Why Privacy Policies Suck
iubenda.com
iubenda.com
If you give people a good overview of what you are doing with their data, a significant portion will get pissed off. If you bore them with legalese, 99.9% of them will just sign, rather than wade through the terms.
It's broken, but it's broken by design.
https://github.com/wetalky/privacy-policy/blob/master/POLICY...
We're trying to be completely open with updates to this document, and we welcome outside commits. We intend to do the same with our ToS.
I'm not sure anyone has tried this before, so I'm really excited to see where this experiment goes.
Also think about Creative Commons: many people use it and many people rely on it when needing to know how to share content. The world is a better place with Creative Commons, and I think it will be a better place with simpler Privacy Policies and TOS :)
Firstly, "[...] and any other information I've shared with anyone" could quite easily result in people accidentally permitting access to data they didn't mean to. In contrast to it being viewed by anyone, there is a good chance that data will be stored elsewhere and stashed, regardless of whether the user later notices and removes it.
Having some mechanism to fully disclose what your "any other information" is, from that popup, might help people to notice accidentally shared data sooner, and prevent them sharing it with people who are storing it. The UI might take a little work, but afaik they've already got "view my profile as $foo" abilities, but that's tied to the account privacy settings pages, and not directly accessible from this sort of popup.
Secondly, and maybe not nearly as practically, but it'd be nice to see actually optional disclosure settings for apps like this. Android has a similar problem with its apps, it tells you what (coarse-grained) permissions it requires, but you only get a choice of all or nothing.
Granted, it doesn't make much sense to install your GPS-map application without giving it access to your GPS data, but in the Facebook realm, there can definitely be data or services which you want to consider optional.
There's probably even a business model in charging users (more) if they wish to disclose less about themselves, making them less attractive from your advertising revenue. The major problems I can foresee are (a) microtransactions, and (b) actually making your user aware you're effectively selling their personal details in exchange for providing them with whatever service.
Facebook has probably reasons for not including too much detail on that page, but Facebook also uses users' data like nobody else. For the average website this problem is much simpler, even for the average SaaS startup which is not a social network (or a simple one like Quora). Probably that kind of website can really have a privacy policy covering every personal data use within a simplified popup, without missing relevant information.
The Facebook's popup surely has issues, but I still love it since it's something people read, and it helps people take better choices. This is what, to me, is really important of Privacy Policies.
Yesterday I observed that companies still sell products in that hard-to-open plastic packaging that has injured a lot of people. That this packaging is still common indicates to me that we do not in fact live in a sue-happy society.
I recently wrote a privacy policy for my new startup; I think it complies with all but two of those guidelines (lightbox and standardised). Any feedback would be appreciated: https://theescortcompanion.com/privacy/
What do you think?
You're right about the parties involved - I also forgot to mention our location/jurisdiction. Thanks for the feedback!
I agree with 'broken by design' in many cases, but first step is at least having a non-broken design.
That said, I definitely agree that putting a simpler layer on top of it so non-lawyers can get the gist of your policy quickly is a great idea - now item 1,000,001 on my startup's to-do list!