I was emailed after abandoning a registration form. I did not click Submit
dev.to
dev.to
Going to paraphrase the article a bit here but yes, the website is capturing the filled-in data even if the user hasn't hit the submit button. However, they're also running a tracking script from an advertisement network in the background that attempts to capture your e-mail. If you visit Site A as a result of one of the ads from that network, but leave without putting down your e-mail address, and then go to Site B and do leave your e-mail address, the ad network will send your e-mail address to Site A in an attempt to "re-capture" that lost impression for Site A even if you never even hit submit on Site B. They're marketing it as a way of reducing ad-spend because you don't have to keep trying to target potential customers who've already shown interest through more ads.
I'm not a lawyer so I'm very curious to know how this doesn't easily violate COPPA for Site A, Site B, and the ad network, among other privacy laws. The wording from the ad network shown in the article is a bit vague around enabling a "triggered email sequence", so I'm wondering if they get around some legal issues by sending emails for Site A on their behalf rather than sharing the email address itself.
* Edited for minor typos I noticed after hitting submit.
THIS IS A THIRD PARTY ADVERTISEMENT This email was sent to @gmail.com on 2020-05-16 23:06:22.669518 (UTC). If you no longer wish to receive Aeroflow Breastpumps communications via SafeOptⓇ, please unsubscribe here.
I can never figure out why people don't realize that even if it's legal, it comes across as creepy.
I sure hope that browser makers have patched that somehow but I still avoid auto-complete whenever possible.
Enter autocomplete completing hidden fields :/
If anyone at Mozilla is reading this, please fix this, it's incredibly obnoxious. I'd also appreciate it if you styled your master password prompt better than a javascript alert dialog so I know I'm typing in my most valuable password in the world into the browser and not some site pretending to be you.
Something like "fraudulent practise" or "criminal process" seems to capture the essence of the thing more accurately. I'm sure we can do better than those too.
Here, it is unlikely that a user who has yet to click 'submit' understands that merely entering data (but not submitting it) is actually submitting that data.
WHAT IF for the sake of argument, a user typed (but did not submit) data which could get them in trouble if shared? (defamatory or trade secret info are just two examples)
And again -- a court might find otherwise -- but this behavior as presented is absolutely not consensual.
That might sound horrible, and it is, but it's also entirely legal in many, many jurisdictions.
Now tell me how something that sounds like a colour scheme conveys the awfulness and ethical bankruptcy of the party who ordered it and the engineers who programmed it.
"Eh someone else would take money for doing something unspeakable if I didn't." Actually there's what you can live with and what you can't. Names kind of matter to convey meaning. Dark pattern is an abysmal failure.
Good point, but an important distinction here is that when two people are having a phone conversation both parties are knowingly participating.
If both people in a conversation know that the things that they are saying are being perceived by at least one other person their expectation of privacy regarding the things they say is necessarily limited. In some jurisdictions a person's belief that the conversation is strictly private and limited to just the two of them is a reasonable expectation but other jurisdictions disagree. Those other jurisdictions instead believe that there is no reasonable expectation of privacy by one party that the conversation will not be recorded by another party to that conversation.
And so - although a reasonable belief forms the outlines of the permission granted, not all jurisdictions agree as to what constitutes "reasonable". Some states have held that they don't think the permission granted protection against single-party-recording (because those states held that this specific expectation of privacy to not be reasonable) while other states think it does (because those other states thought this specific expectation of privacy was reasonable).
But this disagreement among jurisdictions is primarily about what constitutes one's "reasonable expectations of privacy" and highlights how the "reasonable" aspect changes based on context (for example, given the ubiquity of recording devices and their use by private parties you should expect that the two-party consent requirement for phone conversations will eventually go away; at some point it is no longer "reasonable" for somebody to think that the other party will not record the conversation --- and yes there are enormous implications here w/r/t government surveillance of its citizens; Kyllo is a good example: the govt used a thermal imaging device to identify a possible marijuana grow house and then get a warrant -- but because this thermal imaging device was not in general public use SCOTUS agreed that Kyllo had a reasonable expectation of privacy and the govt's actions constituted an unreasonable search, saying that "[t]o withdraw protection of this minimum expectation would be to permit police technology to erode the privacy guaranteed by the Fourth Amendment"(1)).
Importantly though these distinctions do not change how consent and its interplay with permission-granting operates.
Which brings us to the issue at hand:
What is the reasonable expectation of privacy that the general public has when typing info into a website form but never pressing 'submit'?
It is reasonable for a user to believe that if they do not press 'submit' then that info was never submitted (otherwise why have a 'submit' button?). If the user believes the unsubmitted-info remains private and if that user's expectation is considered reasonable then that means the website lacks permission to access the unsubmitted-info.
If the website then retrieves that unsubmitted-info it does so without the user's consent. If we allow otherwise then the users' otherwise "reasonable" expectation becomes unreasonable over time.
How about "scumbag site technique". Or "Shyster Design" Or viciously dishonest intent.
Arguing the semantics of whether it's /sometimes/ not actually fruadulent according to law or /sometimes/ not criminal because the law isn't there yet does not alter one itoa of the wild and deliberate dishonesty going on.
The intent is to deceive. Make excuses for it all you like knowing it doesn't change what this is but reveals something else.
So what is a beter name than "Dark Pattern" for this kind of intentionally dishonest and deceptive program?
I still vote criminal. I want the law to catch up with reality. if your corner store behaved like that they'd go to jail when caught for most of this vile crap.
But I guess a lot of people love those dark patterns for every silicon valley company to be using them. Probably grates to think of them for what they actually are.
The page thought I was hemming and hawing on whether to buy it and then offered a discount to help push me over the edge.
In many cases you have to fill out your address and email info before you can get to a shipping page to see shipping charges. In so many cases, even though I did not place an order or create an account, I am still sent an email saying that I have contents in my "shopping cart" and they are looking forward to "making me a satisfied customer".
Guessing all of the shops that implement Shopify automatically pick up the behaviour.
Nothing makes me want to shop with your company less than blatantly violating my trust before I'm even a customer.
They charged the card anyway (and did not send any product).
They got an earful from him.
I suspect their form was a piece of junk, but that doesn't sound particularly PCI-compliant, to me.
This ad-targeting, email-harvesting thing is really bad, though. It may not be illegal in most of the US (but I'll bet it is in some states), but I will lay odds that this company had better make sure they don't have any EU data mixed into their little bouillabaisse.
I wonder about this. I feel the same, but wonder if it's true for everyone? I kinda assume it must work some of the time, otherwise they wouldn't do it.
This maybe the next level wikibuy/honey ... Intentionally abandon carts to get more % off to undermine companies that do stupid things to get customers.
Yeah, I do that all the time when I'm dealing with real humans. Get a quote, then let them know you're considering it along with some other options, and hold off for a day or two and the human will often get back to you with a discount.
Sometimes works with rental apartments as well.
It's almost a perfectly scriptable thing -- I sometimes wish Google Assistant could do this negotiating stuff instead of reserving haircuts.
Probably these scenarios occur far more regularly than somebody rules out buying from a store solely because they received a marketing email concerning an earlier order they abandoned.
My last employer had a team of 3 (a dev, a copywriter, and a designer) dedicated to tweaking the abandoned cart sequence. When we implemented an abandoned card email dripper, we doubled sales in 3 months (from 40K P/M to 80+K P/M).
I hate email sequences like this as well, but they work (just like popovers with an email newsletter).
Not like, "I can't write software in my spare time" short.
Like, "I might not be able to finish writing this comment" and "There's a 50% chance I'm going to get interrupted if I try to buy this thing online right now" short.
I can still get things done at night but often I just don't have the energy.
So anyway, that's one reason why abandoned cart notifications have actually been useful for me now and then. More than 1 email is pushing it though...
I've since used this technique a few times to my advantage when renting trucks. So, it can be a downside for the business if customers catch on, unless it's considered part of doing business.
Javascript with more than about 1% its current capabilities, in a hyper-text document navigator and e-commerce platform, is a security hole. It can't be fixed because its features are security holes.
How the hell is that legal?
We all definitely underestimate how far marketing surveillance has gone.
It freaks people out when we reach out on the partial fill, but since I sell lead generation, it's a nice trick that they appreciate.
It's definitely problematic.
Luckily, our time is costly so only one single follow up occurs ..no list selling, mailing lists or repeat calls occur, but would be easy to do.
Its actually just an available feature on existing form software
Casual scum is casual.
Modern CMS's, specifically SiteCore have this kind of progressive profiling built in. It was one of the selling points for why we adopted it in our last rewrite.
You get a "left something in your cart" discount code.
So I've started to do that on purpose when I can't find a discount for a site, works about 50% of the time. Start to checkout, enter email, get to payment and just close tab. Wait an hour or two.
Only if you have an office in the EU.
Not any more than US companies need to comply with arbitrary Chinese laws, or Japanese companies need to comply with arbitrary Saudi Arabian laws. Why does the EU have special status in being able to impose laws on the US?
The EU can feel free to block the website if they don't like it. (But we know their citizens would throw a riot if they started censoring the internet, sshhh...)
However, independently of GDPR, I agree that it's wrong and that you shouldn't be saving contact information by deception. You'd lose me as a customer if you did that.
Of course the main problem with the GDPR is that it's so far not really been enforced, so people feel free to contravene it at will.
- (a) not do business in the EU, but leave your website accessible throughout the world. It's upto the EU to block it if they hate it
- (b) invite people from the EU to do business with you on US soil, where they would be subject to US laws instead of EU laws
I complained to their data protection officer, who basically fobbed me off and told me they did nothing wrong. A few months down the line I finally found the time to recap everything and collect the proof and complaint to the ICO?
Their response? They threw the complaint away on a technicality because it's been more than 3 (or 6, can't remember) months since my last contact with the company despite them persisting with the behavior.