However, would decent if they allowed selective Dropbox permissions (eg limited to a single folder). It's disturbing when startups (even a single individual/founder) has access to all my private data. It's not necessary most of the time either.
"Please trust us" seems suboptimal.
That you don't isn't really an argument for them changing their practices.
For example Mint.com keeps your banking passwords in order to do offline-logins, but people still trust Mint not to steal their money.
If many people don't trust a startup, I think they likely need to change their presentation style and not their practices.
As one data point, my credit union specifically recognizes accesses to my account from Yodlee, due to my Mint usage.
Zapler does not have as much practice so screw-ups are more likely.
The Zapier people are probably decent and honest etc, however that's not the point. It introduces a new security threat and attack vectors unnecessarily
It violates the principle of needing just enough access, to perform a task.