The Line Between Personal And Creepy

Behavioural data can make CRM personalisation significantly more relevant, but there is a difference between using a signal and showing a customer exactly what you know. The best approach is often to turn detailed activity into useful summaries that improve the message without making the customer feel watched.

Introduction

Every CRM manager has felt this flinch at least once, either sending a message and wondering whether it went too far, or receiving one themselves and feeling a small, specific unease they could not immediately name.

The difficult thing is that customers absolutely do want personalisation. McKinsey found that 71% of consumers expect companies to deliver personalised interactions, while 76% get frustrated when they do not. When brands get it right, 78% say personalised communications make them more likely to repurchase.

So the answer is not to personalise less. It is to understand what makes personalisation feel useful rather than invasive.

There is no universal line where that happens. It depends on what the customer told you, what you inferred, how granular the information is, what you do with it and, perhaps most importantly, whether the customer gets anything useful in return.

The good news is that you do not need to guess where your audience’s line sits. You can build towards it in stages, measure the reaction at each one and put some fairly simple guardrails around how customer data gets used.

Step One: Start With What The Customer Told You Directly

The safest tier of personalisation, and the right place to start if you are building this up from nothing, uses information the customer gave you deliberately or would obviously expect you to remember.

Their name. Their plan. A recent purchase. Their loyalty status. A preference they selected. An answer to a survey you sent them.

Referencing these things usually reads as attentive because a good member of staff in a small, personal business could plausibly have remembered them too. There is a useful distinction here between having permission to hold a piece of data and the customer expecting you to use it in a particular context. Before turning a CRM field into customer-facing copy, ask three questions:

Where did this information come from? 

Would the customer remember giving it to us? 

Would they reasonably expect us to use it here?

If the answers are obvious, you are probably operating in relatively safe territory. If you are not personalising much yet, this tier alone can be a meaningful first step. You do not need behavioural models and real-time event streams to make CRM feel considerably more relevant.

Step Two: Move To Behavioural Summaries, Not Raw Events

 

“It has been a while since we have seen you” is a summary.

“You have not logged in for eleven days, having previously visited on average every thirty-six hours” is essentially the same insight, stripped of its warmth by precision.

A status or pattern can read as care. An exact count or timestamp can read as surveillance, even when technically it reveals very little additional information.

There is another important rule here: the information that decides which message somebody receives does not necessarily need to appear in the message itself.

Your CRM might know that somebody has visited the same product page six times this week. That could be an excellent signal for deciding what content would be useful to them next. It does not follow that your email should say, “We noticed you’ve visited this page six times.”

Use the observation to improve the experience. Surface the observation only when doing so adds something useful for the customer.

Book A Call

Expert help is only a call away. We are always happy to give advice, offer an impartial opinion and put you on the right track. Book a call with a member of our friendly team today.

Step Three: Test The Reaction Before You Go Further

Do not ask a room full of people where the creepy line sits.Measure it. Once you have a mix of personalisation going out, start recording the approximate intensity of each campaign alongside its performance.

You do not need a sophisticated model initially. A simple framework is enough:

Tier 1, Generic: segment or campaign-level messaging with no individual personalisation.

Tier 2, Provided: name, plan, stated preferences and other information deliberately supplied by the customer.

Tier 3, Relationship: purchases, account tenure, loyalty status and previous interactions.

Tier 4, Derived: behavioural states such as engaged, drifting, high intent or at risk.

Tier 5, Granular: specific recent behaviours, individual product views, interaction counts or precise timing.

Tier 6, Inferred or sensitive: attributes or predictions that the customer did not explicitly provide and may not realise you have inferred.

Tag campaigns with the highest tier they use and compare the reaction. Start with unsubscribe rate and spam complaint rate. Add negative reply sentiment where customers can reply. Then compare those against the positive outcome you were actually trying to create: conversion, retention, reactivation, revenue or engagement.

You may discover that your audience is perfectly comfortable with behavioural segmentation but reacts badly when those behaviours are explicitly mentioned. Another audience may tolerate considerably more specificity because they have a different relationship with the product. That is far more useful than applying somebody else’s universal rule about what counts as creepy.

The More Personal The Data, The More Useful The Outcome Should Be

There is another way to think about the line between personal and creepy: the more surprising the data you use, the more obvious the benefit to the customer should be.

Using purchase history to remind somebody that a product they regularly buy might need replacing has an obvious value exchange.

Using that same browsing history simply to tell them that you have noticed what they have been looking at is much harder to justify.

Before using a deeper personalisation signal, ask what the customer actually gets because you used it.

Better timing? Fewer irrelevant communications? A genuinely useful reminder? A more appropriate offer? Avoiding a message they should never have received? Faster help with something they appear to be struggling with?

Those are customer benefits.

“We think it might increase click-through rate” is primarily a benefit to you. This becomes increasingly important as CRM analytics becomes capable of deriving things customers never explicitly told you. 

 
 

Build Guardrails Into Your Data

All of this becomes harder to manage once personalisation scales beyond what one person can review message by message. 

Build the boundary into the data layer itself. Create a personalisation eligibility classification between raw customer data and anything capable of generating customer-facing copy. A simple version might look like this:

Surfaceable: name, plan, purchase history, stated preferences and other information that can normally appear directly in copy.

Surfaceable with context: account tenure, loyalty status and previous interactions where the appropriateness depends on the message.

Targeting only: engagement score, churn propensity, behavioural segments, browsing intensity and similar derived signals. These can decide what happens without being exposed as sentences.

Restricted: sensitive attributes, highly granular tracking and inferred vulnerabilities that should not be available to normal person This means the underlying data still earns its keep.

A churn model can still use behaviour. A recommendation system can still learn from browsing. An orchestration layer can still decide that somebody should receive one journey rather than another. But the copywriter, mail-merge tool or AI agent cannot casually reach into those raw signals and turn them into a sentence. This becomes particularly important with agentic CRM.

If an AI system should never expose a particular field, do not rely solely on the prompt telling it not to. Wherever practical, remove that field from the customer-facing generation layer entirely.

The Data Worth Watching Throughout

Personalisation needs its own safety metrics alongside its performance metrics.

Track unsubscribe rate and spam complaint rate by personalisation tier, particularly whenever you introduce a deeper level.

Where customers can reply, monitor reply sentiment and complaint themes. A handful of messages saying “How did you know that?” or “Why are you tracking this?” may tell you something that an aggregate campaign dashboard will take much longer to reveal.

Track the positive outcome by tier as well. Conversion, retention, reactivation, revenue per send or whatever outcome the campaign was actually designed to influence.

Then look at the two sides together.

If moving from Tier 2 to Tier 3 produces a meaningful improvement in relevance with no deterioration in customer signals, that is useful evidence.

If moving from Tier 3 to Tier 4 produces a tiny conversion increase alongside a disproportionate rise in complaints or unsubscribes, you have learned something equally valuable.

Finally, record which personalisation tier every campaign actually used. Without that basic metadata, six months later you will have performance data but no reliable way of reconstructing how aggressively each campaign was personalised.

Conclusion

None of this is a reason to personalise less.

The commercial argument for useful personalisation is strong. McKinsey found that 71% of consumers expect personalised interactions and 78% say personalised communications make them more likely to repurchase.

But customer expectations around data are moving at the same time. Salesforce reports that 71% of customers are becoming increasingly protective of their personal information.

Those two trends are not contradictory.

Customers want businesses to understand them. They just do not necessarily want businesses constantly reminding them how much they have been observed in order to achieve that understanding.

So build personalisation depth gradually. Start with information customers deliberately gave you. Move from raw behaviour to useful summaries. Measure reactions as you introduce deeper signals. Separate data used for targeting from data that can appear in customer-facing copy. Put the boundary into your data architecture before AI and automation make the volume too large to police manually.

The goal is not to discover the maximum amount of personalisation your customers will tolerate.

 

Get In Touch

Our friendly team are always on hand to answer questions, troubleshoot problems and point you in the right direction.