You personalise without creepiness in three steps: write explicit rules of use for every customer data field, make the value exchange visible at every point of use, and police the line with a pre-send check owned by one person. It is a policy decision on data you already hold, not a new capability you buy.
The risk here is recognised but inconsistently policed. Most teams know some personalisation feels creepy. Few have written down where their own line sits, so it gets enforced by mood and deadline. This playbook turns that instinct into a standing control. No new platform. Just three moves on the data you already own.
Step 1: Write the rules of use, field by field
Governance almost always covers access: who can see a field. It rarely covers use: what you are allowed to do with it. That gap is where creepy lives.
Close it. List every customer data field you hold, from email and purchase history to location, browse behaviour, and inferred attributes. For each one, answer three questions. May it feed targeting at all. Which channels may use it, email versus SMS versus location push. In which contexts is it fine, and in which does it tip into surveillance.
The output is an allow list, not a principle. “Browse history may personalise on-site and email content. It may not trigger a location push.” Specific enough that a marketer under deadline can check it in ten seconds.
Owner: the customer or data lead, not legal alone. Legal tells you what is lawful. This decides what is welcome, which is a higher bar. Measure it by coverage: what percentage of your active data fields have a written, agreed rule of use. Aim for all of them before you extend targeting any further.
Step 2: Make the value exchange visible
A rule of use tells your team what is allowed. The value exchange tells the customer why it is worth it. Both have to be true.
The line between useful and creepy is whether the customer can connect what you know to what they get. Precision they cannot explain feels like being watched. The same precision, attached to an obvious benefit, feels like a service. Tesco Clubcard sent tailored offers to millions and it read as a reward, because the customer scanned a card and got relevant deals back. The trade was in plain sight.
So for every personalised experience, make the exchange legible. Say what you used and what the customer gets for it. “Because you bought X, here is Y.” Give a real benefit for a real permission: a discount, early access, a better fit, points. If you cannot state the benefit in a sentence the customer would accept, that is your signal the personalisation is taking more than it gives.
Owner: campaign and lifecycle marketing. Measure it two ways. Opt-in and data-sharing rates, which should hold or rise as you make exchanges clearer, and opt-out spikes per campaign, which flag an exchange the customer did not think was fair.
Step 3: Police the line before send, not after the complaint
Steps one and two fail quietly if nobody checks them at the moment of firing. The default failure mode is to discover the creepiness line through an opt-out report a week later. Move the check upstream.
Add a pre-send gate to every personalised campaign. Before it goes out, one owner confirms two things. Every signal the campaign uses appears on the approved rules-of-use list from Step 1. And nothing in the message would make the customer ask “how did they know that.” A single “would this surprise them” question catches most of the damage.
Keep it light so it survives deadlines. A one-line checklist in the campaign brief, not a committee. The point is that the line is drawn on purpose, in advance, rather than found by accident after you have crossed it.
Owner: one named person in the customer or data function, with authority to hold a send. Measure it by leading and lagging signals together: campaigns passing the pre-send check on first pass, and opt-out and complaint rates trending down over a quarter as fewer intrusive messages get out the door.
How to train your team to hold the fix
A rule of use only works if the people writing campaigns believe in it, so teach the why, not just the what. Show your marketers the numbers. Only 37% of customers trust brands with their data (Contentful), and a quarter feel less comfortable sharing than a year ago (Segment). Then make the connection explicit: over-personalisation does not just underperform, it spends down the trust every future campaign relies on. Once a team sees personalisation as a trust budget, they stop treating deeper targeting as a free win.
Run the rules-of-use list as a living document, reviewed when you add a new data source or channel. Give one person clear ownership so the line is policed consistently rather than by whoever happens to be nervous that week. And build the pre-send question into onboarding for every new marketer, so “would this surprise the customer” becomes reflex rather than a policy they were emailed once and forgot.
Where Morphy helps
This is a quick win, and we run it as one. In a four to six week engagement we build your rules-of-use list across your live customer data fields, wire the pre-send check into your existing campaign process, and rewrite your highest-volume personalised flows so the value exchange is visible. No new platform, because the fix is policy on data you already hold.
The metric we commit to is honest and observable: opt-out and data-sharing rates on the flows we touch, measured before and after, plus full rules-of-use coverage of your active fields. You leave with a written control your team owns, not a slide about trust. It works alongside treating consent and privacy as a data type, and it directly narrows the personalisation perception gap.
Go deeper on customer data maximization
Three ways forward. Pick the one that fits where you are.
- Get the playbook. Practical notes on turning the customer data you already own into revenue, straight to your inbox. Join the newsletter at the foot of this page.
- Take the assessment. Score your customer data maximization in four minutes and see your top revenue blockers. Start the assessment →
- Book a meeting. Bring your data problem. Leave with a prioritised fix, not a platform pitch. Book a call →
The playbook companion to How do you personalise without crossing the creepiness line?. Post 13 of 25 in the Customer Data Maximization series.
Frequently asked questions
How do you write a rule of use for customer data?
Take each data field and answer three questions: may it feed targeting, in which channels, and in which contexts. Write the answers down as an allow list, not a vague principle. A rule of use governs what you do with data, separate from access rules that govern who can see it.
What is a visible value exchange in personalisation?
A visible value exchange is when the customer can plainly connect the data they gave to the benefit they got. Scan a loyalty card, get relevant offers. Share a size, get better fit. Creepiness happens when the customer cannot see the trade. Make the benefit obvious and the same data stops feeling intrusive.
How do you stop creepy messages before they send?
Add a pre-send check. Before a personalised campaign goes out, one owner confirms every signal it uses is on the approved rules-of-use list and would not surprise the customer. This catches the creepiness line in advance, instead of discovering it through opt-outs and complaints after the send.
Who should own the creepiness line?
One named person, usually in the customer or data function, owns the rules of use and the pre-send check. Without a single owner the line gets policed inconsistently: recognised in principle, ignored under campaign deadline. Ownership is what turns a good intention into a standing control.