Skip to content
This repository has been archived by the owner on Dec 26, 2023. It is now read-only.

Privacy policy updates (summer 2022) #116

Merged
merged 9 commits into from
Jul 18, 2022
Merged

Conversation

abigailsphillips
Copy link
Contributor

@abigailsphillips abigailsphillips commented Jul 11, 2022

We have made a number of edits to our privacy policy to bring it up to date, remove sections that are no longer current, and to add some limited marketing objectives. Following is a summary of changes:

  • Updated to reflect company name change from Basecamp to 37signals
  • Added new disclosures for newsletter & surveys
  • Added retention of user identifiable web analytics data as long as account is active
  • Added provision for limited analytics on users coming to Basecamp.com from contextual ads (where permitted)
  • Added provision for sharing one-way hash of email address for ad exclusion (where permitted)
  • Added limited exception to law enforcement compliance policies for emergency requests
  • Removed warrant canary (we still have never received a NSL or FISA order, but we are removing this language now to avoid a future situation where we receive one but are not permitted to remove the statement from our policy)
  • Updated notice provision for more discretion over how to provide notice
  • Removed "Information we do not collect" section
  • Merged Privacy Regulations Reference (https://basecamp.com/about/policies/privacy/regulations) with main privacy policy and removed the webpage

We also updated both the Privacy Policy and the Cancellation Policy to clarify what is deleted when an account is canceled.

Clean version of the new policy with all current changes: https://github.com/basecamp/policies/blob/8fce58f5033eae642b20f89783d3228daa058e97/privacy/index.md

Minor edits to introduction to notify of new policy and company name change.
Updates to "What we collect and why" section, including:
- Added survey and newsletter disclosure
- Provided for retention of user identifiable web analytics data as long as account is active
- Removed "Information we do not collect" section
- Minor line edits
Updates to "When we access or share your information" section, including:
- Added provision for sharing one-way hash of email address for ad exclusion
- Added limited exception to compliance with LE for emergency requests
- Removed warrant canary (we did not receive a NSL or FISA order; however, lest we receive one and not be permitted to remove this language, we are choosing to avoid the risk of misleading users by removing it now)
- Minor line edits
Updates to "Your rights with respect to your information" section:
- No substantive changes
- Minor line edits
Updates to "How we secure your data"" 
- Line edits; no substantive changes; 

Updates to "What happens when you delete data in your product accounts"
- No substantive changes
- Line edits including some clarification of what we mean by "data"

Updates to "When transferring personal data from the EU"
- No substantive changes

Updates to "Changes & questions"
- Remove specifics about how 37signals will provide notice of significant privacy policy changes so that it is discretionary
Clean-up commit for missed updates (from manual compare of GH preview and Gdoc redline)
Clarified what is deleted when an account is canceled.
Clean-up commit
@basecamp basecamp locked as resolved and limited conversation to collaborators Jul 11, 2022
@dhh dhh marked this pull request as ready for review July 11, 2022 15:47
@dhh dhh changed the title Ap/privacy summer 2022 Privacy policy updates (summer 2022) Jul 11, 2022
@seanmitchell seanmitchell merged commit 9faa05b into master Jul 18, 2022
@seanmitchell seanmitchell deleted the ap/privacy-summer-2022 branch July 18, 2022 16:09
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants