3 ms·
I don't have a lot of time to comment to this, unfortunately, because I think it is a really important discussion. However, whenever I see these issues arise on
by mdlman 6y ago
I don't have a lot of time to comment to this, unfortunately, because I think it is a really important discussion. However, whenever I see these issues arise on Hacker News, I rarely see much said in defense of Terms of Service and Privacy Policies. Speaking only about Terms of Service right now, the problem is that if things are not laid out at the beginning, the business takes on all liability (or at least runs the serious risk of that liability). While that may sound reasonable initially, that means that nearly all of the amazing services we have would be impossible from a business perspective.
The problem is, we have an extremely litigious society, and lawyers are asked to think through and address all of the risks. The lower the dollar amount, the lower the liability that a company can reasonably take for the transaction.
Do you want to have an account? Great, but we need to be clear about who is responsible for use of the account and its credentials. We also need to clarify when it can be suspended or terminated. Do you want to submit content? Cool, but we should confirm that what you submit is your own responsibility, and we need to add some language about ownership and licensing to avoid copyright and other IP issues. We should also confirm that certain types of activities are not OK (e.g., pornography, harassment). Do you want to provide feedback? Awesome, but you cannot sue if it is used. Do you want to use APIs? Sweet, but there are things you can and cannot do so you don't break or abuse our system. Are you paying for things? We need to be clear how that works. And through it all, we need to have key provisions about warranties and limitations of liability so the business is not on the hook for millions when the account is worth $10.
And all this is for a simple service. There are countless ways to add complexity to a service.
I still agree with a ton of points here about the dangers of one-sided agreements, limited options for services, complex legalese, etc. But I will say that this is a trickier issue than people seem to give it credit. It may be nonsensical to say that a consumer read and understood a contract, but it is also nonsensical to say that companies should risk bankruptcy for free or cheap services (unless we are OK with free or cheap services no longer existing).
- Wowfunhappy 6y agoYou sound like you know a lot about this, and I'm basically a layperson, so please excuse me for asking what are possibly stupid questions--but I still feel like I have to ask them. > Great, but we need to be clear about who is responsible for use of the account and its credentials. We also need to clarify when it can be suspended or terminated. Do we, though? I purchased a membership at an ice skating rink last winter, which gave me unlimited entry and access to a private locker. I didn't sign a contract[1]. Is my skating membership any different than an online account, and if not, why are contracts only seen as necessary in the digital realm? > we need to add some language about ownership and licensing to avoid copyright and other IP issues. Isn't this stuff laid out in Section 503--the service provider isn't responsible for what their users upload, as long as they take action when they're informed of a violation, or some such? If that's US law, why does it need to get restated in the Tos? > Do you want to provide feedback? Awesome, but you cannot sue if it is used. I'm not sure what "if it is used" means, but if, say, someone goes ahead and reuses my review in promotional material without my knowing consent, I think I should be able to sue! That's exactly the problem with agreeing to a contract you don't realistically have the ability to read. > Do you want to use APIs? Sweet, but there are things you can and cannot do so you don't break or abuse our system. If someone is abusing your API by, e.g. making too many requests, you should cut them off--why do you need a contract for that? If it's a private API for businesses, I actually think a ToS is fine. Professionals can reasonably be expected to read business-critical contracts. --- As I acknowledged at the jump, these are probably dumb questions. But--and I'm trying to anticipate your answer here, so maybe it's off base to begin with--if the issue is that a Twitter spammer could sue Twitter for being banned, then we need broader legislation to address that, in a way that applies universally to all companies. Because, clearly you should be able to ban people who spam, contract or no contract. Although, since restaurants can kick me out for holding up pornographic posters, and I can enter a restaurant without signing a contract... I have to wonder, again, why this is really necessary. --- [1] I did need to sign a waver before stepping onto the rink, in which I acknowledged I might fall and injure myself. However, this wasn't related to my membership, and it was two paragraphs long.
- mdlman 6y agoNot stupid questions at all. I'm not entirely sure of the best way to answer this, as the internal quoting is getting messy. Here are my initial thoughts, though: In a perfect world, maybe we would not need contracts. Certainly not so many. For low risk and low volume agreements, like your skating rink membership, maybe a contract is not helpful. Although I would be interested to know what happens this winter if a pandemic means the skating rink shuts down. Should the rink reimburse customers who only got partial use out of their membership? There are statutory protections for service providers, but they do not cover everything. For example, they do not give the service provider recourse against the user for their bad actions. They also do not address the service provider's IP, nor do they address licenses from the user to the service provider. By "feedback," I meant suggestions for changes, like if you told Facebook about a new feature that you would like to see but then sued them if they built that feature. Or if you sent them an email they never saw but then they implemented the feature. I guess it boils down to three big points: 1. Litigation is nasty and expensive, even if you are totally in the right. It is expensive to go before a judge or jury to say "This user did awful things, so I banned them and did not provide a refund. Here's what they did and why we kept their money." It is much cheaper to cut it off early with a motion to dismiss or motion for summary judgment by saying "This person violated Section 7 of the TOS, so I terminated in accordance with Section 8." 2. Lawyers are hired to look out for their clients' interests. It is their duty to their client, and they can be sued for malpractice if they do not. We generally agree that this is a good thing, I think. But it is a risk to the lawyer, not just the business, if the lawyer leaves a lot of issues open. 3. Your point about legislation is interesting. However, you could approach from the other direction as well, and have legislation that says certain liability cannot be limited or certain actions cannot be taken by businesses regardless of contract. This is what we do now and arguably could/should do more, and it has the added benefit of not making lawyers act out of their clients' interests. I don't expect this to be very satisfying, but hopefully it at least puts this all in a bit of context.
- monadic2 6y ago> While that may sound reasonable initially, that means that nearly all of the amazing services we have would be impossible from a business perspective. Is that not the point of pursuing this train of thought? You aren't going to get businesses that have honest transactions with customers when such dishonest practices are allowed and generate enormous profits.
- mdlman 6y agoYou can certainly be of the opinion that these contracts are by definition dishonest, and there are definitely companies that do shady things and protect themselves with these types of contracts. But I think that there have to be at least some examples of services that are honest that still need these types of protections. Imagine a service that is objectively good -- maybe a non-profit organization creates a free app to help connect homeless people with food, shelter, and potential employment opportunities. Businesses can then use the app to post jobs, etc. The non-profit runs on a shoe-string budget and certainly cannot afford to get caught up in litigation related to issues arising between users of the app (e.g., a homeless user upset that they did not get a job because a bug in the app lost their application, or a business upset because they were connected with a dishonest applicant). It seems fair that the non-profit should be able to limit its liability here. You have a really good point about deceptive businesses and the importance of transparency and balancing the power between businesses and consumers. It is bad that shady businesses can be protected by contracts, but those contracts also protect good businesses. I honestly do not know what the solution is, but I personally think that eliminating contracts is less useful than strong consumer protection legislation like stronger privacy laws.
- monadic2 6y ago> Imagine a service that is objectively good -- maybe a non-profit organization creates a free app to help connect homeless people with food, shelter, and potential employment opportunities. Businesses can then use the app to post jobs, etc. The non-profit runs on a shoe-string budget and certainly cannot afford to get caught up in litigation related to issues arising between users of the app (e.g., a homeless user upset that they did not get a job because a bug in the app lost their application, or a business upset because they were connected with a dishonest applicant). It seems fair that the non-profit should be able to limit its liability here. Certainly they should be liable for their service—of course they should be! You can’t expect a non-profit to do the government’s job, and certainly not without public (by which I mean via tax or capital) funding. Regardless of non-profits, it’s a complete perversion of the very idea of “consent” to refer the users of the internet as consenting to any ads or data mining. There is no transaction to access the service, no way to view the true cost of the service or how much derived value your data has, no way to simply pay for the service with what the ad clients would have paid for the ad slots. In my book that’s completely dishonest. IMHO the onus is entirely on the company to explain and allow transparency into their monetization. If not, there’s nothing distinguishing what people might call “evil” behavior from what is apparently a competitive edge in the market, a “good” in America if I’ve ever heard it.