Loyalty gap recovery: reach the buyers who never joined — only the ones you may
5 min read
By BudAlly
Published
Not legal advice. TCPA, CAN-SPAM and state privacy rules are linked below. This post explains what the software does with each contact depending on what you can prove. Whether a particular message is allowed is a question for your counsel.
The gap
Every dispensary has customers who buy often and never joined the loyalty program. Their purchase history is in the POS, but they aren't in the program. It's tempting to measure "recovery" by how many contacts were found.
That number is the wrong headline. A recovered contact is someone you found. Whether you may contact them depends on what consent you can prove, and for most legacy lists that's a much smaller group. Our earlier post, A checkbox is not consent, covers what a consent record has to contain. This post covers the pipeline that runs before and after that test.
The pipeline, step by step
1. Pick the window and the stores
Use a fixed window (for example, the last twelve months), the stores in scope, and adult-use sales. Revenue figures come from POS totals reconciled to Metrc receipts, with each store's match rate shown beside them. A store that sends only a partial export is marked "partial data" instead of being quietly left out.
2. Dedupe across stores
One person who shops at three of your stores is one person, not three. Where the POS passes an ID scan through, BudAlly matches on a keyed hash of the ID and never stores the ID number. Where the POS exports only a customer record, the match uses phone or email plus name and date of birth, and that is labelled as a weaker match. Possible duplicates go to a merge queue for a person to decide, and accounts holding points in two different states are never merged automatically.
3. Take out medical profiles
Medical-only profiles are excluded before anything else is counted, and they never appear in a segment. Cannabis purchase data tied to a person is sensitive. In Washington, a retailer was sued under the My Health My Data Act over website pixels that shared it (Hintze Law). The medical flag exists to price the medical menu and split tax treatment. It doesn't exist for marketing.
4. Match to members
Each deduplicated buyer is linked to a loyalty member where one exists. Whoever is left over is the gap: buyers who aren't members.
5. Scrub placeholder emails
POS customer records often hold filler addresses, such as none@none.com or the store's own address. These are removed before anyone counts them as reachable. A placeholder isn't a contact, and sending to the store's own inbox isn't outreach.
6. Split by consent proof
This is the step that decides what happens to each person:
| Bucket | Test | What BudAlly drafts |
|---|---|---|
| Marketing consent with proof | Channel, timestamp, source and the wording the person agreed to are all on record | An email invite, sent with a holdout |
| Transactional only | They get e-receipts but there's no marketing consent | A join line on their next receipt, nothing else |
| No consent record | Nothing on file, or a bare "opted in = true" with no time, source or wording | A prompt at the counter on their next visit |
| Phone only | No usable email | Nothing by SMS unless the store's own 10DLC is live and SMS consent is proven |
A few notes on the table:
- The receipt line. CAN-SPAM treats a message by its primary purpose, and a transactional message has different obligations from a commercial one (FTC). Whether a "join rewards" line keeps an e-receipt transactional is a wording question for your counsel.
- SMS. Marketing texts need prior express written consent under the TCPA (47 CFR §64.1200). Carriers treat cannabis as restricted content, and 10DLC campaigns for it may be denied or filtered (cannabisregulations.ai). BudAlly sends no SMS from its own numbers. The SMS option stays off until the store registers its own 10DLC brand and campaign, and even then it carries a label that delivery isn't guaranteed.
- Legacy flags. An "opted in" boolean imported from an old POS counts as no record. It keeps its purchase history and receives nothing until the person opts in again.
7. Look at the top spenders, but only in groups of 8 or more
A top-spender view, such as the top 5% of non-members by net spend, shows where the gap matters most, split by store and by consent bucket. Any group with fewer than 8 people is shown as a dash and can't be viewed or sent to. That stops a "segment" from turning into a list of named individuals.
8. Draft the invite and keep a holdout
The invite is drafted, not sent. It says plainly that joining is a separate opt-in. In California, a program that offers an incentive in exchange for personal data needs a Notice of Financial Incentive at enrollment (11 CCR §7016). The draft goes to the campaigns queue, where the person who approves it can't be the person who drafted it. A holdout (10% by default) receives nothing, so the result is a measured lift. If the confidence interval includes zero, the report says "not significant" instead of quoting attributed revenue.
What we won't do
- No auto-enrollment. Being found in POS data isn't the same as joining a program.
- No retroactive points. Points start when someone joins. Backdating them for people who never asked creates a points liability nobody agreed to.
- No SMS without the store's own 10DLC and proven SMS consent.
- No medical profiles in any count, segment or campaign.
- No groups smaller than 8.
- No send without approval, and no approve-all.
Illustrative funnel
Hypothetical round numbers, not customer data.
| Step | People |
|---|---|
| Buyers in the window, after cross-store dedupe | 10,000 |
| Not loyalty members | 6,000 |
| With a valid, non-placeholder email | 3,000 |
| Marketing consent with proof | 600 |
| Of those, held out | 60 |
| Email invites drafted | 540 |
| Transactional only (receipt line) | 2,000 |
| No consent record (counter prompt) | 400 |
The number to plan around is the 540, not the 6,000. The other 2,400 with a valid email aren't lost. They're reached at the register and on the receipt, and each one who opts in moves into the first bucket with proof attached.
Where this sits in BudAlly
Loyalty gap recovery is one of the agents on the retail intelligence page. It builds on the consent ledger and campaigns in loyalty and customer relationships, and it runs only on store data BudAlly is permitted to use for loyalty. Stores outside that scope produce no rows.
Sources
- FCC — Telephone Consumer Protection Act rules (47 CFR §64.1200) · 2026
- FTC — CAN-SPAM Act: a compliance guide for business · 2026
- California — Notice of Financial Incentive, 11 CCR §7016 (Cornell LII) · 2026
- cannabisregulations.ai — 10DLC reality check for cannabis and hemp texting · 2025
- Hintze Law — Washington marijuana retailer sued under the My Health My Data Act for website pixel use · Nov 13, 2025