The minimum needed: a name, a mobile number, and visit history
A Waya barbershop card stores only what's needed to run the program: the first name and mobile number a client enters at enrollment, plus a running history of visits, stamps or points, and rewards redeemed. There's no separate account, no password, no payment card details collected by the loyalty card itself — enrollment doesn't touch anything beyond that short two-field form.
This is a genuinely narrower data footprint than most retail loyalty apps, precisely because there's no app requiring a full account with email, birthdate, or address as a signup condition. The one Waya-specific fact worth naming here: a birthday field exists on a client's profile and it's entirely optional, and nothing sends on its own when that date comes around — any birthday outreach the shop wants to send is a manual, one-off message the owner writes.
Data flow: who can see what
The barbershop owner and any staff given dashboard access can see a client's enrollment details, visit history, and reward status, since that's what makes the stamp-and-scan mechanic work day to day. Staff with the Cashier role can add or deduct stamps and points but don't need broader account access to do it; Branch Manager access covers everything except running campaigns.
Waya, as the platform operator, processes this data to run the wallet passes, deliver notifications, and power the merchant dashboard — the same processing role any Saudi PDPL-covered service provider plays for the businesses that use it.
| Data point | Collected at enrollment? | Notes |
|---|---|---|
| First name | Yes | Required field |
| Mobile number | Yes | Required field, used to identify the client's pass |
| Visit history / stamps / points | Generated over time | Created by staff scans, not entered by the client |
| Email, birthdate, address | No | Not part of the enrollment form; birthdate is an optional profile field, no automatic use |
The limitation stated honestly
Waya is a loyalty and wallet platform, not a law firm, and this page describes what the platform stores and processes — it isn't legal advice on a barbershop's own PDPL compliance obligations as a data controller. A shop owner handling personal data of Saudi residents should still understand their own responsibilities under the Personal Data Protection Law independently of any vendor's setup.
One honest limitation worth flagging: there's no SMS channel, so a client's mobile number is used only to identify their wallet pass and isn't used to send text messages — all notifications go to the wallet lock screen instead. That narrows, but doesn't eliminate, what the mobile number is used for.
Exporting and removing client data
Owners can export their loyalty data from the dashboard, which covers enrollment details and visit history for every client on the card — useful both for the owner's own records and for responding to a client who asks what's held about them.
Because the data footprint is narrow to begin with — name, mobile number, visit history, nothing more — reviewing or removing a specific client's record is a straightforward lookup rather than a search across scattered systems.
- Enrollment data: first name, mobile number only
- Visit history: generated by staff scans, not client-entered
- No payment details, no email, no address collected by the card
- Export available any time from the dashboard
Responding to a client data request
If a client ever asks what a barbershop holds about them, the answer is short enough to give on the spot, and the lookup itself takes only a few steps on the dashboard.
- Step 1: search the client by mobile number
The dashboard's client list is searchable by the number entered at enrollment.
- Step 2: review the enrollment record
Confirm what's stored: first name, mobile number, and visit history — nothing else.
- Step 3: export if requested
Use the dashboard's export feature to hand over a copy of the client's own record.
- Step 4: remove the record if asked
A staff member with dashboard access can remove a client's enrollment on request.
Why a narrow footprint is also a practical advantage
Beyond the compliance angle, collecting less data is simply easier to manage day to day — there's less to secure, less to explain to a client who asks what's stored, and less risk if a staff account is ever compromised. A shop that never asked for an email address in the first place doesn't have to worry about an email leak.
This narrow-by-design approach is one reason a wallet card fits a small barbershop better than building a custom app or CRM from scratch, where the temptation is usually to collect more fields than the loyalty mechanic actually needs.
Next step
For the loyalty mechanic itself — stamp thresholds, staff roles, notification triggers — see the barbershop loyalty program guide, which covers the operational side this data question sits underneath.
Frequently asked questions
What personal data does a barbershop loyalty card collect?
Just a first name and mobile number at enrollment, plus visit history, stamps or points, and reward redemptions generated by staff scans over time. No email, address, or payment details are collected.
Does a barbershop client's card store payment information?
No. The loyalty card only tracks stamps, points, and visit history — there's no payment processing built into the card itself.
Is a birthdate collected and used automatically?
A birthday field exists on a client's profile but it's optional, and nothing sends on its own when that date arrives — any birthday outreach is a manual, one-off message sent by the owner.
Can a barbershop export a client's loyalty data?
Yes, from the dashboard's export feature, covering enrollment details and visit history for every client on the card.
Is this page legal advice on PDPL compliance?
No. It describes what Waya's platform stores and processes for a loyalty card; a barbershop's own obligations as a data controller under Saudi PDPL are a separate question to confirm independently.