Live data from Hacker News

Removing email registration improved retention

solitaired.com

121–130 of 180 posts

Re: Removing email registration improved retention

#121
post #92

>you can target them on Quora, Reddit etc as well. This is one of the reasons I stopped giving out my primary email address for user signups. I use a service called Blur which allows for unlimited "masked" emails to be created, allowing me to give companies read-only email addresses. In the four years I've had it I have created 378 email addresses. If I'm including the email addresses that I've already deleted, the l…

Once the marketers discover people are doing this, they'll ban email addresses from this service as if they were fraudulent. Wouldn't be surprised if companies started disallowing everything except gmail.

Re: Removing email registration improved retention

#122
post #92

>you can target them on Quora, Reddit etc as well. This is one of the reasons I stopped giving out my primary email address for user signups. I use a service called Blur which allows for unlimited "masked" emails to be created, allowing me to give companies read-only email addresses. In the four years I've had it I have created 378 email addresses. If I'm including the email addresses that I've already deleted, the l…

If you're using gmail, plus-suffixing is a low-effort but effective countermeasure: username+servicename@gmail.com gets delivered to username@gmail.com.

Re: Removing email registration improved retention

#123

Earlier quoted context omitted.

Exactly, and this is why users don't want to give it to you.

I would much rather get an ad from someone I shared my email address with than whatever random businesses decided to pay google/facebook/etc the most

I used to think that way too, then changed my mind.

I'd rather get random, un-targeted, irrelevant, and even annoying ads from companies that have no idea who I am or that they're even advertising to me.

Less creepy that way, also more likely to result in the serendipity of learning new things outside my filter bubble/what the algorithm predicts for me.

Sometimes in order to find the real signal, you have to accept that a lot of noise comes with it.

Re: Removing email registration improved retention

#124
post #92

>you can target them on Quora, Reddit etc as well. This is one of the reasons I stopped giving out my primary email address for user signups. I use a service called Blur which allows for unlimited "masked" emails to be created, allowing me to give companies read-only email addresses. In the four years I've had it I have created 378 email addresses. If I'm including the email addresses that I've already deleted, the l…

Care to provide a link for the service you're using?

I run https://kopi.cloud - let's you give out burner addresses you can just make up on the fly. SSO through Google, Facebook, Twitter. One touch blocking of burner addresses. Supports replying and attachments. Mail 2 RSS - read Facebook / StackOverflow, newsletters, etc. as RSS feeds. And you can use your own domain if you want, so no lock-in.

Re: Removing email registration improved retention

#125

Earlier quoted context omitted.

> you target Facebook/Google ads specifically at that email address That is scummy as hell and might even get you in trouble when it comes to the GDPR if you're operating in the EU. If I sign up for your web service the last thing I want is Facebook/Google knowing that fact.

This is a core feature of every ad platform I've seen and is absolutely not a violation of the GPDR since users are giving consent when they signup. You've signed up for a web service and never seen ads on other sites for it ? Very strange.

This is a core feature of every ad platform I've seen and is absolutely not a violation of the GPDR since users are giving consent when they signup.

I think we'll see regulators take a different view when they get around to challenging this practice, and the businesses who get made into examples might find it an expensive lesson. Handing over personal details to big data hoarders for remarketing purposes is the epitome of behaviour the GDPR was intended to curtail. You can't just mutter the word "consent" and claim some small print on a Ts & Cs page no-one reads protects you, and regulators have shown very little sympathy so far for data controllers who have tried to weasel their way out of GDPR obligations with this kind of strategy.

Those regulators are still under-resourced and it will presumably take some time for them to get around to dealing with this issue. Right now they're still going after serious leaks and the like. But they're already handing out 9-figure fines to big name businesses for those breaches, and by default those fines go back into central government coffers. Given the current economic climate, how long do you think it will be before their governments realise that this is potentially a very lucrative revenue stream that the public is unlikely to mind, and so start pushing the funding for those regulators up? The ICO (the UK's regulator) has already significantly increased its budget and headcount since the GDPR came into effect, and is reportedly looking at ways to ringfence some of the fines to cover the litigation costs when it inevitably has to defend the big penalties it will hand down from time to time.

When the Cambridge Analytica scandal happened here in the UK, the ICO fined Facebook £500,000. That was the largest fine they could legally impose at the time. As they observed themselves, in what might charitably be considered a thinly veiled threat, under the GDPR that could have been well over £1B instead. Even an organisation the size of Facebook is going to feel that, particularly since there is nothing that says it can't be repeatedly fined on that scale if it misbehaves in multiple different ways.

A couple of potentially important issues have, as far as I know, not yet been resolved in this area.

Firstly, what happens if processing in violation of the GDPR is widespread, the businesses you give your address to are the data controllers, but you still have the likes of Facebook hoovering up huge amounts of personal data inappropriately but possibly only in a capacity of data processor? No doubt there will be some interesting legal arguments about where liability is going to be placed if Facebook was actively soliciting that sort of activity as part of its business model.

Secondly, what happens after the UK has fully separated from the EU at the end of this year, if as the government has stated we retain the GDPR in our national law? Until Brexit was relevant, the GDPR was an EU-wide measure, and typically one member state's regulator would take the lead role in any given case. Anyone breaking the GDPR's rules could be duly investigated and penalised, but only once, not in the same way by every regulator in every member state where there was offending behaviour. If the UK is no longer to be a part of that scheme, will regulators still co-ordinate in this way, or will the businesses sharing data with Facebook face a kind of double jeopardy where both the UK and a lead regulator from an EU member state can potentially fine them for the same behaviour, effectively doubling the maximum penalty they could receive?

If both of those issues were resolved in ways unfavourable to the marketing platforms like Facebook, they could be looking at huge fines for promoting this sort of scheme on the scale that they do, potentially enough to make whole strategies based on selective targeting unviable.

Re: Removing email registration improved retention

#126

Earlier quoted context omitted.

> users are giving consent when they signup Questionable. I guarantee the vast majority of users don't even read the massive legalese text walls companies show them before they sign up. Usability studies have shown that people don't even read small error messages, they just want to get rid of the annoying message as quickly as possible. The few of them that actually do read these things probably won't have the foggie…

A legalese wall or a banner saying "by using this site you agree to ..." is not GDPR-compliant anyway: https://ico.org.uk/for-organisations/guide-to-data-protectio... Under the GDPR, any non-essential data processing (analytics, ads, marketing, etc falls into that) should be opt-in and dark patterns like pre-ticked checkboxes are not allowed.

Under the GDPR, any non-essential data processing (analytics, ads, marketing, etc falls into that) should be opt-in

This isn't strictly true. Consent is only one lawful basis for processing under GDPR, and it comes with a lot of strings attached that other bases don't necessarily have, which is why so many lawyers and consultants were recommending against relying it unless it was the only way during the mad rush to GDPR compliance a few years back.

In particular, even some of the regulators have themselves indicated that marketing might be a legitimate interest of a business. Obviously the details matter here, and handing personal data over to third parties like Facebook without their knowledge or consent seems materially different to, for example, the original business sending a relevant email about a new product that is related to something that the recipient already bought from them. Time will tell how the regulators decide to handle this.

Re: Removing email registration improved retention

#127

This is not advice any startup should ever listen to. The most successful and lucrative form of marketing, by far, is re-marketing. That is where you take someone who signed up but is not currently a customer and you target Facebook/Google ads specifically at that email address. I've seen conversion rates as high as 30% and it's typically pretty affordable. It's such a critical part of marketing that many companies w…

> Are we the baddies?

And proud of it, apparently...

Re: Removing email registration improved retention

#128

This is not advice any startup should ever listen to. The most successful and lucrative form of marketing, by far, is re-marketing. That is where you take someone who signed up but is not currently a customer and you target Facebook/Google ads specifically at that email address. I've seen conversion rates as high as 30% and it's typically pretty affordable. It's such a critical part of marketing that many companies w…

> I've seen conversion rates as high as 30% and it's typically pretty affordable.

Just 30%? Pfft. Just wait until they become a customer, and then advertise to them. Bingo, 100% conversion success. Best way to do it? Advert on the conversion page. Customer pays money, you show them an advert, 100% relationship between the advert and conversions, sterling job, and you cut out the middleman because it doesn't need a third party agency to do the placement, so it's affordable even after your fees.

Re: Removing email registration improved retention

#129

Earlier quoted context omitted.

> you target Facebook/Google ads specifically at that email address That is scummy as hell and might even get you in trouble when it comes to the GDPR if you're operating in the EU. If I sign up for your web service the last thing I want is Facebook/Google knowing that fact.

Ask yourself this: Would you rather have targeted ads, for something you might be interested in, or completely random junk you couldn't care less about? Targeted advertising benefits both you and the advertiser.

Completely random junk 100%.

Need creation is not a benefit.

Re: Removing email registration improved retention

#130
post #92

>you can target them on Quora, Reddit etc as well. This is one of the reasons I stopped giving out my primary email address for user signups. I use a service called Blur which allows for unlimited "masked" emails to be created, allowing me to give companies read-only email addresses. In the four years I've had it I have created 378 email addresses. If I'm including the email addresses that I've already deleted, the l…

I registered a domain name that’s basically just a UUID, and pointed it’s MX records to my self-hosted email server (you could also point it to Google Apps or Fastmail).

Everything before the UUID domain is just the name of the service, so something like hackernews@e913ff00...xyz. If someone sells out my email address, I can instantly burn it by just adding a sieve rule since they’re all unique. I even know who sold it based on what name I picked before the @ symbol. This has been working out pretty well for me so far.

Post reply on HN