*.ycombinator.com Terms of Use
ycombinator.com
ycombinator.com
I wonder what changed and made them add the new terms of use.
[0]: http://web.archive.org/web/20141020194316/https://www.ycombi...
CCPA's April enforcement deadline, most likely.
Probably a lawsuit, mandatory arbitration avoids lawsuits. I’m just guessing, I have no concrete info.
I’m not crazy enough to sue over that shit; but somebody might be.
> advertise or offer to sell or buy any goods or services for any business purpose that is not specifically authorized;
Heh. I'd say this part is disconnected from reality.
A very significant number of posts and comments recommend aka advertise (in one way or another) various goods or services. Typically third-party goods or services ("I use this"), sometimes first-party ("we made this"). And this is what brings huge value to the website. I get it, ToS are about spam, but it's probably impossible to discern good and bad advertising in legal terms.
https://news.ycombinator.com/newsguidelines.html
> Please don't use HN primarily for promotion. It's ok to post your own stuff occasionally, but the primary use of the site should be for curiosity.
Emphasis mine.
---
Edit: It gets more interesting with the WhoIsHiring threads. I haven't seen specific authorizations for them, but considering HN staff have commented in said threads in the past (https://news.ycombinator.com/item?id=26306206), this may also be specifically authorized. (I don't know who owns WhoIsHiring)
Pre-2017: http://web.archive.org/web/20161229045611/http://www.ycombin...
2017: http://web.archive.org/web/20170303015020/http://www.ycombin...
2020: http://web.archive.org/web/20200130013739/https://www.ycombi...
2021: http://web.archive.org/web/20210301143626/http://www.ycombin... (current linked)
I'm still doing diffs.
Edit:
2021 (left) v. 2020 (right) diff:
2020 (left) v. 2017 (right): Privacy policy was significantly reworked, not the biggest surprise considering CCPA, but n++ is choking on the compare. Some interesting TOU changes though:
> h. Future Changes to Arbitration Agreemen
Someone forgot to dot their Is and cross their Ts :)
https://news.ycombinator.com/item?id=26962860
Here's what HN admins were responding last yeat to requests to have your account deleted (article 17 of the GDPR):
>Our understanding based on the analysis done by YC's legal team is that Hacker News does not fall under the GDPR, so for the time being we're sticking with the approach of not deleting account histories wholesale but helping with privacy concerns in any other way we can. The problem with deleting entire histories is that it guts the threads the account had participated in, which is unfair to the other users who posted.
I don't know why terms can't be written that simply in the first place.
Though certainly there is a 'pattern' to these that I think lawyers just fall back into that can be less understandable than needed.
If nothing else, many contracts are written in a somewhat weird frame, where one party is referred to in third person, and the other in second person. And often phrasing is so that the second person needs to recognize a claim of the third person ("you acknowledge etc etc").
In many ways, contracts are like the ultimate reversal of YAGNI. Imagine deploying code that you literally could not fix after release, and you knew that nearly all deviations from intended behavior would just kick you in the butt. Your code (and general product function) would probably get a bit weird too.
1. Legal contracts are supposed to be as detailed as possible so there's as little room for disagreement as possible when taken to court.
2. It's better for companies if users don't take the time to read and understand their terms, and beyond a certain length and complexity they will just scroll through and click yes.
4. It's easier to write incompehensible legal text than simple English that a layman can follow, and customers seldomly call lawyers out on it because they've been trained to accept this as the status quo (also see 3).
> Commercial Use: Unless otherwise expressly authorized herein or in the Site, you agree not to display, distribute, license, perform, publish, reproduce, duplicate, copy, create derivative works from, modify, sell, resell, exploit, transfer or upload for any commercial purposes, any portion of the Site, use of the Site, or access to the Site. The buying, exchanging, selling and/or promotion (commercial or otherwise) of upvotes, comments, submissions, accounts (or any aspect of your account or any other account), karma, and/or content is strictly prohibited, constitutes a material breach of these Terms of Use, and could result in legal liability.
This means: don't use the content of the site to make derivative works to make money, otherwise we might sue you.
It's mostly straightforward stuff like that. If there's a specific part that you're having trouble with, I'm happy to have a crack at explaining it.
Unless you are prepared to completely sever business ties with Europe.
1. Processing that takes place in the context of processors and controllers that are in the Union, regardless of whether or not the processing itself takes place in the Union.
2. Processing the data of subjects who are in the Union by controllers or processors who are not in the Union if the processing is related to offering goods or services to such subjects in the Union or the processing is related to monitoring the behavior of such subjects that takes place in the Union.
3. Processing of personal data by a controller not established in the Union, but in a place where Member State law applies by virtue of public international law.
If none of those cover an entity, that entity's processing is not covered by GDPR.
#2 would probably be the only relevant one for HN.
Is HN offering goods or services to subjects in the Union? Sure, people in the Union can access HN and even make accounts. But that might not be enough. One of the recitals for Article 3 elaborates:
> In order to determine whether such a controller or processor is offering goods or services to data subjects who are in the Union, it should be ascertained whether it is apparent that the controller or processor envisages offering services to data subjects in one or more Member States in the Union. Whereas the mere accessibility of the controller’s, processor’s or an intermediary’s website in the Union, of an email address or of other contact details, or the use of a language generally used in the third country where the controller is established, is insufficient to ascertain such intention, factors such as the use of a language or a currency generally used in one or more Member States with the possibility of ordering goods and services in that other language, or the mentioning of customers or users who are in the Union, may make it apparent that the controller envisages offering goods or services to data subjects in the Union.
Does HN envisage offering services in the Union, or is it simply a site that happens to work when accessed from the Union but was not envisaged to do so?
Another recital elaborates on the monitoring of behavior of subjects in the Union:
> In order to determine whether a processing activity can be considered to monitor the behaviour of data subjects, it should be ascertained whether natural persons are tracked on the internet including potential subsequent use of personal data processing techniques which consist of profiling a natural person, particularly in order to take decisions concerning her or him or for analysing or predicting her or his personal preferences, behaviours and attitudes.
HN seems to collect minimal data. It might not rise to the level of monitoring that would be needed to count as monitoring behaviour.
To handle this, we link to theirs in place of a custom one.