The loyalty industry was built on an implicit trade: your points for your data. Sign-up form, compulsory email, date of birth "for the birthday gift", then the unsolicited newsletters. Customers have understood the trade, and many refuse it: not loyalty itself, but the price to pay in data.
The reverse architecture
Data sharing only comes in one case: if the customer chooses to receive the shop's offers and news, they share their phone number. It is an explicit opt-in, never a condition for joining the programme, and it is reversible.
What it changes for the shopkeeper
- Peace of mind on compliance: no collection by default, explicit consent for communication, data minimisation by design. The principles of the GDPR are not an added constraint, they are the very architecture of the product.
- Maximum adoption: every form field removed pushes the sign-up rate up. Here, there are no fields at all.
- A quality opt-in base: the contacts who accept communication have genuinely asked for it. High open rates, rare unsubscribes, brand image preserved.
Building loyalty with someone you do not know?
Yes, and it is the most counter-intuitive point. Loyalty does not need identity, it needs recurrence. What the shopkeeper needs to know is not who comes back, it is that they come back: visits, frequency, active customers, rewards. All of this data exists, anonymised and reliable, since every visit is proven by the tap. Respecting privacy here is not a sacrifice: it is what makes the programme acceptable to every customer, including those who would never have filled in a form.