THE INDUSTRY FILES

Retail

The loyalty card turns every basket into a named record, merged with bought-in data and sorted into groups by income and lifestyle. The discount is priced as what your data is worth, and the profile lasts the life of the customer relationship.

TRACKING PRIORITY RECOMMENDED

A detailed purchase profile, sometimes with your face. Worth keeping.

IF IT LEAKS HIGH
EXPECT IT KEPT FOR YEARS

Loyalty and purchase history is kept for years; profiles linger until you object.

IDENTITY DEMANDED OPTIONAL

Buying needs payment; loyalty ties purchases to your identity.

Industry profile reviewed 23 August 2026. Also machine-readable via the free API.

IF IT LEAKS

A purchase history reads like a diary: pregnancy, medication, who you buy for. One retail breach exposed 56.9 million shopper accounts, with purchase histories and dates of birth included.

What repeats in the policies

AT THE TILL

The card turns every basket into a named record

Scanning the card or app at the checkout ties each purchase to you: the products, the price, the time, the store, and how you paid, all assigned to your named profile. The lower price only applies once you have identified yourself this way. One card links years of shopping into a single file the shop can read back.

WHERE IT GOES

Your receipts become advertising

The shop compares what you buy against other households, merges it with data bought from outside firms, and sorts you into groups by income and lifestyle. Those groups feed ad platforms and the chain's own advertising arm, both to target you and to find shoppers like you. The record built to hand you offers is the same one packaged as audiences for brands.

IN THE AISLES

The building watches too

Cameras run for what policies call operational purposes, measuring foot traffic and stock levels, not just security. A few chains now name facial recognition in the policy itself, one of them as a live in-store trial. In-store wifi can pick up your phone's identifier and tie it to your loyalty account.

What a company here typically holds

Worked out from the industry, not from any one company. What you actually handed over is yours to record.

Contact InfoAccount ProfileBrowsing & ActivityPurchasesFinancial Messages maybeLocation maybePhotos & Biometrics maybe

What this can reveal about you

Built only from what this kind of service actually collects. A dimension that the data does not support is not listed.

Money and net worth LIKELY

What you buy estimates your spending power.

Health POSSIBLE

Purchases can imply pregnancy, conditions, or medication.

What lawfully stays after you leave

Two kinds of hold. LAW SETS IT: a statute makes them keep it. THEY SET IT: a ground the company grants itself.

identity and age-check records AS LONG AS THEY CHOOSE THEY SET IT

To prove they checked your age or identity and to block known fraud, sometimes held by a separate verification company.

tax and accounting records ABOUT 6 YEARS LAW SETS IT

Tax and company law makes them keep billing and payment records.

records tied to a live or potential dispute THE LIMITATION PERIOD OF THE CLAIM THEY SET IT

They can keep records to defend a live or possible legal claim.

Who wants this data

Your receipts are the product. Segments built from what you buy are matched back to your real account and rented to brands and ad platforms as audiences. When a retailer is breached, that ledger is what spills: one breach exposed 56.9 million shopper accounts with purchase histories, dates of birth and partial card details.

SOLD OR SHARED HIGHLY LIKELY

Loyalty and purchase data is prime targeting and resale data.

AI TRAINING MODERATE

Purchase patterns train recommendation and pricing models.

Even anonymised, this can still be you

Anonymised is their word. Loyalty purchase histories are highly distinctive: four transactions identify 90% of people (de Montjoye et al., Science, 2015).

Name, date of birth, postcode TYPICAL

Fifteen demographic attributes re-identify 99.98% of Americans in a released dataset (Rocher, Hendrickx and de Montjoye, Nature Communications, 2019); date of birth, postcode, and sex alone did it for most people in the first study of the problem (Sweeney, 2000).

Location traces SOMETIMES

Four time-and-place points single out 95% of people in mobility data (de Montjoye et al., Scientific Reports, 2013).

Payment patterns TYPICAL

Four card transactions identify 90% of people in payment data (de Montjoye et al., Science, 2015).

How you write SOMETIMES

Language models infer where a person lives, their income, and their sex from their writing alone, at near-human accuracy and at scale (Staab et al., ICLR 2024).

Face and voice SOMETIMES

A face, voice, or fingerprint template identifies a person directly; there is nothing left to anonymise, and it cannot be reissued like a password.

Browsing fingerprint TYPICAL

Browser and device fingerprints were unique for 84% of visitors in the first large study (Eckersley, 2010), and sparse histories of what people viewed re-identified them against public reviews (Narayanan and Shmatikov, 2008).

THE STUDIES Estimating the success of re-identifications in incomplete datasets using generative models (Nature Communications 10, 3069, 2019)·Simple Demographics Often Identify People Uniquely (Carnegie Mellon University, Data Privacy Working Paper 3, 2000)·Unique in the Crowd: The privacy bounds of human mobility (Scientific Reports 3, 1376, 2013)·Unique in the shopping mall: On the reidentifiability of credit card metadata (Science 347 (6221), 2015)·Beyond Memorization: Violating Privacy via Inference with Large Language Models (ICLR 2024, 2024)·How Unique Is Your Web Browser? (Privacy Enhancing Technologies Symposium (PETS 2010), 2010)·Robust De-anonymization of Large Sparse Datasets (IEEE Symposium on Security and Privacy, 2008)

The wording that does the work

Clauses that recur across this industry, and what each one actually permits.

“to provide and improve our services”

The catch-all purpose. Analytics, profiling, personalisation, and increasingly AI training can all ride under it. When they want to do something new with your data, this sentence usually already covers it.

THE MOVE An objection draws the line: use your data to run the service, not to improve, target, or train on it.

“we do not sell your personal information”

Often technically true, and still misleading. It usually means no cash changes hands. Data can still flow to ad networks, analytics firms, and partners: on their definition, sharing is not selling.

THE MOVE Flip the do-not-sell switch where one exists. The written objection on top of it goes on your record.

“service providers, partners, and affiliates”

How data leaves the building with no name attached. Recipients are listed by what they do, never who they are. You cannot send a request to a company you cannot name, which is the point.

THE MOVE An access request can ask for the recipients by name, not just the categories. UK and EU law put that choice with you. The reply, or the silence, goes on your record.

“aggregated or de-identified information”

Stripping the name does not strip the pattern, and the pattern often still points at you. Policies grant themselves free, indefinite use of this data because in their telling it is no longer about you.

THE MOVE If a deletion comes back as 'anonymised', keep the reply. It is their claim, not a fact you can check.

“retained as long as necessary, or as required by law”

They can keep it for: legal duties, tax rules, fraud prevention, possible lawsuits, their own business reasons. None of them carries a firm end date. Deletion becomes a negotiation, not an event.

THE MOVE Which reasons apply to you, and how long each runs, is a request of its own. Their reply goes on your record.

“you grant us a licence to use your content”

A contract term, not a data setting, so a privacy request cannot undo it. The careful version ends with your account. The broad version can be passed on, never expires, and survives deletion.

THE MOVE Whether the licence ends with the account is written in their terms, not yours. Closing the account goes on your record.

“we keep your data for as long as you continue to shop with us”

The purchase ledger has no fixed end, because being a customer never formally finishes. A rare few schemes cancel the account after a long stretch of not shopping; most name no horizon at all, so the record can sit for years after your last visit.

THE MOVE A deletion or access request makes them act on a record they would otherwise hold with no end in sight. Their reply, or their silence, goes on your record.

“these financial incentives are reasonably related to the value of the data you provide”

In the US, the loyalty scheme is written up as a formal data-for-discounts trade, so the lower prices are the payment for your data. The policy lets the chain put a figure on what you are worth: one chain's own estimate is about $4.13 per member.

THE MOVE Whether your account is run as a US financial-incentive scheme, and what they value your data at, is theirs to state. Their reply goes on your record.

“your prices are personalised to you based on your shopping habits”

The discounts you are shown are shaped by your own purchase history, so two shoppers can be offered different prices for the same item. The more you scan, the further your prices drift from what other members see.

THE MOVE What data sets your prices, and how, is theirs to explain. Their reply goes on your record.

From the Dispatch

Their own policy is the one that binds them. Pin it down with a request, and keep the reply. Start your record →