3 ms·
"* Unlimited number of lincences" Also, your privacy policy makes no mention of what data is included with validation requests, and what you do with that infor
by TheGrumpyBrit 8y ago
"* Unlimited number of lincences"
Also, your privacy policy makes no mention of what data is included with validation requests, and what you do with that information. GDPR is still very fresh, and if my app is passing every URL data to a third party, that sounds like it could be a problem.
- frits1993 8y agoThanks, fixed the typo. I'll include a section in the privacy policy on what's sent in the request, which is just the application UUID and the licence key. Our service then uses the origin of the request to determine the domain.
- teraflop 8y ago> I'll include a section in the privacy policy on what's sent in the request, which is just the application UUID and the licence key. And the complete URL of the originating page, as the parent commenter mentioned.
- teraflop 8y agoI just noticed this text in the FAQ: > Whenever we receive a validation request and grant access, we create a fingerprint of the page from which the validation was requested. Then, when we deny access to a page which did not provide a (valid) application uuid, we try to match the fingerprint of that page with one of the ones we indexed. This means that in many cases, we will still be able to notify you about invalid use of your application. Does this mean that your service is collecting not just URLs, but page contents as well?