Customer-owned transaction records

A Customer Transaction Record (CTR) is a structured record of a purchase, including information about the product or service and the amount paid. When a customer purchases a product or service online, the merchant retains electronic order histories of the transactions and provides digital receipts or invoices to the customer. In physical stores, payment is recorded electronically while the customer may receive a paper or digital receipt. These records are useful to both sides of the transaction: merchants can use purchase history for operations and loyalty, while customers can use itemized records to understand spending, manage purchases, and obtain rewards where a program permits.

Most customers do not have access to CTRs in a consistent electronic format. Offline purchases commonly produce paper receipts, while online purchase records remain in merchant accounts, emails, or merchant databases. The records are therefore fragmented across formats and data silos, leaving customers without a complete, itemized view of their purchases.

The customer is the reason the Customer Transaction Record exists. No purchase, no record. Yet the record is created, stored, and used by everyone except the person whose purchase produced it. So why do merchants and service providers retain a copy of customer transaction records, and the customer profile attached to them, in their own databases? How does this process work, and what would it take to invert it — so that the customer controls the record, decides who sees it, and can share it with a merchant without handing over an identity along with it?

Problems with the retention of Customer Transaction Records

Many merchants operate loyalty programs, sometimes alongside co-branded payment cards or partner networks. Enrollment links a customer identifier to qualifying purchases so that points, cashback, or other benefits can be calculated. Those records are typically retained within the merchant, issuer, or program ecosystem and are governed by the applicable privacy and financial-services rules. The model is useful, but its scope is usually bounded by the participating merchant or partner network; a customer’s purchase history remains fragmented across programs rather than becoming one reusable record under the customer’s control.

Identity-linked loyalty and co-branded-card programs also expand the number of organizations that must protect customer information. Additional cards and accounts can create management overhead for the customer, while digital wallets mainly simplify how credentials are carried and presented. They do not remove the identity and eligibility checks required when a regulated payment account is opened. The wallet may remove the plastic; it does not remove the underlying identity relationship.

What customer control would require

Inverting the default system does not depend solely on new law or better corporate behavior. It requires an architecture in which a useful transaction record can be captured at or near the point of sale and associated with an account the customer controls — without requiring the merchant to receive the customer’s identity or the card issuer to receive the merchant’s line-item basket. For that architecture to preserve the usefulness of transaction data without recreating the concentration of information it is meant to avoid, three design conditions must hold. The record should preserve enough detail, ideally down to the line item, to remain useful. It should be associated with a pseudonymous customer reference rather than a direct identity, so that consolidation does not itself expand identity exposure. And no single intermediary should automatically possess the whole picture.

That separation is the basis for customer control: identity remains with the authorized custodian, transaction detail remains available to the customer, and access by other parties is governed by defined permissions.

What consolidated records make possible

Consolidated CTRs can give the customer a unified record of purchases made across merchants and transaction channels. When online and offline CTRs share a common structured format, line-item records can be brought together without requiring any merchant to hold the customer’s complete purchasing history. The illustration below shows the intended result: line-item purchase records from multiple merchants and transaction channels brought together without requiring any merchant to hold the customer’s complete purchasing history.

For the customer, a consolidated history of CTRs provides a complete view of purchases and spending across merchants. When analyzed at cohort level rather than customer level, the same records can reveal patterns such as repeat purchasing, product switching, and preference for a particular service provider—without identifying any individual customer. These patterns can help businesses plan manufacturing, distribution, and inventory using evidence of actual purchasing behavior.

Illustrative target state: online and offline purchases consolidated into a structured, customer-controlled transaction record.

Consolidating CTRs creates a single source of truth (SSOT) about what was actually bought — and replaces the guesswork that fragmented, identity-bound records force on everyone who depends on them.

Today, the transaction record visible through a bank or payment-card account generally does not contain the merchant’s full itemized basket. Card-payment messages typically carry a merchant descriptor, transaction amount, time, and other payment data, while detailed product or service information remains with the merchant.

Where a merchant separately knows the customer — for example through an account or loyalty program — it can associate purchase detail with that identity. Where the merchant and card issuer are separate and no such relationship is used, the issuer generally sees payment information rather than the merchant’s full line-item basket, while the merchant does not receive the cardholder’s KYC file from the issuer.

Capturing the record without the identity

A customer transaction record does not need to remain a paper receipt. It can be retained electronically in a customer-controlled account and used for spending history, repeat purchasing, reviews, loyalty, and other permitted services. Large e-commerce platforms already demonstrate the utility of structured order histories: customers can revisit purchases and submit feedback, while the platform can use transaction data to improve its operations. The limitation is not that these systems are useless; it is that the record is tied to a platform-specific account and is not designed as a portable, cross-merchant customer record. As a result, transaction histories from different providers remain difficult to combine under one consistent privacy and data model.

PCX proposes a different arrangement — preserve the utility of a structured purchase record while decoupling customer identity from the merchant’s transactions database. That separation allows the transaction record to remain useful across commercial interactions without requiring identity to accompany it.

A merchant can receive a verified transaction record, and run a loyalty program on the back of it, without ever receiving a customer’s personal information. The payment card is already tokenized by the industry; the token, not the customer, becomes the thing the record is filed against. Identity stays with the bank, which has already verified it. The record travels without it. We describe how that works in Token-based Loyalty Program.

Protecting customersʼ private and confidential information

Records captured this way are designed to give customers a consolidated view of participating purchases and to support loyalty enrollment without requiring the merchant to collect a new identity profile. What makes the model work is not a promise; it is the separation of roles and permissions.

Each party sees only what the architecture permits. The customer retains the full-fidelity canonical transaction record and controls how information derived from it is used or shared, while retaining the underlying canonical record in their custody. A merchant receives only the transaction-derived information needed for an authorized merchant or partner-network relationship; it does not receive the customer’s unrelated canonical records or broader purchase history. Cross-merchant intelligence is generated separately from synthetic transaction records and disclosed as aggregated, merchant-safe outputs rather than as individual customer histories. The payment issuer receives the information required to authorize the payment, but not the customer’s line-item basket. The PCX platform operates through protected account references, synthetic records, and bounded interfaces without needing the customer’s identity or unrestricted access to the customer’s canonical transaction history.

When a customer chooses to share information directly with a merchant or another external party, the same principle applies: the recipient receives a bounded artifact or summary appropriate to the purpose, while the underlying canonical records remain under customer-controlled custody.

Closing thoughts

Online information is increasingly difficult to verify, while transaction records that could provide stronger evidence remain fragmented across merchants and platforms. A shared, privacy-preserving record infrastructure could give reviews and market signals a stronger evidentiary foundation while allowing businesses of different sizes to participate under the same record rules.

Many paper receipts are discarded, and even retained receipts are often difficult to reuse computationally. A customer-controlled repository of structured CTRs could support contextually relevant feedback, spending analysis, transaction lookup, and other services without requiring every merchant to maintain the customer’s complete history. Where broader analytics are permitted, the same infrastructure could produce cohort-level signals rather than expose individual customer records.

Customer-controlled transaction records are intended to create a better division of responsibilities across the chain: the customer gains a reusable purchase history, the merchant can work with verified demand signals, the bank or other custodian retains the identity relationship it already manages, and authorized oversight can rely on structured audit evidence without routinely requiring raw customer identity. PCX treats the customer’s copy of the transaction record as a reusable asset under customer control. The missing piece has been shared infrastructure designed around that principle.

Scroll to Top