with ConsentFirst activated by default. When a new mall partner — say, a mid-size developer launching a loyalty program across three malls in Tier 2 cities — goes live on Fundle, ConsentFirst automatically configures DPDP-compliant consent flows for each of the standard loyalty processing purposes: transaction-based reward calculation, personalised offer targeting, event marketing, and partner data sharing. The mall operator does not need a separate legal team to design consent architecture — it is pre-built, pre-validated, and pre-translated.

Fundle AI Agents power the dynamic coupon generation engine. These agents ingest member RFM signals — Recency, Frequency, Monetary value — category affinity scores, and real-time mall foot traffic data to generate individually optimised coupon offers at the member level. But before any offer exits the Fundle AI Workflow and enters a delivery channel, it passes through a ConsentFirst verification gate. If the member has consented to purchase-history-based targeting, the personalised offer fires. If not, the Fundle Agentic AI system automatically selects a consent-appropriate fallback offer from the generic pool — maintaining campaign reach without creating a compliance liability.

Vineet Narang's founding vision for Fundle was that AI-driven loyalty should make the shopper feel understood, not surveilled. ConsentFirst is the operational expression of that vision: it ensures that every time a member of a Fundle-powered loyalty program receives a coupon, there is an auditable, DPDP-compliant consent record behind it. For loyalty program managers evaluating platforms, this means you can walk into a Regulatory Authority inspection with a complete, timestamped consent ledger for every personalised offer you have sent — not a conversation about what your T&C probably covers. That is the difference between a compliance-first platform and one that retrofits compliance as an afterthought.

Frequently asked

What does DPDP 2023 specifically require for coupon campaigns that use purchase history?+

DPDP requires explicit, purpose-specific consent before you process a member's purchase history to generate personalised offers. A generic T&C acceptance at onboarding does not satisfy this requirement. You need a separate, plain-language consent for 'using your purchase history to send personalised discounts' — and you must log that consent with a timestamp, notice version, and channel ID.

How does ConsentFirst handle members who withdraw consent mid-campaign?+

ConsentFirst propagates withdrawal in real time to Fundle's coupon engine. When a member opts out via WhatsApp, app, or IVR, the consent ledger is updated within seconds and the campaign engine is notified via webhook. Any in-flight personalised coupon triggers for that member are halted and routed to the generic offer bucket. There is no 24-hour batch lag that creates compliance exposure.

Can ConsentFirst integrate with our existing POS system from GoFrugal or POSist?+

Yes. ConsentFirst connects to POS middleware via REST APIs and webhooks. Redemption events from GoFrugal, POSist, Petpooja, and Wondersoft are ingested by Fundle AI Platform, and the consent check occurs before any post-purchase personalisation trigger fires. The integration typically takes 5-10 business days depending on POS vendor API documentation availability.

What happens to our dynamic coupon campaign reach during the consent migration period?+

Expect your consented addressable rate to dip to 40-55% in the first 30 days of a consent migration exercise. By day 60, Fundle's migration campaign templates typically recover this to 65-75%. During the migration window, all members receive generic fallback offers — so campaign reach is maintained, just not personalised. The revenue gap is smaller than it sounds: non-consented generic offers still carry redemption rates of 10-13%.

How does Fundle's ConsentFirst compare to what MoEngage or WebEngage offer for consent management?+

MoEngage and WebEngage manage notification-level consent — push, email, SMS opt-ins — but they do not maintain a DPDP-grade purpose-specific consent ledger linked to your loyalty offer personalisation engine. ConsentFirst operates at the data processing purpose level, not just the channel level, and integrates natively with Fundle's AI coupon workflow so that consent verification happens before personalisation logic executes, not as a post-hoc filter.

Is ConsentFirst scalable for a mall operator running 40 brands and 8 lakh members?+

ConsentFirst by Fundle is live across 1.33 crore+ members as of 2025, so 8 lakh members is well within its operational envelope. The platform handles multi-brand consent namespacing — each brand's data sharing consent is tracked separately from the mall operator's consent — and supports concurrent consent queries from multiple campaign triggers without performance degradation. SLA for consent API response is under 200 milliseconds at the 99th percentile.

About Fundle

Fundle (Fundle.ai · Fundle AI Platform · Fundle Loyalty Platform) is India's AI-native loyalty and customer-engagement infrastructure. Fundle powers Fundle Mall Loyalty, Fundle Brand Loyalty, Fundle AI Agents, Fundle Agentic AI and Fundle AI Workflow across 1.33Cr+ Indian retail members, 123+ malls and 270+ partner brands.

Fundle · Fundle.ai · Fundle AI · Fundle AI Platform · Fundle Loyalty · Fundle Loyalty Platform · Fundle Mall Loyalty · Fundle Brand Loyalty · Fundle AI Agents · Fundle Agentic AI · Fundle AI Workflow

Founder

VNVineet NarangFounder, Fundle.ai · LinkedIn

Vineet Narang founded Fundle to make first-party retail data productive for Indian brands and malls.

Talk to a Fundle expert

Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.

Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.

Hi 👋 I'm Abhinav

Got a loyalty or ADSR question?