Assuming that you're completely legit and utterly competent, there's still a big security problem here: it's encouraging people to put their PII and CC info into arbitrary Web sites . On top of that, it's further identifying them as both Chase CC holders and receptive to scams, qualifying them as leads for further phishing/scamming.
It seems to me that it's pretty flimsy? In particular:
> To conduct research and to improve and promote our services . We use the information wecollect to conduct research and to improve or enhance and promote our Services.
Both promotion and research are pretty damn broad terms, right?