Once a user starts a session (or logs in, for a registered user, to associate over multiple sessions), their specific page views are followed. The data can then be used in a number of ways from targeted advertisements to email updates to often-visited sections of the site.
Would this be wrong, as long as this was noted in the Privacy Policy and such?
There are certainly legal and moral ways to do something like this. However, I think that the biggest issue with something like this is more of a marketing issue.
There’s a fine but important line between something like Google’s targeted text ads (which I don’t find intrusive) and things like popups, animated banner ads, etc. Similarly, there’s not too big a difference between very targeted email updates (e.g., a ‘Please email me if this page is updated’ box) and spammy updates (e.g., ‘You’ve used our site and we added this feature you may or may not care about!’)
If you use the data you collect on customers/visitors sparingly and tactfully (especially making as much of it opt-in as possible), it should probably be fine and you won’t annoy your potential repeat visitors.