Live data from Hacker News

Removing email registration improved retention

solitaired.com

71–80 of 180 posts

Re: Removing email registration improved retention

#71

Earlier quoted context omitted.

> you target Facebook/Google ads specifically at that email address That is scummy as hell and might even get you in trouble when it comes to the GDPR if you're operating in the EU. If I sign up for your web service the last thing I want is Facebook/Google knowing that fact.

This is a core feature of every ad platform I've seen and is absolutely not a violation of the GPDR since users are giving consent when they signup. You've signed up for a web service and never seen ads on other sites for it ? Very strange.

I agree that this is a core feature. However, the GDPR mandates that consent should be opt-in, granular (you can provide consent for your data to be used for one purpose but not another) and you can't refuse service because a user is refusing to consent to non-essential data processing (ads would fall into that).

So yes, technically you can ask the user for consent, but it has to be explicit ("we'd like to share your e-mail/phone number with our advertising partners such as Facebook, accept/decline?") and I can't imagine anyone in their right mind consenting to that.

> You've signed up for a web service and never seen ads on other sites for it ? Very strange.

I sign up for stuff only when I have no other choice for exactly this reason, and often provide fake details. Reminds me of an ex-client where they had an issue with their potential customers not providing the right contact details because they're afraid we're going to spam them. "But do we actually spam them? -Yes."

Re: Removing email registration improved retention

#72

This is not advice any startup should ever listen to. The most successful and lucrative form of marketing, by far, is re-marketing. That is where you take someone who signed up but is not currently a customer and you target Facebook/Google ads specifically at that email address. I've seen conversion rates as high as 30% and it's typically pretty affordable. It's such a critical part of marketing that many companies w…

> you target Facebook/Google ads specifically at that email address That is scummy as hell and might even get you in trouble when it comes to the GDPR if you're operating in the EU. If I sign up for your web service the last thing I want is Facebook/Google knowing that fact.

Ask yourself this: Would you rather have targeted ads, for something you might be interested in, or completely random junk you couldn't care less about? Targeted advertising benefits both you and the advertiser.

Re: Removing email registration improved retention

#73

Earlier quoted context omitted.

> you target Facebook/Google ads specifically at that email address That is scummy as hell and might even get you in trouble when it comes to the GDPR if you're operating in the EU. If I sign up for your web service the last thing I want is Facebook/Google knowing that fact.

Ask yourself this: Would you rather have targeted ads, for something you might be interested in, or completely random junk you couldn't care less about? Targeted advertising benefits both you and the advertiser.

Targeted advertising creates a liability for me in the form of leaking which services I use to a third-party advertising partner I may have no relationship with and haven't accepted their privacy policy (the service itself doesn't know whether I use Google/Facebook and sends them the information regardless).

If advertising was targeted at the browser level (the browser has access to the entire catalog of ads out there and then does the selection locally based on sites/services I interacted with previously) then I would be in favor of that.

Finally you are omitting a third option in your comparison: how about no advertising at all? Preferring paid services over ad-supported ones and countermeasures like uBlock Origin make that a real possibility. I can't recall the last time I've seen a proper ad online (in fact my problem with the parent's idea is more about the data sharing than the ads themselves since I won't see the ads anyway).

Re: Removing email registration improved retention

#74

Earlier quoted context omitted.

> you target Facebook/Google ads specifically at that email address That is scummy as hell and might even get you in trouble when it comes to the GDPR if you're operating in the EU. If I sign up for your web service the last thing I want is Facebook/Google knowing that fact.

Ask yourself this: Would you rather have targeted ads, for something you might be interested in, or completely random junk you couldn't care less about? Targeted advertising benefits both you and the advertiser.

How about zero ads instead?

Re: Removing email registration improved retention

#75

Earlier quoted context omitted.

> you target Facebook/Google ads specifically at that email address That is scummy as hell and might even get you in trouble when it comes to the GDPR if you're operating in the EU. If I sign up for your web service the last thing I want is Facebook/Google knowing that fact.

This is a core feature of every ad platform I've seen and is absolutely not a violation of the GPDR since users are giving consent when they signup. You've signed up for a web service and never seen ads on other sites for it ? Very strange.

> users are giving consent when they signup

Questionable. I guarantee the vast majority of users don't even read the massive legalese text walls companies show them before they sign up. Usability studies have shown that people don't even read small error messages, they just want to get rid of the annoying message as quickly as possible. The few of them that actually do read these things probably won't have the foggiest idea what any of it means or the risks associated with the breach of their privacy. So how could this be real informed consent?

Of course, we also have sites where this document is not shown at any time and can only be reached through a link buried in the page's footer. Sites that just write whatever terms they want into this hidden page and then say everyone is agreeing with it by virtue of using the site.

Re: Removing email registration improved retention

#76
post #33

The article mentions the tradeoff of username Vs email of increased willingness for people to sign up Vs losing the simple channel for password reset, but does not propose a solution outside of non-expiring cookies, which to me isn't really a satisfactory solution (though perhaps it works OK enough in practice for some types of use cases). In my view, for most applications, the upside is not really worth that downsid…

I ran a small system for awhile where you could designate three other users to act as backup. If you needed to reset your password each of the three backups would receive a unique token and a request that they forward it to you out of band. With all three tokens you could reset your password. This was optional, though, and in addition to a classic email based reset flow. Obviously a solution like this would only real…

Could you set a minimum amount of time since last login / visit before recovery was possible? If you are visiting the site every day, and your three "friends" decide to collude to reset your password, the site should refuse to issue the tokens since you are still able to access it.

This gets a little more tricky if you have an unexpired session but want to be able to change your password (which likely requires knowing the existing password), but a request from this logged in session to reset your password should be trustable (unless your "friends" have also stolen your unlocked device).

Similarly, if one or more of your "friends" requests a token / password reset of your acccount, the site should highlight that in a banner on every page you visit, to potentially give you warning to find better friends. (The process for replacing a friend on the site should probably require re-entering your password too, to stop someone that's hijacked your session from picking three sock puppet accounts as your new friends, and resetting your password that way).

Re: Removing email registration improved retention

#77

I have a fake email address I use to sign up when I am forced to. I login to that email account once every month not to lose access, but other than that it is a huge swamp of unread emails.

I use 10minutemail.com for this.

Sadly though, it appears all these temporary mail domains are in some central list, that data harvesters use to deny access. It's almost impossible to sign up for forum accounts with these. So it's impossible to download files from vinylengine.com unless you allow them to spam you.

Re: Removing email registration improved retention

#78

Earlier quoted context omitted.

> you target Facebook/Google ads specifically at that email address That is scummy as hell and might even get you in trouble when it comes to the GDPR if you're operating in the EU. If I sign up for your web service the last thing I want is Facebook/Google knowing that fact.

Ask yourself this: Would you rather have targeted ads, for something you might be interested in, or completely random junk you couldn't care less about? Targeted advertising benefits both you and the advertiser.

I would much prefer ads for random junk. 100%.

Re: Removing email registration improved retention

#79
post #3

I'm fairly certain I would rather collect the emails even if it means less retention. Not for marketing purposes but for support purposes. With MakePostSell [1] a customer may add products to their shopping cart and interact with a shop as if they are logged in, but at the point of sale / checkout, we ask them to verify their email. [1] https://www.makepostsell.com

Even the article says this creates "issues for password recovery."

Yea, but you've lost access to a card game score, so nobody really cares.

Re: Removing email registration improved retention

#80

Earlier quoted context omitted.

This is a core feature of every ad platform I've seen and is absolutely not a violation of the GPDR since users are giving consent when they signup. You've signed up for a web service and never seen ads on other sites for it ? Very strange.

> users are giving consent when they signup Questionable. I guarantee the vast majority of users don't even read the massive legalese text walls companies show them before they sign up. Usability studies have shown that people don't even read small error messages, they just want to get rid of the annoying message as quickly as possible. The few of them that actually do read these things probably won't have the foggie…

A legalese wall or a banner saying "by using this site you agree to ..." is not GDPR-compliant anyway: https://ico.org.uk/for-organisations/guide-to-data-protectio...

Under the GDPR, any non-essential data processing (analytics, ads, marketing, etc falls into that) should be opt-in and dark patterns like pre-ticked checkboxes are not allowed.

Post reply on HN