Well that’s fresh. But if the user data is anonymized, it’s OK, right? I’m assuming there isn’t any other PII.
> name, address, credit card, etc.
31–40 of 54 posts
Well that’s fresh. But if the user data is anonymized, it’s OK, right? I’m assuming there isn’t any other PII.
> name, address, credit card, etc.
I think it's pretty rare that a business is going to erase all record that a transaction ever occurred, particularly a transaction involving other people (merchants, gig workers). Rather they are going to erase your association with the transaction, by rewriting your account as a "tombstone" account with fake details. That's a pretty normal approach.
If it really keeps credit card details, that’s way more than just a tombstone.
Suppose HelloFresh found out they should give you a refund after you deleted your account. Would they need the credit card to do that?
Earlier quoted context omitted.
If it really keeps credit card details, that’s way more than just a tombstone.
(Asking out of ignorance, I don’t know how this works) Suppose HelloFresh found out they should give you a refund after you deleted your account. Would they need the credit card to do that?
Or they could call you and ask.. oops now they need your phone number
etc
Somehow this doesn't surprise me, they still want to be able to spam you with offers (I legit got a text today from Martha and Marley, I have not used them for 3+ years) and possibly sell your data to make more money. It does bring up an interesting idea, how many people use unique emails for each company to track spam. If something like that was possible for shipped goods (wouldn't work well for food but that is the…
For gmail and fastmail, you can use jim+xyz@gmail.com and change the xyz for every new email signup.
Earlier quoted context omitted.
If it really keeps credit card details, that’s way more than just a tombstone.
(Asking out of ignorance, I don’t know how this works) Suppose HelloFresh found out they should give you a refund after you deleted your account. Would they need the credit card to do that?
I think it's pretty rare that a business is going to erase all record that a transaction ever occurred, particularly a transaction involving other people (merchants, gig workers). Rather they are going to erase your association with the transaction, by rewriting your account as a "tombstone" account with fake details. That's a pretty normal approach.
No, it's not uncommon to "tombstone" data, but when you do that, you should remove data you have no rights to any more. Order numbers, accounting, payments that sort of stuff is all fair game (for limited time), but the point here is it appears they're not deleting anything, they're just moving it to be inaccessible to the user.
They keep the data. And that's a) scummy and b) illegal in several jurisdictions.
Convenient and interesting as they are, you have to do your own maths and adjust portion sizes accordingly. By the time you've done that, it's easier to just cook something you're used to cooking @500kcal.
Sadly many companies do the same thing, violating the GDPR, even EU-based companies who know better. I wonder if engineers who built and have knowledge of these systems could anonymously disclose/leak details of violations to a site pairing them with other engineers. The other engineers could submit a GDPR forget-me request, which the company wouldn't be able to fulfil, and then people could complain to the national…
A disgruntled former employee makes a GDPR request, etc.
Earlier quoted context omitted.
Article 17 of the GDPR would disagree. """ “The data subject shall have the right to obtain from the controller the erasure of personal data concerning him or her without undue delay and the controller shall have the obligation to erase personal data without undue delay” if one of a number of conditions applies. “Undue delay” is considered to be about a month. """
Does that include data contained in their x years of backups?
If you're keeping data for years, it's an archive and not a backup.