Google keeps records of everything you buy, even if you delete the email receipt
mastodon.social
mastodon.social
Google has been doing this for a while, as can be seen when the reporters wrote about it 2 years ago: https://www.theverge.com/2019/5/17/18629789/google-purchase-.... HN discussed it at the time: https://news.ycombinator.com/item?id=19942219
You can see the information it has already collected if you use Google, by visiting: https://myaccount.google.com/purchases
Though oddly my list is empty. I wonder if I disabled this feature at some point?
The help docs: https://support.google.com/accounts?p=orders&hl=en, explain how you can delete this data if you want to.
"We never use your Gmail content for any ads purposes" emphasis mine.
That might qualify as deceptive.
Not because google is in the business of data and advertising or has the ability to cleverly manipulate language to their advantage or would ever consider being evil. I'm quite confident google wouldn't use such data in ways that could be connected to advertising. All your google data are belong to privacy.
Ironically, since the only purchases my Gmail contains receipts for are for someone who isn't me but apparently decided to use my email address, whatever database these are feeding that Google thinks is "about me" is steadily being corrupted to death by a complete stranger.
Oh well :)
Not going to be so great when they engage in criminal activity that points back to you. I do a password reset on their account whenever I find someone using my email. Then you can change the email to a throwaway or delete the account. It's unsafe to let it be.
Gmail does not allow changing email addresses, and if I delete the account, I lose access to a recovery email that I'm executing a multi-year migration away from. That's simply not an acceptable step to take to mitigate the unlikely risk you describe.
There's also some jerk at AOL who forwarded their email to me mistakenly over a decade ago, and I've tried to contact AOL, which of course they won't consider since I'm not the person who set the broken forward.
While I appreciate your concern, I've already taken it into consideration as best as permitted by the tools available. If you are aware of a way to change a gmail address without creating a new Google Account, then of course I would love to hear about it.
Over 50% of the email this account receives is for other people and frequently the "To:" field isn't even an exact match for my address!
If you do start getting stuff that looks like it might cause you problems: be proactive. Do not wait around to embarrass some prosecutor. By that time, you've already spent thousands of dollars and had your reputation dragged through the mud. I once started getting legal threats meant for someone else. I had a lawyer call up that lawyer and it was cleared up in less than 10 minutes. Another time I started getting emails from/to a person with the same name as me at the State Department that definitely should not have been sent through a non-government server. I talked to someone I knew at the US Attorneys Office about it and those emails stopped immediately (doubt that guy still works there, LOL).
So, my gmail is fname.i.lname@gmail.com. I see SOMEONE else's purchase in my history. That persons name is shown as fname lname@gmail.com. Same as mine except .i. is three spaces.
WTF? Does Google have a bug here? Is there an actual real life human I could send this to?
Edit: the only purchase I see of mine are for Apps I bought from the play store. These don't show up in the link that the Googler posted above.
The dots don't matter.
jennifer@gmail.com marksmith@gmail.com neilpatel@gmail.com
etc. etc. etc.
Win / win either way for OP. Learning opportunity or a bit of cash in hand for relatively little investment.
As an example name.lastname, na.melastname and namelast.name are all the same email address.
"fname.i.lname@gmail.com" is the same address as "fnameilname@gmail.com"
I was an early GMail user and have a common-ish name. I probably get 30-50 emails a month from confused people ranging from contracts to receipts to racy photos.
And not just obscure standards; email addresses are very much public-facing elements of email. The expectation when you register an email address is that that address is now uniquely associated with you. The public does not expect that an email might be delivered to other inboxes than their own.
Why does gmail elide dots again? There must be some reason why a big email provider would deviate so egregiously from the conventions all other email services comply with.
/me not a gmail user, except for certain account recovery purposes.
I sought support but never got anything official and commenters brushed it off. But I'm pretty sure it was similar to your issue.
The weird thing is that page doesn't even list the purchases I've made from google itself. Does it even work?
Recently discovered these all seem to be unlinked, after I has to change my payment instrument in a dozen different places.
It indicates that "Gmail, Chat, and Meet may use my email, chat, and video content to personalize my experience and provide smart features. If I opt out, such features will be turned off."
It's strange that this major privacy setting is buried specifically in the GMail section and not mentioned in the main Google account Privacy Checkup. I never knew it existed.
Might have just been to the EU/UK users though?
Honest question here, why do people put this in their response? I don't think there is any chance that one might thing "kyrra" is speaking on behalf of Google.
But once someone says "I work for X", they must also say that they're not representing the company. Companies get a bit upset if their employees appear to be representing company positions without authorization, even if no reasonable person would thing they were.
Source: I work at Google
Disclaimer: Googler, opinions are my own.
Some comments I see (not speaking of this thread per se, but in general on HN) are really close to conveying internal company information. Which is beyond mere opinion and only available to someone inside the company. Some people clearly use the disclaimer to elevate their "opinion" to the level of authority.
This is in contrast to comments you see here like "hi, Ben Foobar from [company being discussed] here", where the company is being formally represented and communicating with HN.
Naturally Google doesn't engage this way on HN, but the disclaimer is written out of habit and an abundance of caution.
Disclaimer: I am not a googler, opinions are what google tells me to think.
I do wish gmail would keep track of all my purchases. Keeping a folder named "shopping" is ok, but it could be so much more.
Next to each purchase I'd love to see: - link to a manual, youtube videos about this product. - remainders when stock is low (for things I might reorder).
From the screenshot, the items are part of the "Purchases and Reservations" activity category that the parent points to. According to to the help documentation of the category, it specifically refers to purchases made directly within Google Search, Maps, or Assistant. I personally have precious few (4) items in this category, particularly when compared to the large number of purchase confirmation emails sitting in my Gmail account. And there is a UI for deleting the purchase records from my history.
Meta-comment, I find discussions of this type tend to elide the distinction between data used for personalization with data used for advertising. Say what you will about the very fact that the same organization has both, but I do think the distinction is both important, and communicated well neither by Google nor by anyone else writing on the topic.
Personalization of what, exactly, if not ads? What's the proper distinction, in your view?
If you're watching YT and think you are not seeing ads, then you're being foiled.
>> So my data is being used, just for my benefit.
Apart from the word "just", I agree.
Actually running an ad blocker/paying for Premium means you aren't seeing ads, pushed by Google. Any creator might be showing you sponsorships/product placements of course, and Google has no say in that.
Yes
>> guiding you
Yes
>> based on your profile
Yes
>> based on all the data they have collected on you
Yes
>> in order to entice you to consume goods
Yes
My guess is very very few.
If I receive a travel reservation confirmation email, I receive a calendar reminder on my phone a few days before the trip.
This is personalization. But years ago Google made a commitment not to use Gmail data to customize ads (after initially doing so). So there's a real difference between personalization data and ads data.
Closer to home for me, we are legally barred from using Fitbit data for ads or allowing any system (or person!) in the Ads organization to access it in any way. But nobody said we can't personalize your Fitbit experience based on data derived from, say, your Fitbit exercise history.
Oh! Well, I actually did not know this. You are saying they realized they shouldn't use my Gmail to customize what ads they show me; how can I verify you are right to say so?
>> So there's a real difference between personalization data and ads data.
I still don't see the distinction.
Unfortunately this goes against people's default (and incorrect) mental model of how Google operates, so it's been a very hard message to land.
Disclosure: Current Googler and I was a PM on Gmail at the time.
However I now get email from various people around the world with xlastname(at)gmail.com addresses. Apparently your email is not unique in the world, but only in your region, kind of (?!).
I get important emails (hotel bookings, insurance mails, trip reservations, orders, lawyer documents) from people which use xlastname(at)gmail.com in the USA, Canada, Australia, and Europe. All with similar names to me, obviously the surname is the same, but first name is different, just the same initial.
I've confirmed (by contacting some of them) that they are not missing out on any important documents. For some reason Google's system is duplicating emails meant for other people into my mailbox.
Only mails using x.lastname reaches MY inbox. If I tell someone I know to send a mail to xlastname I wont receive it, making the statement here...
https://support.google.com/mail/answer/10313
...false (for me).
I guess I'm God over all the non dotted versions of my email address. Thanks Google!
(However sometimes I wonder if other people see my emails as well)
No, it's globally unique. I worked on this system for years. When it looks up an email address, it first looks in a globally consistent database [1] for an email record keyed by "canonicalized" address, with dots stripped out, everything in lowercase, and certain letter/number combinations replaced that are too similar like '1'->'l'. So if you sign up with x.lastname(at)gmail.com, no one else in the world can have xlastname(at)gmail.com, x1astname(at)gmail.com, xl.astname(at)gmail.com, etc. Part of this record's value is the original email address with the 'l's and '1's how you chose them. If those don't match the query, the system returns not found, just as it would if there were no record for the canonicalized form.
> I've confirmed (by contacting some of them) that they are not missing out on any important documents. For some reason Google's system is duplicating emails meant for other people into my mailbox.
I'd be _shocked_ if that were true. It'd be a very serious privacy incident and is contrary to my understanding of the system. Far more likely it's what I've seen with my own email addresses. Someone else incorrectly writes your email address instead of theirs into some system. Usually you're the only person who gets the email, but they might send something to two addresses, or they could even set up a forwarding rule from an address they have to an address they incorrectly think they have. They may say they're not missing any important documents, but maybe they have the documents in another system and don't know they're supposed to have gotten an email copy also. Or maybe they don't know what they're missing and don't understand what you're saying. This group of people was not selected for tech savviness. They might have just made a typo once, or they might keep doing this because they don't understand email at all.
> Only mails using x.lastname reaches MY inbox. If I tell someone I know to send a mail to xlastname I wont receive it, making the statement here... https://support.google.com/mail/answer/10313 ...false (for me).
That's odd. You can write to support if this is a problem. Support tickets actually reach engineers when necessary (yes, even for free gmail.com users).
It seems vaguely possible given the age of your account that your email record state and the current code are inconsistent in some way, like the field that stores your email address with the 'l's and '1's in your preferred form actually having the dot when it's not supposed to or some such. If there is such an inconsistency, one of my former teammates will fix the code or the database state (running a cleanup that finds all affected records) so they're consistent.
Or maybe the xlastname ones are just ending up in your spam folder. /shruggie
[1] old but: http://citeseerx.ist.psu.edu/viewdoc/download?doi=10.1.1.133...
> how can I verify you are right to say so?
I mean, you could say "how can I verify Google isn't using my Google password to decrypt my Chrome data and pipe it into Google Ads", but you'd have no way of verifying that, besides taking their word for it. https://variety.com/2017/digital/news/google-gmail-ads-email...
But, it's something we've also said legally:
https://support.google.com/googlecloud/answer/6056650#zippy=...
Is Google using my data? What for?
Google processes your data to fulfill our contractual obligation to deliver our services. Google’s customers own their data, not Google. The data that companies, schools, and students put into our systems is theirs. Google does not sell your data to third parties. Google offers our customers a detailed Data Processing Amendment that describes our commitment to protecting your data.EY, an independent auditor, has verified that our privacy practices and contractual commitments for Google Workspace and Google Workspace for Education comply with ISO/IEC 27018:2014. For example:
We do not use your data for advertising
The data that you entrust with us remains yours
We provide you with tools to delete and export your data
We are transparent about where your data is stored
You can get even more detailed in the DPA:
Customer instructs Google to process Customer Personal Data only in accordance with applicable law: (a) to provide the Services and TSS; (b) as further specified via Customer’s and End Users’ use of the Services (including the Admin Console and other functionality of the Services) and TSS; (c) as documented in the form of the applicable Agreement, including this Data Processing Amendment; and (d) as further documented in any other written instructions given by Customer and acknowledged by Google as constituting instructions for purposes of this Data Processing Amendment.
First line in your legal statement:
>> We do everything in our power to protect businesses, schools, and government organizations from attempts to compromise their data.
Where is the "me" in this equation?
https://policies.google.com/privacy#infocollect
"We don’t show you personalized ads based on your content from Drive, Gmail, or Photos."
and
https://support.google.com/mail/answer/6603
> When you open Gmail, you'll see ads that were selected to show you the most useful and relevant ads. The process of selecting and showing personalized ads in Gmail is fully automated. These ads are shown to you based on your online activity while you're signed into Google. We will not scan or read your Gmail messages to show you ads.
The FBI, NSA, CIA, and DoD have access to it, without a warrant (thanks to FISA 702), along with the entirety of the email corpus that produced it.
You can't do threat modeling if you don't accurately model the various threats. Everyone at Google could be completely trustworthy but there's still huge insider risk thanks to US spying.
If we are going to do "threat modeling", we should also talk about the risk of nation state actors penetrating Google, or compromising your browser and getting access to your gmail that way. Or an accidental bug that changes everyone's password to be 12345. Yes, or the federal government could subpoena it.
Lots of things could be true and possible, but none of them are relevant in a discussion that's about the _internally permitted use of data within google_.
I routinely dealt with situations where connecting workspace data with other teams, even with explicit opt-in from users, at best required building incredibly detailed data scrubbing and log redaction to ensure no user data persisted outside of the workspace systems, in case it might accidentally end up used for some non-workspace purpose. At worst it was simply not possible, or not worth the other teams time to build things to a standard that would satisfy legal and privacy.
For sure, it’s possible there is some secret system or accidental data exposure, as I said, can’t prove a negative. But I will freely confess that I was someone who was generally skeptical of Google’s approach to data handling and always believed Gmail data and everything else was mined for every purpose until I joined Workspace. Once I was inside and saw how carefully it was treated and how many rules there were around anything you do with user data even within the Workspace teams, I was honestly nonplussed. It made product development harder.
15 is not a prime number.
There is no elephant in your room right now.
Prove it.
Of course, as people living in the world we don’t necessarily need full proof to try and protect ourselves from the actions of an entity we don’t have full knowledge of. But saying “I don’t want to give google X data because of what they theoretically could do with it” is different rhetorically from saying “I believe that google is doing X with the data, and if you don’t prove otherwise it’s probably true.”
Whether a contract is formed when you register and agree to their terms would depend on locally applicable law. I don't recall stories that courts would have deemed registrations on the internet invalid in general. Certain terms in the aggreement definitely.
- Your "content" (data in Gmail, Docs, Photos, etc) won't be used for advertising. (Only for personalization, like the Gmail smart compose, asking Assistant about the status of your order, etc.) - Your "activity" (your searches, etc -- what you can see at https://myactivity.google.com/item roughly) can be used for advertising, though you can turn it off (see https://adssettings.google.com) or delete it. (IIUC, you have more granular privacy controls as a logged-in user as you can delete individual items….)
But luckily google provides us with a completely gdpr compliant opt-out for Google Analytics.
"Oh! Well, I actually did not know this. You are saying they realized they shouldn't use my Gmail to customize what ads they show me; how can I verify you are right to say so?"
and then my response:
"Googler here, who worked on Workspace (which gmail is a part of). Anyone who works in workspace could confirm that, it's something that is taken very seriously."
I'm not sure how I could have been more clear...
Out of the top of my head: NoScript, Trace [0], uBlock origin, Decentraleyes, Privacy badger.
As well as using a pi-hole.
[0] https://addons.mozilla.org/en-US/firefox/addon/absolutedoubl...
https://myaccount.google.com/permissions?continue=https://my...
And disable Google Account Sign In prompts
Zero respect for Google or Googlers just like I have 0 for perverts.
I think we deserve to hear from Google about this one. Unless we have already?
IIRC, that's why Amazon purchase emails are utterly useless now. They realized Google was getting their precious customer data via Gmail, so they cut off the flow years ago.
It's another example of how the modern economy has many consumer-hostile incentives that have actually led to regressions rather than improvements.
Yeah, and there's nothing you can do. I don't even use gmail anymore, and the emails are still garbage. I think for awhile they used to include a truncated name of one of the products in the order, but it looks like they even removed that (sometime around August 2019, based on my emails).
Unrelated observation: in my original comment I added a second paragraph noting that this regression was due to the incentives caused by modern capitalism (and it is: owners trying to extract maximum value for themselves, even if that means hurting their customers), and it immediately started getting downvoted. Then I change "capitalism" to "economy" and it started going up again. Some people are really sensitive. It must be blasphemy to criticize the invisible hand and the wisdom of the owners ti guides. I guess right is whatever they do.
Not providing intricate details about your purchases in email is a privacy-enhancing feature, given that probably most of their customers are using gmail.
Whereas that is pretty easy with any sort of email client.
I noticed they stopped including product details in emails a few years ago, didn't click until reading it now that they're doing it to prevent data mining. Kind of makes sense if you think about it, but maybe they should have an option for that for people that self-host their e-mail or use privacy-focused providers.
The report contains far more information than you can scrape from their old order emails, including: Date, ID, Title, Category, ASIN/ISBN, UNSPSC, Condition, Seller, List Price, Purchase Price, Quantity, Payment Instrument, Shipping Address, Carrier, and more
It was just in the past week or so that I noticed that it's back.
It's on your main account page under "Download order reports"
They can fix their privacy issues on their platform, I want my email receipts.
I work for another online retailer and have been involved in discussions about this same topic (order information in emails we send), and the way we looked at it was that:
- Gmail collects this data from emails
- The overwhelming majority of users are unaware of this data collection
- If we included the data in the email, while knowing that Gmail was collecting it and knowing that most users are not aware, that was tantamount to us just willingly handing over the data to Google without the users' consent
Because of this, we asked ourselves if users would likely feel upset with us willingly handing over data to Google without consent, and we decided that yes they would. So we made a trade off to not include that data in emails because we thought that was more important than the hit to UX we would take from making the emails less informative.
Either way we had to make a decision on behalf of our customers and we knew that no matter which one we chose, we knew some portion of users would be unhappy and decided to go with the more privacy-conscious choice.
I do see a decent argument for companies being a little bit more conservative about what information they put in emails when this kind of information collection is largely invisible to the general public. It's just important to balance that against data silo worries by making it easy for customers to export their data and hook purchase confirmations up to other services that users might actually want to have access.
I'm not convinced Amazon makes these kinds of decisions out of a concern for user privacy (especially since Amazon isn't actually consistent about hiding this information in their emails as far as I can tell), but I'm sure some retailers are.
Amazon used to let you at least download a CSV for a date range, but the don't even let you do that anymore!
I didn't realize why, but it's always annoyed me how little info is on Amazon's order confirmation emails, forcing you to click the link.
This is why!
I liked getting an email with the item, price, shipping, etc. Now it’s just an order number and shipping notice and I have to click on the order to figure out what items are coming. Particularly fun when I order 6 items and they get split into 6 shipments. Or just trying to keep track of my dozens of Amazon orders.
I switched to Walmart as they send useful product updates.
Also, that’s a great state of things today… Amazon has to make their product worse because Google won’t ever stop siphoning.
I still have a Gmail, but I’m properly compelled to kill it, finally.
It's the opposite.
Amazon wants you to click back into the store to buy things. One way to do that is forcing you to view orders in the store instead of your email inbox. They care more about that than Google seeing your purchase history.
Google has been found to lie and play dirty over and over again throughout their existence. You'd be a fool to think they don't even scan it. For "safety reasons", and oops, the contents of your email have accidentally been logged and stored, what a shame.
To be honest, I actually think it's probably more privacy-conscious to eliminate as much information as possible (but no more) from these kinds of emails. While I suppose Amazon is concerned with competitive behaviors from Google, I'm more concerned that Google or any other actor with access to my email could look through my purchasing list, or my library reading list, or...
Email is an insecure and non-private medium, but we often use it for items that require some level of security or privacy. I'd prefer if more companies held that information closely.
But that makes them useless for what they are, especially the shipping ones: "You made three orders recently, one shipped. If you actually want to know which one (and you haven't memorized your order IDs) click here!"
This is actually a pretty annoying regression for me, because I buy things from many sites and have no way to search my overall order history anymore.
> Email is an insecure and non-private medium, but we often use it for items that require some level of security or privacy. I'd prefer if more companies held that information closely.
It is, but there's no better system and ruining email doesn't solve that privacy problem (e.g. Amazon may sell this information). At a minimum, it should be a setting so people can opt to get useful emails if they want to make that tradeoff.
If I don't want Google to have any access then I'll use a different provider or self host my email. If I want to publish all of my emails publicly that's also my decision.
on the other hand I don't like having stores advertise to me online because Google slurps up my purchase data.
for me the privacy - or the sandboxing if Amazon sells the data - is worth the inconvenience. but that's like just my opinion, dude
Would be nice if Amazon only made their e-mails to Google addresses (Gmail or otherwise) useless.
"You bought a toilet? Would you like another 4 toilets?"
I mean, ffs, maybe recommend a bidet or installation tools.
I see Amazon as doing something similar, but less targeted at gmail specifically.
Downside is Gmail search is a lot better than Fastmail's. But otherwise it's worked great.
Google literally buys a copy of most people's credit card transaction data.
>Google has been able to track your location using Google Maps for a long time. Since 2014, it has used that information to provide advertisers with information on how often people visit their stores. But store visits aren’t purchases, so, as Google said in a blog post on its new service for marketers, it has partnered with “third parties” that give them access to 70 percent of all credit and debit card purchases.
https://www.technologyreview.com/2017/05/25/242717/google-no...
[0] https://mjtsai.com/blog/2020/06/01/unhelpful-amazon-order-co...
I'm sure the advertising PMs were happy to support this decision because it got them more page clicks, but my understanding is that the underlying motive was privacy.
0: https://www.nytimes.com/2019/06/04/opinion/google-purchases....
(I'm not saying this harm is not "worth it" in some sense, but it's a very real consequence of these giant cross-financed markets - see also mobile operating systems and web browsers.)
https://blog.google/products/gmail/new-settings-smart-featur...
Seems a bit odd for the poster to enable it, and then complain. The text seems fairly clear.
Oh, wait... The screenshot shows the Takeout as being from 2019. Why post about it now?
In typical Google fashion, you had either the choice to enable everything or nothing. I want the tabbed inbox, I don't want smart compose, or assistant integration or... anything else from that post, really.
They also lock all kinds of basic features of Google Maps (like manually set and store my home address) behind the permission to record, store and processes indefinitely my location history.
I just went through the Google's "Privacy Checkup" and it wasn't clear to me where this setting is.
Also is the Takeout from 2019, or are there purchases from 2019 in a current Takeout? What specifically are you looking at in the screenshot?
Same with something I can run Google Maps with my account logged in so that Google thinks I am one heck of a super traveler, and shopper of things.
Something that watches random YouTube videos for me, and randomly clicks on ads for me.. :-)
Uploads random photos into a Google Photos account for me :-)
That’s be heck of a lot fun!
I have been getting a lot. (a couple a week, which is a lot compared to zero for N years.) ((I was a customer of Postini before google bought them and integrated them into gmail as, IIRC, their spam system...))
Privacy is such an illusion.
edit: ignore, I just read their privacy policy. God damn it. Can't trust anyone.
Technology is awesome, but it's fallen into the hands of a bunch of god damn authoritarians. Trust absolutely no one. Paranoid should be your default behavior towards any files you have a device that accesses the Internet. There's 10,000 tentacles seeking that data.
[0] https://www.vpro.nl/programmas/tegenlicht/kijk/afleveringen/...
Translated from Dutch: "The stock market should be a level playing field: everyone has the same information. But unnoticed, terabytes of data have entered the stock market. Smart companies dive into the mountain of data that is collected about us, in order to be able to see Apple's sales or the number of Netflix subscribers before the rest of the market does. VPRO Tegenlicht delves into the world of 'alternative data' to see who will win on the stock market, and who will not."
Translated with www.DeepL.com/Translator (free version)
I run a basic GSuite organization and the two times I've had an issue with the service, I literally had a representative on either chat or phone support within minutes. It was a very pleasant experience.
Happy to spend my money on that. They did have to transfer me twice for a technical issue, but that was resolved too in the end.
I had used the account to purchase stuff on Google Play. I wanted to close the GSuite organization account but retain the purchases. Either by transferring to another (disposable) gmail account, or by somehow closing the organization account but continuing to be able to log into other parts of google using a now-third-party email addresss. Or a refund. I don't know what options were available, that's why I contacted support.
So this was a transactional support request, not a Q&A. I did get through to a chat support but their answer was pretty much "I don't know, check the support forums".
I'm not trying to make my point about the situation, more about the customer experience I got for trying to ask what I imagine is a fairly common question.
(I feel like an idiot for spending money on DRM, but different story)
This is me realizing I’m probably locked in for eternity…
Will Google give you the mechanism to ask your question? Will you trust the answer? Will you take that gamble?
1. Migrating core assets:
https://www.39digits.com/migrate-g-suite-account-to-a-person...
2. Sharing Play purchases via family sharing
https://www.quora.com/Can-you-transfer-your-Google-Play-purc...
3. Migrating YouTube channel between accounts via Brand Channels https://support.google.com/youtube/answer/3056283?hl=en
So it appears there is no one-click or Google support method for migration to a personal Google account and you cannot ever have a Google account with the same email address except for reactivation of a Workplace subscription. You can move virtually everything with Takeout and use account sharing features for the rest (so long as you have a small family…).
Not being flippant. Google's whole business model is predicated on operating like this. An accountable Google would probably be a very different company with different products.
(I work on Gmail, but that shouldn't really be relevant here)
Google also does that if I don't use Gmail but send email to someone with a Gmail account, or send email to an address that forwards to a gmail account, etc.
Or, you're part of the 95-99% for whom email and the Internet is of critical importance but because of the ease of access, and the technical minutiae, and generally misplaced trust in corporations, you never learn why this might matter.
Sorry to say it, but I find your comment condescending.
People are not used to email addresses with personal domains. I've had people get confused by my email address when I speak it to them. I've switched to just giving out my gmail address if I ever have to speak it instead of being able to write it down.
And developers don't account for custom domains when obscuring your email address. me@myfullname.tld is usually obscured as m**@myfullname.tld. That's pretty bad on password reset forms since it lets someone easily turn my username into my real name. If I had registered with myfullname@gmail.com, they'd get nothing interesting.
I've found if you use something like firstname@lastname.tld people generally get it if they've dealt with any other business email addresses (in some cases it actually makes you appear more professional). They usually have your first and last names before you get onto email addresses so they can piece it together and validate it.
If you're really worried about password resets showing your domain get a second domain and only use that for online transactions, it can then be as obscure as you like. Sure there's an extra cost to that but it's a trade off of cost vs the level of privacy you want.
It combines bad user experience with giving them too much power.
Google is really not our friend.
>If you use #Google Photos, there's a non-zero chance that there are secret, yet public URLs attached to your photos that allow un-authenticated access to every picture in your account. Mine did, and I tested the addresses in incognito and tor browsers and they worked. #privacy
This is not cool for me because I don’t want my photos available to people other than me, even if they have my magic url with a token I didn’t create and can’t revoke.
Or you can file feedback from the photo web page and just tag me in it.
Edit: I don't work on this stuff, but have seen it challenge me when trying to do this exact thing.
But for how long are they retained? Are they generated during the takeout process or do they exist since the photo was uploaded?
Maybe I'm just too jaded at this point
> When you delete data in your Google account, we immediately start the process of removing it from the product and our systems. First, we aim to immediately remove it from view and the data may no longer be used to personalize your Google experience. For example, if you delete a video you watched from your My Activity dashboard, YouTube will immediately stop showing your watch progress for that video.
> We then begin a process designed to safely and completely delete the data from our storage systems. Safe deletion is important to protect our users and customers from accidental data loss. Complete deletion of data from our servers is equally important for users’ peace of mind. This process generally takes around 2 months from the time of deletion. This often includes up to a month-long recovery period in case the data was removed unintentionally.
> Each Google storage system from which data gets deleted has its own detailed process for safe and complete deletion. This might involve repeated passes through the system to confirm all data has been deleted, or brief delays to allow for recovery from mistakes. As a result, deletion could sometimes take longer when extra time is needed to safely and completely delete the data.
> Our services also use encrypted backup storage as another layer of protection to help recover from potential disasters. Data can remain on these systems for up to 6 months.
> some data we retain for longer periods of time when necessary.
> We keep some data for the life of your Google Account if it’s useful for helping us understand how users interact with our features and how we can improve our services. For example, after you delete a specific Google search from My Activity, we might keep information about how often you search for things, but not what you searched for. When you delete your Google Account, the information about how often you search for things is also removed.
Incredibly vague, there is no reason email purchases couldn't be included in this category.
> Sometimes business and legal requirements oblige us to retain certain information, for specific purposes, for an extended period of time.
Again, "business requirements" can mean anything at all.
Now If Google decided to hold the records forever or far beyond any legal requirements then yeah that’s getting evil.
However, several DPAs and local governments have reviewed Google software for their own GDPR compliance. Several of those findings are available online. These findings don't result in fines, because it's not technically an investigation of Google. But it does involve a thorough investigation of the legal issues of using Google's services, and the results are illuminating.
For example, below is a link to a report the Dutch DPA complied on whether Dutch government agencies can use Google Workspace (formerly GSuite). The conclusion is that Google's privacy protection are catastrophically terribad (for a paid product!). It requires linking to a personal account, purposes of processing are not defined, there's definitely processing going on that's not covered by the contract, etc. Google's linking to personal data in a way that cannot be disabled by administrators means they are a Joint Controller instead of a Processor, and it's not possible for them to comply with various obligations because they're too vague about the purposes of processing.
https://www.rijksoverheid.nl/binaries/rijksoverheid/document...
Again, doesn't result in a fine, because they're not be investigated for violations. Someone is just asking "can we use a Google product?" But the results of that research indicate some deep structural problems.
Also that fine that France issued, where they somehow avoided invoking GDPR directly? Still the third-largest GPDR fine on record. So your expectations for fine amounts are a bit off.
They might be using this order to show what you’ve ordered recently on results or use it as suggestions on Google Shopping.
"Consumer Gmail content will not be used or scanned for any ads personalization after this change"
No longer in effect?
https://qz.com/1014816/google-will-no-longer-mine-your-email...
What do you estimate is the value of a dossier of all purchases I make over my lifetime? Or at least the ones Google knows about.
It seems to me that this is very useful and valuable.
Google's an advertising company. How is having a complete list of all the products I've purchased online not valuable? Seems like a great indication on what kinds of products Google can turn around and advertise back to me.
There is no way to know for sure unless someone wants to do an experiment. It would be pretty easy to conduct: do takeout to find a purchase in the history, delete emails associated with the specific purchase, empty the trash, wait sixty days, then takeout again and check if the purchase is gone. But we won't find out today.
Doesn't matter - I wouldn't want them storing purchase data for things I bought from other companies at all.
That entire maneuver was just to plant tracking cookies into your OTHER browser, for use to track you later on. Dirty, dirty stuff.
Another thing is, do they have a back up of data from the Myaccount. Subdomain that users delete.
Still I trust google and amazon more than Microsoft and apple and Facebook. Just me personal view, I could be totally wrong. The ones I trust are simply more open about data storage and have less dark patterns and clandestine TCS. But yes, wide spread Gmail usage will make google see many things and they will collect a lot of data. Probably even more delicate data than what Facebook gets to see.
1. Log in to gmail 2. Navigate to account settings 3. Select an "enhanced privacy" option 4. Enter a credit card number
The user now owns all of their own content - no sharing without the user's permission.
Replies here show a lot of animosity and distrust... not saying I disagree in general, but on this particular point the response from multiple levels has been unequivocal that "this is not happening", and I believe it.
Only a fool would use Gmail.
If they are so evil and clever, I at least make them work through a lot of bull shit before they profile me.
My emails are at Fastmail as a paid user. Hopefully they are away from advertising companies. But, any Gmail user I have emailed would leak that info to Google.
- Oh, I dont know. Maybe i think my data is worth more than what they give you in kickbacks.
Google: X likes dildos
Dildo Salesperson: Google, who likes dildos?
Google: X
User X: deletes dildo receipt email
Salesperson: Is X still into dildos?
Google: Yeah, they just don't like receipts.
I made an account just to try it out but then I saw all the advertisements it added. Seeing ads based on the content of my email was really creepy. I stopped using Gmail and now I pay Fastmail for my email. It seems worth it to me.
I would expect nothing less of Hacker News veterans.
Apparently. Haven't tested myself yet.
After linking your credit history the targeting and linking of information that would follow would be a privacy blackhole that would be hard to recover from.
And yes, if you bought burgers and fries in the US you actually did pass KYC/AML laws, you are just completely unaware of it. The KYC (know your customer) laws applied when you created your financial account, your bank is obligated to check your identity before creating an account, and the AML laws are about monitoring financial transactions for something fishy.
Here in the US, you need a paper trail for deposits greater than $10k, and banks are on the lookout for “structured” deposits that side step this requirement. So buying a burger occasionally is fine, but if you started buying $15k worth of burgers a month, you’ll start tripping financial systems wondering if you’re doing something illegal.
As a practical matter, this is one reason why people joke about cash only businesses being a front. A cash only laundromat or restaurant is a fantastic way to clean dirty money for use in the us market.
Most likely a $10K deposit will be reported to the tax department by my bank. If they find that suspicious income they can then notify law enforcement or commence an audit. But otherwise it's no one's business how many burgers I buy.