On Wednesday, July 25, 2012 11:39:50 PM UTC-7, Justin Dolske wrote:
> On 7/25/12 3:33 PM, Winston Bowden wrote:
> 
> 
> 
> > To do so, we would like to provide users with the ability to enter
> 
> > their mobile phone number to receive a text to their phone containing
> 
> > the download link.  Although a one-time use, we’d need to keep their
> 
> > phone number to protect against abuse (someone entering the same
> 
> > number multiple times).  We’d also like to include a checkbox for
> 
> > users who would like to opt-in to ongoing SMS messages from Mozilla.
> 
> 
> 
> Overall, this sounds pretty reasonable. But I'd want to ask a couple of 
> 
> questions:
> 
> 
> 
> 1) How reliable/trustworthy are such vendors? I never opt-in to such 
> 
> things (and, conversely, always opt-out :), but have noticed what seems 
> 
> like a trend of getting unwanted spam long afterwards. I can only assume 
> 
> this is a result of sly/aggressive marketers thinking I've forgotten or 
> 
> changed my mind. It's almost pure upside from them to ignore my choice.
> 
> 
> 
> 2) Related, have we considered keeping this list inside Mozilla, and/or 
> 
> using technical measures like hashing to limit its risk?
> 
> 
> 
> 3) How long are these numbers kept for anti-abuse? Seems like limiting 
> 
> it to a few days/weeks (or more if an explicit stop-doing-this is 
> 
> requested) would be sufficient.
> 
> 
> 
> 
> 
> > Proposed Update to Firefox Privacy Policy –
> 
> >
> 
> > [...]Unless you opt-in to ongoing SMS
> 
> > messaging, the mobile phone number you input on the website will be
> 
> > used and stored only for the purpose of sending this one-time message
> 
> > and to provide abuse blocking, where available.
> 
> 
> 
> If a user does not opt-in to ongoing SMS, will the download message 
> 
> still be tracking if they perform the actual download?
> 
> 
> 
> Justin

Hi Justin, 

Thanks for the questions. I just realized I overlooked your comment.  Apologies 
for the delayed reply.

1) The service we'll be using is an industry leader and only delivers opt-in 
communication. It's the same company that we use for our email engagement 
program.  They've been reviewed and vetted by privacy, security and legal.  

2) We did discuss keeping this info internally/managing the program  ourselves 
and decided it was not feasible to do so.  The proposed vendor we're working 
with has hundreds of employees dedicated to security, privacy and abuse 
management.

3) Mozilla designates how long the data is maintained.
_______________________________________________
governance mailing list
[email protected]
https://lists.mozilla.org/listinfo/governance

Reply via email to