IdukkiIdukki
Strategy

Personalization without creepiness: the data-use line shoppers notice

The line between helpful personalization and surveillance isn't how much data you hold. It's whether the shopper can guess how you knew. A signal ladder, a pre-launch test and label templates you can ship.

The email that opened with the customer's first name felt fine. The one that referenced a product she'd only ever looked at once, on her phone, at 2am, felt like being watched, even though both messages were built from data she'd technically agreed to share.

In this article

The email that opens with a customer's first name feels fine. The one that references a product she looked at once, on her phone, at 2am, feels like being followed, even though both were built from data she technically agreed to share. The difference is not the amount of data. It is whether she can explain to herself how the brand knew.

That test, "could the shopper guess the mechanism?", does more work than any data-minimisation policy. Below: a ladder of signals from safe to risky, a decision tree, label templates and a pre-launch checklist.

Why plausibility, not accuracy, is the real test

A recommendation based on something a shopper browsed on your own site five minutes ago is an obviously reasonable inference: "I looked at running shoes, now I'm seeing running shoes." A recommendation inferred from another device, another platform or a data partner can be every bit as accurate and still feel wrong, because the shopper has no story for how you would know. Accuracy makes it worse, not better: a precise guess from an invisible source is exactly what surveillance feels like.

Gartner has measured the commercial cost twice, and both surveys point at the same fix.

  • 38%

    would stop doing business with a company whose personalization felt "creepy"

    Gartner, 2019

  • 50%+

    would unsubscribe from that company's communications

    Gartner, 2019

  • 53%

    of customers had a negative experience with personalized marketing

    Gartner, 2025

  • 44%

    less likely to purchase again after that negative experience

    Gartner, 2025

What badly judged personalization costs. Sources: Gartner press releases, March 2019 (2,500+ customers) and June 2025 (1,464 B2B buyers and consumers, surveyed Nov to Dec 2024).

Gartner's 2025 guidance is blunt: "nearly half of personalized digital communications miss the mark" because customers find them creepy, irrelevant or both, and marketers do better "by leveraging data shared by customers, as opposed to collected data that customers did not directly provide." That is the plausibility test in analyst language.

The signal ladder: from obviously fine to obviously not

Not every signal carries the same risk. The table ranks the common ones by how easily a shopper can reconstruct them, and says how to use each without crossing the line.

SignalCan the shopper guess how you knew?How to use it
Stated preference (size, skin type, style quiz answer)Yes, they told youUse it everywhere, and show it back: "Showing size 10 because you picked it"
Items viewed on your site this sessionYes, they did it minutes agoRecently viewed rails, related UGC on the next page
Items saved to a wishlist or cartYes, deliberate actionBack-in-stock and price-drop messages, UGC for the saved item
Order history on your siteMostly, if it is recent and relevantReplenishment and accessories; exclude gifts where you can tell
Email or SMS engagementPartly; people forget what they openedUse to choose topics, not to quote their behaviour back to them
Browsing from weeks ago on another deviceRarelyOnly for logged-in customers, and label the source
Third-party enrichment or data-broker attributesNoAvoid for anything the shopper can see
Inferred sensitive traits (pregnancy, health, finances)No, and it feels intrusive even when rightDo not infer. Let the shopper opt in explicitly
Personalization signals ranked by plausibility. Use the top rows freely; treat the bottom rows as a legal and brand review, not a growth experiment.

The top half of the ladder is also where the durable data lives. Browser rules around cross-site tracking are covered in first-party data strategies post-cookie, and first-party signals are the ones that survive those changes as well as the plausibility test.

Sensitive inferences deserve their own rule

The worst personalization failures are not wrong guesses. They are right guesses about something private: a baby-product rail shown to someone who hasn't told anyone, a "you might need these" block of incontinence products, a finance offer that implies you know money is tight. In the UK, data concerning health is special category data under the UK GDPR, with stricter conditions for processing. The ICO's guidance is explicit that inferred details in those categories "may count as special category data", depending on whether you are intentionally drawing the inference or treating someone differently because of it.

The practical rule. Never infer a sensitive trait from behaviour and act on it in a customer-facing surface. If a category genuinely benefits from tailoring (maternity, mobility aids, dietary needs), ask the shopper to opt in and let them opt out just as easily. A stated preference is both lawful ground and plausible ground.

Explain the mechanism, in six words or fewer

A short, honest label next to a personalized block does more for trust than almost any amount of data restraint. It turns an invisible inference into a visible one. The labels below cover most ecommerce cases:

  • Viewed items. "Because you viewed the Trail Runner 2"
  • Saved items. "From your saved items"
  • Stated preference. "Picked for size 10" or "For oily skin, as you told us"
  • Purchase history. "Goes with your last order"
  • Popularity fallback. "Popular this week" (say so when it isn't personal at all)

Pair every label with a control: a "not interested" option, a way to change the stated preference, or a reset. Controls turn "they know things about me" into "I'm steering this". The same principle applies to UGC galleries that reorder by shopper interest, covered in personalizing UGC display by shopper segment.

Channel and timing change how the same signal lands

On-site personalization happens while the shopper is doing the thing that generated the signal, so the connection is obvious. Email and SMS arrive later, out of context, sometimes on a shared screen.

A workable rule of thumb. Behavioural signals are safest in the session and on the site that produced them. When you carry them into email, generalise them (the category, not the exact product) unless the shopper took a deliberate action such as adding to cart or saving an item. The UGC in email and Klaviyo flows piece shows how to use customer content in those messages without quoting browsing back at people.

Should this personalization ship?

Start here

Could an average shopper guess how you knew, within a few seconds?

  • Yes

    Ship it, labelled

    Add a short "because you..." label and a way to change or reset it.

    • It is a message sent later (email, SMS): Generalise to the category unless the shopper saved or carted the item.
  • No, but the shopper gave you the data

    Surface the source

    Show where it came from ("From your quiz answers") so the mechanism becomes visible.

    • The data is sensitive (health, pregnancy, money): Only with explicit opt-in, and never inferred.
  • No, and the data came from elsewhere

    Do not ship to a shopper-facing surface

    Use it for internal analysis at most. An accurate guess from an invisible source is the definition of creepy.

Run every new personalized surface through this before launch.

A pre-launch checklist for any personalized surface

  1. 1Write down every signal the feature reads, and where each one came from.
  2. 2Mark each signal on the ladder above. Anything below "order history" needs a named owner to sign it off.
  3. 3Draft the label a shopper will see. If you cannot write an honest one in six words, the mechanism is too opaque.
  4. 4Add a control: reset, "not interested", or edit preference.
  5. 5Check for sensitive inferences, including indirect ones (a product category can imply a health condition).
  6. 6Decide the expiry. How long should a viewed item keep influencing what a shopper sees? Days, not forever.
  7. 7Confirm the consent basis. In the UK, the ICO's 2026 guidance says the "appearance" exception to cookie consent does not cover choosing content from browsing history or inferred interests, so behaviour-based personalization that stores data on the device sits inside your consent banner, not outside it.
  8. 8Test it with a holdout, not just a click-through comparison. The A/B testing guide for UGC and social proof covers the setup.

How this applies to UGC galleries

Customer photos and videos are a relatively low-risk place to personalize, because reordering a gallery toward what someone already looked at is visibly connected to their own browsing. Idukki's widget works from that end of the ladder. Merchants can switch on an interest picker where shoppers tap the topics they care about, with a reset. With retargeting enabled on an embed, UGC tagged to products the shopper recently viewed or saved is moved up the gallery. Those signals are kept in the shopper's own browser, expire after a window the merchant sets, and re-rank the gallery rather than filtering anything out.

What that design deliberately avoids is the bottom of the ladder: no third-party enrichment and no inferred traits. For the wider picture of how personalized galleries fit a UGC programme, see personalised UGC galleries, and for the consent side of the content itself, GDPR consent and UGC.

Frequently asked questions

  • What makes personalization feel creepy?

    A correct guess the shopper cannot explain. When the source of the inference is invisible (another device, a data partner, an inferred trait), accuracy makes it feel more like surveillance, not less.

  • Is it OK to use browsing data in emails?

    Carefully. Behaviour is most plausible in the session that produced it. In later messages, generalise to the category unless the shopper saved or carted the item, and avoid quoting exact browsing times or devices.

  • Do "because you viewed" labels actually help?

    They make the mechanism visible, which is the thing plausibility depends on. They also give you a natural place to put a reset or "not interested" control, which shifts the shopper from being tracked to steering.

  • What personalization should ecommerce brands avoid entirely?

    Inferring sensitive traits such as pregnancy, health conditions or financial stress and acting on them in anything the shopper sees. Under the UK GDPR, inferred health details can themselves count as special category data. If tailoring genuinely helps, ask for an explicit opt-in.

  • Is first-party data automatically safe to personalize with?

    No. First-party means you collected it on your own properties, which helps with durability and plausibility, but a first-party order history can still reveal something sensitive. Apply the ladder and the sensitive-inference rule regardless of where the data came from.

Sources

  1. 1Gartner (2019): Gartner Survey Shows Brands Risk Losing 38 Percent of Customers Because of Poor Marketing Personalization Efforts · Survey of 2,500+ customers: more than half would unsubscribe, 38% would stop doing business over "creepy" personalization.
  2. 2Gartner (2025): Personalization can triple the likelihood of customer regret at key journey points · 53% had a negative experience with personalized marketing; 44% less likely to purchase again. 1,464 respondents, Nov to Dec 2024.
  3. 3Gartner (2025): Marketing leaders can unlock commercial value by redefining personalized digital interactions with customer-shared data · Nearly half of personalized communications miss the mark; recommends customer-shared data over collected data.
  4. 4ICO: Special category data (UK GDPR guidance)
  5. 5ICO: Guidance on storage and access technologies, what are the exceptions? · The appearance exception is not about adapting content based on known or inferred interests or browsing history.
  6. 6Idukki: First-party data strategies post-cookie for ecommerce personalization
#personalization#privacy#first-party-data#trust

Continue reading

3 pieces in this cluster

These long-form pieces on the Idukki blog link back to this article, go deeper on the cluster.

More from Rohin Aggarwal

We use cookies

We use essential cookies to run this site and optional analytics cookies to understand how it’s used. You can change your choice anytime in our privacy policy.