Insights / Data, Privacy & Security · · 11 min read
Marketing consent vs product consent: why we keep them separate in every company
Agreeing to use a product is not agreeing to be marketed to. How Oryvelon separates product consent from marketing consent, keeps consent records inside each company, and refuses to build cross-brand marketing lists — plus the data model, wording and checks that make the separation hold.
Marketing consent and product consent are two different things, and most privacy trouble in growing companies begins when they are treated as one. A person who signs up to use a product has agreed to let that product work for them. They have not agreed to receive promotions, to be added to a newsletter, or to hear from a sister brand they have never heard of.
At Oryvelon we build and operate several independent companies. That structure creates an obvious temptation: pool the audiences, cross-promote everything, and turn every sign-up into a group-wide lead. We decided early not to do that. This article explains the distinction between product consent and marketing consent, how we record consent per company, why we do not build cross-brand marketing lists, and the practical details that make the rules hold. It describes our practice, not legal advice; GDPR, KVKK, electronic marketing rules and other laws set specific requirements that each company checks for its own markets.
Two different questions
The simplest way to see the difference is to look at the question each one answers.
Product consent — or, more precisely, the basis on which a product processes someone's data — answers: what does this service need in order to do what you asked? A Shopify merchant installing MerchNivo needs the product to read store orders so it can write a daily briefing. A visitor taking KeşifAtlası's eligibility test needs the product to process their answers to evaluate them against the rules database. Often this is not "consent" in the legal sense at all; it is processing necessary to provide the service. Either way, it is scoped to the service.
Marketing consent answers: may we contact you to promote things? It is optional. It is about the relationship after or beyond the service. And critically, refusing it must not stop the person from using the product.
When the two are bundled — "By creating an account you agree to receive offers" — the person has no real choice. Many regulators consider that invalid consent for marketing. Even where the law is looser, it is a poor way to start a relationship.
What goes wrong when they are merged
Merging product and marketing consent causes a predictable chain of problems.
- The list is inflated and unreliable. Every user becomes a "subscriber", but many never wanted to be. Open rates fall, complaints rise and deliverability suffers across the whole sending domain.
- Withdrawal becomes confusing. If unsubscribing from emails seems to mean closing the account, people complain instead, or mark messages as spam.
- Product messages get mixed with promotions. A password reset, a failed payment notice and a discount campaign should not share one channel and one preference. When they do, people unsubscribe from everything and then miss critical service messages.
- Nobody can prove anything. When a person asks "why am I getting this?", a merged system has no record of what they actually agreed to.
For a group of companies, add one more: a merged list crosses brand boundaries. Someone who bought a phone case from Noveniq did not ask to hear about visa eligibility reports or beauty courses.
How we separate them in each company
Every Oryvelon company follows the same pattern, adapted to its product.
Service messages are part of the product. Account confirmations, receipts, security alerts, report delivery, school notices and similar messages are sent because the service needs them. They are not promotional, and they do not carry sales offers. People cannot switch off security alerts, but they can control optional product notifications.
Marketing is a separate, unticked choice. Sign-up forms show marketing as its own option, not pre-selected, with plain wording about what the person will receive and from whom. The product works the same whether they tick it or not.
Marketing is branded clearly. A newsletter from ZodiVela comes from ZodiVela, about ZodiVela. The light "An Oryvelon company" endorsement may appear in a footer, but it is not an invitation to send group-wide promotions. We explain the brand structure in Naming, domains and brand architecture.
Withdrawal is one click. Every marketing message has a working unsubscribe. The preference centre, where one exists, separates marketing topics from service notifications.
Consent can be narrower than "all marketing". Where it helps the person, we split consent by channel (email, SMS) or topic. More granular choices lead to fewer blanket unsubscribes.
Per-company consent records
The most important structural decision is where consent lives. At Oryvelon, each company holds its own consent records, in its own data store, under its own access controls. There is no group-level consent table, just as there is no group-level user table. This follows from our wider principle of shared infrastructure, separate data and from the isolation patterns in Tenant isolation explained.
A consent record is more than a boolean. A useful record includes:
| Field | Example (hypothetical) |
|---|---|
| Subject | Internal ID for the person in this company |
| Purpose | Marketing email: product updates and offers |
| Channel | |
| Status | Granted / withdrawn |
| Source | Checkout page, newsletter form, account settings |
| Wording shown | The exact text or a version reference to it |
| Timestamp | When it was given |
| Withdrawal timestamp | When it was withdrawn, if it was |
| Company | The company that collected it — and the only one that may use it |
Two details are easy to miss. First, store the wording version, not just "yes". If the text changes, you need to know what each person actually agreed to. Second, keep the history. A person who subscribed, unsubscribed and subscribed again has three events, not one flag.
When a company uses an email or messaging platform, the platform receives only the contacts and preferences for that company, in a workspace or account that belongs to that company. Credentials for those platforms are per company too (see Secrets management basics).
No cross-brand marketing lists
This is the rule people outside the group most often question, so it is worth stating plainly: we do not build marketing lists that span our brands, and consent given to one company is never used by another.
It would be possible to ask for group-wide consent — "hear from other Oryvelon companies" — and some groups do. We choose not to, for four reasons.
It does not match what people expect. Our companies serve very different people for very different reasons. A parent using EduRelia, a talent on CastLyra and a merchant on MerchNivo do not expect to be treated as one audience. For EduRelia, student data is never used for marketing at all.
It weakens each company's independence. Every company should be able to stand alone. A company whose audience depends on a shared group list cannot be sold, spun out or evaluated on its own merits. A company whose list it built itself is a real asset.
It blurs the evidence. When we decide whether to continue, stop or scale a company, we want to know whether it can acquire its own customers. Borrowed audiences hide the answer.
It creates a group-level data risk. A single cross-brand list would be the most valuable and most exposed dataset in the group. Not having it is the simplest protection.
What we do instead is ordinary, honest marketing per company. If a CastLyra user wants to know about other Oryvelon companies, the companies page is public. If a company wants a partnership with a sister company — say, a Sinem Keser Beauty Academy course promoted on its own channels and linking to content elsewhere — it is done through public content, not by exchanging contacts.
Wording that is clear on the page
Consent quality starts with the words on the form. A few patterns we use and avoid:
Use: - "Send me product updates and offers from ZodiVela by email. You can unsubscribe at any time." - "Email me when new eligibility rules affect my report" — a service-adjacent option that is still optional and clearly scoped.
Avoid: - Pre-ticked boxes. - "Partners", "affiliates" or "group companies" as vague recipients. - Consent hidden in terms of service. - Double negatives: "Untick this box if you do not wish to not receive…" - Making the marketing checkbox look like a required field.
For product surfaces with AI, the same honesty applies to onboarding: say what the product does with the person's data before they give it. We cover that in AI product onboarding and trust.
Worked examples across our companies
The same rule plays out differently in each business.
Noveniq (DTC commerce). A customer checking out needs to receive order confirmations and delivery updates; that is part of the purchase. Whether they want new-product emails is a separate checkbox at checkout, unticked. If they decline, they still get their order updates. Noveniq's list contains only people who chose Noveniq marketing.
MerchNivo (software for Shopify stores). The merchant installs the app and receives daily briefings; that is the product. MerchNivo may also offer an optional newsletter about new features or e-commerce operations. The merchant's store data — their customers, their orders — is never a marketing asset for MerchNivo. The shoppers in a merchant's store are the merchant's customers, not ours, and they never enter any MerchNivo list.
KeşifAtlası (eligibility reports). A visitor takes a free test and may buy a paid report; we describe the flow in From free test to paid report. Emailing the report and notifying the buyer when a relevant rule changes can be part of what they purchased. Promotional email about other destinations is a separate choice. The answers they gave about their nationality and circumstances are never used for targeting.
CastLyra (marketplace). Talent and brands receive messages about bookings, verification and account security as part of using the marketplace. Promotional emails about features or events are optional. Talent contact details are governed by the marketplace's access rules and are never turned into a marketing list for anyone, inside or outside the group.
EduRelia (edtech). Pupils enrolled by a school are never marketed to. Families who use EduRelia directly may opt in to updates as adults; the child's account is not a marketing channel. See Data minimisation for children in edtech.
Consent and measurement
Marketing consent interacts with analytics and advertising in ways that are easy to get wrong.
- Cookie and tracking consent is its own question. Where a company needs consent for analytics or advertising cookies, that is recorded separately from email marketing consent. Someone can accept one and refuse the other.
- Advertising audiences follow the same rules. Uploading customer lists to an advertising platform is a use of personal data. It needs its own basis, it stays within the company that holds the data, and it never mixes lists across brands.
- Campaign tagging is not personal data. Consistent UTM parameters tell us which campaign brought a visit without needing to identify anyone. See Analytics without surveillance.
Consent as events, not flags
A common implementation stores marketing consent as a single yes/no column on the user record. It is simple, and it loses almost everything you need later.
We prefer to treat consent as an append-only series of events. Each event says what happened: granted, withdrawn, re-granted, changed channel. The current state is derived from the latest event for each purpose and channel. This design has a few practical benefits:
- It answers "why am I getting this?" Support can show exactly when and where someone opted in, and what the form said.
- It survives wording changes. When a company rewrites its opt-in text, old consents keep their original version reference. If the new wording covers something materially different, the company knows whose consent needs refreshing.
- It makes syncing safer. When a withdrawal happens in the email platform (through its unsubscribe link), it is written back as an event in the company's own store. The company's record stays the source of truth, not the vendor's.
- It supports deletion properly. When a person asks to be erased, the company deletes their personal data but may keep a minimal suppression entry so they are not re-added by a later import, where the applicable rules allow that. See Data retention and deletion.
The model is small — one table, a handful of columns — and it pays for itself the first time someone asks a difficult question.
When a company is sold, closed or spun out
Because each Oryvelon company is designed to be independent, we plan for the day one changes hands or stops. Per-company consent makes this straightforward.
If a company is sold, its consent records go with it, together with the wording people agreed to, and the buyer can see exactly what it is inheriting. No other company's contacts are mixed in, so nothing has to be untangled. If a company is closed, its lists are handled according to its own retention rules, rather than quietly absorbed by a sister brand. People who signed up for a closed brand are not "migrated" to another one. Our reasoning on endings appears in Continue, stop or scale.
Merged, group-wide consent makes each of these moments harder and riskier. Separate consent makes them routine.
Common mistakes
A short list of errors we check for when reviewing a company's forms and flows:
- A marketing checkbox that is pre-ticked, or required to proceed.
- A "welcome series" of promotional emails sent to everyone who created an account.
- Unsubscribe links that lead to a login screen.
- A single "email preferences" toggle that turns off security alerts along with offers.
- Consent stored in the email platform only, with no record in the company's own system.
- Importing an old list without knowing what those people agreed to.
- A new brand launched by "warming up" an existing brand's audience.
A quick consent review checklist
When a company launches or changes a form, we run through these questions:
- Is the service usable without marketing consent?
- Is marketing consent unticked, separate and clearly worded?
- Does the wording name the specific brand?
- Is the consent recorded with source, wording version and timestamp in the company's own store?
- Do service messages avoid promotional content?
- Does every marketing message have a one-click unsubscribe that works without logging in?
- Is withdrawal reflected everywhere the list is used within a reasonable time?
- Is there any path by which this list reaches another company in the group? (The answer must be no.)
The cost, stated honestly
Keeping consent separate and per company means smaller lists and slower early growth. A new company cannot start with a ready-made audience. Some campaigns that would be easy for a merged group are unavailable to us.
We accept that. Each list we have is one that people chose, for a brand they know, and it will hold up to scrutiny from customers, partners and regulators. It also gives us honest signals about which companies are genuinely earning attention. That is worth more to a company builder than a large list of reluctant contacts.
Summary
Product consent and marketing consent answer different questions: what a service needs to work for someone, and whether that person wants promotion. Keeping them separate means service messages stay free of offers, marketing is an unticked and clearly worded choice, withdrawal is one click, and every consent is recorded with its wording, source and date. At Oryvelon each company keeps its own consent records, consent never transfers between brands, and there are no cross-brand marketing lists. It makes growth slower at the start, but every audience in the group is one that its company earned and can defend.
Questions and answers
What is the difference between marketing consent and product consent?
Product consent, or more broadly the basis for processing product data, covers what a service needs to work for the person using it. Marketing consent is a separate, optional permission to send that person promotional messages, and refusing it should not affect their use of the product.
Can consent given to one brand be used by another brand in the same group?
At Oryvelon, no. Consent is recorded and held by the company that collected it, and it is never shared with or reused by another company in the group, even though they share an owner.
How should marketing consent be recorded?
Record who consented, to what, through which form, with the exact wording shown, the date and time, and any later withdrawal. Keep the record in the same company that will use it.