3 ms·
That barely readable grey-on-white text declaring this use of the data and the pre-checked "Opt in to email updates" checkbox hidden in an expandable element be
by Jon_Lowtek 5y ago
That barely readable grey-on-white text declaring this use of the data and the pre-checked "Opt in to email updates" checkbox hidden in an expandable element below the form is a dark pattern (1) and a red flag that this "petition portal" and the organization behind it does not care about the core element of data privacy: informed consent. (2)
There are some smaller red flags in the privacy statement and cookie notice. (3) ("As is standard practice on many websites, we may [use] ... tracking technologies") and "(We will only make Personal Information about users available to third parties as [...] permitted under the terms in place with our third-party partners."). Wow such data protection, much privacy ^^ very informed - not.
But it gets even worse, when one looks at the API (4,5). The gist of it: the data a user enters on this page can be seen by anyone responsible for the petition the user engages with - named "sponsors" or "partners" aka "paying clients". The red flag: "unsubscribing" does not delete the data or prevent it from being shared, it just sets a "please don't use this data" bit. At least the partners (hopefully) can only see their own engagements, not which other campaigns a user engaged with.
Looking at the business model (6) it is basically a newsletter service painted blue for ngos and political corporations: and - like many newsletter businesses - it is looking at CRM for features.
The big one however is the integration with BlueLink (7,8) as a message bus that allows their clients to share the user data with other cloud based systems. The red flag here is that the user does not seem to have any say in that: total lack of consent mechanics. The practical implication of the implementation: if you sign a petition the petitioner can use your contact data however they want. For comparison: in the EU this might be illegal.
I wonder: if a consumer/user requests their data, would they get details like "we sent you the A variant of this A/B tested newsletter for our partner xy and you clicked on the link to read more" or "partner foo tagged you as 'potential-volunteer' after you responded to an event invitation" or "partner bar send your data to service Z after you signed their petition"?
Honestly, for me this doesn't really look like a pro-privacy platform at all, which raises suspicion that this is a bait-and-switch and the true intention is harvesting contact data. But it is probably a radical opinion that privacy advocates must use privacy friendly tools for advocacy. Maybe this platform will change as well, if and when congress enacts laws as requested by the petition they host.
1: https://en.wikipedia.org/wiki/Dark_pattern https://en.wikipedia.org/wiki/Dark_pattern
2: https://en.wikipedia.org/wiki/Consent#Internet_and_digital_services https://en.wikipedia.org/wiki/Consent#Internet_and_digital_s...
3: https://actionnetwork.org/privacy https://actionnetwork.org/privacy
4: https://actionnetwork.org/docs/v2/people/ https://actionnetwork.org/docs/v2/people/
5: https://actionnetwork.org/docs/v2/delete/ https://actionnetwork.org/docs/v2/delete/
6: https://actionnetwork.org/partnerships https://actionnetwork.org/partnerships
7: https://help.actionnetwork.org/hc/en-us/search?query=bluelink https://help.actionnetwork.org/hc/en-us/search?query=bluelin...
8: https://bluelink.org/ https://bluelink.org/