4 ms·
Heya. I work for Heap (mentioned in the article). If anyone has questions for me. Let me know. Heap doesn’t sell or share data to third parties, we don’t do an
by codezero 7y ago
Heya. I work for Heap (mentioned in the article). If anyone has questions for me. Let me know.
Heap doesn’t sell or share data to third parties, we don’t do any cross site identifiers, or fingerprinting. We aren’t in the ad business, that’s Google and FB.
In other threads folks have said “but you can’t control what might be done with Heap data in the future” that’s right. I’m happy and pretty secure, and will fall on a sword if Heap ever becomes an unethical company.
(I’m commuting for the next hour but will get back to reply soon)
- saagarjha 7y ago> In other threads folks have said “but you can’t control what might be done with Heap data in the future” that’s right. I’m happy and pretty secure, and will fall on a sword if Heap ever becomes an unethical company. This doesn't help me one bit, though :/
- codezero 7y agoWhat would?
- jahlove 7y agonot being tracked.
- saagarjha 7y agoOr, specifically, my data not being stored in a place that I have no control over.
- codezero 7y agoMakes sense. I think that individuals are much more empowered to block tracking on the web than in other places (usually). Banks and credit card companies are massive sellers of personal and behavioral data, and the FCC rolled back consumer protections which prevented ISPs from selling your data - which is much more broad than just what sites you visit (think applications, DNS, TV watching behavior). Add the pervasive CCTV, mobile phone location selling by carriers, private companies recording license plates and selling the data about your physical whereabouts and patterns, and I agree we have a problem, and it’s less about whether you clicked a call to action and more about the normalization of pervasive surveillance. In the US we’re especially screwed because ISPs have largely blocked off competition that could offer privacy. Most analytics tools that aren’t coupled with ad networks aren’t trying to get around ad blocking extensions, even though it’s pretty easy to do. Like, surprisingly easy. Unethical companies are doing that and more - see the aggressive stance Apple has taken with ITP. They’re not reacting to general cookie sharing, but to companies that are attacking the browser’s storage mechanisms to expose data from other sites. Long story short, vote for privacy forward leaders if you live somewhere that allows you to. Laws like GDPR and the CCPA are moves in the right direction. Heap is already compliant with both and I hope more protections continue to make their way to the public. Edit: I know we are GDPR compliant and intend to be CCPA compliant but I’m not sure we are yet since it isn’t yet in effect.
- danShumway 7y agoAt the very least, a credible precommitment that Heap won't transfer data to other companies in the event of a merger, and that if Heap goes out of business that data will be destroyed. Here's what Heap's privacy policy says: > We may share or transfer your information in connection with a prospective or actual sale, merger, transfer or other reorganization of all or parts of our business. You're banking on Heap being an ethical company forever, yet your privacy policy basically gives you carte-blanch rights to sell my data to any other company in the event of a merger. Heap runs into tough times and Oracle/Google buys them out? Any privacy guarantee you make here is immediately out the window. You're asking people here to trust you, while your privacy policy explicitly states in legal language that you're allowed to stab us in the back. If you're not planning to stab us in the back, then why is that language necessary?
- codezero 7y agoThis is a great idea. I’m going to try to find if any other companies have language like you describe. I understand that you are assuming any acquisition will lead to some malicious or unethical intent, but I’m not so cynical, that said, it’s be nice to have some protections.
- saagarjha 7y agoFYI: many other companies do have this exact language in their privacy policy and treat their data as an asset during acquisition negotiations.
- zeeed 7y agoThe question the article raises is whether collecting user data, fingerprinting and cross-site tracking isn’t unethical in itself since it happens without the user’s express knowledge and consent