Skip to content

AI personalisation that's relevant,
not creepy.

An AI recommendation engine for on-site content, products and email segments, shaped by what your customers actually do and built on consented first-party data from your own stack. Measured against a holdout group (customers who never see it) from day one, so any lift is your number, not our brochure's. Working pilot in 14 days.

Pilot scoped in 48 hours · Holdout-measured

  • Hello Peter
  • Gruber Logistics
  • Delhivery
  • Thomson Reuters
  • Qatar Airways
  • Grundfos
  • Save
  • BERD
  • Yale University
  • Kuwait Police
  • Dubai Police
  • Panasonic
  • Infosys
  • Kia
  • Hitachi
  • Orange Business Services
In one answer

PixelCrayons builds AI personalisation (on-site content and product recommendations, search re-ranking and lifecycle segmentation) on the stack you already run. Everything is powered by consented, first-party data with privacy guardrails designed in. Everything is measured against a holdout group that never sees personalisation, so reported lift is real, not implied. The first working pilot lands on one surface in 14 days. Direct for brands, white-label for agencies.

The operating record

Judge the record,
not the adjectives.

Outcomes tied to real engagements, not averages.

21 yrs
Years in continuous delivery
100+
Agency partnerships
2,500+
Projects delivered
30+
Countries served
2+ yrs
Average partner retention
14 days
NDA to first deliverable
340%
Revenue growth · 7 months
Client outcome: eCommerce
+127%
Organic traffic · 5 months
Client outcome: SaaS
85%
Faster delivery · zero churn
Client outcome: via agency partner
Clutch — 4.8 / 5 ratingGoodFirms — 4.7 / 5 rating
Google Partner
Meta Business Partner
Shopify Partner
Where the work happens
ShopifyWooCommerceMagentoWordPressWebflowKlaviyoGoogle AdsMeta AdsGA4Next.js
  • Consented, first-party data only
  • A holdout group in every engagement
  • No invented lift figures: your baseline decides
  • Working pilot in 14 days
  • Proposals itemised in 48 hours
  • Sensitive categories excluded from targeting
  • Your stack: no forced platform
In every build

What a personalisation build
actually includes.

01

Built on data you're allowed to use

Personalisation runs on consented, first-party behaviour from your own properties: what people browsed, bought and searched on your site, never bought third-party profiles or data your privacy policy doesn't cover. Consent state is checked at decision time. A visitor who declined tracking gets the default experience, cleanly, with no dark patterns nudging them back.

Every build
02

On-site content & product personalisation

Content blocks, personalized product recommendations and search re-ranking on the site you already run: returning customers see reorder shortcuts and relevant categories, first-time visitors see your strongest general proposition. Built into your existing storefront or CMS, not a platform you migrate to. Every rule is inspectable, so merchandisers can see exactly why a block appeared.

The surface
03

Lifecycle segmentation

The same behavioural signals feed segments your email and SMS flows can act on (replenishment timing, category affinity, churn risk) so lifecycle messages stop being one blast to everyone. This runs hand in hand with our email and lifecycle team, including Klaviyo builds, so the on-site and inbox experiences tell one story instead of two.

Included
04

Guardrails against creepiness

Relevance earns trust; surveillance burns it. Every build ships with the boundaries written down: sensitive categories excluded from targeting, no personalisation on traits people didn't knowingly share, frequency caps, and copy rules that never reveal how much the system knows. The test we apply is simple: if a customer saw exactly why they were shown something, would they mind? If yes, we don't build it.

Every build
05

Holdout-based measurement

A slice of your audience never sees personalisation. Deliberately. That control group is the baseline every result is measured against, on your own numbers: conversion, order value, repeat rate. You'll notice this page quotes no average uplift; that's policy, not oversight. If the holdout says a tactic isn't paying, the report says so and the tactic is retired.

Every report
Pilot in 14 days

From consent audit
to measured lift.

01
Days 1 to 3

Data & consent audit

We map the first-party signals you actually have, check what your consent flow permits, and baseline the metrics personalisation will be judged against.

02
Week 1

Pilot scoped & priced

A written scope lands: one surface, the segments in bounds, the guardrails, the holdout size and a demo date. You approve the itemised price before anything is built.

03
Day 14

Working pilot, one surface

By day 14 personalisation is live on one real surface: consent-checked, guardrailed, with the holdout group preserved so measurement starts clean.

04
Weeks 3 to 6

Measure, extend or retire

Results are read against the holdout, not a hunch. What pays is extended to new surfaces and segments; what doesn't is retired in writing. Your team learns the runbook either way.

Inside Prism

Your engagement, week to week,
in one workspace.

Your AI build runs in a Prism workspace you log into: requests, approvals, the task list and the weekly review, with each decision and its expected result written down.

  • 01

    Requests and approvals

    One queue, one owner, one due date.

  • 02

    Weekly review

    Each decision recorded with its expected result.

  • 03

    Actions checked against outcome

    What we did and what happened, side by side.

What real signal supports

Personalisation is bounded by
what you actually know.

Every tactic in a personalisation deck assumes a signal. Line the tactics up against the four states a real visitor arrives in, and most of them turn out to need a visitor you have not met yet. That's a scoping problem, not a technology one.

What each visitor state can support, by personalisation tactic
Visitor stateEntry message & offer framingProduct & content rankingPricing & plan emphasisLifecycle & retention
First visit, anonymousReferrer, campaign, search term, geography, device, time of dayWhere most first-touch traffic sitsSupportedMatch the page to the campaign or query that brought them. Cheap, and the single highest-value thing most sites are not doing.PartlyGeography and device only. Ranking by “people like you” has no you yet.No signalNo signal
Returning, anonymousThe above, plus what they viewed this session and lastSupportedPick up where they left off rather than restarting the pitch.SupportedBehaviour is now real signal: viewed, compared, abandoned.PartlyInferred from what they looked at, which is a guess worth testing, not a fact.No signal
Known: logged in or identifiedThe above, plus account, plan, order history, entitlementsSupportedSupportedSupportedCurrent plan and usage make plan emphasis a fact rather than an inference.PartlyPossible, but lifecycle work belongs in email and CRM more than on the page.
Active customerThe above, plus usage, support state, renewal dateSmallest audience, richest signalSupportedSupportedSupportedSupportedRenewal, expansion and churn-risk messaging, coordinated with the lifecycle programme rather than duplicating it.
  • Supported by real signal
  • Partly: coarse signal only
  • No signal: do not fake it

Start at the top row, not the bottom one. The state with the fewest signals is the state most of your first-time traffic is in, and it is the one nearly every proposal skips.

Illustrative matrix: signal availability by visitor state, not measured performance

How we report it, in Prism

The holdout report,
before anyone quotes a lift.

What you receive in month one

Personalisation is reported against a control group that never sees it. In the first month you receive the consent audit naming which signals your privacy policy allows and which it does not, the holdout design with its size and assignment written down, and the baseline for the metrics you chose. Each rule is then read against the control, by segment, and a rule that does not beat it is retired.

  • 01Consent audit: the signals you may use, the ones you may not, and the boundary written down
  • 02Holdout design: the control group, how it is assigned, and what it never sees
  • 03Baseline: the metrics you chose, measured before any rule goes live
  • 04Lift by segment: each rule against the control, with the confidence stated
  • 05Retirement log: the rules that did not beat the control, and when they came out

Related workD2C fragrance retailer: rebuilt store, rebuilt search.Commerce · Gulf · A different discipline, so it is linked here rather than presented as proof of this one.

The rest of the AI bench

Personalisation is one door in.

The signals that shape a page also shape a lifecycle flow, and our email team runs that side, Klaviyo included. Start wherever the pain is, or start at the hub.

Questions

Frequently
asked.

It can be: badly done, it's the "why is this following me" feeling that makes people reach for the cookie settings. The line is usually obvious when you look for it. Helpful personalisation uses what a customer knowingly shared with you to save them effort (their size, their reorder cycle, the category they always browse); creepy personalisation reveals that you inferred something they never told you. We build to the first side of that line and write the boundaries into scope: sensitive categories are excluded, inferred traits are never surfaced in copy, and consent is checked at decision time. The working test: if the customer could see exactly why they were shown something, would they mind? If yes, it doesn't ship.

First-party behaviour from your own properties: pages browsed, products bought, searches run, emails opened, tied to consent your privacy flow actually collected. We don't buy third-party profiles or enrich against data brokers. Besides the ethics, that data is exactly what regulators and browsers are killing. If your traffic or history is thin, a smaller plan helps more than machine learning: we start with a handful of behavioural segments rather than pretending one-to-one prediction is possible, and the pilot scope says so plainly. The discovery audit tells you what you have, what it supports, and what a consent-flow fix would unlock, before anything is priced.

Against a holdout: a randomly assigned slice of your audience that never sees personalisation and acts as the control. Every result is a comparison between the personalised group and that baseline, on your own commercial metrics: conversion, order value, repeat purchase. This is why no page of ours quotes an average uplift number. Vendor averages tell you about the vendor's best clients, not about your site. It also means we find out when a tactic isn't paying: the holdout exposes personalisation that merely reshuffles revenue rather than adding it, and those tactics get retired in the report, not defended.

Personalisation only runs on data your consent flow permits: that's an architectural rule, not a policy aspiration. Consent state is evaluated at decision time, so a visitor who declines tracking gets the default experience with no degradation and no nagging. Withdraw consent later and the personalisation stops with it. Data stays in your own stack, processing purposes are documented so your DPO has answers before the regulator asks, and regional rules (GDPR, UK GDPR, similar regimes elsewhere) are part of the scope conversation, not an afterthought. We work under NDA as standard, and we'll tell you plainly if something you've asked for can't be squared with the consent you actually hold.

They're complements, not rivals. An A/B test asks "which version is better for everyone?" and ships the winner to all visitors. Personalisation asks "which version is better for this segment?" and serves different experiences to different people. Each personalisation rule is itself validated experimentally against the holdout, so the discipline your CRO programme taught you still applies. In practice the two feed each other: test results reveal segments that respond differently, and personalisation rules generate hypotheses worth testing properly. If you already run a conversion-optimisation programme, we plug into it rather than duplicating it.

It depends on the surfaces, the data work and the guardrails your sector needs, so we don't quote from a rate card. Every engagement opens with a scoped pilot: one surface, agreed segments, a preserved holdout, live within 14 days and priced as a small, defined build. The proposal you receive within 48 hours itemises what ships, including the rules built, the integrations wired, and the measurement included. You compare deliverables, not day rates. Extending to more surfaces or lifecycle flows is priced per step, only after the holdout numbers have earned it.

Both. On a store it recommends products, re-ranks search and shapes content blocks for returning customers and first-time visitors. The same consented signals feed lifecycle segments your email and SMS flows can act on. It is built into the storefront or CMS you already run, not a platform you migrate to.

Personalise one surface,
and measure it honestly.

Scope a pilot: one surface, consented data, a preserved holdout, live in 14 days, with the guardrails written down and results judged against your own baseline, not a brochure.

48-hour proposal · NDA standard · You own what we build

Last updated

May we run analytics (Google Analytics via Google Tag Manager) to see which pages are useful? Nothing loads unless you accept, and declining means no analytics script runs at all. No advertising cookies either way. Cookie policy · Privacy policy