DIGIKART

The Digikart blog · 16 September 2026 · 6 min read

Loyalty cards and GDPR: what a shop owner needs to know

A customer asks what you keep on them, and the answer does not come. A loyalty card, even a digital one, is still a customer list: few rules, but real ones. Here is what a shop owner needs to know, without the jargon, with the sources.

Your loyalty card in Apple Wallet and Google Wallet, for free. Create my free card

What a Wallet card really knows about your customers

It always happens at the same moment. The customer has scanned the QR code, the add screen is in front of them, and they look up. “What are you keeping on me, exactly?” If you hesitate, the card does not get added. The good news is that the answer fits in one sentence, as long as you have prepared it.

On Digikart, a loyalty card holds a card identifier, which says nothing about its holder, a balance of stamps or points, and the dates of each visit. If you award points based on how much a customer spends, the amount of each visit is stored with it, and it shows up in your figures and in your export. Add to that the wallet used, Apple or Google, and, once the card is installed, the registration of the device with the notification service. Three more fields can appear, and only if the customer fills them in: first name, phone number (so they can be found at the till without scanning) and date of birth, which only shows if you have switched on the birthday reward. Each one is marked optional on the sign-up screen. No payment details are collected, and the individual items bought are never recorded: even connected to an EPOS, only the receipt reference and its total come through.

The contrast with a supermarket scheme makes the point. There, the barcode of every product in the basket is tied to the customer record, which is how those schemes end up sending offers on the brands you actually buy. Anything linked to an identifiable person is personal data, so all of it is data the customer can ask to see. A stamp card does not go that far: it counts visits and, at most, what they were worth, never the contents of the basket. The less you collect, the less you have to explain, keep and protect.

The lawful basis your customer list rests on

The GDPR asks that every use of personal data rests on one of the lawful bases it sets out. The phrase is heavier than the reality: for a loyalty card, the natural basis is performance of a contract. The ICO accepts contract where the processing is objectively necessary to deliver what the person asked for, and that is the case here. The customer asked for the card, you promised a reward after ten visits, counting those visits is what keeps the promise. There is no box to tick for that. The optional fields sit outside it: a phone number and a date of birth are not needed to count, they rest on what the customer chooses to give, and they can ask you to take them out without losing the card.

What changes nature is everything that leaves the programme. Sending a commercial message that has nothing to do with the card is direct marketing, and a second set of rules applies: PECR in the UK, the ePrivacy Regulations (SI 336 of 2011) in Ireland. The default is consent, given by a clear affirmative act, and you keep the proof. Both allow a narrow exception for existing customers: your own similar goods or services, with an easy way to object offered when you took the details and again in every message. Ireland adds a condition the UK does not, under Regulation 13(11): the first marketing message has to go out within twelve months of the sale. Renting or sharing your list with a partner is the same logic, only more serious.

The practical rule fits on one line. Anything that serves the card (counting, saying a reward is ready, reminding someone of a balance) travels with the card. Anything about something else deserves a question put to the customer, separately, with a record of the answer.

Telling the customer: three lines at the counter

This is the easiest duty to meet and the most often forgotten. You have to give people your privacy information at the moment you collect their details, not later and not only if they ask. The paper version of this was the loyalty card application slip sitting on the shop counter.

With a Wallet card, that counter has become the sign-up page that opens after the QR scan. The page does not display your notice for you: that stays your job, on the poster next to the till and on your website. The notice has to say who you are, why you are collecting this, on what basis, who sees it, how long you keep it, that the fields are optional, how the customer can exercise their rights, with an address to write to, and that they can complain to the ICO in the UK or to the Data Protection Commission in Ireland. Nine lines, not nine pages.

In practice: a few lines on your counter poster, the same on your website if you have one, and one sentence your staff know by heart. This is not a solicitor's contract, it is a text the customer has to be able to read in ten seconds with a phone in one hand.

How long to keep the data

There is no universal retention period. The ICO is explicit that data protection law sets no timescale for how long you keep people's details for marketing purposes. What it asks is that you can justify the period you pick, that you record it, that you tell people what it is, and that you review what you hold so it does not go stale. The period is yours, but it has to exist.

For a loyalty card, the end of the relationship is the last visit. Three years without a visit is a defensible line for a small shop, and nothing stops you choosing two or five. What matters is that the number is written down and actually applied. A period you keep to beats a list that never empties.

Doing it takes five minutes once a year. In Digikart, your customer list shows the date of the last visit: you spot the dormant ones and you delete them. Deleting removes the record, the balance and the visit history, and unregisters the device from the notification service. Two useful details. A card already installed stays visible in the customer's phone, because neither Apple nor Google lets you pull it back remotely, but it no longer scans and no longer updates. And if you are connected to an EPOS, the sales lines stay for your accounts, since HMRC expects a limited company to keep its records six years from the end of the financial year and a sole trader five years after the 31 January filing deadline, while Revenue expects six years in Ireland. Once the customer record is gone, those lines point to nobody.

Access and erasure: answering within a month

Two rights stand out, because they are the ones customers actually use. The right of access: knowing what you hold on them. The right to erasure: asking for it to go. You have to reply without undue delay and within one month. You can extend that by up to two further months where the request is complex or the same person has sent several, provided you tell them, and tell them why, inside the first month.

Answering is not just copying out the record. The reply has to set out the purposes of the processing, the categories of data, who it is disclosed to, how long you keep it, the person's other rights and their right to complain to the supervisory authority. And telling the customer that they already know all this, because they typed it in themselves, is not an answer.

There is one confusion worth knowing, because it comes up often. A customer who deletes the card from their Wallet has removed the card from their phone, not their line from your list. If they want erasure they have to ask you, and you are the one who deletes. Worth saying at the moment they add the card.

Notifications, the point worth some attention

A Wallet card can put a message on its holder's phone. No text message, no email, no number to know: the message travels through the card itself. That is very convenient, and it is exactly where things go wrong.

The channel is not the question, the content is. “Your reward is ready” is about the card the customer asked for. “Big sale on Saturday” is an advert. The ICO already treats in-app messages as electronic mail for the marketing rules, so a promotional push sits close enough to that line to be handled as marketing. And in practice, one notification too many rarely ends in a complaint: it ends in a deleted card, which is worse for you.

The customer keeps control on their side. They can switch off notifications for that card in their phone settings, or remove the card. Say so, it reassures more than it scares. On the tool's side, our terms put it plainly: the merchant alone is responsible for the content of the notifications they send.

The record of processing, ten minutes once a year

This is the duty that surprises small shops most. Employ fewer than 250 people and you get an exemption, but a limited one: you still have to document processing that is not occasional, processing likely to be risky for people, and processing of special category or criminal offence data. Running a customer list is not occasional. A loyalty programme is in.

In practice it is a table. One line per activity, with its purpose, who is concerned, the categories of data, who receives it, how long you keep it and your security measures. The ICO publishes documentation templates and says plainly that keeping records is worth doing even where you are not obliged to. Nobody will ask you for it, right up until someone asks you for it.

One UK duty travels with it and is easy to miss. Unless you are exempt, you have to pay the ICO a data protection fee. A micro organisation, meaning up to ten staff or a turnover up to £632,000, sits in tier 1 at £52 a year, with £5 off for paying by direct debit. There is no equivalent in Ireland: since 25 May 2018 controllers no longer register their processing with the Data Protection Commission, and there is no public register to join.

What is on you, what is on your tool

The split is easy to remember. The tool hosts, encrypts and secures. You decide what you collect, what you tell your customers, what you send and what you keep. Software cannot be compliant on your behalf, because half the decisions are yours.

What Digikart does on its side is written on the privacy policy page: servers hosted in France with OVH, no data sold to third parties, no advertising or third party tracking cookies, passwords never stored in the clear, encrypted communications, daily backups. A merchant can delete their account and their data from their own dashboard. For a UK shop, France sits inside the EEA, which the UK adequacy regulations cover in full, so the data can flow without you arranging anything extra. For an Irish shop the question does not arise at all.

What falls to you is in our terms, clause 8: inform your end customers of the processing of their data and obtain any required consent. That is not passing the buck, it is how it works on the ground. You are the one facing the customer, you choose the reward, the message and the period. The rest of the practical questions are answered in the FAQ.

Try Digikart, it is free.

Loyalty card in Apple Wallet and Google Wallet, unlimited customers, no bank card, ready in 15 minutes.

Read next

Reward ideas for your loyalty programme, trade by trade16 September 2026 · 8 min What a loyalty programme is really worth16 September 2026 · 7 min How to win back a customer who stopped coming16 September 2026 · 6 min
Powered by Digikart · Rennes, France · CGV · Privacy