|
|
|
|
|
by hnbad
927 days ago
|
|
Simple: explicitly state what regions you provide your service to, optionally use cheap/free IP geolocation to block users from regions you don't wish to provide your service in and wherever you have to record a user's region anyway limit the options to regions you support or display a warning about your terms of service prohibiting use from other regions. There are plenty of sites that only cater to US users and have signup forms requiring data like postal addresses or payment methods that contain regional information. Heck, some US sites even exclude users from certain states for various reasons. This service costs money so they need the user's billing address anyway. Just restrict access there and then like the rest. The guy who created omg.lol did not "spin up a webserver and charge for access", they run a company that collects, stores and processes their users' behavioral data and personally identifiable information. It's more like a hosting company except it's apparently cobbled together from various third parties without any due diligence about how they operate. And it even uses the phrase "privacy-focused" in various parts of its claims. Yeah, I'd say it's reasonable to expect a company like that to provide basic information like what data it collects, how it ensures that data is protected and how a data subject can get that data deleted or corrected. We have laws preventing corporations from selling products that are unfit for purpose or food that is blatantly toxic and we have laws preventing corporations from offering you contracts that demand personal harm or indentured servitude. In places like the EU we also have laws that prevent companies from using your data without consent and making sure you follow the best current practices when handling that data. And yeah, if you want to make a service that collects all data and monetizes the ever living fuck out of it you can still do that, you just need to ask your users for consent and allow them to opt-out if it isn't essential to doing what the users would want to use the service for (i.e. no bait and switch). I don't know why some people find it so hard to understand the idea of informed and non-coerced consent. |
|