It's fine that OP bought a t-shirt, not fine that that is somehow reported to Facebook.
It would be nice if it were, or that they promised that they wouldn't just hand it out to everyone.
> If it bothers you, though, it does really work to a) periodically reset your IDFA/AdID on your mobile device, and b) delete cookies on your browsers.
How does this help in this case?
True, but that's not the expectation in play here. I think there is a general expectation that when you're doing business in a brick-and-mortar store, that store is not going to be reporting your business to the likes of Facebook, Google, etc.
"Some chat apps (like Viber and others) have Facebook SDK integrated in them, without any direct Facebook functionality people would use. Discovered after using NetgGuard, and seeing who is calling home, and not only home. (Why viber is making requests to graph.facebook.com anyway?)
Duolingo is a nice app for learning new languages, yet it might be using the same sdk, since it likes to call facebook.com domain.
Netflix is a good streaming service, but it has some option somewhere, which allows them to share data with others, and enabled by default. And yes, it's present in fb activity.
The list can go on...
There are developers who integrate dozens of SDKs, without any specific purpose for users, and not knowing what is happening. We need something like PrivacyBadger/ublockorigin for phones/laptops/routers/homes/cars. It's getting more than creepy.
And why would Facebook allow third-parties/businesses upload into FB info they have on their customers...
PS: analysis of how a simple menstrual tracking app is leaking data about the owner https://media.ccc.de/v/36c3-10693-no_body_s_business_but_min... "
For one app I worked on, we made a decision not to include Facebook or Google login and only support email/password login, specifically to avoid leaking information.
A subset of users was not pleased at all -- and they sure let us know about it. Maybe around a third of our support requests were asking for third-party sign-in. People often made privacy arguments in support of it: they'd say "why do I have to give you my email address to create an account?" (though usually much less politely). And they kind of had a point. You may trust yourself more than you trust Facebook, but most people are going to trust Facebook more than they trust [random developer].
Anyway, it takes a lot of effort to deal with these support requests, it sucks getting yelled at (even in text). Some of these users probably went on to give the app a 1-star rating, and just a small percentage of those will really drag down your overall score. Dealing with this was not fun. It would have been much easier to just add FB or Google login.
Sure I can. And I do. Developers are making these choices, after all. I understand the economic drive behind them, but that doesn't get the devs off the hook.
I have seen apps sending requests to facebook graph without using the login, or they don't have facebook login at all..
I haven't rated any apps based on this, though.
Edit: How they matched it up though is a mystery to me, as I use another e-mail address for FB than for the rest of the online world.
Firefox's Container system is a powerful solution to this general problem, but normally you need to do curation work proportional to the effort being taken to track you. Their Facebook Container though comes with that curation done.
If you use Login with Facebook (you want Privacy, but you choose to Login with Facebook? Maybe reconsider your life choices) the Container puts everything you logged into this way inside the Container too, so that dissolves your privacy but you chose to have it happen.
Yet some mobile apps still use heavy analytics which is sent to some domains, again, you need something like netguard, vpns, to filter your mobile traffic. Privacy becomes a pain https://media.ccc.de/v/35c3chaoswest-32-toll-of-personal-pri...