DxtraBETA
Back to blog
Use CasesSingaporeSmall Business July 2026 6 min read

Everyone at the counter just saw my name: the loyalty-programme privacy moment nobody designs for

You give your mobile number to help track reward points and your name lights up on the counter screen for everyone to see. As small businesses scale and add loyalty, privacy becomes dozens of tiny moments — here's how to design them well under Singapore's PDPA.

Daryl ArnoldDaryl Arnold
A cafe counter with a customer-facing payment tablet greeting a loyalty member by name, a queue softly blurred behind.

There is a coffee shop I loved years ago in Singapore — back when it was one small independent shop on a corner, the kind of place where the person behind the counter knew your order before you said it. Warm kaya toast, a couple of tables, a hand-chalked specials board. Over the years it did what every good little place quietly dreams of: it grew. A second outlet, then a handful, then an acquisition by a larger food-and-beverage group. And somewhere in that journey — as almost always happens — it added a loyalty programme.

I was reminded of all of this recently, at one of its counters, by a tiny moment that has nothing and everything to do with privacy.

The moment

I ordered, and at the till the cashier asked for my mobile number to add reward points. I gave it. And there, on the customer-facing tablet angled out toward the queue, my full name appeared: "Hi, [my name] — you have 240 points." The three people waiting behind me could read it as easily as I could.

It is a small thing. Nobody meant any harm. But I felt the flicker most of us feel and then shrug off — everyone just saw that — and it stuck with me, because it is the perfect illustration of something that happens to every growing business. Privacy stops being a document filed somewhere and becomes dozens of tiny, real-world moments. And almost nobody ever sat down to design them.

Why loyalty changes the picture

Here is the shift that sneaks up on you. When you were one shop remembering regulars in your head, data-protection law was barely in the frame. The moment you run a loyalty programme — collecting mobile numbers, names, and spending history to award points — you are an organisation handling personal data, squarely within Singapore's Personal Data Protection Act (PDPA).

And that loyalty database is quietly your most data-rich asset: who your customers are, how to reach them, what they buy, how often. It is valuable because it is personal — which is exactly why it comes with a few responsibilities you never had when it was just you and a chalkboard.

The three things loyalty programmes most often miss

None of this means loyalty is a bad idea. It is a lovely idea. It just tends to arrive with three things most programmes never quite finish.

  1. Consent and purpose, at sign-up. When someone hands over their number for points, they are agreeing to that — points. If you also plan to send them marketing, or to share the data across the affiliated brands in the group, the PDPA expects you to say so and get their agreement for those purposes too, at the moment you collect it. A number captured for points is not a number you can quietly fold into a group-wide mailing list later.
  2. A notice that actually names this programme. Members have a right to find a clear notice describing this loyalty programme — what it collects, who runs it, how long it is kept, their rights to see and correct their data, and a named contact (the PDPA requires you to appoint a Data Protection Officer). Not a generic "our affiliated brands" umbrella policy three companies up the chain. No website of your own? A QR code on the sign-up card or at the till does exactly this.
  3. Displaying — and collecting — only what you need. This is the name on the screen. A full name on a public-facing display is avoidable exposure: the counter tablet does not need to greet me by full name for me to get my points. Initials, a member number, or the last three digits of my phone would do the identical job with none of the announcement. This is not a dramatic breach — it is a reasonableness question, the kind the PDPA's Protection Obligation is pointed at — and it is the single easiest win in this whole piece.

Two more, quickly, if your programme has grown up: if an outside company or an overseas platform runs it for you, that relationship — and any data sent abroad — needs to meet the PDPA's comparable-protection standard; and because a loyalty database is precisely what a data thief wants, it is worth having a simple plan for who you notify if it is ever breached (for serious breaches, the PDPA requires telling the regulator and affected members).

The honest picture

Let me be clear about the stakes, because scare stories help no one. The realistic issue here is not a regulator kicking down the door of a coffee shop. It is trust. The reason to mask the name on the screen, and to write a proper loyalty notice, is that your customers handed you their details because they like you — and the entire point of a loyalty programme is that relationship. Respecting the data is respecting them. (Singapore's regulator can levy real financial penalties — up to S$1 million, or 10% of annual turnover for larger organisations — but that is context, not the reason to do this.)

How to design the small moments well

So the fix is not a compliance mega-project. It is designing the small moments with a little care.

Give the programme a real privacy notice and proper consent at sign-up. Say what you collect, why, who runs it, how long you keep it, and whether it is used for marketing or shared across the group — and let people agree to that, specifically. Dxtra generates the notice, the consent form, and the point-of-collection line, and gives you a QR code you can put right on the counter or the sign-up card, so a member can scan, read, and consent in seconds. It is the loyalty notice for a business that lives at a counter, not on a website.

Mask the display. Ask whoever supplies your point-of-sale system to greet members by initials or member number instead of full name. It is usually a setting, not a rebuild.

And if you run a website too, it is worth seeing what else is quietly exposed — a free Dxtra scan reads your public pages the way a regulator would.

That is the afternoon's work, and much of it is one-time. The dividend is a loyalty programme your customers can trust — which is the only kind worth running.

Stand up a privacy notice and consent for your loyalty programme — shareable at the counter by QR code → Dxtra generates all of it, hands you the QR code and short link, and you review everything before it goes live. From $10 a month (about S$13).

That little corner shop taught a lot of us what good service feels like: being known, and being treated with a bit of care. A loyalty programme is really just that instinct, scaled — and the privacy is the part that keeps the care in it.


This article is for general information and is not legal advice. Privacy obligations depend on your circumstances — confirm anything that matters with the PDPC (pdpc.gov.sg) or a qualified adviser before you rely on it.

Ready to get compliant?

Start your privacy program today — from $10/month.