Fuel Loyalty Apps and Customer Data Platforms

Known errors in this article have been corrected.
A full claim-by-claim review is still pending. Confirm any figure with your state program before acting on it. Last verified 2026-09-08. Not legal advice.
A loyalty program is a data business you are agreeing to run
The pitch for fuel loyalty is a marketing pitch: more visits, better c-store attachment, a defence against grocery and big-box fuel discounting. That part is real. What it leaves out is that the moment you launch, you are operating a consumer data business — collecting identifiers, location inference, purchase histories and device data on people who live in states whose privacy laws you may never have read.
That is where these projects go wrong. Not in the rewards structure, but in signing before anyone has established what the obligations are, who owns the data, and — a surprisingly live question in this market — who owns the vendor. Consolidation has moved fast enough that much published guidance names products that have changed hands, changed names, or never existed under the name given. So this guide is organised around the two things that decide whether a deployment survives: the obligations you take on, and the diligence to do first.
The obligations, stated correctly
Email and SMS are governed by opposite defaults
This is the single most commonly inverted point in loyalty compliance guidance, and getting it backwards will cost you either customers or a lawsuit.
Commercial email is opt-out. Under the CAN-SPAM Act, at 15 U.S.C. 7704, you do not need a recipient's prior consent to send marketing email. What you must do is not use deceptive headers or subject lines, identify the message as an advertisement, include a valid physical postal address, provide a clear and conspicuous opt-out mechanism, and honour an opt-out request within ten business days. Building an email programme around a consent requirement that does not exist is a self-inflicted wound; failing to honour opt-outs promptly is the actual exposure.
Marketing SMS is opt-in. The prior express written consent requirement people misattribute to CAN-SPAM comes from the Telephone Consumer Protection Act, 47 U.S.C. 227, as implemented by the FCC's rules at 47 CFR 64.1200, and it applies to autodialed calls and texts. The TCPA also carries a private right of action, which is why loyalty text programmes are a recurring class-action target. Do not pre-check the box, keep the consent record, and keep it linked to the number.
Practically: separate the email consent, the SMS consent and the push permission at enrolment. Three legal questions, three checkboxes.
State privacy law follows your customers, not your address
A station in a state with no comprehensive privacy statute can still owe duties to enrolled customers who live elsewhere. The number of states with such laws changes every legislative session, so check the current position rather than relying on any count — but the mechanism does not change: obligations attach to the residents whose data you hold.
| Regime | Reach | Core duty | Consequence |
|---|---|---|---|
| California CCPA/CPRA | California residents, where the business meets a threshold in Civil Code 1798.140(d) — annual gross revenue above $25,000,000 as adjusted, or buying, selling or sharing the data of 100,000 or more consumers or households | Privacy notice; right to delete; right to opt out of sale or sharing; contractual terms with service providers | Administrative fines under Civil Code 1798.155 — $2,500 per violation and $7,500 per intentional violation or one involving a consumer known to be under 16, both adjusted for inflation |
| Illinois BIPA | Illinois residents; biometric identifiers only | Written consent and a published retention schedule before collecting a fingerprint or face scan | A private right of action for statutory liquidated damages or actual damages plus fees, under 740 ILCS 14/20 — enforcement here comes from plaintiffs, not an agency |
| Texas TDPSA | Texas residents, where the business meets the statutory thresholds | Privacy notice; opt-out of targeted advertising and sale | Attorney-General enforcement after a statutory cure period, under Tex. Bus. & Com. Code ch. 541 |
| FTC Act Section 5 | All U.S. businesses | No deceptive or unfair data practice — which includes not doing what your own privacy policy says you do | No civil penalty for a first violation; penalties attach to violating a final order or a trade regulation rule, at an amount the FTC adjusts annually |
| COPPA | All U.S. businesses; children under 13 | No collection without verifiable parental consent | Civil penalty per violation, adjusted annually — take the current figure from the FTC before relying on one |
Two scoping points worth getting right. Biometrics are the sharpest edge in this table because BIPA liability runs to private plaintiffs rather than a regulator, so any facial-recognition or fingerprint feature in a loyalty app deserves its own decision rather than arriving bundled. And the GDPR does not attach merely because a European tourist fills up at your pump: it applies where you offer goods or services to people in the EU or monitor their behaviour there.
Payment data is its own regime
Pay-at-pump inside the loyalty app is not standard card acceptance. It requires compliant token handling, and your loyalty vendor must be a certified payment facilitator or partner with one. Ask for the vendor's self-assessment questionnaire type and its current Attestation of Compliance, referencing PCI DSS v4.0.1 — the active version of the standard, with the requirements that were future-dated in v4.0 mandatory since 31 March 2025. Understand also that the consequence of failing is contractual, not regulatory. The PCI Security Standards Council levies no fines; assessments reach you from the card brands through your acquirer, on terms written into your merchant agreement.
Vendor diligence: check who owns what before you check features
The fuel loyalty vendor market has consolidated, and product names have followed. Before evaluating capability, establish identity. Here is the current shape of the field, and each of these should be re-confirmed on the vendor's own site at the time you shortlist:
- PAR Retail is PAR Technology's convenience and fuel retail loyalty product. It absorbed Stuzo — stuzo.com now redirects to parretail.com — so guidance naming Stuzo as an independent forecourt platform is describing a company that no longer trades under that name.
- Punchh Loyalty is also PAR Technology's, acquired by PAR and marketed principally to restaurants. It is not a PAX Technology product; PAX is a payment terminal manufacturer, and confusing the two is a common error.
- PDI Technologies publishes PDI Loyalty, the PDI Engagement Mobile App, PDI Experience Designer and PDI Subscriptions. Those are the product names. It is tightly coupled to PDI back-office and common in wholesaler and distributor networks.
- Paytronix sells an enterprise loyalty and customer data platform with gift card and online ordering modules and multi-site reporting.
- Rovertown (Rover Enterprises LLC) is an app platform for convenience retail, not a customer data platform. It builds the branded customer-facing app and connects to loyalty, payment and ordering vendors including Punchh, Kickback, Patron Points and Olo. If you buy it expecting unified profiles and segmentation, you have bought the wrong layer.
- DRB, a Vontier company, sells car wash point of sale, and Patheon is DRB's own product for unlimited plans and recurring billing — the two are one company, not competing vendors.
Branded operators start elsewhere. Shell's Fuel Rewards, BP's BPme and ExxonMobil Rewards+ are ready-made and need little from you, and the trade is explicit: the brand owns the customer data and your ability to tailor offers is limited — which is why unbranded and jobber-supplied operators often end up with the better dataset.
The questions to put to every shortlisted vendor
- Who owns the customer data, in the contract? Get the clause, not the sales answer. Then get the exit clause: what you receive, in what format, if you leave.
- Produce a data flow diagram. Where does customer data travel, who can access it, how is it encrypted at rest and in transit. A vendor that cannot produce one has told you something.
- Which point-of-sale platforms and software versions are you certified against? In writing, with versions.
- Will you sign a data processing agreement? Every party touching customer data needs one — loyalty platform, analytics, email provider.
- How do you support deletion requests? Under CCPA you must respond within 45 days, and the data has to actually be purged from your systems and your processors'.
- What is your breach notification obligation to me, and on what clock?
- Do you run annual penetration testing, and will you share results?
- What does your consent capture look like for email, SMS and push separately?
- What happens to my programme if you are acquired? Given this market, it is a fair question.
Integration: certification is the gate, not the API
Every platform claims API integration. What matters is certification against your specific configuration. Both Passport — sold under the Invenco by GVR brand since Gilbarco Veeder-Root rebranded its retail solutions business in July 2023 — and Verifone Commander support loyalty integrations, but depth varies by vendor and by software release, and a mismatched version is the most common failure point. Get the certified version list from the loyalty vendor and the upgrade quote from your point-of-sale distributor before signing either contract.
Verify these four capabilities specifically, because they are where generic integrations fall short:
- Loyalty identifier capture at the dispenser itself — can a customer enter a number or scan a code at the Gilbarco Encore or Wayne Ovation screen, or only inside?
- Real-time discount authorization — does the cents-per-gallon discount apply before the transaction closes, or as a later adjustment?
- Inside redemption at the register without a second terminal
- Transaction-level loyalty data flowing into your back-office reconciliation automatically
Because a loyalty platform aggregates payment tokens, personal data and behavioural profiles in one place, segment its traffic from your fueling network and point-of-sale LAN, require multi-factor authentication on admin portals, and monitor for point-draining fraud. Our guide to station cybersecurity covers the segmentation work.
Economics you can actually control
Cents-per-gallon discounting is intuitive and expensive if uncalibrated, because the cost scales with the product carrying your thinnest margin. Points-based structures give you more control: you set the redemption value and can push bonuses into your slow hours rather than subsidising volume you would have had anyway. Model it before launch with your own numbers — a ten-cent-per-gallon discount across 100,000 monthly gallons costs $10,000 a month, and the question is what inside-sales attachment rate repays that at your c-store margin. That break-even, not a vendor benchmark, is your design constraint.
Personalization is the genuine argument for a customer data platform over a plain loyalty app. Vendors publish lift figures for it; measure it yourself against a control group instead, as you would with any other analytics tool. Linking loyalty data to c-store inventory management closes the loop and shows which promotions drive incremental purchases rather than discounting ones that were happening anyway.
Track member versus non-member visit frequency, average transaction value, attachment rate, redemption rate, enrolment rate and ninety-day churn, each against your own launch baseline rather than a published target. Plan three to six months from selection to live; compressed timelines are where integration and consent gaps surface after go-live, when they are expensive.
Sources
Citations in this article were checked against the following primary sources on 2026-09-08.
- 15 U.S.C. 7704 — CAN-SPAM, requirements for commercial electronic mail
- 47 U.S.C. 227 — Telephone Consumer Protection Act
- 47 CFR 64.1200 — FCC rules on telephone solicitation and prior express written consent
- Cal. Civ. Code 1798.155 — CCPA administrative fines
- Cal. Civ. Code 1798.140(d) — CCPA business thresholds
- PCI Security Standards Council — Document Library
- PCI SSC — future-dated PCI DSS v4.x requirements effective March 31, 2025
- FTC — CAN-SPAM Act: A Compliance Guide for Business, at ftc.gov
- PAR Technology — PAR Retail, the convenience and fuel retail loyalty product, at partech.com; stuzo.com now redirects to parretail.com
- PDI Technologies — loyalty and marketing products, at pditechnologies.com
- Rovertown (Rover Enterprises LLC) — c-store app platform and its published integrations, at rovertown.com
- DRB, a Vontier company — car wash point of sale and Patheon unlimited-plan billing, at drb.com
- Invenco by GVR — Gilbarco Veeder-Root retail solutions rebrand, July 2023, at invenco.com