← All articles

First-party data: building your customer base from scratch

The data your customers declare survives browsers, blockers and third-party cookies. Here are the six moments to ask for it, and what to offer in return.

Dots Papers cover for the article on building a customer base from first-party data

In short

  • Three families, only one is yours. First-party data belongs to you, second-party data is lent to you by contract, third-party data is rented to you for the length of a campaign.
  • What the customer declares beats the trace they leave. An email address or a size depends on no cookie and stays usable years later.
  • You collect at six precise moments where the customer already expects a service in return: account, order tracking, loyalty, after-sales, warranty, appointment.
  • An unmaintained base loses value every month. Duplicates, dead addresses and inconsistent formats ruin deliverability before they skew the reports.

How many customers could you contact tomorrow morning, without going through a platform and without paying for it? Put to a company director, the question rarely gets a direct answer: people cite traffic, orders, social followers. The real answer is the number of valid, consenting addresses in your database, and it is almost always lower than expected.

The rest is rented. A remarketing audience built inside an ad network does not follow you if you change agency, and the identifiers feeding it erase themselves: Firefox has blocked third-party cookies by default since September 2019, Safari since March 2020, and Google gave up removing them in Chrome in April 2025. That timeline is not a strategy, it is weather.

The useful question is not when third-party cookies will disappear, a subject covered in our article on the end of third-party cookies, but how to build a base that belongs to you when you start from almost nothing.

The three families of data, and what each one costs you

The distinction is not about the nature of the information, but about who holds it. First-party data comes from your own touchpoints: site, till, customer service, forms. Second-party data is someone else’s first-party data, passed on under a commercial agreement. Third-party data is aggregated then resold by a broker who has never met your customers.

Family Who holds it What it is worth What it costs
First party You, through your sites, shops and customer service Maximum precision, reusable as long as consent allows Time, a reason to give the customer, continuous maintenance
Second party A partner company, by contract A close audience without going through a broker A legal basis to document, use limited to the agreement
Third party A broker aggregating multiple sources Immediate volume, broad coverage A price per thousand, unverifiable quality, and GDPR responsibility that stays yours
Reading: only the first row survives a change of agency, tool or ad network.

On bought files and third-party enrichment Buying a file makes you the controller: you must be able to prove the origin of each contact’s consent, which a seller rarely documents verifiably. The risk is not only a fine. A campaign sent to a bought list generates complaints that lastingly damage your domain’s sending reputation, including towards your real customers.

Declared data survives, observed data evaporates

Observed data is a trace: page view, click, abandoned basket, attached to a technical identifier. Declared data is information the customer gave you: email, first name, size, sector, birthday.

The first has a very short life. Since 2019, Safari caps JavaScript-set cookies at seven days, and a visitor who changes phone starts from zero. The second does not move: an email address crosses browsers, devices and changes of tool.

Above all it is directly usable, in email as in advertising. A browsing trace only serves the tool that set it, and only while measurement works, which is far from guaranteed: we have documented how far tracking can degrade without warning.

Six moments to ask for information without breaking the sale

Building a base is not about adding a newsletter form in the footer, it is about spotting the moments when the customer already has a reason to give you something. One piece of information asked, one service rendered immediately: if you cannot name what you give in return, do not ask the question.

Moment in the journey Information to ask for What the customer gets back
Account creation Email, first name, separate marketing consent Finding their orders and addresses, ordering faster next time
Order tracking Email or mobile, their choice Dispatch and delivery notifications without returning to the site
Loyalty programme Date of birth, product preferences Points, a birthday offer, early access to new products
After-sales Email, product reference History kept, no need to explain everything again
Warranty registration Serial number, date and channel of purchase Proof of purchase kept, faster handling
Booking an appointment Phone, slot, need in one line Automatic reminder, appointment prepared in advance
Six moments where the request is legitimate because it serves the customer before it serves your database.

Two rules frame these moments. Marketing consent is a separate box from account creation: opening an account does not authorise campaigns. And every piece of information collected must have a use already planned, otherwise it ends up as an empty column in a spreadsheet.

The classic mistake: asking too much, too early

The most common reflex is to add fields to the form while you are at it: title, company, postcode, sector, headcount. Every extra field lowers the completion rate, and most of that information will never be used.

Good practice is called progressive profiling: the strict minimum at first contact, then a little more at each subsequent interaction. A customer who has ordered three times will happily answer about their preferences. A visitor discovering your site will not.

The mistake to avoid Asking for a date of birth or a phone number at payment, for marketing use, drops conversion without producing anything usable: the fields are filled at random or abandoned. Those questions belong after the order.

What you do with the base once it exists

Segmentation first: separating recent customers from dormant ones, buyers of one range from another, big baskets from small. Three well-defined segments already beat a single send to the whole base, and they give you the material for your first automation workflow.

Advertising audiences next: Google and Meta accept a list of hashed emails to find your customers, target buyers of one product or exclude those who have just bought. That activation assumes reliable server-side measurement, which is the subject of DataFirefly Server-Side, a platform published by Datafirefly Limited, the sister company of our agency, whose free plan covers 10,000 requests a month.

Personalisation last: adapting the site or email content to what the customer declared. The most visible, and the most demanding, because it assumes clean, up-to-date data.

One constraint runs through all three uses: consent is assessed per purpose. Someone who accepted your newsletter has not accepted their address being sent to an ad network. That use must be announced at collection and recorded in the database, a mechanism detailed in our data, analytics and performance expertise.

An unmaintained base loses value every month

A file is not a stock. People change employer and lose their work address, mailboxes are abandoned, customers re-register with a variant of their email.

Three workstreams cover the essentials. Deduplication on the email normalised to lower case, with a clear rule for which record wins. Removal of hard-bounce addresses, the ones that come back as permanent failures. Normalising formats: phone numbers in international form, coded countries, first names without stray capitals.

Neglecting this work costs quickly: mailbox providers judge your sender reputation on your bounce and complaint rates. A dirty base lowers deliverability towards the good addresses.

What to take away A base of 4,000 reachable, consenting contacts beats a file of 40,000 lines whose origin nobody knows. The indicator to follow every month is not the number of contacts, but the number of reachable and consenting contacts, by collection source.

Your first four weeks, concretely

  1. Week 1, the inventory. List the places where contact details already exist: back office, till, customer service inbox, spreadsheets, an old email platform. Count valid addresses and the origin of consent.
  2. Week 1, the single source of truth. Designate one tool as the reference, usually the e-commerce back office or the CRM. Everything else feeds it, never the reverse.
  3. Week 2, two collection points. Wire up the two most profitable moments from the table above, almost always the account and order tracking, with a separate, timestamped consent box.
  4. Week 3, the clean-up. Deduplicate, remove hard bounces, standardise phone numbers and countries. Keep a trace of what you delete.
  5. Week 4, the first activation. Create three segments, send a campaign to one of them, test an advertising audience built on your consenting customers.
  6. Then, the monthly review. One hour a month on three indicators: new contacts by source, share reachable, share consenting.

Frequently asked questions

How many contacts before it is worth anything?

For email, a few hundred qualified contacts already produce measurable results if the segmentation is relevant. Google and Meta, on the other hand, apply a minimum threshold before activating an uploaded list, in the order of a few thousand contacts. So start with email, which has no threshold.

Can I use my customer file to build an advertising audience?

Yes, if your customers were informed of that use and you have the corresponding legal basis. The address is sent hashed and the platform matches it against its own accounts. What blocks this in practice is almost never the technology, it is the absence of any mention of that use at collection.

What is the difference between zero-party and first-party data?

Both belong to you. First party covers everything you collect on your own channels, observed behaviour included. Zero party means what the customer declares voluntarily in answer to an explicit question. It is the most reliable, because it is not inferred.

Am I allowed to buy a B2B prospect file?

Email prospecting towards professionals is framed more loosely than towards consumers, provided the message concerns their work and the person was informed at collection. Proving that information is hard when it was gathered by a third party: demand documented contact origins and test on a sample before buying volume.

Where to start

First-party data cannot be caught up in a quarter: it builds order after order, case after case. A company that wired up two collection points two years ago now holds an asset its competitors cannot buy.

The starting point is not technical: knowing how many customers you can reach tomorrow morning, and through which channel. If that figure does not exist in your company, it is the first one to produce.

Unsure what your customer base is really worth? On a first engagement we count your reachable and consenting contacts source by source, and identify the two collection moments missing from your current journey. Let’s talk.

Want to apply this to your own business?

Get in touch →

Further reading

Leave a comment

Your email address will not be published. Required fields are marked *

twelve + four =