This week's panel
25 contributorsVaibhav Kakkar · Faizan Khan · Ihor Lavrenenko M.S. · Silvia Lupone · Roman Surikov · and 20 more

Vaibhav Kakkar — Founder and Group CEO, Digital Web Solutions
Protect Agency During Vulnerability
We avoid using personalization to exploit moments of vulnerability or urgency. We believe people facing difficult issues deserve respect instead of pressure. A high stakes decision or financial stress should never become a targeting opportunity. That boundary keeps our approach relevant without feeling manipulative or intrusive.
Instead we design for agency through clear controls and simple choices. We make it easy to reset preferences whenever someone wants a change. These features build trust because people feel informed and in control during every interaction with our products and services. The best personalization removes friction while protecting choice and helping people move forward with confidence at their own pace every single time.

Faizan Khan — PR and Content Marketing Specialist, Ubuy Singapore
Offer Preference Cards for Clear Value
Throughout my 10-year tenure as head of digital privacy and personalization strategy, striking a balance between personalized experiences and customer trust can be achieved using the "Explicit Value Exchange" principle: collect only those data points that customers are willing to exchange for immediate value. We never resort to passive or implicit cross-site tracking since such profiling tends to decrease customer trust in the process. The one thing that managed to protect trust and optimize relevancy was the "Micro-Preference Choice Card" approach.
Instead of collecting customer profile data at the very beginning of the interaction, we offer customers light preference cards to choose from right within the journey. In the span of 8 months since implementing this approach, we have reduced the number of opt-outs from accounts by 36%, raised personalized click-through rate by 54%, and increased trust score by 33%.

Ihor Lavrenenko M.S. — Founder, Smarfle CRM
Separate Information Tiers and Reveal Rationale
The boundary that has worked at Smarfle is splitting customer data into two tiers with different rules, instead of one blanket policy applied to everything we collect. Tier one is behavioral data the customer generated by using the product itself, feature usage, login frequency, workflow patterns. We use that freely for personalization because it's a direct byproduct of the relationship they already opted into. Tier two is anything inferred or pulled from outside the product, purchase history elsewhere, third party enrichment, social data. That tier requires an explicit, visible opt-in before it touches any personalization, and we show the customer exactly what changes on screen when they turn it on.
The practice that protects trust is showing our work. When a personalized recommendation appears, we surface a one line reason next to it, based on your recent project types, rather than leaving the personalization unexplained. Users don't mind being tracked nearly as much as they mind being tracked invisibly. The tier split keeps us from needing a company-wide privacy debate every time we consider a new personalization feature, since the rule for which tier it falls into already exists. Relevance went up when we leaned harder into tier one data, and trust held because tier two never activates without the customer seeing the switch flip.

Silvia Lupone — Owner, Stingray Villa
Gather Only Facts That Enhance Hospitality
Guests may be willing to share their information if you use it in a helpful, not invasive, way.
Stingray Villa has access to a great deal of information about its guests. However, there are many things I could learn from my guests but do not have to. For instance, knowing that a couple came to Cozumel to go diving lets me recommend local dive shops, where they can rinse off their scuba gear, restaurants, and activities they may find interesting.
My privacy rule is simple. I only collect information that improves my service to the guest. I don't need to know every site they browse online, what they purchased last week, etc. Additionally, I am very mindful of how I communicate with previous guests. No one likes to feel as though the hotel is keeping tabs on them via social media.
I believe it is much easier to lose a guest's trust than to obtain it. To me, my guests are not simply data points; they are individuals who chose to stay at our small, four-unit boutique hotel in Cozumel.
Ultimately, personalized service should create an atmosphere of understanding versus observation.

Roman Surikov — Founder & CEO, Ronas IT | Software Development Company
Limit Signup Inputs for Better Pairings
For Buke, a dating app centered on anonymity, we set the boundary at an email and nickname for signup, while profile details and the preferences questionnaire remain optional. The matching logic uses shared interests and excludes profiles when certain answers conflict. It ranks the remaining matches by a match percentage, while names and photos stay outside the matching experience.
That design gave the product enough signal to make recommendations useful without forcing people to reveal the most sensitive parts of their identity. It also kept the value exchange legible: a preference improves a match, and the user can update it later. Within three months of launch, the app reached 4,000 active users.
Require only the signals needed to operate the core experience, and keep profile enrichment optional and editable. If someone wouldn't expect a data point to affect their experience, the product needs clearer consent or less data.

Marc Bishop — Director, Wytlabs
Favor Declared Choices Over Expired Behavior
The safest personalization strategy is to make restraint visible in the operating model, not merely promised in policy language. People notice when a business knows too much, but they also notice when it remembers nothing useful. The goal is a narrow middle ground where information supports continuity without turning every interaction into a dossier.
I recommend defaulting to declared preferences and context, then using behavior only when it has a shelf life and a benefit. This creates a hierarchy of trust. What customers tell you outranks what systems guess, and recent intent outranks activity. The boundary helped reduce pressure to chase available signals. It made prioritization easier, strengthened discipline, and kept personalization aligned with the relationship customers are having.

Nicholas Gibson — Marketing Director, Stash + Lode
Center Service on Stated Needs
I use a very simple test: would I be comfortable explaining the personalisation to the customer face to face? If the answer is no, it is probably too far. In our storage and removals business, knowing that someone is renovating or moving soon helps us give much better advice. Knowing unrelated personal details does not. I try to personalise around the problem they asked us to solve. That feels like attentive service rather than surveillance.

Nassira Sennoune — SEO Consultant, Originn Properties
Elicit Buyer Details Through Dialogue
In luxury real estate the personalization question is sharper than in most industries, because the people we market to guard their privacy as a matter of habit. A buyer looking at a property in Marrakech or Dubai from abroad does not want to feel tracked, and a single misjudged email ends the relationship before an agent has spoken to them.
The boundary I work with is that we personalize on what the buyer told us or did on our site, and on nothing bought or inferred from elsewhere. If someone viewed villas in one area three times, the next email can be about that area; that is service, and the reason is obvious to them. If we know their budget, it is because they gave it to an agent, and it goes into the qualification, not into a subject line. We do not enrich contacts with third-party data, we do not guess nationality from a name, and we do not reference anything about their wealth that they did not raise first.
One practice that increased relevance without spooking anyone was moving the questions into the conversation instead of the form. Our enquiry form asks for very little. The detail that makes the follow-up relevant comes from the first call with an agent, who asks it as a person would, and records only what is needed to send the right properties. A form with ten fields signals a database; a short form and a good call signals a brokerage. The data we end up with is less, and every piece of it was given knowingly, which is the only kind a high-value buyer forgives you for using.

Dawn McGrath — Marketing Director, Keller Heartt
Apply a Phone-Call Standard Before Outreach
At Keller-Heartt, our test is simple: we collect data that changes a recommendation, and nothing that only changes how much we know about someone.
We're a family-owned industrial lubricant distributor, in business since 1929. Our buyers are maintenance managers, machinists, and plant purchasing teams. They don't want to feel watched; they want the right oil for their machine, fast. Before we add a form field, a HubSpot property, or a campaign segment, I ask: what will we do differently for this customer because we know this? If there's no clear answer, we don't collect it.
That pushes us toward declared data over inferred data. The most useful input is something customers give us willingly: what they run today and what machine it goes in. Our Truegard Metalworking Fluids cross-reference guide is built around exactly that, matching the product a shop uses now to a Truegard equivalent. The conversation starts from their equipment, not from a profile we assembled behind the scenes. The relevance feels earned because they started it.
The boundary that has protected trust most is what I call the phone-call test. If our sales team wouldn't say it to a customer on the phone, our marketing doesn't say it in an email. "You downloaded our metalworking fluid guide; here's the compatible Truegard product and its spec sheet" passes. "We noticed you viewed this page four times on Tuesday" doesn't, even if the data technically exists. Personalization should sound like a knowledgeable person paying attention, not a system keeping tabs.
We also personalize to the question, not the person. As we build AI-assisted tools, including a customer chatbot grounded in our product documentation, the goal is to answer the technical question in front of us, like viscosity grade, H1 versus H2 food-grade certification, or equipment compatibility, rather than mine the conversation for more about who's asking.
The same restraint applies across channels. We sell on our own site and through marketplaces like Amazon, Walmart, and Fastenal, and we don't try to follow customers from one to the next. A closer relationship is opt-in, earned with useful content.
In a B2B industry built on repeat orders and long relationships, trust is the asset. Data is only worth collecting if it makes us more useful without making anyone uneasy.

Drushi Thakkar — Senior Creative Strategist, Qubit Capital
Exclude Public Research From Initial Emails
A founder in Bangalore replied to one of our emails asking how we knew their round had closed. It was public. They had announced it themselves 3 weeks earlier, on their own page, with a photo. That did not matter to them at all. The research file we open on every founder paired with investors is where that announcement landed. Nearly all of it is information people published about themselves on purpose. Accurate and public is still not the same as welcome.
The boundary we run now is about the email, not the database. You can know a thing and choose not to say it. The first emails got vaguer and the reply rate held, something I did not expect and cannot explain. Anything we worked out rather than got told stays in the notes.

Dr. Igor Ivitskiy PhD — Founder, Doctor Ads
Target Current-Session Queries
From the paid media side, buying search ads for ecommerce and SaaS accounts, the blunt answer is that most of the personal data teams collect never earns its keep. Across the 31 ad accounts I audit, covering 9.46 million search term rows over a six month window, my test for collecting a field is simple: if it does not change what the person sees in the same session they gave it to us, we do not store it, because what someone types in the moment predicts the sale better than anything inferred from a stored profile. The boundary that has held up for me is to use only what the person handed over in the current session, and never to let the creative reveal something the user did not tell us in that context. People rarely object to an ad that answers the question they just asked; they object to an ad that proves it has been watching them. The counterintuitive part is that the privacy conservative setup usually performs better: in those accounts the top 1% of search terms by spend carries a median 62% of conversions, so teams leaning on accumulated profiles spread budget across a long tail of weak signals while the live intent that actually converts sits unattended.

Mark Bietz — CMO, Halloween Costumes
Let Users Reverse Campaign Settings
We avoid spooking users by treating personalization as something people should always control. We apply a reversibility standard before using customer information in any marketing experience. We ask whether customers can understand adjust and opt out without confusion. We reconsider any tactic that feels difficult to explain or control.
This standard changed how we evaluate every marketing idea across the customer journey carefully and consistently. We ask whether each message would feel appropriate if its purpose became clear. That question helps us reject ideas that may earn quick attention but weaken trust later. We create relevance through clear choices limited retention and familiar signals that feel respectful every day for lasting customer confidence.

Christopher Coussons — Director, Visionary Marketing
Link Each Field to a Specific Purpose
When we personalise digital experiences for clients, the creepy line is collecting data that would surprise the user if read aloud on a support call. We aim for relevance from consented behaviour and stated preferences, not shadow profiles built from everything a pixel can see. Useful is remembering the product category someone asked about and the stage of a form they started. Overreach is inferring private attributes they never offered, or stuffing optional fields that slow the form and widen the data store without improving the next message.
The boundary that raised relevance while protecting trust is a collect-only-what-you-will-use rule tied to a named personalisation job. If a field does not change the email, the offer, or the on-site path within one cycle, it does not enter the marketing stack. In Form Completion Rate Statistics 2026 at https://visionary-marketing.co.uk/blog/form-completion-rate-statistics-2026 dropping a single optional field lifted completions by 26 percent across 4,200 tests, and four-field forms converted 67 percent better than forms with seven or more fields. Less data often means more conversions and less creepiness in the same move. Ask for the minimum that improves the next honest message, then stop.

Fahad Khan — Digital Marketing Manager, Ubuy Germany
Restrict Individual Records to Four Staffers
Focused entirely on what data we collected for years, without examining who inside our own company could actually access it, which turned out to be a considerably broader group than necessary once we audited internal permissions.
The boundary that changed our trust posture was restricting individual customer behavioral data access to a small named group, roughly four people, rather than the default broad visibility most of our customer support and marketing tools had granted automatically to any employee logging in.
Everyone else worked from aggregated, anonymized views sufficient for their actual job functions, without needing individual-level access at all.
This meant that when customers asked who could see their specific data, we had a genuinely narrow, accurate answer rather than a vague reassurance about internal policies that broad access made hard to stand behind.
Internal audit findings around data access dropped considerably, and the specificity of our answer during customer trust conversations noticeably changed how those conversations landed, since a concrete number felt more credible than general statements about responsible internal handling.

Anna Evans — Founder, Interlinked Wellness
Confine Clinical Material to EHR
Digital personalization for us means remembering visit logistics, not hoarding sensitive history in marketing tools. We personalize reminders with time, deposit status, and the Texas-during-appointment reminder tied to The Functional Medicine Process: What to Expect at https://www.interlinkedwellness.com/process. Clinical detail stays in the EHR. Useful is a 60-minute hold that shows the right prep. Creepy is a newsletter that recites chart facts. Minimize what leaves the covered system, even when a vendor promises smarter targeting.

Dane Maxwell — Founder, Paperless Pipeline
Cite File Sources, Then Seek Approval
The privacy boundary that raised relevance without spooking users is narrow: only pull transaction data needed for the live file, make the AI cite the source page, require a human confirm, and never pool files across offices without a contract.
Personalization for us means the right disclosure on the right deal, not a shadow profile of the agent. Pipeline AI shows where each field came from before anyone saves, which is the practice on our What's New page at https://help.paperlesspipeline.com/help/-whats-new as intake dropped from 10 to 12 minutes to 2 to 3. Trust holds when people see the citation and still own the save. Cross-office data sharing is a paperwork decision, not a product default. This is operator privacy hygiene, not legal advice.

Julian Gage — Founder, Engage Compliance
Reject Hidden Inferences and Set Retention
The boundary I give clients is that anything you use to personalize has to be something the customer would recognize as data they handed you. Email, order history, what they clicked on your own site, all fine. Inferred health status, inferred income bracket, location traces bought in from a broker, not fine, even where you can construct a lawful basis for it. People react to the inference far more than they react to the collection.
The practice that works best is a plain-words test at the moment somebody specs a new segment. If you would not be comfortable telling the customer how you built it ("we noticed you stopped buying X and guessed Y about you"), it does not ship. That kills maybe a third of what comes out of a growth team, and the two thirds left standing usually perform better anyway, because they run on data the customer gave you deliberately and is therefore accurate. Inferred data is often just wrong, which is its own relevance problem before it is ever a privacy one.
The other thing I would push is setting retention per data type rather than per system. Behavioral signals go stale quickly and a model trained on two years of browsing is mostly noise, so twelve months is usually plenty (and it limits the damage if you do have a breach).

Matet Velasco — PR Manager, Vinfluencer AI
Trace Memories to Deliberate Disclosure
The boundary that has held up best for us: personalize on what the person told you on purpose, never on what you inferred about them behind their back.
That sounds obvious until you notice where the creepiness actually comes from. Users are rarely spooked by a product remembering something they said. They are spooked by a product knowing something they never said. The line is not volume of data, it is provenance. You can hold a great deal about someone and have it feel warm. You can hold almost nothing and have it feel like surveillance, if that little bit arrived from somewhere they did not choose.
This is unusually load-bearing in our category. We run persistent-memory conversations, so a virtual persona remembers that a fan mentioned an exam last Tuesday and asks how it went. That recall is the entire product. It is also exactly the mechanic that would feel invasive if the memory had been assembled from tracking pixels instead of from things the person chose to say out loud in the chat. Same data, completely different feeling, purely because of how it got there.
So the practical test I would hand any team: for every personalized moment in your experience, can you point to the sentence where the user handed you that fact? If you cannot trace it to a deliberate disclosure, either drop it or go ask for it directly. Asking costs a little friction. Getting caught knowing costs the relationship.
The other half is control. Memory that cannot be corrected or deleted is not memory, it is a record, and people treat records defensively. Give someone a visible way to fix or remove what you remember and you tend to get more disclosure, not less, because the stakes of telling you something go down.

Siim Kostabi — CEO, Pageloot
Postpone Context Requests Until Benefits Emerge
Our rule at Pageloot: only collect data that changes what you show someone. If you can't point to a specific personalization it enables, you don't need it.
When we added scan location data to our QR analytics, some early users flagged it as creepy. We were showing city-level scan breakdowns by default, which felt surveillance-y even though it was their own campaign data. We moved it behind a toggle and explained exactly what it was for: helping marketers know if a campaign in Hamburg was performing differently than one in Munich. Opt-in framing on that one feature dropped the "why are you tracking me" support tickets to near zero.
The boundary that's held up: don't collect at signup what you can infer from behavior later. Asking 12 questions before someone's even used your product poisons the relationship. Let them experience value first, then ask for context that makes the experience better. Users across 110 countries interact with Pageloot-generated codes daily and most of them never touch our dashboard, so our obligation to the end-scanner is even higher than to the business customer who created the code.
Practical line: if you'd be uncomfortable explaining a data point to a user in plain language, you probably shouldn't be collecting it. That test has killed more bad ideas internally than any privacy framework we've read.

Maurice Sikkink — Founder of Yogile, Yogile
Follow Actions Instead of Image Analysis
I'm Maurice Sikkink, founder of Yogile, and one boundary we've found useful is simple: just because data could make an experience more personalized doesn't mean we need to collect it.
Yogile stores people's private photo libraries, which can reveal an enormous amount about someone: their family, relationships, locations, interests and years of their life. We deliberately don't scan those photos with AI or use them to train AI models, because we don't need to understand the contents of someone's personal photos to provide a good storage and sharing experience.
Instead, we try to personalize around the user's actions and intent. If someone creates an album, invites contributors or reaches a storage-related point in the product, we can make the next step more relevant without first building a detailed profile of who that person is.
We've also removed data collection where it creates unnecessary friction. For example, people can contribute to a shared Yogile album without creating an account.
My rule is: personalize from what the user is trying to accomplish before personalizing from what you can infer about the user.
In my experience, collecting less can actually make a product feel more trustworthy and more relevant at the same time.

Ankita Pathak — Founder, OneMetrik
Clarify Recommendations With One Sentence
Our rule is to only collect and use data that visibly changes what the customer experiences, not data that just sits in a dashboard for our own analysis. If a piece of data doesn't lead to something the customer would actually notice as more relevant, a more useful recommendation, a message that reflects where they actually are, we don't collect it just because it's available. Collecting data "in case it's useful later" is exactly the kind of thing that erodes trust without adding value, since the customer gets the privacy cost without ever seeing the personalization benefit.
The boundary that's helped us most is being able to explain, in one sentence, why a specific piece of personalization exists, if we can't clearly say "we're showing you this because of X," we don't build it. That forces personalization to stay tied to an actual, explainable benefit rather than becoming a black box that happens to feel slightly more relevant for reasons nobody can point to.
One practical example, in our own attribution work for clients, we deliberately avoid using granular device-level or cross-site tracking data that would technically improve targeting precision slightly, but that most users wouldn't expect or understand was being collected. We accept a modest hit to targeting sharpness in exchange for staying clearly inside what a reasonable person would assume is happening when they interact with an ad. That tradeoff has consistently mattered more for long-term trust and brand perception than the marginal targeting improvement would have been worth.

Rahul Agrawal — Founder & CEO, QuickIntell
Tailor Tasks, Not Sensitive Identities
My boundary is to personalize the task, not infer a sensitive identity. Before collecting another field, ask what decision it changes for the customer and whether the same help is possible with less information.
QuickIntell's published operating principles include PHI minimalism and scoped access. In healthcare automation, that distinction matters: an appointment reminder needs appropriate scheduling context; it does not need to expose an entire clinical history. Those are design principles, not a claimed measurement of improved customer trust.
For a hypothetical digital service, let users explicitly choose their preferred channel and reminder time instead of inferring health concerns from browsing behavior. Explain the immediate benefit beside the choice, offer a useful default, and make changing or withdrawing that preference straightforward. Restrict access to the staff or service that needs it, and set a retention purpose before collecting it.
I would measure completed tasks alongside opt-outs and complaints. A personalization change that lifts clicks while making people uncomfortable is a poor trade. The practical test is simple: could you explain this data use to the customer in one ordinary sentence without surprising them?
Rahul Agrawal, Founder & CEO, QuickIntell

Emma Rusby — Director, Zenvy Beauty
Match Porosity Without Facial Profiles
Personalization stops at what helps match porosity and pattern. We keep the Hair Analyser photo long enough to suggest four of the 28 jars, then we do not build a marketing profile from the face.
The boundary that raised relevance without spooking people was tagging the customer record with porosity and last product from the ticket, never selling the image onward or feeding it into a consumer chatbot. In The UK Hair Porosity Report 2026, 61% of 1,000 UK women had never tested porosity. Trust holds when the data answers that question and nothing creepier.

ExamineIP Team — Editorial Team, ExamineIP
Process Requests Ephemerally, Skip Accounts
Our rule is to collect only what the feature needs to work in that moment, and to keep nothing afterwards. ExamineIP runs free network and privacy tools, and many of them have to see sensitive things — an IP address, an email's headers, a password someone wants to check. So we designed them to process on the fly: IP lookups return a result and the tools don't save them, the email header analyzer runs entirely in the visitor's browser, and our password breach check sends only the first five characters of a hash, never the password itself.
The boundary that helped most: no signup and no email capture on the tools, even though it would be easy to add. It costs us a mailing list, but it's the reason people trust the results enough to share them. For personalization, we lean on context the visitor gives us in the moment — what they're checking right now — rather than building a profile over time. Relevance comes from answering the exact question well, not from knowing who is asking.

Brian Cheboi — Head of Marketing, Eternal Elixir AU
State Collection Purposes Clearly
When it comes to personalizing digital experiences, I have found that the key question isn't what data we can collect but what data we genuinely need to make this experience more useful.
Collecting information simply because it might end up being useful later can quickly make personalization feel intrusive. One practice that has helped our data collection feel less intrusive is clearly stating what the data collected will be used for. We ensure that if we collect or use a piece of customer information, we provide a clear reason that is connected to improving the customer's experience.
For example, understanding broad product interests can help us make more informed supplement recommendations, but this doesn't mean that we need to build an exhaustive profile for an individual customer. We also avoid personalization that feels like the brand knows more about someone than they intentionally shared. There is a big difference between saying, "here are products related to your supplement needs" and revealing you've inferred something personal about a customer.
Ultimately, for us, effective personalization should feel helpful, not watchful. When customers can clearly understand why information is being used and have meaningful control over it, relevance and trust stop being competing priorities.
