Customer Data Ownership in Loyalty Programs
· Beyond Stamping Editorial Team · 7 min read
Who owns your loyalty program customer data? Secure export rights, capture consent, control access and set retention. With a decision table and practical steps.
Customer data ownership means you control which loyalty data is collected, how it’s used, who can access it, and when it’s deleted. In practice, you should be able to export your customer list, document consent for marketing, restrict staff access, and set retention rules. Read the provider’s terms so you know what happens if you cancel. Choose tools that make customer list export simple, provide auditable consent records, and let you action deletion requests without support tickets.
Customer data ownership: export, consent, access and retention
For independent shops and cafés, the idea is simple: you pay for a loyalty tool, but you own the relationship and the data. In detail, assess four pillars:
- Exportability: Can you self-serve a clean customer list export (for example CSV) with fields like name, mobile, join date, and marketing preferences? How often, and are there limits?
- Consent and lawful basis: Does the platform record how and when each customer opted in to SMS or email? Can you evidence that consent later? If you rely on SMS, understand that UK direct marketing has specific rules; get appropriate advice if unsure.
- Access controls: Can you limit what staff can see or change? Are audit trails available for stamp issuance and redemptions?
- Retention and deletion: Can you set retention periods, suppress marketing to opted-out contacts, and erase an individual’s data on request? What happens to your data when you end the contract?
These four areas underpin loyalty card privacy and determine whether your programme is genuinely yours—or effectively leased.
A practical decision framework for loyalty program customer data
Use this table to interrogate any provider before you sign. It focuses on what materially affects your control.
| Decision area | What good looks like | Questions to ask | Red flags |
|---|---|---|---|
| Exportability | Self-serve CSV export any time; includes consent fields and activity | Can I export all contacts and history without support? Is there a fee or limit? | Export only on request; fees; missing consent flags |
| Consent capture | Timestamped opt-in with channel (e.g., SMS); easy to evidence | How is consent captured and stored? Can I view per-contact logs? | Blanket consent assumed; unclear consent records |
| Access controls | Role-based permissions; audit of stamp and reward activity | Can staff issue stamps without seeing full contact lists? Are changes logged? | Single admin login shared by all staff |
| Retention & deletion | Clear settings for data retention; one-click opt-out and erasure | What is your default retention? How do I erase a customer? | Data kept indefinitely; deletion requires tickets |
| Portability on exit | Contract confirms data remains yours; export before/after cancellation | What happens to my data if I leave? How long to export? | Data locked after notice; punitive fees |
| Communications | Respect for local laws; suppression lists for opt-outs | How are opt-outs handled in SMS? | Manual removal; no suppression list |
Keep notes in a simple scorecard. If a tool misses two or more “What good looks like” items, pause your purchase.
How wallet-based stamp cards handle data flow
Wallet-based loyalty places a branded pass in Apple Wallet or Google Pay rather than asking customers to download a separate app. Customers typically join by scanning a QR code or tapping a link at checkout. Staff can then scan a pass or on-screen code from a phone or tablet to issue stamps. The pass itself stores a unique identifier and visuals; the customer data and activity log live in the provider’s system.
- Distribution and updates: Apple Wallet and Google Wallet support distributing passes by link or QR code, and passes can be updated server-side. This helps small teams enrol customers quickly without password resets.
- Data location: The wallet pass does not give you a phone number by default. You collect contact details only if the customer provides them (e.g., entering a mobile number to receive offers). Store consent and opt-out state alongside that record.
- Staff workflow: A scanner workflow on a phone or tablet minimises errors when issuing stamps and reduces the need to handle paper cards.
Beyond Stamping example:
- Independent local businesses can issue a branded digital stamp card that customers add to Apple Wallet or Google Pay via a link or QR code.
- Customers do not need a separate loyalty-app download or a password to participate.
- Staff can use a phone or tablet scanner workflow to issue stamps.
- A customer activity dashboard shows participation and redemptions.
- SMS campaigns operate on pay-as-you-go credit; an optional Referrals add-on provides referral codes and tracks a friend’s qualifying first visit.
- Pricing as displayed on the live website at the time of writing: Digital Loyalty at £34.99/month for one branch, extra branches at £10/month, and Referrals at £24.99/month as an add-on.
These particulars illustrate a wallet-based approach that keeps friction low while giving owners access to operational data. As always, check exactly how exports, consent logs, and retention settings work before rollout.
Setting retention rules and consent logs that stand up to scrutiny
Being able to market is not the same as having permission to do so. Put lightweight governance in place:
- 1. Map consent points
- Identify every place customers provide details: QR sign-up, checkout form, website form. Ensure each point clearly states what they’re opting into (e.g., loyalty updates by SMS) and that consent is recorded with a timestamp and channel.
- 2. Define retention periods
- Decide how long you’ll keep inactive contact data and transaction-like activity (e.g., stamp issue history). Many local businesses choose a pragmatic period (for instance, 12–24 months of inactivity) but obtain appropriate advice for your circumstances.
- 3. Operationalise deletion and suppression
- Create a basic playbook: how to find a customer’s record, how to erase or anonymise it, and how to ensure they are suppressed from future SMS.
- 4. Prepare for access requests
- Keep a simple checklist for data access requests. You should be able to produce what you hold, where it comes from, and what you use it for—without needing developer help.
- 5. Document ownership on exit
- File the clause in your contract that confirms you can export your data during and after notice. Add a calendar reminder 30 days before renewal to run a full export.
If you plan to send SMS, review relevant UK guidance for direct marketing and obtain legal advice where needed. Good records are your safety net.
Common mistakes that cost owners control
- Assuming the provider is the “owner.” Paying for software does not guarantee customer data ownership; read the data terms.
- No customer list export. If you cannot self-serve a full export, you risk vendor lock-in.
- Missing consent evidence. A single opt-in checkbox without a timestamped log is weak evidence if challenged.
- Single shared login. It obscures who issued which stamps and invites errors.
- Indefinite data hoarding. Retaining stale contacts increases risk and degrades SMS performance.
- Treating Google/Apple Wallet as a database. The pass is an access token, not your CRM.
Illustrative example
A neighbourhood coffee shop has 3,200 digital stamp customers. The owner wants to switch providers. Before cancelling, they:
- Run a full customer list export, including mobile numbers, join date, stamp balance, and SMS consent flags.
- Check that opt-outs are represented in a suppression list they can take with them.
- Export the last 18 months of stamp activity to defend any future reward disputes.
- Email the team new access roles so baristas can issue stamps but cannot export contacts.
- Set a retention rule: contacts inactive for 24 months will be anonymised unless they return.
Because the owner prepared exports, consent logs, and retention decisions ahead of time, migration takes hours—not weeks—and customers keep their progress.
When this may not fit
Wallet-based stamp cards are excellent for high-frequency, low-friction visits. They may not suit every case:
- You require deep POS integration, multi-tender loyalty accrual, or complex tiering tied to spend rather than visits.
- Your audience rarely uses smartphones that support Apple Wallet or Google Pay, or connectivity is very limited.
- You handle sensitive membership data that demands bespoke security reviews or sector-specific controls.
- You need rich in-app features (for example, advanced content or embedded ordering) that go beyond a pass and SMS updates.
If any of the above applies, compare wallet-based passes with other CRM or app-led loyalty options using the decision framework table.
Your next practical steps
Action checklist for owners
- Review your current contract’s clauses on exports, data retention, and termination.
- Test a full customer list export and verify consent fields and opt-out status.
- Map every consent touchpoint and add clear wording where needed.
- Create role-based staff access and turn on activity auditing.
- Set a calendar reminder to review retention every six months.
- If you’re evaluating Beyond Stamping, confirm pricing and trial the export and consent logs. See our Privacy page and the digital loyalty card privacy guide for context before you decide.
Make customer data ownership a front-door requirement, not an afterthought. It’s easier to choose well now than to unwind a lock-in later.
What should a loyalty platform include in a customer list export?
At minimum: unique customer ID, name (if collected), mobile or email (if collected), join date, last activity, consent status per channel (e.g., SMS), and opt-out timestamp. If available, include stamp balance and recent reward redemptions so you can migrate fairly.
Can I market by SMS if a customer has a wallet pass?
Not automatically. Possessing a wallet pass does not equal marketing consent. You should collect and record explicit consent for SMS and maintain suppression lists for opt-outs. Consult appropriate guidance and obtain legal advice for your specific situation.
What happens to loyalty data when I cancel a provider?
It depends on the contract. Look for terms confirming you retain ownership, can export during notice, and can request deletion after you leave. Before cancelling, run full exports of contacts, consent logs, and recent activity so you can continue serving customers without gaps.