5 ms·
I read the initial post when it was trending on HN, and had previously noticed that line in Stripe's Privacy Policy. I remember checking immediately afterward t
by tompic823 6y ago
I read the initial post when it was trending on HN, and had previously noticed that line in Stripe's Privacy Policy. I remember checking immediately afterward that my company was only loading Stripe's js on our billing page. I'm a skeptic by nature, so even after reading pc's response I still didn't feel great.
Then I got to reading this new post:
> Amid the discussion on Hacker News, a user expressed concern that, despite Stripe’s current good intentions, user data could fall into the wrong hands in the event that another company purchased Stripe ... Perhaps in direct response to that exchange, the new privacy policy includes this clause:
> > Any other entity which buys us or part of our business will have the right to continue to use your Personal Data, but only in the manner set out in this Privacy Policy unless you agree otherwise.
This is fantastic. I've yet to see a requirement such as this in any Privacy Policy I've read. In fact, I hadn't even considered the possibility of such cleverness. This is now my new gold standard for the company sale terms of any practical privacy policy. I'm going to look into updating my company's privacy policy to reflect this language.
- barbegal 6y ago> Any other entity which buys us or part of our business will have the right to continue to use your Personal Data, but only in the manner set out in this Privacy Policy unless you agree otherwise. I thought this was implied in any contract. A change of owner doesn't mean the terms of the contract stop being applied.
- saagarjha 6y agoOften contracts will include verbiage like “we may alter this at any time without notice and also if we are acquired we can give all our data”.
- barbegal 6y agoWhich may be deemed a "deceptive business practice" [1] [1] https://www.freeprivacypolicy.com/blog/update-notices-changes-privacy-policy/ https://www.freeprivacypolicy.com/blog/update-notices-change...
- tompic823 6y agoI can't speak to the implication, but I've yet to read a policy that didn't explicitly outline how it handles business transfers. Some examples from different industries (the first 3 random sites I thought of): AirBnB [0] > If Airbnb undertakes or is involved in any merger, acquisition, reorganization, sale of assets, bankruptcy, or insolvency event, then we may sell, transfer or share some or all of our assets, including your information in connection with such transaction or in contemplation of such transaction (e.g., due diligence). In this event, we will notify you before your personal information is transferred and becomes subject to a different privacy policy. Segment [1] > We may sell, transfer or otherwise share some or all of our business or assets, including your personal information, in connection with a business deal (or potential business deal) such as a merger, consolidation, acquisition, reorganization or sale of assets, or in the event of bankruptcy, in which case we will make reasonable efforts to require the recipient to honor this Privacy Policy. Repl.it [2] > We share or disclose information only in the following cases ... - As necessary in the event of a proposed or actual reorganization, merger, sale, joint venture, assignment, transfer, financing, or other disposition of all or any portion of our business, assets, or stock. [0] https://www.airbnb.com/terms/privacy_policy https://www.airbnb.com/terms/privacy_policy [1] https://segment.com/legal/privacy/ https://segment.com/legal/privacy/ [2] https://repl.it/site/privacy https://repl.it/site/privacy
- luckylion 6y agoThose are about your data as a customer though. It's obvious that if a company is acquired, the new owner also takes the customer list, and active customers have very different rights regarding data protection than the customer's customers that visit their website and do not know that data is being collected about them. If e.g. Google would sell Google Analytics to Facebook, they cannot use the Analytics data to track users and send them emails, since it wasn't originally agreed upon with the GA-users. They very much can send an email to every GA user and offer them the new FBGA premium service.
- deleted 6y ago[deleted]
- jborichevskiy 6y agoIt’s insane to think we’ve a accepted a world where this isn’t the default. Good on them, hope to see more of this everywhere.
- barrkel 6y agoIME companies change privacy policy seemingly on a whim, and present current users with an interstitial next time they try and log in, gating the immediate gratification of use of the service with a big green OK button, virtually guaranteeing acceptance. It would be much harder for Stripe to do that transitively, though, and presumably the vendors, i.e. Stripe's customers, can't grant this on users' behalf.