Free up to 100 customers · set up in 5 minutesStart free

GDPR Loyalty Program: What You Need to Know About Customer Data

Every week without clear GDPR rules risks fines – but the requirements are straightforward.

8 min read

GDPR and loyalty programs work better together than many shop owners fear. A digital stamp card processes personal data, but the rules are manageable. You need to handle five things: legal basis, separate marketing consent, customer information, deletion, and a contract with your provider. This article explains them clearly. It's not legal advice – if in doubt, have your setup reviewed.

What data does a stamp card collect?

Before thinking about legal bases, look at what's actually collected. With a typical Wallet stamp card, that's:

  • Card ID: a random identifier that links stamps to the card
  • Optional name or first name: for addressing on the card and in messages
  • Optional birthday: only if you offer birthday promotions
  • Stamp and redemption history: when was it scanned, when was it redeemed
  • Technical data: Wallet registration of the device, timestamps, possibly device detection to prevent fraud

The data minimization principle (Art. 5(1)(c) GDPR) says: collect only what you need for the purpose. If you don't plan birthday offers, don't ask for birthdays. If a first name is enough, don't ask for a last name.

Every data processing needs a legal basis from Art. 6(1) GDPR. For loyalty programs, three are relevant:

ProcessingLegal basisWhat it means
Collecting stamps, managing card, redeeming rewardArt. 6(1)(b) (Contract)The customer participates in the program; processing is necessary to run it. No separate consent needed.
Marketing messages, promotions, offersArt. 6(1)(a) (Consent)Requires voluntary, informed, active agreement. Also subject to applicable marketing laws.
Fraud protection, technical securityArt. 6(1)(f) (Legitimate interest)For example, device detection so no one stamps themselves unlimited times. Must be proportionate.

The key point: Stamping and marketing are two different things. Anyone who creates the card can be stamped. Anyone who wants marketing must agree separately.

Most mistakes happen here. For marketing consent to be valid, it must be:

  • Separate from program participation (no forced bundling, Art. 7(4) GDPR)
  • Active: checked by the customer themselves (a pre-checked box is not consent – the European Court of Justice ruled this in Planet49)
  • Informed: the customer knows what they're getting (for example, Wallet messages with offers)
  • Revocable at any time, as easily as it was given

In practice: When creating the card, there's a required checkbox for the privacy policy and a separate, unchecked checkbox for offers and promotions. Customers get their card even if they don't check the second box.

Messages that are part of running the program (like "You now have 5 of 10 stamps" or "Your reward is ready") aren't marketing and don't need consent. "2 for 1 today only" is marketing. How such messages work technically is explained in Sending push messages to customers.

Disclosure obligations under Art. 13 GDPR

When collecting data, you must inform customers. The information must be easily accessible – a link on the signup page is enough. Required information includes:

  1. Name and contact details of the controller (you, the shop)
  2. Purposes of processing and the legal basis for each
  3. Recipients or categories of recipients (like your software provider as a processor, Apple and Google for Wallet)
  4. Storage duration or criteria for it
  5. Rights of the data subject: access, correction, deletion, restriction, portability, objection
  6. Right to withdraw consent
  7. Right to lodge a complaint with a supervisory authority

A shop without its own website often faces a problem here: Where should the policy live? Some providers automatically generate an editable privacy policy per shop and host it. Customers see it when creating the card, and you don't have to write anything yourself.

Data subject rights: access and deletion

Customers can request information about what data you have on them (Art. 15) and demand deletion (Art. 17). You need two things for this:

  • A way to find the customer: With a digital card, usually by name or card ID in your dashboard.
  • A delete function: Either the customer deletes the card from their Wallet themselves, or you remove them in your dashboard. Deletion must be complete, including from histories and reports, unless retention obligations apply.

Also: data can't sit around forever. A sensible approach is to delete or anonymize cards that haven't been used for a long time after a set period. State the period in your privacy policy.

Data processing: the contract with your provider

If you use software for your loyalty program, the provider processes customer data on your behalf. Legally, you're the controller and the provider is the processor. Art. 28 GDPR requires a written contract – a data processing agreement.

It states what data is processed, that the provider only acts on your instructions, how they protect data, and which subprocessors they use (like hosting providers). Reputable providers present the data processing agreement for acceptance when you sign up. Also check the server location: hosting in the EU simplifies things significantly.

Self-check: Is your loyalty program GDPR-compliant?

  • I collect only data I really need
  • Marketing checkbox is separate, unchecked, and voluntary
  • Privacy policy is linked when creating the card
  • Customers can request information and deletion
  • I have a data processing agreement with my provider
  • My team knows customer data is confidential

If you can't check more than two boxes, you should make changes.

What happens if you do nothing

Without clear GDPR rules, you risk warnings from competitors or complaints to the data protection authority. Fines can be painful, even for small shops. More importantly: customers lose trust if they feel their data isn't protected. For comparison: with paper cards, most points disappear as long as you don't record personal information. Once a name is on the card, the same rules apply, but without a delete function and without a hosted policy. The comparison of both models is in Paper stamp card vs. digital stamp card.

Conclusion

GDPR and loyalty programs aren't contradictory: stamping runs on the contract basis, marketing needs a separate checkbox, customers are informed and can request deletion, and you have a data processing agreement with your provider. Important: this article isn't legal advice – review your specific setup. stampa handles the technical side for you, with separate marketing consent, auto-generated privacy policy per shop, and data processing agreement at signup. You can start free, up to 100 active customers, no credit card needed.

Frequently asked questions

Do I need consent for a digital stamp card?
Not for stamping itself, because it's part of running the program (Art. 6(1)(b) GDPR). For marketing messages you need separate, voluntary consent.
Do I need a privacy policy for my loyalty program?
Yes. You must inform customers when collecting data: who's responsible, what data is processed and why, and what rights they have. A link during card setup is enough.
What is a data processing agreement and do I need one?
A data processing agreement (Art. 28 GDPR) governs the relationship between you and the provider processing data on your behalf. If you use stamp card software, you need one.
How long can I keep customer data from my loyalty program?
Only as long as needed for the purpose. If a customer deletes their card or requests deletion, data must be removed. You should delete inactive customers after a set period.
Is a paper stamp card simpler under data protection law?
Yes, if you don't collect names – no personal data means no GDPR rules apply. Once you write down names or phone numbers, the same rules apply as digital, just without technical safeguards.

Turn customers into regulars.

Digital stamp card in Apple & Google Wallet. No app, no hardware – set up in 5 minutes.

Start free

Free up to 100 active customers · no credit card · cancel monthly

Read more

Strategy & Metrics

A/B Testing in Your Small Shop: Which Offer Works Better?

Which of two offers brings more customers back? An A/B test answers this question without guesswork. You split your customers randomly into two groups, give each a different version, and count who came. The math fits on a napkin. Here's the step-by-step process, a real café example, and the rules for when a difference actually matters.

7 min read
Strategy & Metrics

Café Marketing Metrics: 8 Numbers Every Week

Eight numbers, ten minutes per week, and you know if your café is really growing or just making sales. Every metric comes with a formula, example calculation, and a hint on what to do if the number moves the wrong way.

8 min read
Strategy & Metrics

Calculate Churn Rate: Measure Customer Loss in Your Shop

Churn rate shows you how many customers your shop loses silently in a month. The problem: attrition hurts only after it's already happened. Nobody announces they're leaving. Here you get the formula, a worked example for a café, and a plan to spot attrition before it hits your revenue.

7 min read