Is it possible to be a "white hat" hacker if you weren't actually contracted by the target for penetration testing?
Mostly this is just to evaluate the product and to see if it is trustworthy, but they'll often send along a polite FYI to the site owners letting them know if they have security issues that need addressing.
Actions like that: finding vulnerabilities, privately disclosing them, not disrupting the service, are all fairly innocuous things that most reasonable technically savvy people would consider 'white hat'.
It sucks, but if your goal is to avoid legal drama, don't test without permission.