On top of that, it's further identifying them as both Chase CC holders and receptive to scams, qualifying them as leads for further phishing/scamming.
On top of that, it's further identifying them as both Chase CC holders and receptive to scams, qualifying them as leads for further phishing/scamming.
https://www.pcicomplianceguide.org/faq/#4
Disclaimer: I work in governance/risk/compliance, but have not performed PCI compliance work in the last several years.
In terms of what users are taught (which is plainly the context of the comment you are replying to), this website is identical to ecommerce sites.
But you don't just let them download it. You make them give you their email address first.
Edit: Haha! No wait, you have to click through two levels of "Don't want to give us your info? Click here to get the letter". The first one asks for you email, only after the second do you actually get the letter. Why? They already said "dont want to...". Just give it to them!
Edit2: Also the form letter, prepopulated with the Chase customer service P.O. box address, is another scam pitfall. Anyone using this kind of form letter should always check the address with the financial institution before sending any forms, especially that include PII/financial information.
They're pretty clearly trying to collect email addresses through this campaign. I'm okay with that. My email address isn't exactly private, and this site is going to pay to mail physical letters for me.
> Also the form letter, prepopulated with the Chase customer service P.O. box address, is another scam pitfall. Anyone using this kind of form letter should always check the address with the financial institution before sending any forms, especially that include PII/financial information.
Is the address fradulent? If so, please tell us. If not, I don’t see the concern.
really? No concern downloading a form letter from some web site and mailing PII/account information to the address they provided? Call me paranoid, but that kind of behavior is just waiting to run into a scam.
My point was not about the address, it was about general wariness of scams. No different than always calling your financial institution using a valid/known number, rather than a number provided to you by a voicemail/email/letter.
If I don't use this website, there is a 100% chance I will "agree" to binding arbitration. I know myself. There is absolutely no way I am going to print, fill out, and mail in a paper form.
Is this website a perfect solution? No, but I don't see a better option under the circumstances, and from what I can tell, the people running it are doing the right things within the confines of what is necessary for their solution to work.
If that's not the case, criticize away, and certainly let us know if you have a clear reason to believe this specific project is a scam. But keep the goal in mind. It certainly set off some alarm bells for me, but when I read through the site it all made sense.
Tomorrow, an enterprising scammer might clone the site to chaseoptoutservice.com, and do all the nefarious things mentioned above, and they'll be neck-and-neck in SEO.
If the response is to attack the legit version, then Chase wins! That's not an acceptable outcome either.
It's a false dichotomy to say its either this web site or Chase wins.
Promoting risky and insecure behavior is just wrong. period. That's independent of whatever Chase or any other company is putting in their agreements.
I think you'd be helping people far more by pointing out all the problems with this kind of website, so they can be aware of the risks and hopefully avoid scams, rather than getting them out of binding arbitration clauses.
But it's not! No one is going to mail in a form. Chase specifically chose that go that route because they know nobody nobody is going to mail in a form. The only way to get around this is to make the process easier. How else do you do that?
It strikes me as a very shortsighted to say "this behavior is wrong in all circumstances, period," while ignoring the benefits. Everything in life is some kind of risk trade-off.
Edit: I suppose your larger point is, the potential harm of this project greatly outweighs any potential good. I can respect that, but I'd really encourage you to research how messed up binding arbitration agreements are, particularly with regards to institutions like a bank.
I would say that more broadly speaking the harm of arbitration agreements is solvable in other ways, such as government or advocacy actions. I'm guessing that's what led to this letter/form in the first place: some regulator, or litigation resulted in Chase having to provide an "opt out", and they fulfilled their requirement by making it a mail-in form to discourage opt-out. If the harm persists then consumer advocates, elected representatives, and regulators can take another crack at it.
Educating people to be wary and careful with personal information is trickier. It's hard enough to spot a very well crafted spear-phishing attack, even when you know better and are generally vigilante. I don't know how else to deal with that except hyper-vigilance, and yes "this behavior is wrong in all circumstances, period," But again, I guess I'm weighing that risk higher than you are.
Yeah. That got me a bit irritated. Here's the form without having to give any info : https://www.chaseoptout.com/ChaseOptOut.pdf
But they also do B!
Doesn’t matter. A is bad.
People who order stamps online?
If the problem is writing the letter or stamps, then why not just send the user a postage-paid envelope, pre-addressed to Chase, with a generic letter that she can fill in with her personal information and deposit into the mail?
You should now be wondering how this "service" can be "free". As someone else has figured out, this is a company that wants lists of Chase customers to which they can market their consumer arbitration-related services.
This is interesting since the whole point of opting out here is that consumers want to avoid arbitration and reserve their rights to sue.
Other websites are offering a more sensible solution for those who cannot be bothered to write a letter: templates for a simple letter a customer can just print out, fill in her information, sign and mail.
Everyone here fearmongering this site is the enemy of good enough. Your credit card information is no more at risk than at a gas pump that possibly has a skimmer (and you’re not liable). Your PII has already been leaked by Equifax. Why give up even more rights by not opting out through a service that has taken reasonable precautionary measures for data protection?
It seems to me that it's pretty flimsy? In particular:
> To conduct research and to improve and promote our services . We use the information wecollect to conduct research and to improve or enhance and promote our Services.
Both promotion and research are pretty damn broad terms, right?
The fact that your privacy policy's fine print allows you to use the information for something other than the express purpose at hand seriously undermines that, even if you have no actual intentions of doing anything shady.
Personally, I'm very much okay with the exchange in this case, particularly given the cost of mailing physical letters.
They literally ask for their customers to pick up the phone from unknown numbers and give your bank details.
Idk but I only have Chase through Amazon. Chase might get effed, but my Amazon account will probably always be fine.