et RGPD : ce que tout commerçant doit savoir loyalty card
As soon as your loyalty card records a first name, a number or an email, you are processing personal data. Nothing complicated, but a few rules are mandatory. Here are the essentials, in plain words. (This guide is for information only and is not legal advice.)
Collect the minimum
Only ask for what you really need: a first name and a way to get in touch are enough for a loyalty card. Date of birth is only useful if you offer a birthday gift, and can stay optional.
Consent for offers
To send marketing offers by SMS, email or notification, you generally need the customer's prior consent: an unticked checkbox, or notifications turned on voluntarily. Every message must offer an easy way to unsubscribe.
Let your customers know
At sign-up, the customer must know who processes their data, why, for how long, and how to exercise their rights (access, rectification, deletion). A link to a clear privacy policy is usually enough.
How long should data be kept?
For marketing, the CNIL recommends keeping a customer's data for at most 3 years after their last contact (last purchase, last visit). Beyond that, delete or anonymise it.
Secure the data
Protected passwords, limited access, regular backups: you are responsible for the security of your customers' data. If you use software, choose a provider that explains this clearly and signs a data processing agreement.
And with a loyalty solution?
A good solution builds in these obligations: consent at sign-up, one-click unsubscribe, account deletion by the customer, data export. You remain the owner of your customer file.