Loyalty Programs and Data Privacy: What Shopify Brands Need to Get Right

Written by
Graeme
Graeme
Co-Founder
Reading time
10 min read
Date posted
September 24, 2026
White text reading “Loyalty Programs and Data Privacy” over a soft gradient background

A loyalty program processes far more than a points balance, which is why loyalty program GDPR compliance needs to be designed into the program before launch. Enrollment, purchases, rewards, referrals, customer accounts, receipt uploads, and marketing integrations can each create a separate use of customer data.

Short answer: A loyalty program needs a clear purpose, lawful basis, retention rule, and customer-rights process for each data activity. Joining the program, accepting its terms, and opting into promotional email or SMS should be separate choices, explained in plain language.

Loyalty program GDPR compliance starts with a data map, not a checkbox

What a loyalty program actually processes

Start by mapping the information your program collects, receives, creates, and shares. A Shopify loyalty program may use a customer’s name, email address, phone number, account details, purchase history, points activity, redemption history, VIP status, referral activity, reviews, wishlist actions, receipt images, and integration events.

A purchase-based earning rule needs order and customer data to calculate points. A referral program may need referral links, conversion records, and fraud checks. Receipt scanning creates another category because customers submit an image.

Joining a program gives a customer access to its benefits. It does not automatically mean they agreed to promotional email or SMS.

A customer may want points updates, reward confirmations, or a balance in their account without agreeing to product launches, sale announcements, or recurring text campaigns. Treat these as separate choices in both the form design and your underlying records.

Why Shopify does not make the program automatically compliant

Shopify says merchants are generally the controller of their customers’ data, and that using Shopify alone does not guarantee GDPR compliance (Shopify). Your loyalty app, email platform, review tool, and support system add more data flows that you need to assess.

Build the map first. Then assign a purpose, lawful basis, owner, and retention rule to each flow.

GDPR, UK GDPR, PECR, and US privacy rules

GDPR and UK GDPR set data-protection obligations when your processing falls within their scope. PECR adds UK rules for electronic marketing, including email and SMS. US privacy obligations vary by state and can apply alongside European requirements depending on your business locations, customers, and applicable laws.

This is not legal advice. Ask qualified privacy counsel to assess which rules apply to your store and loyalty program.

Signup elementWhat it coversHow it should be presentedWhat to record
Program enrollmentAccess to points, rewards, and account benefitsClear explanation of the program and links to noticesEnrollment date and program version
Loyalty termsCommercial rules for earning and redemptionLink near enrollment, written in plain languageTerms version accepted
Email marketingPromotional email permissionSeparate unticked optionChannel, time, source, wording
SMS marketingPromotional text permissionSeparate unticked optionChannel, time, source, wording
Operational updatesBalance, reward, and account communicationsExplain as part of program operationMessage purpose and delivery record

What customers should see at signup

The enrollment screen should say what the customer receives, what information you use to run the program, and where they can read the privacy notice and loyalty terms.

Use separate optional boxes for marketing channels. Email and SMS are not interchangeable permissions.

For UK-facing stores, electronic marketing rules under PECR sit alongside UK GDPR. The ICO says unsolicited email and SMS marketing to individual subscribers generally needs specific consent, subject to a limited soft opt-in (ICO guidance).

Record who consented, what they were shown, when they consented, how they consented, and whether they later withdrew permission.

Your records should distinguish enrollment from marketing. If a customer withdraws email consent, your team needs to know whether that changes promotional messages only or affects program access as well.

Operational loyalty messages versus promotional messages

A reward confirmation or points-earned update can be an operational program message. An email promoting a new collection is marketing, even if it mentions the customer’s tier.

The ICO notes that loyalty-scheme members may receive scheme-related messages under the soft opt-in when clear opt-out information is provided, while marketing outside the scheme may require clear consent (ICO guidance). Classify messages before building loyalty email templates.

If loyalty events sync to your email platform, document the customer properties and events involved. A Klaviyo loyalty integration, for example, should be part of the data map.

Build a loyalty privacy notice customers can actually understand

The data categories and purposes to name

A useful privacy notice names the data you collect at enrollment and the data created later. Cover profile details, purchase and earning activity, reward redemptions, VIP progression, referral records, reviews, social actions, wishlist behavior, receipt uploads, and account activity where relevant.

Explain why you use each category. Common purposes include calculating points, issuing rewards, managing referrals, preventing fraud, responding to support requests, measuring program performance, and sending requested operational communications.

Mage is a loyalty and rewards platform built for Shopify stores, and its customer metafields can include points balance, lifetime points, redeemed points, VIP tier, and member status (Mage help center). Those fields are a useful prompt for your own inventory, not a substitute for a privacy assessment.

The providers and integrations to disclose

Identify the providers that process program data, including Shopify, your loyalty platform, email and SMS tools, review tools, subscription tools, support tools, and analytics providers. Explain international transfers where they apply, and point customers to the relevant provider information.

Confirm whether you have appropriate data processing agreements, or DPAs, with providers acting as processors. Document controller and processor roles, subprocessors, international transfers, deletion procedures, security commitments, and breach-notification obligations.

Your notice should provide a contact route for access, correction, objection, portability, and erasure requests. Do not promise that every deletion request removes every transaction record. Some records may need to be retained under a legal exception.

I looked into so many different integrations for loyalty and referrals for our Shopify Store, but no one impressed me more than Mage on human connection, customer service, and value.
Juan Niño
Juan Niño
Director of Ecommerce, Reelie
Reelie

Read the Reelie case study →

Set a retention schedule for points, rewards, and customer records

Data categoryWhy it existsRetention decisionDeletion or anonymization trigger
Member profileOperate the account and programSet a documented periodAccount closure or inactivity review
Points ledgerCalculate balance and resolve disputesRetain only as long as justifiedExpiry of need or approved anonymization
Reward redemptionsConfirm issued benefits and refundsAlign with operational needsEnd of retention period
Referral recordsAttribute rewards and review fraudDefine a fraud and dispute periodEnd of review period
Marketing consentProve permissions and withdrawalsKeep while needed for complianceConsent withdrawal and documented period
Receipt imagesVerify qualifying purchasesKeep for a limited verification periodVerification complete and no exception

Data retention is purpose-based

There is no universal GDPR retention period for loyalty data. The ICO says organizations should not keep personal data longer than necessary and should document their retention periods (ICO storage limitation guidance).

Set separate rules for active profiles, points ledgers, reward redemptions, referral records, consent records, support tickets, receipt images, and financial or tax records.

How points expiry differs from data deletion

Points expiry changes a customer’s available balance. It does not automatically delete the personal data connected to the earning activity.

Mage points expiry is off by default and can run from the date points are earned or from the customer’s last purchase date (Mage points expiry guide). Merchants can surface balance and expiry information across the Rewards Widget, Loyalty page, and Account Sidebar. That is product context, not a compliance guarantee.

Handle erasure requests without guessing what happens to points

Data or recordPossible actionDecision ownerCustomer communication
Customer profileErase or redact identifiersPrivacy ownerExplain completion or exception
Points balanceErase, anonymize, or retain under an exceptionPrivacy and program ownerState the balance outcome clearly
VIP tierRemove or anonymize statusProgram ownerExplain effect on membership
Referral recordRemove identifiers or retain limited fraud recordPrivacy and fraud ownerExplain what remains and why
Order historyRedact personal details where appropriateFinance and privacy ownerExplain retained transaction information
Marketing consentSuppress future marketing and retain proof as neededMarketing ownerConfirm opt-out status

The right to erasure is not absolute

A customer does not need formal legal wording for an erasure request. Train support teams to recognize requests such as “delete my information,” route them correctly, and avoid improvised promises.

The right to erasure is not absolute. Your team may need to assess legal obligations, disputes, fraud prevention, and other applicable exceptions before acting. Organizations normally have one month to respond, with a possible extension of up to two additional months for complex or repeated requests.

A practical Shopify deletion workflow

Use a documented workflow. Confirm the request, identify the customer record, assess what data is held, send the request through Shopify, coordinate with connected providers, and record the outcome.

Shopify lets merchants request customer data access and erasure from the admin, including requests sent to installed apps and sales channels (Shopify). Shopify’s workflow can send requests to installed apps and sales channels, but merchants remain responsible for confirming how each provider processes the request and coordinating with providers connected outside that workflow.

Mage Test Mode can block non-test customers from earning, redeeming, or triggering integration events while you validate program behavior.

Points, tiers, referrals, and order history after deletion

Review whether the points balance, points transactions, tier status, referral links, reward history, and account identifiers should be erased, anonymized, or retained under a documented exception.

Do not promise that deleting a customer profile preserves their points. An account-based benefit may no longer be usable if the identity and account needed to operate it are removed.

Shopify explains that erasure can redact personal details while some sale information, such as what was sold and the date and time of sale, may remain visible (Shopify).

Write loyalty terms and conditions that match the actual program

Points and reward mechanics

Loyalty terms explain the commercial deal. State how customers earn points or store credit, what purchases or actions qualify, which products or transactions are excluded, and how refunds or canceled orders affect earned value.

Explain reward types, minimum spends, reward limits, code expiry, combination rules, and whether a reward is applied through a code or at checkout. Terms should match the program customers actually see.

Expiry, refunds, fraud, and account closure

Explain when the expiry clock begins, whether it resets after a purchase, how reminders work, and what happens when points expire.

Address refund reversals, duplicate accounts, self-referrals, suspicious activity, account closure, and misuse. Be specific about the situations that can affect points or rewards.

Changes to the program and customer rights

Say how you will communicate program changes and whether existing balances or issued rewards are protected. A change to future earning rates is different from canceling an already-issued reward.

Keep the distinction clear: the privacy notice explains how personal data is processed, while the loyalty terms explain how the program operates.

Use this Shopify loyalty privacy checklist before launch

  • List every loyalty data field and every system that receives it.
  • Define the purpose and lawful basis for each activity.
  • Separate enrollment from email and SMS marketing opt-ins.
  • Link the privacy notice and loyalty terms at enrollment and from customer-facing loyalty surfaces.
  • Record consent details and withdrawals.

Vendor, security, and data-flow checklist

  • Identify controller and processor roles for each provider.
  • Confirm DPAs with loyalty, email, SMS, review, subscription, support, and analytics providers.
  • Document subprocessors, international transfers, deletion procedures, security commitments, and breach-notification obligations.
  • Use appropriate access controls and limit access to customer data to people who need it.
  • Document integrations, events, and automated triggers.
  • Maintain an incident process for escalating suspected breaches with vendors. Where GDPR or UK GDPR applies, a qualifying personal data breach may require notification to the relevant supervisory authority within 72 hours.
  • Test new earning, redemption, and integration behavior before release.

Customer-rights and retention checklist

  • Document retention periods for profiles, ledgers, rewards, referrals, receipts, and marketing records.
  • Decide what happens to points, tiers, referral links, rewards, and order history after closure or erasure.
  • Assign an owner and response deadline for customer-rights requests.
  • Add a privacy and data-flow review when you audit your loyalty program.

This checklist is operational guidance, not legal advice. Have qualified privacy counsel review the program for the jurisdictions where you sell.

Frequently asked questions

Does GDPR apply to a Shopify loyalty program?

Yes, GDPR or UK GDPR may apply when the merchant’s processing falls within their scope. Loyalty programs process personal data through enrollment, purchases, rewards, referrals, and communications, so merchants should assess their purposes, lawful bases, notices, vendors, retention rules, and customer-rights process. Shopify tools can support compliance workflows, but they do not determine the merchant’s obligations.

Consent is not automatically the required lawful basis for operating every loyalty program. The appropriate basis depends on the program structure and legal advice, while promotional marketing permission should remain separate, specific, and voluntary.

Loyalty emails can be operational or promotional, and the distinction determines the compliance analysis. A balance update or reward confirmation may support program operation, while a sale announcement is marketing. UK merchants should consider PECR, consent requirements, and any available soft opt-in before sending electronic marketing.

What happens to loyalty points after a GDPR erasure request?

Review the request, relevant legal exceptions, loyalty terms, and connected systems, then decide whether the balance and related records are erased, anonymized, or retained for a justified purpose. Do not promise that points survive deletion.

How long can I keep loyalty program data?

Loyalty program data can be kept only for as long as it is necessary for its documented purpose. Set separate retention rules for member profiles, points ledgers, redemptions, referrals, receipt images, marketing permissions, and legally required transaction records.

What should loyalty program terms and conditions include?

Loyalty program terms and conditions should cover earning, redemption, refunds, expiry, reward limits, referrals, fraud, account closure, program changes, and customer support. They should also direct customers to privacy information and rights requests.

A loyalty program needs a written answer for each data flow before customers enroll. Map the data, separate permissions, confirm vendor responsibilities, test deletion and incident workflows, and assign an owner for customer requests.

About the author
Graeme

Graeme

Co-Founder

Graeme is the co-founder at Mage Loyalty. He heads product development, from complex loyalty migrations and large-scale data handling to building the features shaping the future of loyalty on Shopify.

Build a loyalty experience your customers remember.

See how modern Shopify brands use Mage to build stronger customer relationships and drive repeat revenue.

Trusted by
  • Reelie
  • Gelato Pique
  • MiaDonna
  • Tea Drops
  • West Coast Goalkeeping
  • Joy Dravecky
  • Love Sweat Fitness
  • The GoTo
  • Youswim

Related articles

Loyalty Program Compliance for Cannabis and CBD Brands: What You Need to Know
Loyalty & Retention

Loyalty Program Compliance for Cannabis and CBD Brands: What You Need to Know

A cannabis reward that pushes a product below a permitted price floor, reaches an ineligible customer, or uses unapproved health language can create more risk than the repeat purchase it generates. Loyalty program compliance for cannabis and CBD brands requires a controlled launch process because product rules, promotional pricing, age eligibility, privacy, and marketing rules can vary by product and market.

Ecommerce Retention Benchmarks by Industry: 2026 Data
Loyalty & Retention

Ecommerce Retention Benchmarks by Industry: 2026 Data

Ecommerce retention benchmarks by industry reveal retention rates from 9.9% to 70% across categories in 2026. Learn where your business stands.

Clean Beauty Loyalty Programs: Why Brands Need Different Strategies
Loyalty & Retention

Clean Beauty Loyalty Programs: Why Brands Need Different Strategies

Clean beauty brand loyalty strategy must prioritize values over discounts. Discover cause-based rewards, sustainable packaging credits & communit...

Ecommerce Conversion Rate Benchmarks 2026: Real Data & Industry Standards
Loyalty & Retention

Ecommerce Conversion Rate Benchmarks 2026: Real Data & Industry Standards

Average ecommerce conversion rate in 2025 revealed. Find out where your store stands and get actionable tips to improve your conversion performance

How to Get Your Loyalty Program Ready for Black Friday Traffic
Loyalty & Retention

How to Get Your Loyalty Program Ready for Black Friday Traffic

Black Friday and Cyber Monday account for roughly 5-10% of annual revenue for most eCommerce stores, but the pressure is relentless. Traffic spikes 10-50x normal levels. Payment systems struggle. Email infrastructure chokes. And loyalty programs—the systems designed to retain your best customers during this critical window—often become the weakest link.

B2B Loyalty Platforms For Ecommerce: Why You Need One In 2026
Loyalty & Retention

B2B Loyalty Platforms For Ecommerce: Why You Need One In 2026

B2B loyalty platforms drive repeat bulk orders and retention for wholesale brands. Learn why Shopify merchants need dedicated platforms, not gene...