# What data a loyalty card should collect

> A phone number. The rest is optional, and the year of birth is never asked for and never stored. What Kanz collects, what it refuses, and what a customer undoes in one move.

- Source: https://usekanz.com/en/blog/loyalty-card-customer-data
- Language: en
- Other languages: [ar](https://usekanz.com/ar/blog/bayanat-zabain-bitaqat-alwala), [fr](https://usekanz.com/blog/donnees-clients-carte-fidelite)
- Format: Markdown, generated from the same source as the page.

- Published: 2026-09-16
- Author: Kanz
- Topics: Privacy, Sign-up, Product
- Reading time: 4 min

A phone number. That is the only required field for a loyalty card to work, and everything
else you add to that form costs you sign-ups while usually bringing back nothing.

First name, email address and birthday are optional in Kanz. The birthday is limited to
**the day and the month**: the year of birth is never asked for and never stored. It is of
no use for wishing somebody a happy birthday, and it is one of the most sensitive things a
form can pick up while nobody stops to ask why.

## The rule: every field pays its rent

A field on a sign-up form at the counter has an immediate cost, measurable in lost sign-ups,
and a deferred one, which is keeping it, protecting it and having to answer for it.

So ask the question this way round: **what do I actually do with this data tomorrow
morning?**

The phone number identifies the person and lets you reach them: it pays its rent. The first
name lets you write a message that does not open with a bare "Hello": it pays its rent too,
just about. A full date of birth, a postal address, an occupation, a gender, a number of
children: none of that turns into an action in a small local business. These are fields
collected because a form offered them.

## What a wallet card cannot do

There is a difference in kind between a loyalty card in the phone's wallet and an installed
loyalty app.

An app can ask for location, contacts, photos and the camera, and can ask again after an
update. A wallet pass cannot. It is not an app: it is a data object in the standard format
of the two systems, with no code to run. There is nothing to grant because there is nothing
running.

That is why the sentence "we do not track your customers" is worth something here and not
elsewhere: it is not a promise that can be withdrawn, it is a property of the format.

## Consent is a record, not a tick box

When somebody signs up, Kanz writes a line of consent: what, when, through which channel,
and under which version of the legal text in force that day.

That last part is the one everybody forgets and the only one that counts on the day the
question gets asked. "The customer agreed" cannot be checked two years later if the terms
changed in between. "The customer agreed to version 3, on 14 March, from the sign-up page"
is a statement that holds.

## Unsubscribing takes a single move

The unsubscribe link is on the back of the card and in every message sent. It is signed, it
does not expire, and it does the job immediately: no confirmation page, no "are you sure",
no exit survey, no account to track down.

That it never expires is deliberate. A card added today still has to be able to unsubscribe
in two years, including for somebody who has changed phone in the meantime and has no way
left of finding anything.

And the link does one thing only: **what it exists for is part of what is signed**, so an
unsubscribe link cannot be replayed as a card download link, or the other way round. It
stays usable as many times as you like, and it can never do anything other than what it was
issued for.

A page that tries to catch somebody at that moment is exactly why people end up wary of
loyalty programmes in general. The unsubscribe has already happened before the page loads.

## The business owner cannot undo it

This is the part that surprises people, and the part to remember.

Once a customer has unsubscribed, no setting on the business side puts them back on the
list. There is no path in the product to reverse an unsubscribe, not for the owner of the
business, and not for the people who operate Kanz either.

The only thing that can bring them back is **the customer**, by signing up again through
the same public form as the first time. Signing up again is the same move as signing up:
nobody is ever made to ask twice.

In the check that runs before every send, the unsubscribe is verified in second position,
before the time of day, before the caps, before the budget and before the credits. It is
not at the bottom of the list with the rare cases.

## What this changes at the counter

A one-field form gets filled in standing up, with a queue behind. A six-field form gets
filled in at home, which is to say never.

So ask for the number. Ask for the first name if you intend to use it. And leave the
birthday to the person who wants to give it, because that is the person who really is
expecting something that day.

The sign-up flow is set out in full [here](/en/blog/loyalty-without-an-app), and the
[sending rules](/en/blog/when-to-message-customers) in another article.

## Create an account

The trial runs 30 days and asks for no card.

- [Sign up](https://usekanz.com/signup)
- [Merchant panel](https://usekanz.com/panel)
