Personalization without creepiness: the data-use line shoppers notice
The line between helpful personalization and surveillance isn't how much data you hold. It's whether the shopper can guess how you knew. A signal ladder, a pre-launch test and label templates you can ship.
The email that opened with the customer's first name felt fine. The one that referenced a product she'd only ever looked at once, on her phone, at 2am, felt like being watched, even though both messages were built from data she'd technically agreed to share.
In this article
The email that opens with a customer's first name feels fine. The one that references a product she looked at once, on her phone, at 2am, feels like being followed, even though both were built from data she technically agreed to share. The difference is not the amount of data. It is whether she can explain to herself how the brand knew.
That test, "could the shopper guess the mechanism?", does more work than any data-minimisation policy. Below: a ladder of signals from safe to risky, a decision tree, label templates and a pre-launch checklist.
Why plausibility, not accuracy, is the real test
A recommendation based on something a shopper browsed on your own site five minutes ago is an obviously reasonable inference: "I looked at running shoes, now I'm seeing running shoes." A recommendation inferred from another device, another platform or a data partner can be every bit as accurate and still feel wrong, because the shopper has no story for how you would know. Accuracy makes it worse, not better: a precise guess from an invisible source is exactly what surveillance feels like.
Gartner has measured the commercial cost twice, and both surveys point at the same fix.
38%
would stop doing business with a company whose personalization felt "creepy"
Gartner, 2019
50%+
would unsubscribe from that company's communications
Gartner, 2019
53%
of customers had a negative experience with personalized marketing
Gartner, 2025
44%
less likely to purchase again after that negative experience
Gartner, 2025
Gartner's 2025 guidance is blunt: "nearly half of personalized digital communications miss the mark" because customers find them creepy, irrelevant or both, and marketers do better "by leveraging data shared by customers, as opposed to collected data that customers did not directly provide." That is the plausibility test in analyst language.
The signal ladder: from obviously fine to obviously not
Not every signal carries the same risk. The table ranks the common ones by how easily a shopper can reconstruct them, and says how to use each without crossing the line.
| Signal | Can the shopper guess how you knew? | How to use it |
|---|---|---|
| Stated preference (size, skin type, style quiz answer) | Yes, they told you | Use it everywhere, and show it back: "Showing size 10 because you picked it" |
| Items viewed on your site this session | Yes, they did it minutes ago | Recently viewed rails, related UGC on the next page |
| Items saved to a wishlist or cart | Yes, deliberate action | Back-in-stock and price-drop messages, UGC for the saved item |
| Order history on your site | Mostly, if it is recent and relevant | Replenishment and accessories; exclude gifts where you can tell |
| Email or SMS engagement | Partly; people forget what they opened | Use to choose topics, not to quote their behaviour back to them |
| Browsing from weeks ago on another device | Rarely | Only for logged-in customers, and label the source |
| Third-party enrichment or data-broker attributes | No | Avoid for anything the shopper can see |
| Inferred sensitive traits (pregnancy, health, finances) | No, and it feels intrusive even when right | Do not infer. Let the shopper opt in explicitly |
The top half of the ladder is also where the durable data lives. Browser rules around cross-site tracking are covered in first-party data strategies post-cookie, and first-party signals are the ones that survive those changes as well as the plausibility test.
Sensitive inferences deserve their own rule
The worst personalization failures are not wrong guesses. They are right guesses about something private: a baby-product rail shown to someone who hasn't told anyone, a "you might need these" block of incontinence products, a finance offer that implies you know money is tight. In the UK, data concerning health is special category data under the UK GDPR, with stricter conditions for processing. The ICO's guidance is explicit that inferred details in those categories "may count as special category data", depending on whether you are intentionally drawing the inference or treating someone differently because of it.
The practical rule. Never infer a sensitive trait from behaviour and act on it in a customer-facing surface. If a category genuinely benefits from tailoring (maternity, mobility aids, dietary needs), ask the shopper to opt in and let them opt out just as easily. A stated preference is both lawful ground and plausible ground.
Explain the mechanism, in six words or fewer
A short, honest label next to a personalized block does more for trust than almost any amount of data restraint. It turns an invisible inference into a visible one. The labels below cover most ecommerce cases:
- Viewed items. "Because you viewed the Trail Runner 2"
- Saved items. "From your saved items"
- Stated preference. "Picked for size 10" or "For oily skin, as you told us"
- Purchase history. "Goes with your last order"
- Popularity fallback. "Popular this week" (say so when it isn't personal at all)
Pair every label with a control: a "not interested" option, a way to change the stated preference, or a reset. Controls turn "they know things about me" into "I'm steering this". The same principle applies to UGC galleries that reorder by shopper interest, covered in personalizing UGC display by shopper segment.
Channel and timing change how the same signal lands
On-site personalization happens while the shopper is doing the thing that generated the signal, so the connection is obvious. Email and SMS arrive later, out of context, sometimes on a shared screen.
A workable rule of thumb. Behavioural signals are safest in the session and on the site that produced them. When you carry them into email, generalise them (the category, not the exact product) unless the shopper took a deliberate action such as adding to cart or saving an item. The UGC in email and Klaviyo flows piece shows how to use customer content in those messages without quoting browsing back at people.
Should this personalization ship?
Start here
Could an average shopper guess how you knew, within a few seconds?
- Yes
Ship it, labelled
Add a short "because you..." label and a way to change or reset it.
- It is a message sent later (email, SMS): Generalise to the category unless the shopper saved or carted the item.
- No, but the shopper gave you the data
Surface the source
Show where it came from ("From your quiz answers") so the mechanism becomes visible.
- The data is sensitive (health, pregnancy, money): Only with explicit opt-in, and never inferred.
- No, and the data came from elsewhere
Do not ship to a shopper-facing surface
Use it for internal analysis at most. An accurate guess from an invisible source is the definition of creepy.
A pre-launch checklist for any personalized surface
- 1Write down every signal the feature reads, and where each one came from.
- 2Mark each signal on the ladder above. Anything below "order history" needs a named owner to sign it off.
- 3Draft the label a shopper will see. If you cannot write an honest one in six words, the mechanism is too opaque.
- 4Add a control: reset, "not interested", or edit preference.
- 5Check for sensitive inferences, including indirect ones (a product category can imply a health condition).
- 6Decide the expiry. How long should a viewed item keep influencing what a shopper sees? Days, not forever.
- 7Confirm the consent basis. In the UK, the ICO's 2026 guidance says the "appearance" exception to cookie consent does not cover choosing content from browsing history or inferred interests, so behaviour-based personalization that stores data on the device sits inside your consent banner, not outside it.
- 8Test it with a holdout, not just a click-through comparison. The A/B testing guide for UGC and social proof covers the setup.
How this applies to UGC galleries
Customer photos and videos are a relatively low-risk place to personalize, because reordering a gallery toward what someone already looked at is visibly connected to their own browsing. Idukki's widget works from that end of the ladder. Merchants can switch on an interest picker where shoppers tap the topics they care about, with a reset. With retargeting enabled on an embed, UGC tagged to products the shopper recently viewed or saved is moved up the gallery. Those signals are kept in the shopper's own browser, expire after a window the merchant sets, and re-rank the gallery rather than filtering anything out.
What that design deliberately avoids is the bottom of the ladder: no third-party enrichment and no inferred traits. For the wider picture of how personalized galleries fit a UGC programme, see personalised UGC galleries, and for the consent side of the content itself, GDPR consent and UGC.
Frequently asked questions
What makes personalization feel creepy?
A correct guess the shopper cannot explain. When the source of the inference is invisible (another device, a data partner, an inferred trait), accuracy makes it feel more like surveillance, not less.
Is it OK to use browsing data in emails?
Carefully. Behaviour is most plausible in the session that produced it. In later messages, generalise to the category unless the shopper saved or carted the item, and avoid quoting exact browsing times or devices.
Do "because you viewed" labels actually help?
They make the mechanism visible, which is the thing plausibility depends on. They also give you a natural place to put a reset or "not interested" control, which shifts the shopper from being tracked to steering.
What personalization should ecommerce brands avoid entirely?
Inferring sensitive traits such as pregnancy, health conditions or financial stress and acting on them in anything the shopper sees. Under the UK GDPR, inferred health details can themselves count as special category data. If tailoring genuinely helps, ask for an explicit opt-in.
Is first-party data automatically safe to personalize with?
No. First-party means you collected it on your own properties, which helps with durability and plausibility, but a first-party order history can still reveal something sensitive. Apply the ladder and the sensitive-inference rule regardless of where the data came from.
Sources
- 1Gartner (2019): Gartner Survey Shows Brands Risk Losing 38 Percent of Customers Because of Poor Marketing Personalization Efforts · Survey of 2,500+ customers: more than half would unsubscribe, 38% would stop doing business over "creepy" personalization.
- 2Gartner (2025): Personalization can triple the likelihood of customer regret at key journey points · 53% had a negative experience with personalized marketing; 44% less likely to purchase again. 1,464 respondents, Nov to Dec 2024.
- 3Gartner (2025): Marketing leaders can unlock commercial value by redefining personalized digital interactions with customer-shared data · Nearly half of personalized communications miss the mark; recommends customer-shared data over collected data.
- 4ICO: Special category data (UK GDPR guidance)
- 5ICO: Guidance on storage and access technologies, what are the exceptions? · The appearance exception is not about adapting content based on known or inferred interests or browsing history.
- 6Idukki: First-party data strategies post-cookie for ecommerce personalization
Continue reading
3 pieces in this clusterThese long-form pieces on the Idukki blog link back to this article, go deeper on the cluster.
- Strategy
The For-You feed comes to the storefront: how per-shopper UGC ranking actually works
TikTok trained a generation of shoppers to expect feeds that adapt to them. Here is what that ranking loop looks like when the feed is your storefront UGC gallery: the signals, the cold-start problem, the over-rotation trap, and where merchandising control fits.
- Strategy
Personalization pitfalls: over-fitting to a customer's last purchase
A personalization engine that treats the latest order as the whole customer gets gifts, one-off needs and shared accounts badly wrong. How to spot the purchases that lie, weight patterns over recency, and let shoppers correct you.
- Strategy
First-party data strategies post-cookie for ecommerce personalization
Chrome kept third-party cookies, but Safari and Firefox block them by default and consent rules still apply. Where each browser stands in 2026, which first-party signals to collect, and how durable each one really is.
More from Rohin Aggarwal
- Strategy
Shopify App Store SEO: how merchants actually discover apps like Idukki
How merchants actually find Shopify apps (App Store search, ads, category pages, Google and referrals), what Shopify documents about listings and Built for Shopify ranking boosts, and how to read those signals when you are shortlisting a UGC or video app.
- Strategy
Headless Shopify and UGC widgets: what still works, what breaks
A theme-block gallery doesn't survive a headless migration unchanged. What breaks, what the API-based alternative looks like, and what to plan for before the rebuild starts.
- Strategy
Owned video vs. UGC video: budget allocation by growth stage
Studio-produced video and customer UGC serve different jobs at different growth stages. A practical budget split by revenue stage, not a philosophical either/or.