Live data from Hacker News

Didn’t Homejoy Shut Down?

medium.com

161–170 of 361 posts

Re: Didn’t Homejoy Shut Down?

#161

Earlier quoted context omitted.

Aaron, I was a homejoy customer. I am frustrated and concerned that my credit card # was sold to another company without my consent. How can users opt-out of having their data sold to flymaids (or any future ventures)? The fact that flymaids' site is a poorly-built clone of a competitor's site also makes me scared that my data is not being protected.

Your CC is probably safe on Stripe's servers. Which makes me wonder -- does Stripe allow entire accounts to change hands willy-nilly like this?

I was wondering the same thing about Stripe or any of the big credit card processors. That'd be shady.

Re: Didn’t Homejoy Shut Down?

#162

Earlier quoted context omitted.

Aaron, I was a homejoy customer. I am frustrated and concerned that my credit card # was sold to another company without my consent. How can users opt-out of having their data sold to flymaids (or any future ventures)? The fact that flymaids' site is a poorly-built clone of a competitor's site also makes me scared that my data is not being protected.

Your CC is probably safe on Stripe's servers. Which makes me wonder -- does Stripe allow entire accounts to change hands willy-nilly like this?

Are they using stripe on the new site(s)? Looks like those have all been taken down.

Re: Didn’t Homejoy Shut Down?

#163

Earlier quoted context omitted.

Aaron, I was a homejoy customer. I am frustrated and concerned that my credit card # was sold to another company without my consent. How can users opt-out of having their data sold to flymaids (or any future ventures)? The fact that flymaids' site is a poorly-built clone of a competitor's site also makes me scared that my data is not being protected.

Your CC is probably safe on Stripe's servers. Which makes me wonder -- does Stripe allow entire accounts to change hands willy-nilly like this?

My guess is the account never changed hands. Stripe can't really prevent a legitimate owner of an account from doing something stupid with it. At least, not until after the fact.

Re: Didn’t Homejoy Shut Down?

#164

Earlier quoted context omitted.

I am going to sound contrarian, but I don't mean to be. How does this violate PCI-DSS? The data itself is likely stored somewhere secure (who knows) – what's being displayed in the web app is the last four digits of the card and expiration date, this isn't where it's stored. There is obviously a question of what the retention should be, but it's definitely the case that payment information can be transferred between…

I thought it was pretty clear, but I'm willing to elaborate. The requirement is that card data is securely removed when it is no longer required. They are no longer billing customers at HomeJoy as the business has been wound up, so the credit card data should have been deleted. Also: no customer has given them any right to have their credit card billed to an entirely new entity. Credit card information should not be…

Yeah, I get your position (hopefully!), but I think I'd rather hear from a lawyer whether this is OK or not, my guess is that it is OK.

The snippet you pasted says also:

... regulatory, and/or business requirements

A business that is going out of business may treat this data as a business asset and may need to retain it for a certain period even when they are inactive.

Most terms of service do allow for transfer of account information to third parties, and have contingencies for what happens to the data if the company goes under, and as far as I'm aware, selling that customer data is an option unless they've explicitly said they won't.

As long as the credit card data is transferred in a PCI compliant way, it's legal.

You're absolutely right that it would be a serious violation if they were to charge someone without their knowledge, it doesn't look like that's happened yet.

It's also quite possible the underlying business entity is still Homejoy with a name change. ZenPayroll* didn't have to get people's permission to charge them when they changed their name to Gusto, but it obviously helps to communicate that change very clearly!

I am pretty sure we generally agree, though, it's very clear that there are dozens of egregiously bad things being done by Aaron and his team that can only hurt them and their desired future customers.

*I said Zenefits :( :(

Re: Didn’t Homejoy Shut Down?

#165
post #142

Earlier quoted context omitted.

In my experience, life is easier when you admit your mistakes without business speak, and just take the blame (for example: "I" instead of "We"). I've written a lot of mea culpas for mistakes which impacted customers, and the more direct and transparent I was, the better responses I always got. You made a mistake, you know you made a mistake. Admit it, apologize, and move on. Your excuses or context probably aren't g…

When that mistake might be very costly litigation-wise, and anything you say/do might be brought up in court, it's time to break out the business speak and obfuscate like there is no tomorrow.

Maybe. That sort of nonsense may decrease the odds of losing a lawsuit. But you increase your odds of having a lawsuit, because you leave more people mad at you.

That might be a good choice for a large company, as they already have lawyers on staff, can afford to pay for a lawsuit, and have enough money to advertise away the reputational stain.

I'm not sure it's a good idea for a startup, though. Unless you are well funded, just dealing with a lawsuit could be fatal given the reputational cost, the legal bills, and the amount of founder time that will get soaked up. Personally, I'd try to be human and humane about it.

Re: Didn’t Homejoy Shut Down?

#166

I'm one of the founders of Homejoy. I'm still very passionate about the home service space. After leaving Homejoy, I started FlyMaids, where we're exploring a few different angles on the space. We recently acquired the customer and service provider data from Homejoy. We're a small team that has been focused on moving quickly while bootstraping. We tried to quickly test different approaches, but we realize now that we…

You're passionate about a "space"?

And keeping it clean!

Re: Didn’t Homejoy Shut Down?

#167
post #120

From what I gather from the other comments, it looks like most likely Homejoy's liquidator (Nortonsgroup) has sold Homejoy's user data to Homeaglow. Homeaglow copied and rebranded their own tech as Fly Maids to service this user list.

> has sold Homejoy's user data to Homeaglow Sold it with credit card numbers attached though? That sounds awfully.. illegal even for a liquidation.

They probably just exported a database of credit card tokens into a PCI-compliant system (Stripe, Braintree or the like.) The motives and method are equally shitty, but at least get some solace in assuming that your credit card number is just not out in the open.

Now... how secure this transfer of tokens was, no idea. So there could be a DB dump somewhere with a token to my credit card, and anyone can use it to start charging from it. I'll keep an eye on my bills.

Re: Didn’t Homejoy Shut Down?

#168

Earlier quoted context omitted.

Aaron, I was a homejoy customer. I am frustrated and concerned that my credit card # was sold to another company without my consent. How can users opt-out of having their data sold to flymaids (or any future ventures)? The fact that flymaids' site is a poorly-built clone of a competitor's site also makes me scared that my data is not being protected.

Your CC is probably safe on Stripe's servers. Which makes me wonder -- does Stripe allow entire accounts to change hands willy-nilly like this?

Most likely they just have the same API keys

Re: Didn’t Homejoy Shut Down?

#169

Earlier quoted context omitted.

Aaron, I was a homejoy customer. I am frustrated and concerned that my credit card # was sold to another company without my consent. How can users opt-out of having their data sold to flymaids (or any future ventures)? The fact that flymaids' site is a poorly-built clone of a competitor's site also makes me scared that my data is not being protected.

Your CC is probably safe on Stripe's servers. Which makes me wonder -- does Stripe allow entire accounts to change hands willy-nilly like this?

I was also thinking through which rules would apply here. (What entity owns a Stripe account? What constitutes a transfer of data? How does this case differ from say, an acquisition?)

The medium article only shows info you can get from a Stripe card_id request. Not using https on that page is troublesome, but I don't think there's any evidence to suggest FlyMaids (or even HomeJoy) ever had access to actual CC information.

It seems more likely that this depends on Homejoy's ToS/Privacy Policy. (Although it's certainly possible the transfer was done in a way that violates Stripe's policies, I'm just not familiar with those)

Edit: It might even be the same business entity with different d.b.a names. Good discussion here: https://news.ycombinator.com/item?id=10468161

Re: Didn’t Homejoy Shut Down?

#170

I'm one of the founders of Homejoy. I'm still very passionate about the home service space. After leaving Homejoy, I started FlyMaids, where we're exploring a few different angles on the space. We recently acquired the customer and service provider data from Homejoy. We're a small team that has been focused on moving quickly while bootstraping. We tried to quickly test different approaches, but we realize now that we…

[deleted]
Post reply on HN