But you don't just let them download it. You make them give you their email address first.
Edit: Haha! No wait, you have to click through two levels of "Don't want to give us your info? Click here to get the letter". The first one asks for you email, only after the second do you actually get the letter. Why? They already said "dont want to...". Just give it to them!
Edit2: Also the form letter, prepopulated with the Chase customer service P.O. box address, is another scam pitfall. Anyone using this kind of form letter should always check the address with the financial institution before sending any forms, especially that include PII/financial information.
Yeah. That got me a bit irritated. Here's the form without having to give any info : https://www.chaseoptout.com/ChaseOptOut.pdf
They're pretty clearly trying to collect email addresses through this campaign. I'm okay with that. My email address isn't exactly private, and this site is going to pay to mail physical letters for me.
> Also the form letter, prepopulated with the Chase customer service P.O. box address, is another scam pitfall. Anyone using this kind of form letter should always check the address with the financial institution before sending any forms, especially that include PII/financial information.
Is the address fradulent? If so, please tell us. If not, I don’t see the concern.
really? No concern downloading a form letter from some web site and mailing PII/account information to the address they provided? Call me paranoid, but that kind of behavior is just waiting to run into a scam.
My point was not about the address, it was about general wariness of scams. No different than always calling your financial institution using a valid/known number, rather than a number provided to you by a voicemail/email/letter.
If I don't use this website, there is a 100% chance I will "agree" to binding arbitration. I know myself. There is absolutely no way I am going to print, fill out, and mail in a paper form.
Is this website a perfect solution? No, but I don't see a better option under the circumstances, and from what I can tell, the people running it are doing the right things within the confines of what is necessary for their solution to work.
If that's not the case, criticize away, and certainly let us know if you have a clear reason to believe this specific project is a scam. But keep the goal in mind. It certainly set off some alarm bells for me, but when I read through the site it all made sense.
Tomorrow, an enterprising scammer might clone the site to chaseoptoutservice.com, and do all the nefarious things mentioned above, and they'll be neck-and-neck in SEO.
If the response is to attack the legit version, then Chase wins! That's not an acceptable outcome either.
It's a false dichotomy to say its either this web site or Chase wins.
Promoting risky and insecure behavior is just wrong. period. That's independent of whatever Chase or any other company is putting in their agreements.
I think you'd be helping people far more by pointing out all the problems with this kind of website, so they can be aware of the risks and hopefully avoid scams, rather than getting them out of binding arbitration clauses.
But it's not! No one is going to mail in a form. Chase specifically chose that go that route because they know nobody nobody is going to mail in a form. The only way to get around this is to make the process easier. How else do you do that?
It strikes me as a very shortsighted to say "this behavior is wrong in all circumstances, period," while ignoring the benefits. Everything in life is some kind of risk trade-off.
Edit: I suppose your larger point is, the potential harm of this project greatly outweighs any potential good. I can respect that, but I'd really encourage you to research how messed up binding arbitration agreements are, particularly with regards to institutions like a bank.
I would say that more broadly speaking the harm of arbitration agreements is solvable in other ways, such as government or advocacy actions. I'm guessing that's what led to this letter/form in the first place: some regulator, or litigation resulted in Chase having to provide an "opt out", and they fulfilled their requirement by making it a mail-in form to discourage opt-out. If the harm persists then consumer advocates, elected representatives, and regulators can take another crack at it.
Educating people to be wary and careful with personal information is trickier. It's hard enough to spot a very well crafted spear-phishing attack, even when you know better and are generally vigilante. I don't know how else to deal with that except hyper-vigilance, and yes "this behavior is wrong in all circumstances, period," But again, I guess I'm weighing that risk higher than you are.
https://www.pcicomplianceguide.org/faq/#4
Disclaimer: I work in governance/risk/compliance, but have not performed PCI compliance work in the last several years.
In terms of what users are taught (which is plainly the context of the comment you are replying to), this website is identical to ecommerce sites.