One privacy issue I'm seeing is that it seems like the users device still needs to make a request to get the metadata? So the retailer could use fingerprinting of requests to track people around. I wasn't entirely clear on where the metadata comes from so I could have this wrong.