All guides
10 min read
Updated September 10, 2026
Loyalty program compliance in the US is less about one big law and more about a handful of rules that each cover a piece of what a program does: texting customers, emailing them, storing their details and handling their card payments. This guide explains the main ones in plain English so you know which questions to ask. It is general information, not legal advice - the rules differ by state and change over time, so consult a lawyer who knows your state before you rely on any of it.
The Telephone Consumer Protection Act is the federal law that governs texts and automated calls to consumers, and it is the rule most likely to catch a small business by surprise. For marketing texts - anything promoting an offer, a sale or a new product - you need the customer’s prior express written consent before the first message. Written consent can be given electronically, but it must be a clear, knowing action by the customer. A pre-ticked box, or consent buried in terms nobody reads, does not meet that standard.
Transactional texts are different. A message that confirms points earned, says a table is ready or acknowledges a reservation is delivering information the customer asked for, and it is not treated as marketing. Keep the two kinds of message separate and do not slip a promotion into a transactional text. Whatever you send, honour STOP and its cousins immediately and without argument, and keep sending nothing to that number until the customer opts back in. Holding non-urgent texts outside daytime hours is not a legal requirement everywhere, but it is a good habit and it is what customers expect.
Marketing email in the US is governed by CAN-SPAM, and its requirements are practical rather than onerous. Every commercial email needs a working unsubscribe method that is honoured promptly, a subject line that reflects what the message is about, an accurate "from" name, and your real business name and physical address in the body. A message that mixes a receipt with a promotion is generally treated as commercial, so apply the rules to anything that sells.
The habit that keeps you compliant is to send marketing email only to people who have said yes to it, and to make leaving as easy as joining. One tap, no login, no "are you sure". If your loyalty software mutes a customer the moment they unsubscribe and never lets a campaign reach them again, most of CAN-SPAM takes care of itself. Sopoints sends merchant campaigns with a working unsubscribe link and a per-merchant mute, and consent boxes are unticked by default.
The US has no single federal privacy law, so privacy is a patchwork of state statutes. California’s CCPA, as amended by the CPRA, is the best known. It gives residents rights to know what a business holds about them, to have it deleted and to opt out of sale or sharing. It applies to businesses above certain revenue or data-volume thresholds, which puts many small businesses formally out of scope. Customer expectations, however, are not out of scope: people now assume they can ask what you hold and ask you to delete it, wherever you are.
Other states have followed with their own comprehensive laws. Texas has the TDPSA and Florida the FDBR, both in force since 2024. Colorado, Virginia and Connecticut have theirs, and more states add laws each year. The details differ on thresholds, definitions and enforcement, which is exactly why a state-specific legal check is worth the fee. The practical response is the same everywhere: collect only what the program needs, say plainly what you do with it, and be able to export or delete a customer’s record on request.
Illinois’ Biometric Information Privacy Act regulates the collection of fingerprints, face geometry and similar identifiers, and it allows individuals to sue directly. Other states have biometric provisions of their own, and the cost of getting it wrong is out of proportion to any convenience a face-recognition loyalty kiosk might offer a small business.
The simple way to stay clear of the whole area is to identify customers with something that is not part of their body. A phone number, a QR code from a digital loyalty card or a tap of an NFC tag all work at the counter and none of them creates biometric exposure. Sopoints identifies customers by phone number, QR or NFC only, with no facial recognition or fingerprint features. If a vendor offers biometric check-in, ask your lawyer before you switch it on.
Every one of the fifty states has a data breach notification law. The triggers, timelines and definitions of personal information differ, but the shape is the same: if personal data you hold is exposed, you may have to tell the affected people and sometimes a state authority, within a set period. New York’s SHIELD Act goes further and requires reasonable security measures in the first place. The less you hold, the less can leak, which is another argument for a program that runs on a phone number rather than a full profile.
Card data deserves its own mention. If your loyalty platform also takes payments, the card details should be handled by a payment processor and never touch your systems or the vendor’s web pages. Sopoints uses Stripe for payments and stores no card numbers, which keeps the platform in the lightest PCI-DSS category. Whoever you use, ask directly where card numbers are entered and stored, and be suspicious of any answer that is not "with the processor".
Consent boxes are unticked by default, worded plainly, and separate for texts and email. Signing up for points is not the same as agreeing to marketing.
Keep a record of every consent: who, when, how and what wording they saw. If a complaint arrives, this record is your defence.
One-tap opt-out everywhere. STOP for texts, a working link for email, and a mute that takes effect immediately and permanently until the customer says otherwise.
Be able to export a customer’s data and delete it on request, and know who on your team handles those requests.
Never buy or rent a contact list. Consent given to someone else is not consent given to you, and bought lists are how businesses end up in TCPA trouble.
Keep marketing and transactional messages separate, and do not sneak an offer into a "your table is ready" text.
Write a short, honest privacy notice that says what you collect, why, and how to reach you. Link to it wherever people sign up.
Choose software that does these things by default so compliance does not depend on a busy staff member remembering.
Good loyalty software removes most of the day-to-day risk by making the right behaviour the default. Sopoints, as one example, captures marketing consent through unticked boxes and records it, honours STOP automatically, gives customers a per-merchant mute, holds non-urgent texts during quiet hours, exports customer lists on every plan and processes payments through Stripe so no card numbers are stored. Other platforms offer similar controls, and any vendor you consider should be able to describe theirs in plain words.
What software cannot do is decide what your state requires of a business your size, write your privacy notice, or tell you whether a particular campaign counts as marketing. Those are questions for a lawyer, and the cost of an hour of advice is small next to the cost of a complaint. Treat this article as a map of the territory, not as the territory itself.
How to Start a Loyalty Program in the US: A Step-by-Step Guide for Small Businesses
United States
Restaurant Waitlist Best Practices: How to Cut Walkaways and Fill Every Table
Waitlist & Reservations
Restaurant No-Show Fees and Deposits: A Practical Guide to Policies That Guests Accept
Waitlist & Reservations
Loyalty system
How the platform works
The free plan needs no credit card and no hardware — the fastest way to find out whether a loyalty system works for your business is to run one for a month.
Sopoints
Universal loyalty rewards that work everywhere. Join the coalition and start earning points today.
PCI-DSS
SAQ A
GDPR
Compliant
CCPA
Compliant
OWASP
Secured
NIST CSF
Aligned
© 2025 SoPoints. All rights reserved.
Made with ❤️ for merchants and customers