“The best campaign is the one that didn't run. Fundle's churn-prediction model has saved Indian retailers crores in unnecessary discounting on customers who were already coming back.”
VN
Vineet NarangCo-founder, Fundle · LinkedIn
TL;DR
  • Audit every consent touchpoint in your loyalty enrolment funnel before DPDP enforcement begins
  • Design consent flows that explain value exchange in plain Hindi or regional language, not legalese
  • Separate consent for communications, profiling, and third-party sharing into distinct, skippable steps
  • Measure consent opt-in rate, withdrawal rate, and downstream revenue impact as first-class KPIs
  • Deploy WhatsApp-native consent flows to capture mobile-first Indian shoppers where they already live

India's Digital Personal Data Protection Act, 2023 is no longer a distant regulatory horizon. With the DPDP Rules expected to be finalised in 2025, every retail CMO and CIO running a loyalty programme in India now faces a hard question: is your enrolment flow actually legal, and does it still convert? The two goals are not mutually exclusive, but most platforms in the market were built when consent was an afterthought buried in a 14-page terms-and-conditions PDF that nobody read.

The stakes are real. India has roughly 140 million loyalty programme members across organised retail, according to KPMG estimates, and the average Indian shopper is enrolled in 3.2 programmes simultaneously. Yet CRM teams at brands like Reliance Trends, Lifestyle, and Pantaloons routinely report that fewer than 40% of their registered members have a verifiable, timestamped consent record for marketing communications. Under DPDP, that gap is a compliance liability — and it is also a data quality problem that silently erodes every personalisation model downstream.

Consent based loyalty data management is the discipline of designing enrolment, preference, and data-collection flows so that every permission a shopper grants is explicit, purposeful, revocable, and tied to a clear value exchange. It is distinct from simply adding a checkbox. Done well, it is a brand trust signal that measurably increases Customer Lifetime Value. Done poorly, it is a dark-pattern minefield that regulators are already watching. Fundle.ai was built from day one with this discipline as a core architectural principle, not a compliance bolt-on.

This article is written for the retail CMO or CIO who is simultaneously trying to grow first-party data assets, meet DPDP obligations, and not crater enrolment conversion rates in the process. We cover UX design principles, real Indian retail context, mobile and WhatsApp-native considerations, and the metrics that separate world-class consent management from checkbox theatre.

The Indian Loyalty Consent Gap: Four Numbers That Matter

₹4,200 Cr
Estimated annual marketing spend wasted on non-consented or unverified contacts in Indian organised retail (KPMG, 2024 est.)
38%
Share of Indian loyalty members with a verifiable, timestamped consent record for email or SMS marketing
2.7×
Higher CLV for customers who actively opted in to personalisation versus passive sign-ups in Indian fashion retail (internal Fundle benchmark, 2024)
270+
Indian brands using Fundle's WhatsApp-native platform for compliant consent collection, per Fundle platform data

Designing Clear and Compliant Consent Flows

The single biggest UX mistake Indian retailers make is conflating programme enrolment with blanket data consent. When a shopper signs up for a loyalty card at a Select CITYWALK kiosk or scans a QR code at a FabIndia store, they are agreeing to participate in the programme — nothing more. Every subsequent permission — to receive WhatsApp promotions, to allow purchase-history-based profiling, to share anonymised data with mall operators or partner brands — must be a separate, affirmative act. The DPDP Act's concept of 'specific and informed consent' makes this bundling illegal.

Operationally, this means redesigning enrolment flows into a layered architecture. Step one is programme sign-up: name, mobile, email, and the core loyalty T&Cs. This is a functional contract, not a marketing consent. Step two is a communications preference screen — opt-in to WhatsApp, SMS, email, and push notifications, each as a standalone toggle, each with a one-line plain-language description of what you will actually send. Step three, presented optionally after the shopper has experienced at least one reward redemption, is an offer to unlock 'personalised recommendations' in exchange for profiling consent. Sequencing matters enormously. Front-loading all requests in a single wall-of-toggles screen produces opt-out rates of 60-70% in A/B tests run on Indian retail apps.

Language is the other critical variable. India's DPDP Act explicitly requires that consent notices be provided in a language the data principal understands. For a Manyavar store in Patna or a Cafe Coffee Day outlet in Coimbatore, that likely means Hindi or Tamil respectively, not English. Brands on the Fundle AI Platform can configure consent copy in 12 regional languages with a single back-end toggle, ensuring the notice a shopper receives on their phone matches the language of their device OS — a technically trivial step that most legacy CRM platforms from the Capillary or EasyRewardz era were never built to handle at scale.

Finally, every consent interaction must produce a durable, retrievable audit trail: who consented, to what, via which channel, at what timestamp, on which device. This is not just regulatory hygiene — it is the raw material of a trustworthy first-party data asset. Retailers that build this discipline now will be able to demonstrate data provenance to brand partners, mall operators, and eventually to Data Protection Board auditors, while competitors scramble to reconstruct consent histories they never captured.

Layered Consent Enrolment Funnel for Indian Retail Loyalty

Programme Sign-Up (Functional T&Cs) — 100% of startersCommunications Opt-In (WhatsApp / SMS / Email toggles) — 72% opt-in at least one channelPersonalisation Consent (Purchase profiling) — 48% opt-in after first redemptionPartner Data Sharing (Mall / brand analytics) — 31% opt-in with clear value explanation
Each stage of the loyalty enrolment funnel should capture a distinct, purposeful consent. Drop-off at each stage is expected and legal — forced consent is invalid consent.

Balancing Engagement and Transparency

There is a persistent myth in Indian retail CRM circles that transparency kills conversion. The evidence does not support it. What kills conversion is poorly timed, poorly worded, or visually cluttered consent requests — not honesty itself. When Apollo Pharmacy or Tanishq explains precisely why they want to track purchase history — 'so we can remind you when your prescription is due' or 'so we can show you pieces that match what you already own' — the opt-in rate is materially higher than a generic 'we use your data to improve your experience' boilerplate.

The UX principle at work here is called the value-exchange moment. Consent requests convert best when they are attached to an immediate, tangible benefit that the shopper can feel. 'Unlock double points on your next visit by completing your profile' is a consent request disguised as a reward. It is also fully DPDP-compliant as long as the underlying data use is accurately described. The critical design guardrail is that programme access must never be conditioned on consenting to marketing or profiling — that would constitute coerced consent under the Act. The double points offer must be optional, not a gate.

Progressively disclosed consent — surfacing additional permission requests only as the shopper deepens their engagement with the programme — is now the gold standard for privacy-first loyalty platform design in India. It mirrors what best-in-class global platforms like Antavo recommend in their 2024 global loyalty report, but with the additional constraint of India's relatively low average session time on retail apps (1.8 minutes on Android, per AppsFlyer India data) and the dominance of WhatsApp as the primary engagement channel. Every extra tap is a dropout risk.

A related engagement design principle is the consent dashboard — a single, always-accessible screen within the loyalty app or WhatsApp menu where the shopper can see exactly what they have consented to, when, and with the ability to withdraw any permission in two taps. Most Indian loyalty platforms, including those built on WebEngage or Xeno, do not offer this natively. It is not just a compliance requirement under DPDP; it is a trust-building feature that reduces churn. Research from Edelman's 2023 Trust Barometer shows that customers who believe a brand handles their data responsibly are 2.1× more likely to increase their spending with that brand.

Privacy-First Loyalty UX vs. Legacy Consent Theatre

Legacy Loyalty Consent UX
Privacy-First Loyalty UX (Fundle Standard)
Single bundled consent checkbox at sign-up covering all data uses
Layered, purpose-specific consent screens triggered at relevant journey moments
Consent copy in English only, buried in T&Cs PDF
Consent notice in shopper's device language (12 Indian languages supported)
No withdrawal mechanism beyond calling customer care
Self-serve consent dashboard: withdraw any permission in 2 taps via WhatsApp or app
Consent record stored inconsistently across POS, app, and CRM — no single audit trail
Immutable, timestamped consent log synced across all channels via Fundle AI Platform
Profiling and communications consent bundled; shopper cannot opt in to rewards without accepting marketing
Programme access never gated on marketing consent; each permission is independently optional

Examples of User Friendly Consent Management in Indian Retail

Look at how Lenskart handles progressive profiling in its app: after a first purchase, it prompts users to save their prescription data with a specific explanation — 'so you never need to re-enter it at checkout' — and a clear link to its privacy policy. The consent language is conversational, the benefit is immediate, and the skip option is equally prominent as the accept button. That design philosophy, applied to loyalty programme data collection, is precisely what DPDP compliance looks like in practice.

Contrast that with the enrolment flows still common at many Phoenix Marketcity outlets, where a CRM executive manually keys shopper details into a POS terminal while the shopper is distracted at checkout. No consent screen is shown to the shopper, no record of what was explained is captured, and the data is siloed in a mall-level system that the individual brand tenants cannot access in real time. Under DPDP, this workflow is non-compliant from the first interaction. It also produces data quality rates of roughly 55% — meaning nearly half of all records have at least one corrupted field.

A better model comes from Petpooja-integrated loyalty pilots in the QSR sector, where post-order WhatsApp messages include a one-tap 'join our loyalty programme' button. The enrolment confirmation message immediately displays what the shopper has consented to in two bullet points, with a 'manage preferences' link. The entire consent interaction happens in 25 seconds, produces a verified OTP-linked identity, and automatically populates a consent audit trail. This design reduces enrolment drop-off by approximately 34% versus app-based flows in QSR contexts, based on comparable pilots on the Fundle platform.

The takeaway for CMOs is that user-friendly consent management is not about minimising friction at the cost of clarity. It is about eliminating unnecessary friction — redundant fields, irrelevant permissions, confusing language — while preserving the friction that actually builds trust: explicit toggles, clear explanations, and visible withdrawal paths. MoEngage's 2024 India Email and Push Benchmark Report notes that brands with clear consent architectures see 22% lower unsubscribe rates and 18% higher click-through rates on CRM communications — a direct revenue signal that compliance is also commercial strategy.

Talk to a Fundle expert

Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.

Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.

Five-Step Playbook for Consent Based Loyalty Data Management

01

Map Every Consent Touchpoint

Audit all places where shopper data is collected: POS terminals, loyalty apps, WhatsApp chatbots, brand websites, mall kiosks, and third-party integrations (GoFrugal, POSist, Wondersoft). For each touchpoint, document: what data is collected, what purpose is stated, what consent mechanism exists, and whether a withdrawal path is available. Most Indian retailers find 6-12 touchpoints, of which fewer than half have compliant consent flows.

02

Classify Consent by Purpose and Risk

Separate all data uses into three tiers: functional (needed to run the programme, no marketing consent required), communicational (opt-in to WhatsApp, SMS, email, push), and analytical (purchase profiling, segmentation, partner data sharing). Build your consent UX architecture around these tiers. High-risk uses — cross-brand sharing, behavioural profiling — require the most explicit, standalone consent requests with the clearest value-exchange explanation.

03

Redesign Enrolment as a Progressive Journey

Restructure the sign-up flow so functional consent is captured at enrolment, communicational consent is captured after the first engagement touchpoint (first visit, first purchase, first reward), and analytical consent is invited after the shopper has experienced genuine programme value. A/B test consent copy in at least two regional languages relevant to your store geography. Target an opt-in rate of 65%+ for at least one communications channel at enrolment.

04

Build a Consent Dashboard and Withdrawal Flow

Every loyalty member must be able to view, modify, and withdraw any consent in a maximum of three steps, accessible from WhatsApp menu, app home screen, or a QR code at any physical touchpoint. Withdrawal must take effect within 72 hours across all downstream systems — CRM, marketing automation, data warehouse, and any partner integrations. Automate this with a consent event that triggers suppression flags in all connected tools.

05

Instrument Consent Metrics and Run Regular Audits

Track consent opt-in rate, consent withdrawal rate, consent coverage (percentage of active members with a valid consent record for each purpose tier), and downstream engagement delta between consented and non-consented segments. Run a quarterly consent audit comparing your CRM database against your consent log. Any record with a purchase transaction but no consent record is a DPDP liability to be resolved by re-consent outreach or record suppression.

Mobile and WhatsApp-Native UX Considerations for Consent

India is a smartphone-first market, but it is not an app-first market. IAMAI data for 2024 shows that the average Indian smartphone user has 38 apps installed but actively uses only 9. Branded retail loyalty apps rarely make that active-use list, with median monthly active user rates below 18% for standalone retail loyalty apps outside of the top five grocery and fashion super-apps. WhatsApp, by contrast, has 550 million monthly active users in India and an average daily session time of 38 minutes. The consent design implications are profound.

A WhatsApp-native consent flow must work within the constraints of the WhatsApp Business API: button-based interactions (maximum three options per message), list menus for multi-choice preferences, and character limits on message bodies. This forces a discipline that is actually UX-beneficial: you cannot cram a wall of legalese into a WhatsApp message. Consent copy must be conversational, benefit-forward, and short enough to read in a single scroll. The DPDP Act's requirement for 'clear and plain language' is almost automatically satisfied when the channel enforces brevity.

Practically, this means structuring WhatsApp consent interactions as a short, chatbot-guided conversation: 'Hi [Name], welcome to [Brand] Rewards! Here is what you have signed up for: [two bullet points]. We would love to send you your points balance and exclusive offers on WhatsApp. Tap YES to opt in or NO to skip — you can change this any time.' This format achieves opt-in rates of 68-74% in Indian retail contexts, compared to 43-51% for equivalent in-app consent screens, primarily because the interaction feels personal and low-stakes rather than bureaucratic.

OTP-linked identity verification within the WhatsApp enrolment flow also solves a chronic Indian retail data quality problem: duplicate and ghost records. When enrolment is anchored to a verified mobile number via WhatsApp OTP, the CRM dataset is structurally cleaner from day one. Fundle's WhatsApp-native platform enhances consent collection for 270+ Indian brands, and internal benchmarks consistently show a 31% reduction in duplicate member records compared to POS-only or app-only enrolment flows. For a mall operator running a multi-brand programme across 60 tenants, that data quality improvement alone justifies the platform migration cost.

Consent UX Audit Checklist for Indian Retail Loyalty Teams
  • Every enrolment touchpoint (POS, app, WhatsApp, web) has a documented consent flow with purpose-specific language, not a generic T&Cs bundled checkbox
  • Consent copy is available in the regional language(s) of your primary store geographies — minimum Hindi and one South Indian language for national brands
  • Programme enrolment is not gated on marketing or profiling consent — shoppers can join and earn points without accepting any optional data use
  • A self-serve consent dashboard is accessible within three taps from the loyalty app home screen or WhatsApp programme menu
  • All consent records include: shopper ID, consent type, channel, timestamp, copy version shown, and withdrawal status — synced to a single consent log
  • Consent withdrawal triggers an automated suppression event across CRM, marketing automation, analytics, and all partner data integrations within 72 hours
  • Quarterly consent audit is scheduled and owned by a named person — comparing active CRM records against the consent log to identify and resolve unconsented records
“In Indian retail, consent is not a compliance checkbox — it is the first personalisation signal. The brand that earns explicit permission earns data that actually predicts behaviour. Everything else is noise.”
VN
Vineet NarangCo-founder, Fundle · LinkedIn

How Fundle solves this

Fundle was architected as a consent-first data platform before consent became a regulatory mandate in India. The Fundle AI Platform treats the consent record as a first-class data object — not a flag in a marketing automation tool, but a structured, versioned, auditable entity that governs every downstream data flow. When a shopper withdraws consent for profiling, the Fundle Agentic AI automatically triggers suppression events across all connected brand systems, mall analytics dashboards, and partner integrations — no manual intervention, no 72-hour SLA breach.

Fundle Mall Loyalty is designed for the specific complexity of multi-brand mall environments, where a single shopper may have relationships with 15-20 brand tenants across a Phoenix Marketcity or a DLF mall property. The platform manages consent at both the programme level (mall-wide rewards) and the brand level (tenant-specific communications), maintaining separate consent records for each relationship and providing the shopper a unified preference dashboard where all permissions are visible and manageable in one place. This is a capability that competitors like Capillary and Almonds.ai have not replicated at the same architectural depth.

Fundle Brand Loyalty extends the same consent infrastructure to standalone brand programmes — whether that is a national jewellery chain running a Tanishq-style tier programme or a regional pharmacy chain. Fundle AI Agents handle consent collection interactions across WhatsApp, app, web, and POS — dynamically selecting the channel with the highest predicted opt-in probability for each individual shopper based on their prior engagement patterns. Fundle AI Workflow automates the post-consent journey: welcome sequences, preference confirmation messages, and re-consent campaigns for records approaching the DPDP-mandated consent review window.

Vineet Narang's founding vision for Fundle was that loyalty programmes in India had been built on borrowed data — third-party cookies, purchased lists, and inferred identities — and that the shift to first-party, consent-based data would be the most significant structural change in Indian retail marketing in a decade. The Fundle Loyalty platform was built to make that transition commercially advantageous rather than operationally painful. For the CMO or CIO reading this, the question is not whether to invest in consent based loyalty data management infrastructure — the DPDP Act has already answered that. The question is whether you build the capability in a way that erodes conversion or in a way that, as Fundle's client benchmarks consistently show, actually grows it.

Frequently asked

What does the DPDP Act 2023 require from Indian retail loyalty programmes specifically?+

The DPDP Act requires that any collection or processing of personal data for marketing, profiling, or analytics purposes be based on explicit, informed, and freely given consent. For loyalty programmes, this means: enrolment cannot be bundled with marketing consent, each data use purpose must be described in plain language, shoppers must be able to withdraw consent easily, and all consent interactions must be logged with a timestamp. Brands that continue with implied or bundled consent post-enforcement face penalties of up to ₹250 crore per breach.

How does WhatsApp-native consent collection differ from app-based consent flows?+

WhatsApp consent flows operate in an environment the shopper already trusts and uses daily, which reduces the psychological friction of the consent interaction. The channel's UI constraints — short messages, button responses — force brevity and clarity in consent copy. OTP-linked identity verification via WhatsApp also produces cleaner data from the first interaction. In Indian retail pilots, WhatsApp consent opt-in rates run 15-25 percentage points higher than equivalent in-app screens for the same shopper segment.

Can a shopper be incentivised to give consent — for example, with bonus points?+

Yes, under DPDP, incentivised consent is permissible as long as the incentive is for an optional permission and access to the core programme is not conditioned on accepting it. Offering double points for completing a preference profile is compliant. Requiring marketing consent to enrol in the loyalty programme at all is not — that is coerced consent and invalid under the Act. The design rule: every consent above the functional minimum must have a visible, consequence-free 'skip' option.

What is the difference between consent for communications and consent for profiling?+

Communications consent governs whether a brand can send marketing messages to a shopper via WhatsApp, SMS, email, or push notification. Profiling consent governs whether a brand can analyse a shopper's purchase history, browsing behaviour, or demographic data to build segments or personalise offers. These are legally distinct purposes under DPDP and must be presented as separate consent requests. A shopper may legitimately opt in to WhatsApp messages but decline purchase-history profiling — the platform must support this combination without errors.

How should Indian retailers handle existing loyalty members who lack a proper consent record?+

Brands should run a structured re-consent campaign targeting all active members without a verifiable consent record. The campaign should be delivered via a channel the member has previously engaged with, explain plainly why consent is being requested, and offer a simple opt-in mechanism. Members who do not respond within a defined window (typically 60-90 days) should be suppressed from all marketing and profiling activities. Their transactional records can be retained for statutory purposes but must not be used for CRM targeting without a valid consent record.

How does Fundle.ai help brands measure the commercial impact of consent quality?+

The Fundle AI Platform tracks consent coverage — the percentage of active members with valid consent records by purpose tier — and correlates it with downstream engagement metrics: redemption rate, repeat purchase frequency, average basket size, and CLV by cohort. This allows CMOs to see the revenue delta between fully consented members and partially or non-consented members, making the business case for consent infrastructure investment in CFO-ready numbers rather than compliance abstractions. Fundle's benchmark data across 270+ Indian brands shows consented members generate 2.7× higher CLV than passive sign-ups.

About Fundle

Fundle (Fundle.ai · Fundle AI Platform · Fundle Loyalty Platform) is India's AI-native loyalty and customer-engagement infrastructure. Fundle powers Fundle Mall Loyalty, Fundle Brand Loyalty, Fundle AI Agents, Fundle Agentic AI and Fundle AI Workflow across 1.33Cr+ Indian retail members, 123+ malls and 270+ partner brands.

Fundle · Fundle.ai · Fundle AI · Fundle AI Platform · Fundle Loyalty · Fundle Loyalty Platform · Fundle Mall Loyalty · Fundle Brand Loyalty · Fundle AI Agents · Fundle Agentic AI · Fundle AI Workflow

Founder

VNVineet NarangFounder, Fundle.ai · LinkedIn

Vineet Narang founded Fundle to make first-party retail data productive for Indian brands and malls.

Talk to a Fundle expert

Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.

Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.

Hi 👋 I'm Abhinav

Got a loyalty or ADSR question?