If the data is only shared in an aggregate fashion, I doubt they can do much without a subpoena. And then what? Sue the website? Sorry, no. Section 230.
John Doe suits against anonymous customers?
Nothing requires PriceLevel to retain the PII of users… they can capture the data, validate, and flush the PII. “Sorry, we have no information about the contributor of this data.”
My sense is this will be the primary innovation of this service— how to get this info and keep it useful to end users without very much ability to vet it. Worth the effort.