Consent is a product decision, not a legal formality
Consent is usually handed to lawyers: a checkbox, a link, done. We think that is a mistake. The moment of consent is where a person decides whether to trust the system, and it has to be designed as a product.
A shared customer context of visits, preferences and feedback is still a direction of development for us. Before expanding it, we need to solve more than a technical problem: a person must understand the purpose of processing and the consequences of their choice.
A checkbox is not enough
A tick on its own says nothing about the quality of the explanation. Russian Federal Law No. 152-FZ requires consent to be specific, substantive, informed, conscious and unambiguous. The interface therefore has to make the purpose, data involved and available choice clear.
Our test is simple: if we would have to explain after the fact why we know something about a person, the consent was badly designed. The moment of asking has to be legible without commentary.
We only ask for what we can act on
Our working filter for a new data field is to name its purpose, retention period, legal basis and the concrete action it changes. If those answers are not ready, the field should not be added to the product “for later”.
- There is a clear purpose and basis — we describe the field in the legal documents and design its collection.
- The action is only planned — we first test the hypothesis on anonymised or aggregate data where appropriate.
- The purpose cannot be explained plainly — we do not add the field to the product.
What the person gets in return
Consent is an exchange, and the other side of it must be visible. If someone allowed their visits to be linked, they should notice the difference: in speed of service, in not being asked the same thing twice, in an offer that matches what they actually order.
Until the value to the person is defined and tested, expanding the data set is premature. This slows development of the customer layer but reduces the risk of collecting without a clear benefit.
Withdrawal must be equally simple
The law allows consent to be withdrawn, and the product should explain that route without hidden conditions. The current site publishes the contact route in its consent and privacy documents; simplifying the withdrawal interface remains a product task.
Until a shared customer layer enters verified operation, we do not publish its coverage or describe planned capabilities as if they were already live.
This piece reflects the team’s operating experience as of the publication date and is not investment advice. Where quantitative data appears, it carries a definition, period and source.