Making every Transaction Record usable to Customers as well as Merchants

How transaction records work today

Billions of purchases happen every day, and every one of them creates a record: what was bought, where, when, and for how much.

When the purchase transaction completes, each record immediately splits in two. The merchant files the authoritative copy into its own database, structured, electronic, and retained because the business needs it for accounting, tax, and inventory. The customer’s copy takes whatever form the sales channel dictates: a paper receipt at a store counter, an emailed invoice for an online order, an entry in a platform’s order history. A few large platforms, such as Amazon, maintain complete purchase histories inside the customer’s platform account; most businesses simply hand over the copy and keep the original in their own database.

The result is that the same economic fact (this person bought this item at this price) exists in several places at once, in incompatible forms, under different custodians. The merchant’s copy sits in a silo built for that merchant’s operations. The customer’s copies sit in shoeboxes, inboxes, and scattered platform accounts, most discarded shortly after purchase unless needed for a warranty or a return. No party, including the customer who created the records, holds a complete, machine-readable picture of what was actually bought across merchants.

Why the records stay fragmented

The fragmentation of transaction records is not an oversight. It is the result of constraints that each exist for a sound reason. Payment security imposes the first constraint. The PCI-DSS standard prohibits merchants from storing transaction records alongside the customer’s primary account number, so that a breach of the merchant’s database cannot expose payment credentials. A merchant that runs a loyalty program therefore links purchases to a locally issued membership identifier rather than to the card itself. That identifier is created by the merchant, resolved by the merchant’s point of sale, and is meaningful only within the merchant’s own systems. A customer who shops at five stores carries five unrelated identifiers, and no store can connect its identifier to any other.

Enrollment imposes the second constraint. To join a loyalty program, a customer must disclose identity: an email address or phone number for an ID-based program, copies of official identification for a card-based one. The disclosure is the price of participation: customers who decline remain invisible to the program, and customers who accept are tracked under their real identity, with the attendant exposure to misuse and breach.

Anonymization, the apparent remedy, imposes the third constraint by failing. Removing names and account numbers from transaction data does not remove identity; purchase histories are distinctive enough that de-identified records have repeatedly been re-identified by linking them to outside information. Organizations that hold transaction data therefore face a binary choice: delete the records when regulation requires it, or retain them in personally attributable form under security controls. An established method for retaining and reusing transaction records without identity does not exist.

What the fragmentation costs

Transaction record fragmentation is a cost to each party in the payment chain: customers, merchants, and manufacturing/service businesses. Customers cannot see their own economic lives. The records they created are scattered across formats and custodians, so there is no practical way to review spending across merchants, compare purchases over time, or carry a verifiable purchase history from one context to another. The data exists; the customer simply has no usable copy of it.

Merchants see only their own counter. A store knows what a customer bought under its roof and nothing beyond it. The surrounding picture (what the same customer buys elsewhere, which products they abandoned, where their loyalty actually lies) is invisible, so merchandising, inventory, and marketing decisions are made from a fragment of the customer’s behavior.

Brands and manufacturers are blind in a different way: their customers are hidden behind the retailers who sell for them. A shopper who buys the same shampoo five times from five different stores is, by any reasonable definition, a loyal customer of that brand, yet no single store can see the pattern, and the manufacturer cannot see it at all. The brand has no way to recognize its most loyal customers, let alone reward them.

These are not marginal losses. Loyalty programs, market research, and retail analytics are multi-billion-dollar industries built to approximate exactly the picture that the fragmented records already contain but cannot deliver.

How PCX solves this

The Privacy-Compliant eXtensible (PCX) protocol links each transaction record to a pseudonym rather than to the person behind it, when the record is generated. The protocol achieves this through the payment card itself. Each card is tokenized by its issuer, and the token (not the card number, not the customer’s name) links every transaction record to a customer account on the PCX server platform: the server-side infrastructure that runs the protocol. Transaction records accumulate in a cloud account the customer controls, keyed to a pseudonym that persists across merchants. Reviews attach to the same pseudonymous account. When a customer joins a merchant’s loyalty program, the merchant sees that customer’s purchases at its own store and partner network and rewards on volume; it sees nothing beyond. The platform holds transaction detail; the identity behind it is never captured. This token-based pipeline is protected by a granted patent family, with grants in the US, Australia, and India.

Patent filings in 2026 extend the PCX protocol further. In the new architecture, each record is separated into customer, merchant, and synthetic components; only the customer’s component is complete and attributable. That component is further encrypted with the customer’s own public key, which means the platform cannot read it and a breach yields only ciphertext. Because each record is encrypted to a unique key, there is no master key to steal and no bulk decryption to perform. An attacker who takes the entire database gains ciphertext, and compromising any one record yields only that record. On the synthetic records, a brand defines a rewards policy (for example, reward any account that has purchased its product five times across any stores) and the platform applies it. The brand’s loyal customers are rewarded across unaffiliated stores; the brand receives only scoped eligibility indicators, never the underlying records or the person behind them. Together, the pseudonymized records and reviews form the substrate on which every platform capability operates: loyalty, analytics, and search. 

Read More  How does the token-based pipeline work?

Scroll to Top