4 ms·
Our policies got much longer with GDPR. We only collect information for legitimate reasons (i.e we need it for the service they are using), we ask for it, and
by sontek 8y ago
Our policies got much longer with GDPR. We only collect information for legitimate reasons (i.e we need it for the service they are using), we ask for it, and we never target it / sell the data. It helps that our customers are paying customers and not using a free service.
So our TOS used to be quite simple in plain english that all the data we request is only for the purpose of providing the service.
Now we had to outline all the information we collection (even though they are the ones who provide it, so they know what we collect) and outline all our services we use where that data we collect ends up (AWS, Sentry, Loggly, etc... the services we need to run our system and support them). Most of our clients have no idea what any of the information we added is because its all technical details about how we are providing the service to them.
GDPR required us to do a lot of work that ended up costing us time and money and literally nothing changed because we were already making sure we protected our users privacy.
Hopefully some bad actors get hit but for now GDPR has left a bad impression on me.