Cloudflare keeps sending emails over a year after account was cancelled
shkspr.mobi
shkspr.mobi
My case is somewhat different, not that I want to unsubscribe but at one point they started addressing me as Dick in all their mass marketing emails. That's despite the fact that my name is not Richard or any variation thereof, nor have I used that name to sign up for anything at Cloudflare. It began immediately after I shot down one pushy salesperson's "invitation to arrange a call or videoconference" for a product that I already told them would not work for me. Could be just a coincidence, though.
The minute the call started it was clear he didn’t want to hear anything I had to say about workers and began pressing me to tell him where I worked. I told him and the conversation immediately turned into “what can I do to get you guys a contract for workers?”
The whole interaction was unsettling for me. Seems like a pretty sleezy sales tactic.
The self-serve platform is great and I wish all products were self-serve, because dealing with sale teams is very annoying when you're just trying to evaluate a product.
Life Pro tip, do this for conference registrations otherwise you'll be crushed.
Why is the CTO deleting tweets? But because the last thread was about archive.org I love the fact that the tweet is archived on archive.org
Sadly data protection agencies are understaffed and overwhelmed with requests. So if not hundreds of people complain about one company there will be no action (none of my complaints up to now has resulted in anything but notifications that I'm in a waiting queue - in some I'm for over a year now).
"Our mission to help build a better Internet is rooted in the importance we place on establishing trust with our Customers, users, and the Internet community globally. To earn and maintain that trust, we commit to communicating transparently, providing security, and protecting the privacy of data on our systems."
It looks very deceitful.
To me it's similar to scheduled stock selling for CEOs, which gets rid of any doubt for whether there's insider trading.
Just not good enough for me given the circumstances; maybe he should delete them after he resolves them or follows up, especially if he says he’s going to look into it and never does. That’s worse than not responding on Twitter at all IMO — and then the tweets were deleted too. The optics here are just horrible.
For you and me yes, but for the CTO [1] of a publicly traded company? YMMV.
[Edit] [1] Officer in the company
For example, at no point on HN have I even stated who my employer is, much less responded to a customer and said I would take action on their behalf. The reason is that, once I did so, it wouldn't be unreasonable to assume that anything I post under this account represents a company position.
[0] - https://www.sec.gov/Archives/edgar/data/1318605/000119312513...
PS I automatically delete tweets after two weeks. Have done for a long time.
Saying 'sorry, should be fixed now' is kind of unacceptable and more than a little patronizing to the people here.
What would you prefer his response be?
If you get email that you're not supposed to get, it seems like marking it as spam is the logical option.
He’s said this to OP multiple times and done nothing. You’re totally in your right to ask...
Sending an email or support ticket ends up in a level 1 support agent who cares a lot less then the CTO.
I'm confused, don't you go on to say the same thing as GP?
Now, just because I understand and sympathize with how things got this way, doesn't mean I'm not glad this guy is holding CFs feet to the fire for doing something about it. This emergent anti-pattern/"worst"-practice needs to improve, who better than the poster child for consumer tech saas.
Edit: I'm aware that GDPR considers email as confidential PII, but my post isn't legal advice. I just don't see my email as confidential.
OP, make a complaint to the ICO, it actually works
I remember reading about someone who went a step further. When they got a default judgement against a company and the company didn't pay, they put a lien on the owner's home so he couldn't ever sell it until he paid up. I don't know what that takes to do, but it sounds fun!
But I think posts like this explain why I’m not a huge GDPR fan yet.
On the one hand we have enormous tracking empires, who most likely are maliciously compliant with GDPR. They have probably not lost much precision / revenue due to the legislation. Mostly business as usual.
Then on the other side we have “normal” companies who are doing mostly “normal” crappy stuff all larger enterprises do. Clouddlare aren’t maliciously spamming people, they’re just incompetent handling their email lists. And sure it’s not a great look, but keeping someone’s email address around is probably not something governmental agencies should get involved in, in most cases.
The tone used in this post would, for me, be appropriate if Cloudflare did something horrible with your data. Selling traffic infi to data-aggregation firms, having lax security for accessing your customer portal, beeing hacked and leaking data etc.
Not “just” being sloppy with ther mailing lists.
Why not? They are unwilling or unable to do it without government intervention. I agree that for an honest mistake you don't need the government to step in. But after a year and multiple tries and broken promises, it's not an honest mistake, it's either intentional or gross incompetence.
I especially like that they keep stuff despite GDPR to "comply with internal policies and legal obligations". Making up an internal policy has no relevance to GDPR whatsoever (otherwise it would be quite easy "sorry, we have an internal policy to keep all your data forever"). Sounds like they simply don't care about GDPR.
> Then on the other side we have “normal” companies who are doing mostly “normal” crappy stuff all larger enterprises do. Clouddlare aren’t maliciously spamming people, they’re just incompetent handling their email lists.
... but your comment seems to be mostly self-serving and geared towards points-scoring.
I’d bet they’d fix it really quick once regulators get involved
Edit: correct "PNY->"PNC"
I have "${lastname}${firstname}@gmail.com" and i routinely get emails directed to "${lastname}.${firstname}@gmail.com" (notice the dot in the middle).
This was no big deal for me. But I received important documents (sometimes even legal document) that were not directed to me, at all. They were meant to be delivered to people in other areas of the country.
This is because Google has moronically and unilaterally decided that the dots are not meaningful and that they are smart enough to understand who is the actual recipient of an email (spoiler: they are not).
This also means that somebody else is also getting mail directed to me. This is super scary and made me distrust gmail as an email provider.
Nowadays I keep my gmail account for my android phone only.
But knowing I cannot trust the email address I am not confident to, for example, start using Google Cloud Platform with my private account.
I also have a "${lastname}${firstname}@gmail.com" email account and experience misdirected emails somewhat frequently. I wish more websites supported a “delete and recreate your account” feature, because some of my account were principally created by someone else and I can’t edit the details (Hulu).
Yup! Both the account switcher and the "From" address on emails I send include the dots.
> Can you sign in with the dot removed?
Hadn't tried it before, but yes I can. (In fact, you can try this at home: it also works if you add dots.) Signing in this way doesn't change what Google thinks my "canonical" email address is -- after logging in, the account switcher etc. still shows the dots in the places they were when I first registered.
My solution: create a filter that matches "to:${firstname}.${lastname}@gmail.com" and archives those emails in a separate folder.
By what mechanism do you think that's happening? There is no account with same username as yours, except with a dot, and never has been. Guaranteed. So just how would your emails be going to somebody else?
It seems like your mental model of how this is working has to be incorrect to have that fear.
You can set-up a lot of things and even have a load-balancer. I was also impressed by the smooth and easy onboarding process.
Unfortunately, after starting to use it I realized that my site was extremely slow for everything that is not cached. Cloudflare was adding 250ms of latency to every request to my server. I certainly did not expect that much. When you try to send a support ticket, they aggressively try to make you not do it. My support ticket did not receive an answer for 2 months.
I stopped using it last week and will certainly not look back.
Company like Cloudflare , Netlify etc... are generally built for Sale or to IPO.
People in charge of this type of Startup care about two things Growth - ARR.
It’s very common for those business to have multiples teams with their own « Mailing List » because it’s just faster and simpler to operate this way rather than having one single mailing system.
Add to that Software Turnover and your good for some trouble just to get rid of something that should have never been a problem in the first place.
What I really want to know is if the OP actually tried to unsubscribe or just went directly to twitter about still receiving e-mails after cancelling his account for that nice twitter/HN buzz?
It would be one thing if OP was receiving cookie-cutter responses from CloudFlare's support team, but the CEO repeatedly personally intervenes and makes assurances that simply aren't true (and he's already made the same promises in this thread). How can those promises be taken at face value when it's still a problem a year later?
Most people wouldn't consider a multi-million dollar corporation that is beholden to federal regulation their 'friend' though. And if we're continuing your painfully hyperbolic analogy, if said friend kept insisting that they had or were in the process of giving me back my pencil any time I asked them over the course of a year, I would have some grounds to complain.
Oh, my bad. By complain on a small independent forum I really meant 'crucify him in front of seven billion people'. My mistake.
Is shaking your head, maybe adding an email filter or reporting as spam, and moving on with your life too traumatic an experience to go through? Is your life not worth living at that point unless you pull the fire alarm, evacuate the whole building, and publicly obtain vengeance?
I run into this all the time at work. We're at the point where we've spent 5 whole minutes talking about some software-driven bad behavior. Nobody is sure if this is the first time we've been affected by it (maybe it's the fifth time already, but it is starting to feel like deja vu.)
Someone suggests it isn't really a problem and we should ignore it. This person is very effective at their job and gets lots of stuff done once we've decided to take action. But there's a problem, actually tons of them, they're piling up now and we still have daily conversations about how they aren't a problem, (on a big long rotation so nobody seems to recall if we've seen this one before on any given day.)
If it was just a problem for this one person, well that would be a real anomaly. But adding a filter rule to always block is ignoring the problem, in the context of my work-life analogy, not fixing it.
I mean, I know in America, corporations are people and even have constitutionally-protected religious beliefs, but I'm sure Cloudflare will, with enough counselling, cope with the trauma of some mild public shaming.
It might be minor if it's only affecting one person, but the OP seems to suspect (on fair grounds) that there might be a lot of people affected by the same dubious corporate practice.
Has it? See the following page (which also contains complaints about unsolicited e-mail, among others): https://codeberg.org/themusicgod1/cloudflare-tor
Lots of companies (big and small) don't unsubscribe me properly and I end up getting emails a year or two later. It's nice to have the nuclear options of deleting the alias if needed.
So yes, it's relatively minor compared to internet infrastructure products and tooling that Cloudflare is responsible for, but it's still an issue that erodes trust in a company.
[1] Detailed here: https://jonpurdy.com/2020/06/using-email-aliasing-to-detect-...
IMO this is just a weird form of grandstanding.
That doesn't always work.
I receive spam from a major US university to a Gmail account. Marking it as spam for over a year has done nothing.
Whether they keep sending you email or not, you should never see a message from the same address again.
A decent client would give you the option to block the whole domain.
Don't blame the victim. GMail does this. I have the same problem, and I only use GMail's web interface.
Email clients do need to be able to successfully handle spam, it’s a pre-requisite for using email. I would absolutely blame the email client software before shouting into the void.
I do understand about the tweets, though. Calling out perceived hypocrisy, especially when there are legitimate reasons it's not hypocrisy, is a threaty sort of thing.
If you are using an e-mail provider that does something about it.
I have a GMail address that receives spam from several specific companies regularly. I've marked the messages as spam every month for at least five years. They keep coming, and GMail keeps showing them to me.
Account was suspended about 10 months ago (for no reason given). I sent Heroku, Salesforce, their data protection officers emails asking them to remove my account, databases, codes, everything on it.
I kept receiving notifications that an active account would receive. And their DPO lied to me that they have closed the account.
Another US company doing that is not really a coincidence.
About 11 months after they confirmed that my data had been deleted, they sent me an email informing me about their changed Terms of Service. So I guess my email at least wasn't pruned. Who knows how much more data they are holding on.
1. retaining information because of a legal requirement and acting on their legal obligations as is necessary from time to time
2. retaining the information as above while saying that there's no such thing?
The only way I see that to matter is if their TOS said they'd save more data/ save it for longer than legally required. Changing their TOS would then affect what data they'd store on ex-customers if they retro-actively applied it. However, their TOS would be irrelevant in that case, as they'd violate GDPR.
They might also lessen the amount of data they hold on you, maybe after a review of what they actually needed.
I agree they should not send you anything if they store no data whatsoever, but if they do - they should probably inform you about changes in their privacy policies, even if they don't affect you personally.
Are you sure? Laws that compel you to do something usually don't go into effect retroactively. They're like price-hikes in that regard: you can't just unilaterally decide that your customer's monthly subscription fee has doubled since three years ago.
In any case, it wouldn't have anything to do with their TOS or privacy policies, and I don't think they'd have to inform you about their compliance with the current laws.
> they should probably inform you about changes in their privacy policies, even if they don't affect you personally
You're not a customer at that point, why would you be getting information that only concerns customers? Updating someone on the TOS changes implies that they either requested to be updated or are a customer.
I understand the idea behind preferring to err on the side of informing too many people rather than too few, but we should value the recipient's time and attention as well. And once we do that, I believe it's clear that the sender has to spend the extra time to figure out who should receive this email and who shouldn't.
A company that does not validate that the email address actually belongs to the person/entity they have consent from does not have any reason to store and process that email address. The same goes for other PII.
If I sign up with your data, you've never consented, and whatever terms I accepted with a click or two have no relevance to you. Companies just usually don't bother with validation unless they need it for billing purposes, because it's a hassle and might make the customer reconsider.
No, I can widthdraw consent as much as I want. If they have a legal basis for storing my email address, then they can keep it regardless of my consent. However, I have no way of knowing if they actually have a legal basis for storing my email address or if they are just holding onto it.
However if they process your e-mail for several purposes based on different legal basis (for instance they also use e-mail for marketing purposes), they should stop using it for these reasons which you requested (for instance - all applicable) where consent was the basis for processing.
The safe assumption is that any data a company has ever had on you is still stored by them no matter what they say to the contrary, and will be until the end of time. Apart from being a hermit living in a cave in Montana from birth to death, there is no guarantee of data privacy in the modern world. Anyone who tells you otherwise is trying to get and sell your data.
It's also interesting just how many regulations deal with e-mail addresses. https://www.absolute.com/blog/are-email-addresses-confidenti...
More than a year?
If the company's processes are not set up to handle the proscribed faster timeframes, it must not handle personal data at all. Doubly shocking since this is cloudflare, where a large percentage of the internets personal data passes through...
At any rate, demanding that customers send an email to have their account deleted is ridiculous. Put a damn button in there already. And before any claims are made to the contrary, invoking "security" here is nonsense; if someone hacks my login, having my account deleted is the least of my problems.
On this specific aspect, they're not wrong. For example, they might keep that info to contact past clients about breaches, tax compliance issues, etc.
Sure it would be better if this issue was explicitly spelled out and maybe more specific, but it is not wrong. (Sure, using that email to warn about a downtime is outside of that scope)
That was exclude any data breaches though, wouldn't it? Because they are always incompetence rather than intentional bad behaviour on the part of the breached companies.
Nope. It is to protect users.
Users are harmed by both intentional bad behaviour and incompetence. This is the same principle as strict liability for product faults.
Nothing in there limits responsibility, damages or punishments to intentional behaviour. Incompetence, be it organisational or individual, is not excluded. And a company can be punished for not implementing appropriate controls for individual incompetence or malice towards personal data.
If Cloudflare is unable to even remove a deleted account from a mailing list, how do you know they have actually deleted ANY other information?
[0] it is possible to use data for other purposes than originally collected in some circumstances, but I'm not sure if there are many legal precedents for that yet.
Companies work to priorities lists based on how important things are for customers. So it's perfectly plausible that the very reason they're not flawless at removing cancelled users from all their email databases is that they're too busy focusing on, as you put it, "the many far more privacy-relevant things they offer as a company", which they regard as far more important.
I'm not saying that's definitely the case here; I have no idea of any specifics. But I've definitely seen things happen that way in other companies/teams I've observed.