Micropayments company Coil distributes new privacy policy with email that puts users’ addresses in the ‘To:’ field

Micropayments company Coil has emailed users its new privacy policy but placed hundreds of their addresses in the “To:” field and therefore breached their privacy.

The mail had the Subject line “Updates to Coil’s Terms and Privacy Policy” and offered links to the document. The Register has read it and can report that while it reveals that Coil seeks permission to share users’ details with service providers, partners, and “related entities”. We cannot find a clause that resembles: “We reserve the right to expose your email address to countless other Coil users in the ‘To:’ field of an email.”

The tweets below are typical reactions to the situation.

At the time of writing the mails appear not to have spawned a Reply-All storm. The Coil user who tipped us off to the situation told us he was “tempted to start one” and reported “everyone’s been well behaved. They sent it from a no-reply email address anyway :)”.

Coil has become aware of the incident and sent an apology email with a subject line “Please forgive us”.

Founder and CEO Stefan Thomas offered the following sentiments:

The company has not addressed other questions we asked regarding how the incident occurred and its plans to prevent similar events in future.

Coil offers a service that charges users $5 a month, then shares that sum with publishers and content creators. The company offers the latter a chance to monetise their work without having to operate a subscription service. Users get the chance to send some cash to sites they appreciate. ®

Source link

Related Articles

Back to top button