Glossary
What is first-party data?
First-party data is information a business collects directly from its own customers, such as a phone number given at the counter, and in a loyalty programme it is the asset the programme produces.
Most small businesses reach their customers through something they do not own: a delivery aggregator, a booking platform, a coalition scheme, a social feed. Each of those intermediaries holds the relationship and can change the terms of access or withdraw it. A loyalty programme's least-discussed output is a list of customers a business can contact directly, without asking anyone's permission or paying for reach. That is often worth more over several years than the incremental visits the rewards themselves generate.
Why does first-party data matter to a small business?
Because it is the only route to a customer that cannot be taken away or repriced. A platform can raise its commission or change what it shows; a phone number the customer gave you directly keeps working.
It is also the only basis on which a business can tell who its regulars are. Without a record, a shop recognises faces and learns nothing when one stops appearing.
What data does a loyalty programme need?
A phone number and a record of visits is enough to run a wallet loyalty programme and to identify lapsed customers. Anything beyond that should be justified by a specific use, because unnecessary data is a liability rather than an asset.
Under the GDPR that restraint is also an obligation: data minimisation means collecting what the stated purpose requires and no more. A birthday collected for a birthday reward is fine; one collected in case it becomes useful is not.
Who owns the customer list?
The business does, as data controller, with the loyalty platform acting as a processor on its instructions. Confirm two things before committing: that the contract says so, and that the customer list belongs to the business and can be returned on request to [email protected], including stamp balances.
The customer retains their own rights over that data throughout, including erasure, and those rights sit alongside the business's ownership of the list rather than contradicting it.
See also
- Data controller: The data controller is the organisation that decides why and how personal data is processed; in a loyalty programme this is the business running the programme, not the software vendor.
- GDPR consent: GDPR consent is the freely given, specific and recorded permission a business must obtain before processing an EU customer's personal data for a loyalty programme.
- Coalition loyalty: Coalition loyalty is a scheme shared by many unrelated businesses, where customers collect one currency across all of them (Payback and DeutschlandCard in Germany, Nectar in the UK) and the scheme operator, not the business, owns the customer relationship.
- Customer lifetime value: Customer lifetime value is the total revenue a business expects from one customer across the whole relationship, rather than from a single transaction.
Further reading
GDPR and loyalty programmes: what a small business must do
The practical compliance checklist for running a digital loyalty programme in the EU: lawful basis, consent for marketing, retention limits and data subject rights.
Do loyalty programmes work?
An honest look at the evidence: where loyalty programmes measurably change behaviour, where they only subsidise customers you already had, and how to tell which is happening.