Consents & GDPR compliance
Mobile Wallet notifications: transactional, marketing, and GDPR consent.
Mobile wallets can surface contextual and campaign-driven notifications. Because some messages are marketing, consent must be managed correctly.
This page explains the difference between transactional and marketing notifications and the controls needed for GDPR compliance. For delivery mechanics, see Push notifications.
Transactional vs marketing notifications
Transactional notifications stem directly from a contract or loyalty-program membership. They must be necessary to deliver the service. Contract performance usually covers them, so marketing opt-in is not required.
Marketing notifications promote a product or service without a direct link to an existing contract. They are commercial prospecting and typically require explicit marketing opt-in.
A prospect who downloads a pass without enrolling is not covered by contract performance. Any proactive notification is marketing outreach.
Legal basis
A lawful basis is required for wallet notifications. Transactional notifications typically rely on contract performance under GDPR Article 6(1)(b). They must remain necessary to deliver the service.
Marketing notifications typically rely on consent under GDPR Articles 6(1)(a) and 7. Consent must be free, specific, informed, and unambiguous. Keep proof of consent and make withdrawal easy.
Collect consent
Collect marketing consent before sending promotional notifications. Registration is a common collection point. Consent can also be captured on a pass-download landing page, website, or app.
Keep service and marketing choices separate. Store them as independent flags. Do not bundle both purposes into one “Wallet notifications” checkbox.
Privacy policy and legal notices
Privacy information must explain that a wallet pass can generate notifications. It should state the triggers, distinguish service and promotional messages, describe processing purposes, and explain customer controls.
Mention the main triggers and expected frequency. Keep the information easy to scan.
Best practices
Classify every notification. Decide if it is transactional or marketing.
Separate consent flags. Maintain independent service and marketing choices.
Gate marketing sends. Send promotions only to opted-in customers.
Keep proof of consent. Store timestamp, source, and privacy notice version.
Make opt-out easy. Provide a preference-management link.
Test the full journey. Validate capture, updates, notifications, and opt-out synchronization.
Wallet notification settings
Customers control notifications globally and per pass. They can disable automatic updates, push notifications, and contextual presentation for an individual pass.
Apple Wallet
Apple Wallet notifications are triggered by pass updates. Any visible field change can trigger a notification. Typical changes include points, tier, or event reminders.
For promotional content, reserve a dedicated pass field. Update only that field for marketing copy.
Google Wallet
Google Wallet can notify through pass updates or its notifications API. This supports more flexible messaging, but frequency must remain controlled.
How The Wallet Crew helps
The Wallet Crew supports consent-aware notification strategies. Brands can separate purposes, segment based on consent status, and activate campaigns conditionally.
The Wallet Crew acts as a data processor for wallet notification services. The brand remains responsible for the legal basis, consent collection and storage, privacy notices, and data-subject rights.
Marketing consent must be collected through the brand's own consent mechanisms. The Wallet Crew does not collect it on the brand's behalf.
FAQ
Last updated

