Shopping Without Being Tracked: Self-Checkouts, Loyalty Cards and Aisles That Watch You

Back to the blog
11 September 202611 min read

Introduction: seven minutes, a complete profile

An ordinary Saturday morning. You push the trolley, scan your loyalty card at the entrance to activate your personalised offers, hesitate for three minutes in front of the yoghurts, pick up two packs of nappies, a box of paracetamol and a bottle of wine. You go through the self-checkout, pay contactless, decline the paper receipt — it will arrive by email, which is greener.

Seven minutes. And during those seven minutes, the retailer has recorded: the full, time-stamped list of what you consume, the probable presence of a baby in the household, an indication about your health, your relationship with alcohol, the fact that you shop alone and early, the fingerprint of your bank card, your email address, and — if the store is fitted with footfall sensors — exactly how long you paused in front of the chilled aisle.

Young woman in a black jacket sitting on the floor, typing on a keyboard surrounded by laptops and screens

None of this is illegal, provided everything was properly disclosed and consented to. The problem is that almost nobody knows what is being collected, and even less what is done with it afterwards. The till receipt is now one of the most intimate documents a French household produces — far more revealing than a browsing history.

This guide takes stock, without alarmism, and sets out the steps that actually work.


What a till receipt says about you

The shopping basket as biography

Retailers talk about "transactional data". Behind the term lies a raw material of formidable precision. Twelve months of purchase history make it possible to infer, with a reliability that marketing researchers have been documenting since the 2000s:

What you buyWhat is inferred
Nappies, baby food, infant formulaA birth, the child's age to within a month
Tests, supplements, specific hygiene productsHealth status, pregnancy, menopause
Gluten-free, halal, kosher, vegan productsMedical condition, religion, beliefs
Alcohol, tobacco, scratch cardsRisk profile, potential insurance targeting
Total spend, value-range brandsIncome level and how it changes over time
Times and frequency of visitsWork rhythm, whether you live with a partner

Several of these categories qualify as sensitive data under Article 9 of the GDPR (health, religion, orientation). Retailers do not claim to process them as such — but a statistical inference reaches the same result without ever ticking the box.

The case of the digital receipt

Since August 2023, the automatic printing of till receipts has been discontinued in France (under the anti-waste law for a circular economy, known as AGEC). An excellent environmental measure. A rarely highlighted side effect: it handed the retail sector a sweeping pretext to collect email addresses and phone numbers.

A paper receipt is anonymous if you pay in cash. A receipt sent by email never is: it links your basket to a stable identity, reusable and tradeable within a corporate group.

You can still ask for a printed receipt. The law prohibits systematic printing, not printing on request. It is a right, not a favour.


The loyalty card: the most lopsided contract in your wallet

What you give, what you get

The principle is simple: you hand over your entire consumption history in exchange for discounts whose real average rate generally sits at around 1 to 3% of the basket. That is little, measured against the value of a complete consumer profile on the data market.

This does not mean you should give up loyalty cards. It means you should know what you are signing.

The questions to ask before joining

  • Is the scheme shared across several retail brands? Some groups cover groceries, DIY, electronics, perfumery and fuel. One card, a 360° view of your household.
  • Is the data shared with brands? Food manufacturers buy basket analyses from retailers. That is legal if it is disclosed.
  • What is the retention period? The CNIL recommends limited retention of loyalty data, with deletion after a period of inactivity (usually three years). Beyond that, the retailer must justify itself.
  • Is it bundled with a payment card or a revolving credit facility? That is where profiling changes in nature, as we discussed in our article on financial scoring.

The compartmentalised identity strategy

The most effective solution is neither outright refusal nor blind sign-up: it is compartmentalisation.

  1. Create an email address used exclusively for loyalty programmes. It serves no other purpose: no banking, no government services, no personal contacts.
  2. Use a secondary number for sign-ups that require one — a dedicated prepaid SIM card, or an SMS service that requires no registration when it is simply a matter of validating a contact detail.
  3. Fill in only the strictly mandatory fields. Exact date of birth, household composition, occupation: these fields are almost always optional, even when the form suggests otherwise.
  4. Always decline the "sharing with our partners" box. That is the one that lets your data travel beyond the retailer's perimeter.

A simple principle: one identity per use. One address for taxes, one for retailers, one for throwaway sign-ups. The day one of them leaks, the others hold.


Self-checkouts: far more than a scanner

Person typing on a backlit keyboard in a dark room, facing screens displaying code

"Anti-shrinkage" video

Self-service checkouts are fitted with cameras. Officially, they serve to combat stock shrinkage — theft, in plain language. The CNIL strictly regulates this use: the footage must not be used for anything else, retention must be short (one month maximum in most cases), and customers must be clearly informed.

For some years now, more advanced systems have been appearing: automated gesture analysis, detection of unscanned items, comparison between expected and measured weight. These systems involve algorithmic processing of images, and the CNIL has repeatedly pointed out that augmented video cannot be deployed just anywhere — it requires an impact assessment and a solid legal basis.

Facial recognition: what is prohibited

An important point: facial recognition in stores, for the purpose of identifying customers or spotting unwanted individuals, is in principle prohibited without explicit consent. The CNIL has sanctioned retailers that tested such systems. The European regulation on artificial intelligence has, moreover, tightened the framework for biometric identification in publicly accessible spaces.

If a store informs you of biometric processing, you can refuse. If it does not inform you, that in itself is a breach.

Free wifi and journey tracking

Your phone, if wifi is switched on, constantly emits requests containing a MAC address. Devices installed in stores can count passers-by, measure dwell time per aisle and reconstruct a route. Modern mobile operating systems randomise this address, which greatly limits tracking between visits — but not always within a single visit.

The useful reflex is mundane and free: switch off wifi and Bluetooth before going in, or put the phone in airplane mode while you shop. An RFID-blocking card holder also protects your contactless cards from opportunistic reads in the queue.


Click-and-collect and apps: profiling, the full version

Why online shopping reveals more than the store

Shopping online means accepting a higher level of granularity. The retailer no longer knows only what you buy, but also:

  • what you viewed without buying;
  • the time spent on each product page;
  • the substitutions you accepted or refused;
  • your exact delivery address, your floor, your building entry code;
  • your GPS position if the app has access to it;
  • your phone's advertising identifier, which links your groceries to your browsing elsewhere.

The settings that genuinely make a difference

On Android as on iOS, three actions cut off most of the leakage:

  1. Refuse ad tracking at system level ("Ask App Not to Track" on iOS, deleting the advertising ID on Android).
  2. Restrict location access to "while using the app" at minimum, or even "never": a grocery app does not need to know where you sleep.
  3. Use the mobile website rather than the app where possible. A sandboxed browser collects far less than a native app, which has access to durable hardware identifiers.

For households that want to go further, a home router capable of filtering advertising domains, or simply a privacy-friendly DNS configured on the home gateway, blocks part of the data flow before it even leaves the house.


Paying without telling your life story

A person's hands typing on a laptop keyboard in a dark room

The payment method is the pivot of profiling: it is what allows a basket to be reattached to an identity even without a loyalty card, via the technical fingerprint of the bank card.

Payment methodTraceability by the retailerNote
CashNoneThe right to pay in cash remains protected up to a legal ceiling
Standard bank cardHigh (stable identifier)Cross-referenceable with the receipt
Mobile payment (Apple Pay, Google Pay)Medium (variable token)But the phone's ecosystem knows more
Prepaid cardLowUseful for sensitive purchases
ChequeVery highName, bank, signature

Paying cash for a few purchases each month — those touching on health, beliefs or intimate life — is enough to break the continuity of a profile. This is not clandestinity, it is hygiene. A compact wallet is enough to make the habit less of a chore than it sounds.


Your rights, and how to actually exercise them

The GDPR is not a Brussels abstraction: applied to retail, it offers very concrete leverage.

The right of access

Write to the retailer's data protection officer (DPO) — their contact details must appear in the privacy policy. Ask for:

  • the entire purchase history held on you;
  • the categories of inferred or derived data (marketing segments, scores);
  • the list of recipients, including partners;
  • the retention period applied.

The retailer has one month to reply, extendable to three in complex cases. The result is often instructive: many customers discover they are filed under segments with explicit names ("price-sensitive large family", "urban organic shopper").

The right to object to profiling

You can keep the loyalty card for its price advantages and object to marketing profiling. The two are not legally inseparable: refusing personalised offers must not deprive you of the scheme's general discounts. If the retailer claims otherwise, that is worth reporting.

Erasure and complaints

The right to erasure applies when you close your loyalty account. If there is no reply after two months, filing an online complaint with the CNIL is free, takes around ten minutes and triggers a genuine investigation. The CNIL's annual reports show that the retail sector regularly ranks among those most targeted by complaints.


A dashboard for a week of discreet shopping

SituationReflex to adopt
Signing up to a loyalty schemeDedicated email address, optional fields left blank
Being asked for your phone number at the tillPolite refusal; the number is never required in order to pay
Digital receipt offeredAsk for the paper receipt, or decline both
Entering the storeWifi and Bluetooth switched off
Sensitive purchases (health, intimacy)Cash, no loyalty card scan
Click-and-collect or deliveryMobile site rather than app, location denied
Intrusive promotional mailWritten objection to the DPO, then the CNIL if silence follows

To go further on the general logic — understanding what a profile is, how it is built and why it is so resilient — the popular science books on personal data protection published in recent years offer a solid grounding without requiring any technical background.


Conclusion: discretion is not deprivation

Nothing in this guide is about giving up discounts, paying more or shopping in disguise. The stake lies elsewhere: restoring reciprocity. The retailer knows exactly what it gets from you; you should know exactly what you are giving.

Three habits are enough to shift the balance: compartmentalise your identities, leave optional fields blank, and take a few purchases a month out of the continuous profile by paying in cash. It takes less time than looking for a parking space.

The rest comes down to a principle that runs through all our guides: the data you do not give away will never leak. No privacy policy, no encryption promise and no environmental pledge is worth as much as that rule.

#Vie privée#Confidentialité#Anonymat#Cas d'usage#RGPD#CNIL

On the same topic

// Anonymous SMS · Hidden number · To France

Envoyez votre message, gardez l'anonymat

Votre numéro reste masqué, aucune inscription, aucune trace. Rédigez, confirmez, et votre SMS part de façon totalement anonyme.

Envoyer un SMS anonyme