Short answer: yes, a shop may keep customer data for a loyalty card: rewarding customers is a legitimate purpose under the GDPR. You stay compliant with five simple rules: collect as little as possible, be clear about what you use it for, store it securely, give your customer their rights (view, take along, delete), and keep it no longer than needed. A loyalty card without an app makes that a lot easier: there is nothing to install and you collect almost nothing from the start. With BLOK a card is by default no more than an anonymous card number and points, on European servers. Below, the rules in plain language.
This is general information to get you started, not legal advice. If in doubt about your own situation, consult the Belgian Data Protection Authority, your own country's authority, or a specialist.
May you keep customer data at all?
In short: yes. The GDPR does not forbid using customer data; it asks that you do it carefully. Setting up a loyalty program to reward regular customers is a clear, justified purpose. The question is not whether you may keep a loyalty card, but how. And that comes down to five principles.
The five rules in plain language
- As little as possible (data minimisation). Ask only for what you really need. A card that only counts visits needs no name or email. Every extra field is an extra responsibility.
- Be clear (transparency). Tell your customer briefly what you use their data for (saving and rewarding), and nothing sneaky on top.
- A valid basis. For the loyalty card itself that is the service your customer asks for; for something extra such as a newsletter you ask separate consent.
- Store it securely. Encrypted traffic, European servers, no data resold. Pick a system that does this by default, so you do not have to watch over it.
- Your customer's rights. They may view, take along or delete their data. Make that easy, preferably without you having to do anything.
Why “without an app” is already more privacy-friendly
A loyalty app your customer has to install often asks for access to location, notifications or contacts, and regularly contains trackers that follow behaviour across several shops. A loyalty card without an app simply runs in the browser: your customer scans a QR code at the counter and saves immediately, nothing to install, no account, no tracking SDK. Less data on the move means less for you to account for, and a lower threshold for your customer to join.
What BLOK keeps (and what it does not)
Concretely, so you know exactly where you stand:
- By default: an anonymous card number and the number of points. Nothing more.
- Optional: name, email address and birthday, only if your customer gives them, for example for a birthday treat.
- Where: on European servers (Vercel in Paris, database with Neon in the EU). Your data does not leave the EU and traffic is encrypted.
- Never: sold, used for advertising or shared with another shop. Each shop only sees the points earned at its own counter.
Your customer stays in control
A request to view or delete data does not have to be a hassle. With BLOK your customer views or downloads their data directly on their card, and deletes their card whenever they want; their data then disappears for good. As a shop you handle this in your settings. So you meet your customer's rights without turning it into a procedure.
GDPR-compliant saving, in short
- Start with a card that only counts visits; add data only when you really use it.
- Say in one sentence what you use the data for.
- Pick a system with European servers and encrypted traffic.
- Never sell or share customer data.
- Make viewing and deleting easy for your customer.
A free loyalty card that follows these rules by default? Your shop is online in five minutes, without an app for your customer. Start free →
Read the Dutch version of this article.