1. There is an opportunity.
2. You did lose a lot of trust.
3. You didn't have enough trust in the first place to really take advantage of this opportunity.
I would encourage you to think about how you can earn that trust. This comes back to transparency and checks-and-balances. If you want to go that route, you will need to build hard constraints: legal and technological constraints which would have prevented this in the first place which you can't later remove.
This shouldn't have been down the bad judgement by the CEO. I don't know you, but even if I did, the Board can toss you ought next month, and the next CEO might have worse judgement.
Baseline: Right now, your privacy policy is not bad. However, you can change it anytime. You can eliminate it in the case of sale. Etc. You're paying a lot in trust right now for abstract flexibility down-the-line. I would not give you a model of what I know with that privacy policy, and to get to your vision, you'd need my data.
Good: Think through how organizations engineer legal constraint (GPL, AGPL, CC-BY-SA, etc.) to build community and trust. Engage folks like Eben Moglen and Larry Lessig, and come up with robust ways where Triplebyte can be trusted to manage user data, without needing to trust the Triplebyte management team.
Your team has a fiduciary duty to maximize shareholder value. Down the line, you might become Google (which has a trillion dollars to lose if it breaks trust) or you might become Yahoo (which is now mining personal emails in really evil ways, since that's the most effective way to scrape out the last little bits of profit). I want to know that if you go the route of Yahoo, or other companies I trusted with my data which went south, you won't be able to weasel out.
You should figure problems like:
* What happens if you do have a problem? If my data leaks, will you be liable, or do I bear that cost? If you are, that sets up incentives for you to have proper security. Consider it a cost of business (you can get insurance too).
* How can I verify what happened to my data, as you send it off to partners and "trusted" affiliates?
* How do I know my data was properly de-identified (I don't believe this at all, at this point).
If you can build something really robust, it will go a long ways to making you into a Google, by ensuring you won't turn into a Yahoo. It's a trillion-dollar opportunity.
I would encourage you to not go it alone.
1) There are people who have been thinking about this problem long and hard for a long time. Most are pretty accessible, and would be excited to see something strong here. There's a big pool of knowledge to build on.
2) You don't need to have something finished or polished to start to engage with either those people or with the community. You can toss out an early draft and solicit feedback if you're on the right track (rather than tossing out a fait accompli). You can even just solicit ideas.
1. Versioning of user consent.
A lot of services have been designed around the idea that once a user consents to the terms, they consent to any alternations you make in the future. This is legally very questionable, at least in many countries. Some services manage to keep track of the version of the agreement a user has approved, but then force agreement with any updated version. But in reality there's no need for this - users should be able to granularly consent (and withdraw consent) to different things, as and when it's desired.
In any case given the way this is interpreted in GDPR, and the direction of travel in California and other states, having granular consent seems to be a sensible short term investment to save a lot of pain down the line.
2. Handling data at a sale, acquisition or liquidation.
This one is more tricky, and I believe a Stripe co-founder mentioned this recently on HN as something to look into. Lots of companies see their database as an asset to sell. There's an interesting history of companies like RadioShack, ToysRUs, and others going through this issue and ending up in court over it...
3. Aligning your goals with your users.
It might be a bit idealistic, but it always seems to me that privacy works best when everyone's interests are aligned. I'm not sure how this fits for your situation, but it strikes me users wanting visibility get visibility, and if they get a job you'll benefit, as do they. That seems nicely aligned. And for people who want to be incognito, they remain incognito, but they know you're there. It's probably counter to lots of the "startup playbook", but even these incognito users are likely still valuable, maybe even net promoters, just not currently looking to be seen. So it seems your goals align nicely with users', and there need not be any hyper growth "dark patterns".
If you want to build a LinkedIn competitor it should be a completely different product to what you offer now with private employer<->employee hookups.
The two services should be physically separate in every sense, so there's no possibility of someone flipping a bit and accidentally making public someones private job search intentions.
Please don't comment about the voting on comments. It never does any good, and it makes boring reading.
Please don't post comments saying that HN is turning into Reddit. It's a semi-noob illusion, as old as the hills.
That’s actually not true.
Also, your comment comes off as needlessly offensive:
> 3. You didn't have enough trust in the first place to really take advantage of this opportunity.
> I would encourage you to think about how you can earn that trust
You’re attacking him when he’s come back, owned up, and apologized for the mistake.
I'm also suggesting an alternative which I /think/ would have more privacy and more business value. I'm not an insider, so I could be wrong about either of those, but that's the point of a conversation. This way, he knows what would work for me, as a potential user. He can take it and run with it, take it as a problem statement and run with a different solution, or take me as 0.0001% of the market and ignore it. In his shoes, I've done all three at different times.
> That’s actually not true.
@woofie11, you should internalise this.
What the board has a duty to do is enact the desires of shareholders as they have made those desires clear. If the shareholders want to sacrifice profitability for some other goal, that's fine, normal, expected, and ordinary.
There is no fiduciary duty to maximise shareholder value.
Obviously negligence, fraud, and other possibly criminal or immoral behaviour that reduces or ruins shareholder value can certainly be a problem, but that's a separate issue.
Haters gonna hate and I wouldn’t take it too seriously.
Because you opted in to creating those profiles and the information they contain, and made them public. You opted in.
I’ve always found Triplebyte open and insightful and their response shows they’re receptive to feedback, which is a rare thing these days. People should be respecting that instead of crucifying one of the only companies that actually listens to them. No company is perfect all the time.
The CEO's whole attitude towards privacy shows how they treat privacy, and no, I'm not going to "respect" that.
The analogy with dating services that people were bringing up earlier was a good one. Sure, some people are in open relationships, which is fine, but if Tinder were to assume that everybody was OK with having that aspect of their personal life exposed in public, it would be a massive problem.
Even in the midst of a shitstorm where the CEO/Founder is publicly admitting to a complete lack of insight?
I'm only commenting now to cancel out your anecdote.
(And FWIW, I would have done nothing had it been opt-in. I would have been happy to leave my information private and strategically take it public when it suited me. The email, and Ammon's behavior in the original thread gave me little confidence that was an option, so I nuked my data.)
1) really pissed off about it
AND
2) compassionate enough to tell him why
The easier course of action, which I chose, was to quietly say "fuck you" and delete my profile. Ammon is getting a lot of valuable feedback right now. Yes, hatemail is valuable feedback. Because for every hatemail you get, there are ten users like me that will just bounce without a peep.
But, pushing features out the door is different than just deploying, so seems this is what happened. Then it doesn't matter what day you release your unfinished feature, it's gonna cause bad times.
The absolute most important part of the feature was a last-minute addition?
I don't buy it, and I'll be steering clear.
I still wonder why you tried the infamous "I'm sorry that you cannot understand" line here?
I don't mean to flog a dead horse, but you seem to be intent on digging a deeper and deeper hole.
It's not for you or anyone else to make someone's data public without their consent, because you think it helps them.
> and me to really hear what people were saying
Nobody should need to tell you any of this. If it truely did, then you clearly don't care a jot about privacy, and simply aren't responsible enough to manage other people's data.
A companies ethos and values cascade down from the top, so your attitude towards privacy is especially concerning.
I don't see this in any way as still digging the hole.
As for the rest of your comment, you seem purely to be repeating what he says he now knows. Although others have, I haven't downvoted you, but it feels like you're still being angry about what the situation was, and not trying to adapt to what this situation is.
I agree that there are still legitimate causes for concern, but it's worth taking time to think about what they really are.
I'm not still angry about what the situation was - I believe the only reason this feature was rolled back is because there was a big backlash. I really believe his whole attitude towards other people's data means he isn't responsible enough to store it.
It's exactly irresponsible moves like this that led to the GDPR in the first place (something else contravened by this feature)
I think it's also important to distinguish the idea from the execution. A LinkedIn alternative for developers is a great idea. The problem was the incredibly short opt-out (instead of opt-in) with notice given to users on Friday afternoon of a long holiday weekend.
I somewhat agree, in that the important thing for now is that he did eventually relent. But I'm not convinced he actually listened, so much as relented under pressure. I don't think those values bode well for the company going forward. I certainly hope I'm proved wrong on that.
I'm talking 20 million euros in fines
Second, you really think GDPR is going to be applied to some tiny American startup because they said they might do something and then didn’t?
Third, my understanding is that if you don’t target EU customers, GDPR doesn’t apply. It’s not enough that an EU customer happens to wander into your store. You have to have some accommodation targeting the EU (like translated pages, international shipping, different currencies, etc)
When the regulation does not apply
Your company is service provider based outside the EU. It provides services to customers outside the EU. Its clients can use its services when they travel to other countries, including within the EU. Provided your company doesn't specifically target its services at individuals in the EU, it is not subject to the rules of the GDPR.
Source: https://ec.europa.eu/info/law/law-topic/data-protection/refo...
Unfortunately, the real fines are nowhere near the theoretically possible ones.
This is egregious enough that it could have actually resulted in a fine as opposed to a "please don't do that", but realistically, I doubt the fine would get near 100k.
Best case scenario you spend the whole weekend focused on whether the release went right...
Worse you spend the whole weekend cleaning a mess up.
Its pretty much always a lose/ lose.
I said don't release on Friday.
No ones release process is perfect and the best time to find holes in it is when you are just ready to have the week be over so you can happy hour on a Friday.
In this case at least part of the release process that was broken was how it was communicated to users. Now they have to spend the whole weekend putting out this fire.
Why take the chance in a non emergency situation? Enjoy your weekend and do it with a fresh mind Monday morning.
You could also come up with incentives to encourage job seekers to opt in; for instance, you could temporarily tag such users as "likely to get hired sooner" in reports for prospective employers.
Lets start lying to the customers on top of this fiasco.
If @ammon had said, “this will be a great feature,” the devs would keep quiet because they either (1) don’t want to be fired, or (2) trust he knows better than them.
A business saw an opportunity to make more money and took it. A large portion of consumer interests no longer aligned with their interests and we were caught in the crossfire. Fortunately, enough people shared the same concern that the risk for the business (Triplebtye) was now high enough that they had to mitigate fallout.
That's all that happened and all that typically happens. Perhaps Triplebyte management didn't see the risk or misjudged the backlash and expected only a few users to complain. I find it hard to believe this side effect wasn't at least a considered risk brought to to table and ultimately ignored by management looking purely at growth.
Yes, sometimes a shift in a business's goals cease to align with our interests and isn't necessarily meant to be malignant move against us directly, but there is certainly no concern for us in the process unless it is ultimately perceived as more net profitable.
This is why we should be quite careful as to what we allow business ownership over/access to and remember that profit seeking cost optimizations are only useful to us while they're aligned with our interests. Whatever behaviors we allow businesses to pursue without enough repercussion to care, they will pursue seeking profit: a proverbial "cost of doing business."
When a business's profit seeking interests are misaligned with ours or run counter opposite to our interests, we're in for a fight against a resource heavy entity we're likely lose, especially when certain behaviors are allowed to normalize across entire industries and accepted by culture in large segments.