One customer. Many systems. One brand's responsibility.
Follow one customer's personal data through advertising, website tracking, checkout, payment, fulfilment, delivery, customer support, returns, reviews, loyalty programmes and long-term marketing databases - and count every place it ends up, and where you lose control of it.
- 1
Ads, discovery & tracking control breaks
+3 places · 3 so farA person sees an ad, a creator's post, a search result or a marketplace listing. Pixels, tags and platform consoles start observing them before they have given a name, an email or any choice.
Where control breaks: Tracking starts before the visitor has any choice
Moving hereOrder & transaction data (new at this stage)Device & tracking identifiers (new at this stage)Browsing & session behaviour· inferred (new at this stage)Customer profile & segments· inferred (new at this stage)DPDPAKnow every tag on your storefront and what it sends where. Keep the site working without optional advertising trackers, give notice before those fire, and be able to stop them when someone says no.
- 2
Browsing, search & personalisation
+3 places · 6 so farThe customer browses, searches, adds to cart and gets recommendations. Behaviour is recorded and turned into a profile - product affinity, price sensitivity, intent - long before an order exists.
Moving hereCustomer identity (new at this stage)Contact data (new at this stage)Health & wellness indicators (new at this stage)Device & tracking identifiersBrowsing & session behaviour· inferredCustomer profile & segments· inferredDPDPABehavioural profiling is processing you must be able to explain. Mask form fields in replay tools, keep browsing history to a defined window, and do not quietly attach an anonymous session to a named customer.
- 3
Account, cart & checkout control breaks
+3 places · 9 so farThe customer creates an account or checks out as a guest. Name, mobile, email and delivery address are captured - and marketing permission is very often bundled into the same click that pays for the order.
Where control breaks: Marketing permission is bundled into the order
Moving hereDelivery & billing address (new at this stage)Marketing permission & preferences (new at this stage)Gift recipient details (new at this stage)Customer identityContact dataOrder & transaction data+1 moreDPDPASeparate the order from the marketing. Ask only for what fulfilment needs, never pre-tick a promotional box, and record what the customer actually agreed to and when.
- 4
Payment, fraud screening & invoicing
+3 places · 12 so farPayment is taken, screened for fraud and invoiced. Transaction references, failed-payment history and automated risk scores are created across systems the brand does not run.
Moving herePayment & financial data (new at this stage)Fraud & risk flags· inferred (new at this stage)Customer identityContact dataDelivery & billing addressOrder & transaction dataDPDPANever store card details yourself. Keep tax and transaction records under their own retention rule - not the marketing one - and keep a human able to review any automated fraud decision.
- 5
Order management, warehouse & packing control breaks
+3 places · 15 so farThe paid order reaches operations. Full customer details are exported to spreadsheets, printed onto pick lists and packing slips, and handled by warehouse staff who only need part of them.
Where control breaks: Order exports become a permanent second database
Moving hereCustomer identityContact dataDelivery & billing addressOrder & transaction dataPayment & financial dataDPDPAGive the warehouse the minimum a parcel needs. Control who can export order data, destroy printed lists once the parcel ships, and remember temporary staff are covered by the same duty.
- 6
Shipping & last-mile delivery control breaks
+3 places · 18 so farName, mobile number and address leave the brand for an aggregator, a courier and an individual delivery agent's phone - and come back as tracking events, delivery photos and call logs.
Where control breaks: Couriers and delivery agents keep name, number and address
Moving hereCustomer identityContact dataDelivery & billing addressOrder & transaction dataPayment & financial dataDevice & tracking identifiers+1 moreDPDPAShare the minimum with logistics partners, use masked calling where the platform offers it, and put the retention and reuse limits in the contract - not just in the conversation.
- 7
Customer support & complaints control breaks
+3 places · 21 so farThe customer asks a question, complains or sends a photo of a damaged product - across a helpdesk, email, marketplace messaging, a call centre, Instagram DMs and personal WhatsApp at the same time.
Where control breaks: Customer records scatter into personal WhatsApp
Moving hereSupport & complaint records (new at this stage)Returns & product evidence (new at this stage)Customer identityContact dataDelivery & billing addressOrder & transaction data+1 moreDPDPAKeep support in official channels with defined access, set a retention period on call recordings and chat evidence, and be able to find every conversation when the customer asks what you hold.
- 8
Returns, refunds & reverse logistics control breaks
+3 places · 24 so farA return creates a second file: reason codes, product photographs from the customer's home, quality notes, refund records - and, quietly, a fraud or abuse label attached to the person.
Where control breaks: Return photos and risk labels build a second profile
Moving hereCustomer identityContact dataDelivery & billing addressOrder & transaction dataReturns & product evidenceFraud & risk flags· inferredDPDPACollect only the evidence the dispute needs, keep the photographs for a defined period, and let a customer see and correct an inaccurate 'abuse' or 'high-return' label attached to them.
- 9
Reviews, loyalty & marketing control breaks
+6 places · 30 so farA completed purchase becomes an ongoing relationship: review requests, loyalty points, referral links, lifecycle campaigns - and the customer list uploaded to ad platforms as a custom or lookalike audience.
Where control breaks: Your customer list becomes an advertising audience
Moving hereLoyalty, reviews & referrals (new at this stage)Customer identityContact dataOrder & transaction dataBrowsing & session behaviour· inferredMarketing permission & preferences+2 moreDPDPAKeep marketing separate from order updates, honour a withdrawal in every channel and every audience it reached, and make loyalty profiling something the customer can see and step out of.
- 10
Archives, analytics, backups & deletion control breaks
+1 place · 31 so farLong after the order, the customer still exists in the commerce database, the CRM, the warehouse, finance records, analytics, the agency's exports, vendor systems and backups. Deleting the account reaches almost none of them.
Where control breaks: Deleting the account does not reach the copies
Moving hereCustomer identityContact dataDelivery & billing addressOrder & transaction dataPayment & financial dataReturns & product evidence+1 moreDPDPAWrite retention rules per record type, separate what the law requires you to keep from what marketing would like to keep, and build a deletion path that reaches vendors, agencies, audiences and backups.
Top risk hotspots - where control usually breaks
The 8 places customer data most often slips out of your control. Each links to the matching check in the readiness assessment.
- Hotspot 1 Critical risk
Contact details and purchase history are uploaded from the CRM to Meta and Google as a custom audience, and lookalike audiences are generated from them - by the brand, and often again by the agency in its own ad account.
Why this matters
This is the largest single transfer a D2C brand makes, and the most invisible. The customer was told about a newsletter, not about being matched inside an ad platform; unsubscribing from email does not remove them from a live audience; and most brands cannot say which lists are still sitting in which ad account.
Fix: Stop routine list uploads, name audience activation in your notice and take a separate permission for it, delete audiences when the campaign ends, push every withdrawal into the ad accounts, and audit which agency logins still have access.
Check this in the assessment - Hotspot 2 High risk
A pre-ticked box at checkout, a line buried in the terms, a number taken at the till, or simply the assumption that buying once is an invitation to message for ever - and no record of what the customer actually agreed to.
Why this matters
Everything downstream inherits this. If the permission behind the list is unclear, then every campaign, broadcast and audience built from it is unclear too - and when a customer objects, there is no evidence of what they were asked and no reliable way to stop it in every channel.
Fix: Ask about marketing separately from the purchase, never pre-tick, store the choice and its timestamp on the customer record, and make that record the single source every channel checks before sending.
Check this in the assessment - Hotspot 3 Critical risk
Complaints, addresses, payment screenshots, photos taken inside the customer's home and the occasional health question all arrive on a chat app - frequently on a team member's personal phone rather than a business account.
Why this matters
There is no access control, no retention and no export. When a customer asks what you hold about them, this channel cannot be searched; when a team member leaves, the whole history leaves with the handset.
Fix: Move support to an official business account routed into the helpdesk, ban customer conversations on personal numbers, set a deletion rule for media, and make sure a rights request can actually reach this channel.
Check this in the assessment - Hotspot 4 Critical risk
Orders are pulled out of the platform - or the seller portal - into Google Sheets and Excel for dispatch, reconciliation and reporting, then forwarded, copied into other folders and never deleted.
Why this matters
The spreadsheet becomes a customer database nobody administers. It keeps working for ex-staff and agencies, it is invisible to every access, correction and deletion request made against the real system, and it is the most common way an entire customer list leaves a brand.
Fix: Restrict who can export, delete the raw file once it has been used, keep an exports register, replace recurring downloads with a permissioned view, and sweep old sheets out of shared drives.
Check this in the assessment - Hotspot 5 High risk
Every parcel sends the customer's name, mobile number and full address to an aggregator, a courier and finally an individual delivery agent's personal phone - and back come tracking events, delivery photographs and call logs.
Why this matters
This is the brand's largest routine external transfer, and the one with the least oversight: no stated retention, no visibility into onward use, and a well-known pattern of delivery numbers being reused for calls that have nothing to do with the order.
Fix: Share the minimum fields a delivery needs, insist on masked calling, put retention, reuse and deletion terms into the logistics contract, and ask what the aggregator still holds for orders you shipped last year.
Check this in the assessment - Hotspot 6 High risk
Meta Pixel, Google tags, analytics and whatever the previous agency installed fire as the page loads, sending device, cookie and behaviour data to outside platforms before a banner has been answered - and old tags nobody owns keep firing for years.
Why this matters
Data about a person leaves for several companies before that person has been told anything, and most brands cannot produce a list of what is installed on their own storefront or say who receives what.
Fix: Inventory every tag and its purpose, keep the store working without the optional ones, hold those until the visitor has seen the notice and chosen, delete tags nobody can name an owner for, and re-check after each theme or agency change.
Check this in the assessment - Hotspot 7 High risk
A return collects photographs taken inside the customer's home, quality notes and refund records - and attaches a 'high return' or 'abuse' label to the person that shapes how their future orders are treated.
Why this matters
The label is an inference the brand created, not something the customer provided. They were never told it exists, cannot see it, cannot correct it, and may be refused COD or blocked because of it.
Fix: Collect only the evidence the dispute needs, delete photographs once it closes, write down how a risk label is set and reviewed, and give a customer a way to challenge one that is wrong.
Check this in the assessment - Hotspot 8 High risk
Deleting a customer from the storefront leaves them intact in the CRM, the analytics warehouse, the old exports, the finance archive, the agency's files, the courier's records, the ad audiences and every backup.
Why this matters
This is the question the whole map exists to answer. If a customer asks you to delete their data tomorrow, the honest answer for most brands is that they do not know where all the copies are - and the ones they can name, they mostly cannot reach.
Fix: List every place customer data lands, write a retention rule per record type, separate what the law requires you to keep from what marketing would like to keep, and build a deletion path that reaches vendors, agencies, audiences and backups.
Check this in the assessment
How to read this journey
Pick your model
Switch between Own website, Marketplace-first and Omnichannel to see the systems each kind of brand actually uses. Own website is the default; marketplace-first is a leaner, platform-mediated picture; omnichannel is the biggest, because store, marketplace and website all feed one profile. The place-counter recalculates for the model you choose.
When it leaves you
A violet left edge and a tag mark systems outside your brand - payment gateways, couriers and delivery agents, ad platforms, marketplaces, review tools, agencies and backups you do not run. Once data lands there your control is indirect: it runs through your contract and instructions, not your admin panel. Risk is shown separately, as an amber or red fill - so an outside system can be low risk, and an in-house spreadsheet can be the worst thing on the page.
Where control breaks
Red flags mark the hotspots - the eight places D2C brands most often lose control of customer data, from a pixel that fires before any choice to an order export nobody deletes to a customer list living inside an ad account. Tap any system to see what it holds and how to fix it.
Now check whether your controls hold up
The map shows where customer data travels in a typical D2C brand. The 3-minute readiness scan checks whether your brand has the controls that matter at each hotspot - and the Discovery tool builds your own data inventory.
Educational reference model - not legal advice, and not a scan of your actual systems.