7 ms·
I've seen that too. This API for example [0] called "email enrichment" where I got my full name back, based on email address. Edit: Added main company link pro
by tiimbz 8y ago
I've seen that too. This API for example [0] called "email enrichment" where I got my full name back, based on email address.
Edit: Added main company link providing this API [1]
[0] https://app.livestorm.co/api/v1/utils/email-enrichment/?email=emailaddresshere https://app.livestorm.co/api/v1/utils/email-enrichment/?emai...
[1] https://docs.enrich.email/ https://docs.enrich.email/
- kaoD 8y agoMy data is empty, even though I'm not that paranoid about privacy (but I do take some care). This specific API seems pretty innocuous. They're not doing black magic, it's just aggregating data that people willingly put out there about themselves. I'm sure I'm out there in many datasets with stolen (or just "shared") information.
- distances 8y ago> This specific API seems pretty innocuous. They're not doing black magic, it's just aggregating data that people willingly put out there about themselves. That's has always been illegal in my country though (you can't even keep a record of people with pen and paper), and now with GDPR would of course be illegal with actual consequences if it contains data about EU citizens.
- tomgp 8y ago>now with GDPR would of course be illegal with actual consequences if it contains data about EU citizens. which, as an EU citizen, I can confirm it does
- mises 8y agoRegardless, they're not based in Europe. Unless they do business in the EU, they can't touch them. This is due to the fact that extradition requires something to be a crime in both countries, so unless the EU has assets to seize, nothing they can do. And if they try, any American court will be very leery of setting the precedent that Brussels can tell Americans what to do in any sense, particularly with respect to data stored on their servers.
- GenericsMotors 8y agoPerhaps not directly, but if they're processing the information of EU data subjects on behalf of another company that does business in the EU, then that company will have to justify using this service, which is clearly not GDPR compliant. I imagine the company using them will want to recover financial losses they incur after getting reamed by whatever european Data Protection Authority decides to go after them - especially if the culprits did promote themselves as being GDPR compliant. The point of the EU's strong data protection rules is to have accountability - and it will fall on someone along the chain that caused the mess. Companies can't be allowed to completely disregard how they collect and store data and then go "Oops, haha sorry about that!" when the shit inevitably hits the fan, and just continue their business as usual.
- kuschku 8y agoActually (after contacting their support because of wrong data that was returned for my contact), they seem to be using https://clearbit.com/ https://clearbit.com/ instead as backend. enrich.email also does the same, though. There’s also https://fullcontact.com https://fullcontact.com. In the end they all just search and scrape social media profiles and gravatar.
- Kaotique 8y agoWhat surprised my is that when you go to https://clearbit.com/ https://clearbit.com/ at "Understand your customers" it actually showed our company logo. Probably based on Ip address because I'm at the office right now and cleared my cookies.
- FinestFine 8y agoI checked mine and it has only my full name. But "indexedAt" gives the current date and time, interesting :)
- megous 8y agoMine has information harvested (provided by?) from about.me. (I had a page there about my dancing activities) So this API tells anyone where and when they can meet me for a dance. (9 years ago, that is) :D
- giancarlostoro 8y agoMine only has whatever Gravatar had.
- tmaly 8y agoI am just waking up, is there a link to check if your email was part of this?
- gilles_bertaux 8y agoHi, Gilles here CEO of Livestorm. Thank you for surfacing this. What is this URL: This is not a public API route, it is a proxy to a service called Clearbit to enrich professional emails with public company and person data from multiple public sources such as AngelList or LinkedIn (cf https://clearbit.com/enrichment https://clearbit.com/enrichment and https://clearbit.com/our-data https://clearbit.com/our-data). By using this route, you are using Clearbit with our credentials. Most importantly, we don’t store any data on our end when accessing this route. We don't own this data, it is stored on Clearbit servers. Why are we using them: We entered in business with Clearbit to help our users get more insights on their webinar sign ups from public data sources. Are they GDPR ready: Clearbit is GDPR compliant (cf https://clearbit.com/gdpr https://clearbit.com/gdpr). You can claim your data here: https://claim.clearbit.com/claim https://claim.clearbit.com/claim. We took all the steps necessary with Clearbit to ensure our process was GDPR compliant. However, this information makes us double guess it. Therefore, we are revaluating the compliancy of this specific process and in the meantime, we have deactivated this route.
- secfirstmd 8y agoHang on a minute. Your GDPR compliance page is absolute crap. Ditto your Privacy policy. https://clearbit.com/privacy https://clearbit.com/privacy For starters: At what point does this site should that I have given consent for you to process my data? Who are the third parties that have given you my data?
- StavrosK 8y agoNot only that, but their "delete my data" button says "we've deleted your data" but it's still there when I revisit.
- gilles_bertaux 8y agoThat's Clearbit's page. Not Livestorm's. Again, this URL is a proxy to Clearbit's API :)