Skip to content
ceaksan

An Email Automation Setup for Ecommerce Sites: Customisable, Flexible, With Full Data Ownership

Keep your audience even when your platform changes. A guide to flexible email automation for ecommerce, with behavioural personalisation, KVKK/GDPR compliance and predictable cost.

Apr 29, 2026 12 min read
TL;DR

In ecommerce email automation, store owners and agencies lose three things at once: ownership of the data, flexibility in behavioural personalisation, and control over cost. Hosted SaaS solutions (Klaviyo, Brevo, Omnisend) and in-platform automations (Shopify Flow, İkas, Ticimax) solve that trio only partly. A vendor-independent, behaviour-driven pipeline takes all three; in return it asks for a maintenance load and a technical setup. For merchants in Türkiye, İYS consent lookup, filing and rejection sync can become a natural step in the pipeline, and it is possible for agencies to run this infrastructure on behalf of their clients.

Ecommerce stores often go through a similar cycle: a decision is made about email automation, the setup is done, then as the list grows either the bill swells, or the customisations that were wanted cannot be made, or a planned behavioural rule cannot be added, or the email data ends up trapped with the vendor. When all of these happen at once, moving to another email solution goes on the agenda. The problem is not picking “the wrong tool”, it is not noticing that the real dividing line is not in the feature list but in the trio of data ownership, behavioural flexibility and cost control.

This post is for stores that sit on ecommerce platforms such as Shopify, İkas, Ticimax, T-Soft and IdeaSoft, or integrate with them, and for the agencies working with them; it covers how to look at a setup that can take all three of those values at once in ecommerce email automation. The technical depth is in a separate post on orchestrating behavioural triggers with Inngest, Listmonk and Resend, which is Turkish-only for now. The aim here is a decision guide.

The 3 Things Lost in Ecommerce Email Automation

1. Data Ownership

Subscriber state, open history, segment definitions, behavioural tags. If you use a hosted SaaS, all of that data lives on the vendor’s side. A store is built on top of this data over the years: which customer showed interest in which category, who opened which email, who responded to which discount code. When you need to change vendors, that accumulation does not move 1:1. The subscriber list moves, custom properties move partly, but 2-3 years of behavioural history is not copied to the new platform.

When a store moves from Shopify to İkas, or from Ticimax to T-Soft, the most expensive loss is not the email list but the behavioural intelligence sitting on top of it. Because the data does not stay on your side, that intelligence starts from zero at every move.

2. Behavioural Personalisation Flexibility

In hosted SaaS and in-platform automation alike, the “trigger” pool is predefined. Cart abandonment, a welcome after sign-up, a win-back for someone who has not purchased in X days, a birthday. That very likely covers 70% of your needs. The remaining 30% is the part specific to your store: “offer free shipping to customers who bought from the men’s category, have not come back within 14 days, and are in cities outside İstanbul”, “prioritise warning Premium tier members who have not ordered in the last 30 days and have an item running low on stock in their cart”. Where you can write these finer rules is only as far as the SaaS allows.

A self-hosted state layer like Listmonk lets you add unlimited attributes to a subscriber (tier, last_category, lifetime_orders, geo_segment, flag_at_risk and so on). An orchestration layer like Inngest lets you build event-based flows that branch on those attributes. Adding a new rule does not depend on vendor approval; it goes into the pipeline in a day.

3. Cost Control

Contact-based pricing like Klaviyo’s grows with the list. Around $150/month at 10K subscribers, around $400/month at 25K, and with the February 2025 “contactable profile” change, inactive subscribers started counting at the same rate.1 Volume-based alternatives such as Brevo and Omnisend rise sharply with campaign intensity. In-platform solutions (Shopify Flow, İkas built-in) look free but narrow in behavioural scope; the gaps get filled with extra modules. The pipeline this post is about offers enough flexibility to integrate with those solutions too.

In a vendor-independent pipeline the cost is predictable: a fixed infrastructure fee (server, deliverability provider) + volume-based sending. The bill does not multiply as the list grows. As you move toward 25K-50K subscribers, the maths shifts in this approach’s favour.

KVKK and İYS compliance is the hidden fourth constraint. An extra operational load for TR and EU stores; separate section below.

The Limits of the Existing Solutions

Hosted SaaS (Klaviyo, Brevo, Omnisend, Mailchimp)

Strong: fast setup, ready-made segments and AI suggestions, native Shopify integration, a familiar ecosystem for agencies.

Limit: contact-based pricing grows with the list; the behavioural rule set goes as far as the vendor offers; İYS lookup is not native and needs a manual bridge; for KVKK, reading the DPA, checking the sub-processor chain and verifying data location fall on the merchant. They do not connect to local TR platforms (İkas, Ticimax, T-Soft, IdeaSoft) as well as they do to Shopify; it takes either a Zapier bridge or a custom integration, both fragile and both an extra bill.

Klaviyo is the strongest product in this category, refined for ecommerce over years. The problem is not the quality of the product, it is that the price-value curve inverts as the list grows and that compliance with the Türkiye regulation is left to the store.

In-Platform Automation (Shopify Flow, İkas, Ticimax, T-Soft, IdeaSoft)

Strong: free or included in the package; TR platforms have İleti Yönetim Sistemi (İYS) modules; simple setup; the store owner manages it from a single panel.

Limit: the behavioural scope is generally narrow; segment depth is shallow; there is no multi-platform consolidation; adding a custom rule depends on the platform roadmap. Scenarios beyond cart abandonment and a simple welcome flow (post-purchase upsell chains, segment-based drip, behavioural win-back, lead magnet delivery) are either absent or very limited. For multi-store setups or headless installations it is out from the start.

These solutions are enough for a store that is “happy to stay inside the platform, mid-level in volume, standard in its list of needs”. In scenarios above the platform (migration, multi-store, headless, niche segments) they fall short.

A Vendor-Independent Behavioural Pipeline

A three-layer structure:

  1. Orchestration (event handling): the layer that listens to events coming from the store and branches on rules. Event-based orchestration tools like Inngest do this job; durable execution and retry come built in.
  2. State (subscriber + segment): the subscriber list, attributes, segment definitions and sending history live in your storage. Self-hosted Listmonk is the centre of this layer; you can add unlimited attributes to a subscriber and define segments at the SQL level.
  3. Delivery: the API that actually sends the email. HTTP APIs like Resend, Postmark and Mailgun fill this role. This layer is fully replaceable; changing the delivery provider does not affect the rest of the pipeline.

What it gives:

  • The data is yours: the subscriber table, the event log and the segment definitions live on your own server. No vendor lock-in.
  • The behaviour is yours: a new trigger, a new rule, a new branch goes in within a day. No vendor approval.
  • Cost is predictable: fixed infrastructure + volume-based sending. It does not grow with the contact count.
  • KVKK and GDPR friendly: EU or TR data residency can be chosen. The İYS bridge becomes a natural step in the pipeline. The DPA load is minimal.
  • Multi-platform: Shopify, İkas, Ticimax, T-Soft, IdeaSoft and headless setups all connect to the same pipeline.

The maintenance reality: server management, deliverability and sender reputation, the İYS bridge, monitoring. For a store without a technical team it makes sense to take this load as a “managed service”, because the real value is not the extra technical control but control being able to belong to you.

Cost Comparison (A Store With 10K Subscribers)

SolutionMonthly CostBehavioural ScopeKVKK / İYSData Ownership
Klaviyo~$150Wide, vendor dependentManual bridgeWith the vendor
Brevo~$60 (volume)MediumManualWith the vendor
Omnisend~$60-90MediumManualWith the vendor
Shopify Flow + third-party SMTP$0-20NarrowManualWith Shopify
İkas built-inIncluded in packageNarrowYes (TR platform)With İkas
Ticimax cart reminderIncluded from Scale packageVery narrowYes (TR platform)With Ticimax
Vendor independent (managed)€200-300UnlimitedBuilt-inYours

At the 10K subscriber band a managed pipeline can look more expensive than the others. The real value comes from the trio in the columns: the advantage taken in behavioural scope + compliance + data ownership. As you move toward 25K-50K subscribers, the cost gap inverts mathematically as well.

Decision Matrix: Which Route for Whom?

ScenarioRecommended Route
Under 500 subscribers, under 100 orders/monthIn-platform automation is enough
500-5K subscribers, needs limited to cart + welcomeHosted (Brevo, Omnisend) or in-platform
5K+ subscribers, behavioural segment needs, İYS sensitiveA vendor-independent pipeline produces value
Multi-platform or headless storeA vendor-independent pipeline (the only right answer)
Platform migration (Shopify ↔ a TR platform)A vendor-independent pipeline (state transfer + İYS rebuild)
An agency providing the infrastructure for a clientA vendor-independent pipeline, multi-tenant + an İYS connector

The decision is usually taken on the pain threshold rather than on subscriber volume. The threshold is crossed when the hosted SaaS bill starts to bother you at the end of the month, or a behavioural rule has been waiting at the vendor for weeks, or a DPA is asked for during a KVKK audit.

Platform Migration: Where “the Data Is Yours” Actually Pays Off

From Shopify to Ticimax, from Ticimax to İkas, from T-Soft to Shopify; at every move the store owner has the same worry: “what happens to the old email list? The segments built up over years? The welcome flow?”. In a vendor-dependent tool like Klaviyo that accumulation does not move 1:1 to the new platform. The subscriber list moves, but open history, behavioural segments and in-flow states require a manual rebuild.

This is exactly where the real advantage of a vendor-independent pipeline shows. Because subscriber state, segment rules and the event log are not locked to a vendor, “plug in and carry on” is possible on the new ecommerce platform. The frontend (the store software) changes, the backend (the email pipeline) stays. Rebuilding the İYS bridge during the migration is only a configuration change too; the whole flow does not have to be rewritten.

KVKK + İleti Yönetim Sistemi Compliance

For stores in Türkiye there are two extra layers; when both are embedded in the infrastructure, the merchant’s paperwork and audit load drops considerably.

At the moment a subscriber is collected, the explicit consent text, the opt-in timestamp, the IP, the form URL and the version of the disclosure text are logged together. In hosted SaaS this information lives on the vendor’s side; during an audit, the question “where is your data” requires reading the DPA and verifying the sub-processor chain. In a vendor-independent pipeline the log and the consent record are in your own storage; the burden of proof drops, and you can also control the three-year retention period KVKK requires.

İYS: Not a One-Way Lookup, a Two-Way Sync

İYS compliance is often described as “a consent lookup before every send”. In practice the process is two-way and consists of four steps:

  1. Filing consent (at newsletter sign-up): when a user subscribes through the form, the consent is written to İYS with Status: ONAY, Source: HS_WEB, an IP and a timestamp at the same moment as the Listmonk record. This step sits in the pipeline as an Inngest function; if it fails it retries, and if it still fails the subscriber is marked with a pending_iys flag.
  2. Consent lookup (before sending): before a bulk campaign the whole list is confirmed through İYS’s Çoklu İzin Durumu Sorgulama endpoint. If the result is RET, the address is dropped from the sending list.
  3. Withdrawing consent (newsletter unsubscribe): when a user unsubscribes through Listmonk, the Listmonk webhook (subscriber.unsubscribed) fires; the same consent endpoint is called, this time with Status: RET. Bounce and complaint events are not sent as RET (a rejection and a technical delivery failure are different things).
  4. Delta sync (İYS → Listmonk): when a merchant or a user records a rejection in the İYS portal, that change does not reach Listmonk automatically. A daily Inngest cron pulls the records changed since the last sync through İYS’s İzin Hareketi Sorgulama (Pull) endpoint; the ones that come back as RET are moved to the Listmonk blocklist.

So the answer to “how do we remove someone who unsubscribed from İYS” is step 3 of that chain: Listmonk webhook → Inngest event → an İYS RET call, with an iys_request_id added to every request for idempotency and written to the audit log.

Legal responsibility always stays with the merchant. Infrastructure does not make you compliant, it helps you be compliant. Underlining that distinction matters.

On the GDPR side an EU data location (Frankfurt, Amsterdam and similar) can be chosen, and the number of sub-processors is kept to a minimum. That also keeps the DPA short and auditable.

The Agency Model: Running the Pipeline With Minimum Liability

The software stack stays the same, but the distribution of ownership and legal responsibility is set up differently in the agency scenario. The design goal is clear: the agency takes on only the technical orchestration, without stepping into the integrator or intermediary service provider role.

The İYS account belongs to the merchant. Each merchant makes their own İYS registration, and enters their İYS code, brand code and API credential into the panel themselves. That credential is held in a vault belonging to the merchant (encrypted at rest); the agency makes API calls through it, but the İYS counterpart, the application load and the regulatory responsibility stay with the merchant. The agency has no İYS account of its own and does not have to appear on the integrator or intermediary service provider list.

Isolation per tenant. Each merchant is a separate tenant, with their own İYS code, brand code, sender domain (Resend domain auth with separate SPF/DKIM/DMARC per merchant), KVKK disclosure text link and Listmonk list ID. A single Inngest + Listmonk + Resend stack runs; the configuration is resolved per merchant. This structure does not need re-founding when you start with 1 merchant and grow to 10-20.

The split of legal roles. The merchant stays the data controller (it is their own customers’ data); the agency runs the pipeline as a data processor. The contract between them (parallel to KVKK 11/3 and GDPR Article 28) should make clear the purpose of processing, the duration, the sub-processor list (Listmonk host, Resend, server provider), the deletion procedure and the scope of credential access. The party appearing as the sender in İYS is the merchant itself.

Form copy is tenant-aware. The consent text names the merchant’s own legal entity: “commercial electronic messages to be sent by X A.Ş.”. Otherwise the sender becomes ambiguous in the İYS record. The disclosure text link points to the merchant’s own page as well.

The integrator / intermediary service provider line. Positioning the agency in İYS as an “integrator” or an “intermediary service provider” is a different and heavier step; it adds an application, a contract load and audit responsibility. In small-scale operations, staying on this side of that line is a deliberate choice: the pipeline is positioned as a technical component making calls through the merchant’s credential, not as a separate legal role.

When Not Taking This Route Is the Better Call

  • Fewer than 500 subscribers. The maintenance load does not produce value at that volume. In-platform automation or a simple Brevo subscription is enough.
  • Neither technical capacity nor budget. Start with a hosted SaaS; reevaluate when scale arrives.
  • Purely marketing-driven, focused on A/B testing. Klaviyo plus a good agency gets to that goal faster.
  • There is a “I want to control everything” feeling but the real need has not taken shape yet. If the maintenance load is not answering a real pain, it is a waste of time.

The decision is not “vendor independent or hosted”, it is the answer to “which pain am I living with right now”.

Conclusion

In ecommerce email automation the right answer depends on the store’s pain map. If the Klaviyo bill bothers you, if behavioural rules keep getting stuck at the vendor, if a platform migration is on the agenda, if the KVKK/İYS paperwork load is getting heavier, if multi-platform management from one panel is wanted, then a vendor-independent behavioural pipeline is a real alternative. Otherwise, carrying on with in-platform automation or a hosted SaaS is the better call.

For the technical architecture, code examples and operational detail of the setup in this post, there is a separate piece on the transactional email pipeline with Inngest, Listmonk and Resend, currently Turkish-only. For the self-hosted Listmonk install, the Listmonk + Resend on Coolify guide is the starting point.

An email pipeline built for your store

Behavioural email pipeline setup for ecommerce platforms such as Shopify, İkas, Ticimax, T-Soft and IdeaSoft, the İYS bridge, KVKK-compliant infrastructure and platform migration.

See the Service
What's inside
  • Vendor-independent behavioural pipeline setup
  • İYS consent filing, lookup, rejection and delta sync bridge
  • Multi-tenant setup for agencies, isolation per merchant
  • Platform migration and subscriber state transfer
  • Unified multi-platform management (Shopify + İkas + Ticimax + others)

References

Footnotes

  1. For Klaviyo’s 2025 pricing change and the “contactable profile” definition, omnidigitalgroup.com and retainful.com/blog/klaviyo-pricing give the detail.
Key Takeaways
  • 01 The real dividing line in email automation is not the feature list, it is the trio of data ownership, behavioural flexibility and cost control.
  • 02 Hosted SaaS solutions (Klaviyo first among them) struggle to give two of that trio at once: either the data stays with the vendor, or you are stuck inside a rule set, or the bill grows with the contact count.
  • 03 In-platform automation (Shopify Flow, İkas, Ticimax cart reminders) is free or included, but the behavioural scope is narrow and there is no multi-platform consolidation.
  • 04 A vendor-independent pipeline brings an extra maintenance load. Below 500 subscribers, with a simple set of needs, it is too much.
  • 05 For stores changing platform, the 'the data is yours' approach is a critical advantage: subscriber state, segments and history can move to the new platform instead of staying locked to a vendor.
  • 06 İYS compliance is not a one-way 'lookup'; it is a two-way sync in which consent has to be filed, rejections recorded, and changes made on the İYS side written back into Listmonk. The pipeline sets that sync up as a separate step.
  • 07 The agency model: an agency can run the pipeline as a data processor for merchants who remain the data controller; each merchant is isolated with its own İYS code, brand code and sender domain.
Frequently Asked Questions (FAQ)
+ Is it possible to move data out of Klaviyo?

The subscriber list, custom properties and the suppression list can be moved. Segment definitions and automation flows are rebuilt manually. Open and click history moves only partly; starting a fresh event log of your own in the new pipeline turns out to be more manageable in the medium term.

+ How hard is İYS compliance?

Building the bridge is a one-off job; the process itself is two-way. At the moment of sign-up the consent is written to İYS as 'ONAY' (HS_WEB source, with IP and timestamp recorded), and when the user leaves the newsletter the same endpoint is called with 'RET'. In the other direction a daily delta lookup runs (İzin Hareketi); subscribers the merchant marked as rejected in the İYS portal are written into Listmonk as a blocklist. Legal responsibility stays with the merchant; the infrastructure automates the proof and the sync.

+ What does it actually cost to run?

A self-hosted server (€20-30/month) + an email delivery provider (Resend or similar, $20-90/month) + management. The total sits in the €100-300/month band, depending on volume. As you move toward 25K subscribers, the cost gap against hosted SaaS becomes clear.

+ Which ecommerce platform does it work with?

Any platform that emits webhooks: Shopify, İkas, Ticimax, T-Soft, IdeaSoft and custom/headless setups. Multi-platform consolidation is a natural advantage of this approach; the same pipeline can run several stores from one panel.

+ Who writes the behavioural rules?

They are defined on the DNOMIA side, or through the scenarios the merchant asks for. There is no vendor lock-in, and your own technical team can edit them later. The rules live in attribute and event definitions rather than in code, which is why a change is quick.

+ As an agency, can I offer the same pipeline to several merchants?

Yes, but without stepping into the 'integrator' role. The pipeline is set up multi-tenant: each merchant opens their own İYS account and enters their İYS code, brand code and API credential into the panel themselves. The agency runs the technical controls (filing consent, lookups, writing rejections, delta sync) through that credential; the sender identity, the İYS application load and the legal counterpart stay with the merchant. The merchant is the data controller, the agency the data processor. Positioning the agency in İYS as an 'intermediary service provider' or 'integrator' is a separate and heavier step; in small-scale operations it makes sense to avoid it.

Feedback

Share your thoughts on the selected paragraphs. Email is required so I can reply.

Type