
A loyalty program processes far more than a points balance, which is why loyalty program GDPR compliance needs to be designed into the program before launch. Enrollment, purchases, rewards, referrals, customer accounts, receipt uploads, and marketing integrations can each create a separate use of customer data.
Short answer: A loyalty program needs a clear purpose, lawful basis, retention rule, and customer-rights process for each data activity. Joining the program, accepting its terms, and opting into promotional email or SMS should be separate choices, explained in plain language.
Loyalty program GDPR compliance starts with a data map, not a checkbox
What a loyalty program actually processes
Start by mapping the information your program collects, receives, creates, and shares. A Shopify loyalty program may use a customer’s name, email address, phone number, account details, purchase history, points activity, redemption history, VIP status, referral activity, reviews, wishlist actions, receipt images, and integration events.
A purchase-based earning rule needs order and customer data to calculate points. A referral program may need referral links, conversion records, and fraud checks. Receipt scanning creates another category because customers submit an image.
The myth: joining a rewards program equals marketing consent
Joining a program gives a customer access to its benefits. It does not automatically mean they agreed to promotional email or SMS.
A customer may want points updates, reward confirmations, or a balance in their account without agreeing to product launches, sale announcements, or recurring text campaigns. Treat these as separate choices in both the form design and your underlying records.
Why Shopify does not make the program automatically compliant
Shopify says merchants are generally the controller of their customers’ data, and that using Shopify alone does not guarantee GDPR compliance (Shopify). Your loyalty app, email platform, review tool, and support system add more data flows that you need to assess.
Build the map first. Then assign a purpose, lawful basis, owner, and retention rule to each flow.
GDPR, UK GDPR, PECR, and US privacy rules
GDPR and UK GDPR set data-protection obligations when your processing falls within their scope. PECR adds UK rules for electronic marketing, including email and SMS. US privacy obligations vary by state and can apply alongside European requirements depending on your business locations, customers, and applicable laws.
This is not legal advice. Ask qualified privacy counsel to assess which rules apply to your store and loyalty program.
Separate program enrollment, marketing consent, and loyalty terms
| Signup element | What it covers | How it should be presented | What to record |
|---|---|---|---|
| Program enrollment | Access to points, rewards, and account benefits | Clear explanation of the program and links to notices | Enrollment date and program version |
| Loyalty terms | Commercial rules for earning and redemption | Link near enrollment, written in plain language | Terms version accepted |
| Email marketing | Promotional email permission | Separate unticked option | Channel, time, source, wording |
| SMS marketing | Promotional text permission | Separate unticked option | Channel, time, source, wording |
| Operational updates | Balance, reward, and account communications | Explain as part of program operation | Message purpose and delivery record |
What customers should see at signup
The enrollment screen should say what the customer receives, what information you use to run the program, and where they can read the privacy notice and loyalty terms.
Use separate optional boxes for marketing channels. Email and SMS are not interchangeable permissions.
For UK-facing stores, electronic marketing rules under PECR sit alongside UK GDPR. The ICO says unsolicited email and SMS marketing to individual subscribers generally needs specific consent, subject to a limited soft opt-in (ICO guidance).
How to record consent properly
Record who consented, what they were shown, when they consented, how they consented, and whether they later withdrew permission.
Your records should distinguish enrollment from marketing. If a customer withdraws email consent, your team needs to know whether that changes promotional messages only or affects program access as well.
Operational loyalty messages versus promotional messages
A reward confirmation or points-earned update can be an operational program message. An email promoting a new collection is marketing, even if it mentions the customer’s tier.
The ICO notes that loyalty-scheme members may receive scheme-related messages under the soft opt-in when clear opt-out information is provided, while marketing outside the scheme may require clear consent (ICO guidance). Classify messages before building loyalty email templates.
If loyalty events sync to your email platform, document the customer properties and events involved. A Klaviyo loyalty integration, for example, should be part of the data map.
Build a loyalty privacy notice customers can actually understand
The data categories and purposes to name
A useful privacy notice names the data you collect at enrollment and the data created later. Cover profile details, purchase and earning activity, reward redemptions, VIP progression, referral records, reviews, social actions, wishlist behavior, receipt uploads, and account activity where relevant.
Explain why you use each category. Common purposes include calculating points, issuing rewards, managing referrals, preventing fraud, responding to support requests, measuring program performance, and sending requested operational communications.
Mage is a loyalty and rewards platform built for Shopify stores, and its customer metafields can include points balance, lifetime points, redeemed points, VIP tier, and member status (Mage help center). Those fields are a useful prompt for your own inventory, not a substitute for a privacy assessment.
The providers and integrations to disclose
Identify the providers that process program data, including Shopify, your loyalty platform, email and SMS tools, review tools, subscription tools, support tools, and analytics providers. Explain international transfers where they apply, and point customers to the relevant provider information.
Confirm whether you have appropriate data processing agreements, or DPAs, with providers acting as processors. Document controller and processor roles, subprocessors, international transfers, deletion procedures, security commitments, and breach-notification obligations.
Your notice should provide a contact route for access, correction, objection, portability, and erasure requests. Do not promise that every deletion request removes every transaction record. Some records may need to be retained under a legal exception.
“I looked into so many different integrations for loyalty and referrals for our Shopify Store, but no one impressed me more than Mage on human connection, customer service, and value.”


Read the Reelie case study →
Set a retention schedule for points, rewards, and customer records
| Data category | Why it exists | Retention decision | Deletion or anonymization trigger |
|---|---|---|---|
| Member profile | Operate the account and program | Set a documented period | Account closure or inactivity review |
| Points ledger | Calculate balance and resolve disputes | Retain only as long as justified | Expiry of need or approved anonymization |
| Reward redemptions | Confirm issued benefits and refunds | Align with operational needs | End of retention period |
| Referral records | Attribute rewards and review fraud | Define a fraud and dispute period | End of review period |
| Marketing consent | Prove permissions and withdrawals | Keep while needed for compliance | Consent withdrawal and documented period |
| Receipt images | Verify qualifying purchases | Keep for a limited verification period | Verification complete and no exception |
Data retention is purpose-based
There is no universal GDPR retention period for loyalty data. The ICO says organizations should not keep personal data longer than necessary and should document their retention periods (ICO storage limitation guidance).
Set separate rules for active profiles, points ledgers, reward redemptions, referral records, consent records, support tickets, receipt images, and financial or tax records.
How points expiry differs from data deletion
Points expiry changes a customer’s available balance. It does not automatically delete the personal data connected to the earning activity.
Mage points expiry is off by default and can run from the date points are earned or from the customer’s last purchase date (Mage points expiry guide). Merchants can surface balance and expiry information across the Rewards Widget, Loyalty page, and Account Sidebar. That is product context, not a compliance guarantee.
Handle erasure requests without guessing what happens to points
| Data or record | Possible action | Decision owner | Customer communication |
|---|---|---|---|
| Customer profile | Erase or redact identifiers | Privacy owner | Explain completion or exception |
| Points balance | Erase, anonymize, or retain under an exception | Privacy and program owner | State the balance outcome clearly |
| VIP tier | Remove or anonymize status | Program owner | Explain effect on membership |
| Referral record | Remove identifiers or retain limited fraud record | Privacy and fraud owner | Explain what remains and why |
| Order history | Redact personal details where appropriate | Finance and privacy owner | Explain retained transaction information |
| Marketing consent | Suppress future marketing and retain proof as needed | Marketing owner | Confirm opt-out status |
The right to erasure is not absolute
A customer does not need formal legal wording for an erasure request. Train support teams to recognize requests such as “delete my information,” route them correctly, and avoid improvised promises.
The right to erasure is not absolute. Your team may need to assess legal obligations, disputes, fraud prevention, and other applicable exceptions before acting. Organizations normally have one month to respond, with a possible extension of up to two additional months for complex or repeated requests.
A practical Shopify deletion workflow
Use a documented workflow. Confirm the request, identify the customer record, assess what data is held, send the request through Shopify, coordinate with connected providers, and record the outcome.
Shopify lets merchants request customer data access and erasure from the admin, including requests sent to installed apps and sales channels (Shopify). Shopify’s workflow can send requests to installed apps and sales channels, but merchants remain responsible for confirming how each provider processes the request and coordinating with providers connected outside that workflow.
Mage Test Mode can block non-test customers from earning, redeeming, or triggering integration events while you validate program behavior.
Points, tiers, referrals, and order history after deletion
Review whether the points balance, points transactions, tier status, referral links, reward history, and account identifiers should be erased, anonymized, or retained under a documented exception.
Do not promise that deleting a customer profile preserves their points. An account-based benefit may no longer be usable if the identity and account needed to operate it are removed.
Shopify explains that erasure can redact personal details while some sale information, such as what was sold and the date and time of sale, may remain visible (Shopify).
Write loyalty terms and conditions that match the actual program
Points and reward mechanics
Loyalty terms explain the commercial deal. State how customers earn points or store credit, what purchases or actions qualify, which products or transactions are excluded, and how refunds or canceled orders affect earned value.
Explain reward types, minimum spends, reward limits, code expiry, combination rules, and whether a reward is applied through a code or at checkout. Terms should match the program customers actually see.
Expiry, refunds, fraud, and account closure
Explain when the expiry clock begins, whether it resets after a purchase, how reminders work, and what happens when points expire.
Address refund reversals, duplicate accounts, self-referrals, suspicious activity, account closure, and misuse. Be specific about the situations that can affect points or rewards.
Changes to the program and customer rights
Say how you will communicate program changes and whether existing balances or issued rewards are protected. A change to future earning rates is different from canceling an already-issued reward.
Keep the distinction clear: the privacy notice explains how personal data is processed, while the loyalty terms explain how the program operates.
Use this Shopify loyalty privacy checklist before launch
Enrollment and consent checklist
- List every loyalty data field and every system that receives it.
- Define the purpose and lawful basis for each activity.
- Separate enrollment from email and SMS marketing opt-ins.
- Link the privacy notice and loyalty terms at enrollment and from customer-facing loyalty surfaces.
- Record consent details and withdrawals.
Vendor, security, and data-flow checklist
- Identify controller and processor roles for each provider.
- Confirm DPAs with loyalty, email, SMS, review, subscription, support, and analytics providers.
- Document subprocessors, international transfers, deletion procedures, security commitments, and breach-notification obligations.
- Use appropriate access controls and limit access to customer data to people who need it.
- Document integrations, events, and automated triggers.
- Maintain an incident process for escalating suspected breaches with vendors. Where GDPR or UK GDPR applies, a qualifying personal data breach may require notification to the relevant supervisory authority within 72 hours.
- Test new earning, redemption, and integration behavior before release.
Customer-rights and retention checklist
- Document retention periods for profiles, ledgers, rewards, referrals, receipts, and marketing records.
- Decide what happens to points, tiers, referral links, rewards, and order history after closure or erasure.
- Assign an owner and response deadline for customer-rights requests.
- Add a privacy and data-flow review when you audit your loyalty program.
This checklist is operational guidance, not legal advice. Have qualified privacy counsel review the program for the jurisdictions where you sell.
Frequently asked questions
Does GDPR apply to a Shopify loyalty program?
Yes, GDPR or UK GDPR may apply when the merchant’s processing falls within their scope. Loyalty programs process personal data through enrollment, purchases, rewards, referrals, and communications, so merchants should assess their purposes, lawful bases, notices, vendors, retention rules, and customer-rights process. Shopify tools can support compliance workflows, but they do not determine the merchant’s obligations.
Do customers need consent to join a loyalty program?
Consent is not automatically the required lawful basis for operating every loyalty program. The appropriate basis depends on the program structure and legal advice, while promotional marketing permission should remain separate, specific, and voluntary.
Can I send loyalty emails without separate marketing consent?
Loyalty emails can be operational or promotional, and the distinction determines the compliance analysis. A balance update or reward confirmation may support program operation, while a sale announcement is marketing. UK merchants should consider PECR, consent requirements, and any available soft opt-in before sending electronic marketing.
What happens to loyalty points after a GDPR erasure request?
Review the request, relevant legal exceptions, loyalty terms, and connected systems, then decide whether the balance and related records are erased, anonymized, or retained for a justified purpose. Do not promise that points survive deletion.
How long can I keep loyalty program data?
Loyalty program data can be kept only for as long as it is necessary for its documented purpose. Set separate retention rules for member profiles, points ledgers, redemptions, referrals, receipt images, marketing permissions, and legally required transaction records.
What should loyalty program terms and conditions include?
Loyalty program terms and conditions should cover earning, redemption, refunds, expiry, reward limits, referrals, fraud, account closure, program changes, and customer support. They should also direct customers to privacy information and rights requests.
A loyalty program needs a written answer for each data flow before customers enroll. Map the data, separate permissions, confirm vendor responsibilities, test deletion and incident workflows, and assign an owner for customer requests.
Graeme is the co-founder at Mage Loyalty. He heads product development, from complex loyalty migrations and large-scale data handling to building the features shaping the future of loyalty on Shopify.
















