Personalisation crosses the creepiness line when you use data the customer did not expect you to use. The fix is not less data. It is a rule of use: explicit limits on how customer data gets used, the same way you set limits on who can access it, plus a value exchange the customer can actually see.
A customer walks past your shop. Their phone buzzes with an offer for the aisle they just left. It works once. Then it feels like being followed, and they trust you a little less every time it happens.
Why personalisation tips into creepy
Most teams chase depth. They add another signal, another behavioural trigger, another location feed, because deeper targeting looks like better targeting on a slide. The line where useful becomes intrusive is invisible until you cross it. Then a customer tells you, or worse, they say nothing and quietly stop opening your messages.
That is the trap. You discover the creepiness line only after you have already stepped over it. And by then the damage is not one bad send. Comfort with sharing data is falling, with a quarter of consumers feeling less comfortable than they did a year ago (Segment). Every intrusive message pushes that number the wrong way, for you specifically.
The mechanism is simple. Personalisation depends on data. Data depends on trust. Over-personalisation does not just miss. It burns the trust that the next campaign needs to work at all. You are spending a shrinking asset to buy a short-term lift.
The evidence
Start with the trust you are working from. Only 37% of customers trust brands with their data (Contentful). That is your opening balance, and it is low.
Now the line itself. Nearly half of consumers find a proximity text from a brand they just walked past creepy (Ecommerce Bonsai). The data was accurate. The targeting was precise. The customer hated it anyway, because you used something they did not know you had, in a moment they did not invite.
Precision is not permission. The best personalisation programmes I have run understood that. Tesco Clubcard sent tailored offers to millions of members, and it felt like a benefit rather than surveillance, because the customer knew the deal. They scanned a card, they got relevant offers back. The exchange was visible, so the personalisation was welcome.
Is this you?
Five checks. Yes or no.
- Do you use location or browsing data to message customers who never agreed to that use?
- Have you added targeting signals faster than you have written down which ones are allowed?
- Can a marketer, right now, act on a data field the customer would be surprised you hold?
- Has a personalised campaign ever drawn complaints or a spike in opt-outs?
- If a customer asked why they got a specific message, could you give an answer they would accept?
Three or more yes answers means you are policing the creepiness line by accident, after the fact.
What it costs
The cost does not show up as a creepiness line item. It shows up as opt-outs, as falling open rates, as customers who stop volunteering the very data your personalisation runs on. You train your best customers to share less, and a thinner data set makes every future campaign weaker.
It shows up as wasted spend, because an intrusive message performs worse than a plain one and costs you the relationship on top. And it shows up as a ceiling on AI. Every model you build on customer data inherits this trust problem. Push people to share less and you starve the systems you are investing in to personalise at scale.
Doing nothing is not holding steady. Trust is falling on its own. Cross the line and you accelerate the decline you are already fighting.
Where the line actually sits
The fix is a decision, not a platform. Three directions get you most of the way.
Set rules of use, not just rules of access. Most governance controls who can see a field. Almost none control what you may do with it. Write the second rule down. This data may feed targeting, that data may not. This signal is fine in email, not in a location push. You are drawing the creepiness line on purpose, in advance, instead of discovering it through a complaint.
Make the value exchange visible. The customer gives data. The customer should get something obviously worth it, and should be able to see the trade. Creepy is when they cannot connect what you know to what they get. Welcome is when the benefit is plain.
Personalise on expectation, not on capability. The question is never whether you can use a signal. It is whether the customer expects you to. If using it would make them ask “how did they know that,” leave it out, however much lift the model promises.
This is the same discipline as treating consent and privacy as a data type rather than a legal afterthought, and it is the other half of closing the personalisation perception gap, where customers already rate your personalisation worse than you do.
Get the full personalisation-without-creepiness playbook.
Go deeper on customer data maximization
Three ways forward. Pick the one that fits where you are.
- Get the playbook. Practical notes on turning the customer data you already own into revenue, straight to your inbox. Join the newsletter at the foot of this page.
- Take the assessment. Score your customer data maximization in four minutes and see your top revenue blockers. Start the assessment →
- Book a meeting. Bring your data problem. Leave with a prioritised fix, not a platform pitch. Book a call →
Post 13 of 25 in the Customer Data Maximization series. Previous: Why do customers rate your personalisation worse than you do?. Next: Why is your real-time personalisation always late, and how do you fix it?.
Frequently asked questions
What makes personalisation feel creepy?
Personalisation feels creepy when you use data the customer did not expect you to use, or in a context they never agreed to. A proximity text from a brand someone just walked past reads as surveillance: nearly half of consumers find it creepy (Ecommerce Bonsai). Expectation, not data volume, sets the line.
How much do customers trust brands with their data?
Not much. Only 37% of customers trust brands with their data (Contentful). Trust is also falling: a quarter of consumers feel less comfortable sharing data than they did a year ago (Segment). Every over-personalised message spends down a balance that is already low and shrinking.
Does more personalisation always improve results?
No. Past a point it reverses. Over-personalisation does not just fail to help. It erodes the trust that future personalisation depends on. A message that feels intrusive costs you the next ten that would have landed, because the customer stops opening, stops sharing, and starts opting out.
What is a rule of use for customer data?
A rule of use sets explicit limits on how customer data may be used, separate from who may access it. Access rules ask who can see a field. Use rules ask what you may do with it: which data feeds targeting, in which channel, in which context. It is a policy decision, not a tool.
Is fixing creepiness expensive?
No, which is why it is a quick win. It is a policy decision on data you already hold, not a new capability you have to buy. You set the rules of use, make the value exchange visible, and stop the messages that cross the line. The cost is a decision, not a licence.