GDPR applies to every business that handles personal data about customers, and loyalty programmes are no exception. Many café, restaurant, and salon owners are unsure what they are actually allowed to store, when data must be deleted, and what a legally sound sign-up form looks like. This guide gives you a practical overview of the key rules.
What does a digital stamp card actually record?
When a customer joins your loyalty programme, a profile is created with a minimal set of data: an email address, optionally a name, and a history of visits and redeemed rewards.
All of this is personal data under GDPR because it can be linked to an identifiable person. That includes the visit history itself. Imagine your platform showing that a particular email address has visited your business twelve times in the past quarter: that is personal data, even without a name attached.
A digital stamp card typically collects far less data than a traditional customer app with a full user profile, but any information that can identify a person falls under GDPR regardless of volume.
The legal basis: consent
For loyalty programmes, consent is the most common lawful basis for processing personal data. It means the customer actively agrees to you collecting and storing their information, and knows what they are agreeing to.
A valid consent under GDPR must meet four criteria:
- Freely given: The customer cannot be required to join as a condition of receiving your service. The stamp card is a voluntary offer.
- Specific: You state precisely what you collect, for example an email address and visit history.
- Informed: You explain the purpose and link to your privacy notice.
- Unambiguous: The customer actively ticks a box or clicks "Accept". A pre-ticked field does not count.

A good sign-up form is short. The most important element is a single sentence explaining what the data is used for, with a visible link to your privacy notice. The detail belongs in the policy itself.
For practical tactics to improve your sign-up rate and get more customers saying yes, see the guide on loyalty programme sign-ups.
Data minimisation: only what you actually use
GDPR is built on a principle of data minimisation: collect only what is necessary for the stated purpose.
Imagine setting up a stamp card that asks for a phone number, date of birth, and home postcode at sign-up. If none of these feed into how the stamp card works, you are collecting more than you need.
The minimum for a loyalty programme is typically an email address for account recovery and any communications. A name is useful but not essential. A phone number is only relevant if you actually send SMS to your customers.
Ask yourself for every field in the form: what do I concretely use this for? If you cannot answer precisely, the field should not be there.
What you may use the data for
Data collected to run the loyalty programme may be used for exactly that: logging visits, issuing stamps, calculating and triggering rewards, and letting the customer see their own progress.
Using the same data for email marketing is a separate matter. If you did not collect a specific consent for a newsletter or promotions at sign-up, you do not have grounds to send them. The cleanest solution is to offer both consent options clearly in the sign-up form from the start, each labelled separately: one for the stamp card and one for marketing communications.
Storage limitation: when must data be deleted?
GDPR requires that personal data not be kept longer than necessary for the purpose it was collected for. No specific time limit exists in the regulation for loyalty data, but you must set a retention period yourself and stick to it.
A practical approach is to delete or anonymise profiles of inactive customers after a set period. Imagine setting that threshold at two years: a customer who has not visited in two years is no longer an active member, and their profile no longer serves its purpose. That is a reasonable and defensible point at which to delete.
What matters is that you document your retention period and state it clearly in your privacy notice, so customers know what to expect.
Customer rights: access, correction, and deletion
GDPR gives your customers a set of rights over the data you hold about them:
- Right of access: A customer can ask to see what information you have recorded about them.
- Right to rectification: A customer can ask you to correct inaccurate data.
- Right to erasure: A customer can ask to be removed from your system entirely.
- Right to object: A customer can object to processing they believe is not justified.
You should have a clear process for handling these requests. In a digital loyalty programme, the process is typically straightforward: find the profile by email address, confirm the customer's identity, and delete the account. Requests must be answered within one month.
Three steps to a GDPR-compliant stamp card
You do not need to be a lawyer to run a compliant loyalty programme. The three most important steps are:
1. Write a short privacy notice. It does not need to run to many pages. It should answer: what data do you collect, for what purpose, who has access, and when is it deleted? Link to it at sign-up.
2. Use active consent. The customer ticks the box or clicks "Accept" themselves. A pre-ticked field, or a note saying that signing up implies consent, is not sufficient.
3. Set a retention period and honour it. Decide when inactive profiles are deleted, write it into your privacy notice, and make sure it actually happens.
Your national data protection authority publishes guidance tailored to exactly the kind of business that runs a loyalty programme. In Denmark, that is datatilsynet.dk.
For a full checklist of what to set up before your programme goes live, see the guide on building a stamp card programme.
Frequently asked questions
Do I need to maintain a formal record of data processing activities?
GDPR generally requires businesses to keep a record of processing activities (Article 30). There is an exception for organisations with fewer than 250 employees, but it does not apply if the processing is not occasional. A loyalty programme that continuously logs customer visits is regular processing, so the exception typically does not apply. It is good practice to maintain the record regardless of the size of your business.
Can I send marketing emails to customers who joined my stamp card?
Not automatically. Consent to the stamp card covers use of data to run the loyalty programme. Marketing requires either a separate consent for that purpose or another valid legal basis. The simplest solution is to separate the two consent items clearly in the sign-up form from the start: one for the stamp card and one for marketing communications.
What do I do if a customer asks to have their data deleted?
You are required to comply within one month. In practice: find the profile via the email address, confirm the customer's identity, and delete the account including visit history and reward data. Confirm to the customer that the deletion has been completed. A well-built digital programme makes this possible in a matter of minutes.