Hacker News new | past | comments | ask | show | jobs | submit login
Massive Google Play Privacy Issue (phetdreams.tumblr.com)
31 points by petrel on Feb 14, 2013 | hide | past | favorite | 19 comments



https://plus.google.com/106557483623231970995/posts/Bed6WUJp...

"With apple's app store you buy the apps from apple. With google play you buy the apps from the developer. If you are the merchant of record you need to know the address to correctly compute sales tax.

This is documented on http://support.google.com/googleplay/android-developer/bin/a....

Google cannot give tax advice, so we have to give you the data to make the determination yourself"


In other words, Google, the huge corporation, would rather that the app developer, who may not even be a corporation at all, be the merchant of record?

I guess I can kinda sorta see this from one point of view: they are trying not to be Apple. But they are still taking 30% of the money.


And while they give you the burden of being the merchant of record, they also give you capabilities Apple doesn't (e.g. carrier billing, control of refunds, ability to reply to reviews, etc.). It's a different bundle, with different trade-offs.


>you need to know the address to correctly compute sales tax.

OK, so that explains why they provide the city you're in, which is the least objectionable of the information -- the developer can probably get that from GeoIP in any event.

But why do they provide your real name? Why do they provide your email address rather than an anonymized forwarder like Craigslist does? Walmart doesn't need to know any of that when I buy a toaster, neither should the app developer.


For the e-mail: Google Wallet / Google Checkout has a checkbox that lets you hide your email address (instead using some intermediary one from Google) at checkout. They also have one that let's you tell the merchant that you don't want to receive promotional emails from them (if that is an option with the normal purchase via other means). Both options have been there since Google Checkout came into existence (I've been using this service since it came out in 2006).


I've looked, but cannot find a way to hide my email for app purchases through the Play store. There doesn't seem to be anything in either the Play store settings of the Wallet settings. Do you know if this feature still exists?


Not sure. I left the US and switched to an iPhone right before Google Wallet went live so my only experience with using it (Google Checkout/Google Wallet) is via a web browser. For that, the option is present during checkout, not in the settings. As far as I know, the option has never been in the settings.


Doesn't sound all that unusual. Anyone selling anything via a credit card is going to get the same info....perhaps even more...


The difference is that if you go to, say, Best Buy, and buy a Samsung TV, a Sony Blu Ray player, and a game for your Wii, your personal information doesn't go to Samsung, Sony, and the Wii game maker. The store, Best Buy, gets your info, not the makers of the products sold in the store.

This is what people generally expect from stores that sell a variety of items from many different manufacturers.


What makes you think the first sentence is true? I would in fact, assume the exact opposite. I've bought plenty of things where the warranty was automatically registered by buying it at best buy, and samsung/sony/whoever sent me a postcard, to my name and address, letting me know that.

It's very clear my personal information was shared.


The thing about Google Checkout is that it's more of a "credit card processor" than the merchant. They consider the developer as a merchant (maybe because Google might have first designed Google Checkout to be payment processor, like Paypal) which basically makes transfer of goods between a customer vs. developer, as opposed to customer vs. Play store.

Aside the argument if it's good or bad, it seems to be consistent with that notion -- if Google is considering Google Play to be more of a promotion service with payment processing built-in, as opposed to curated content store.


Uh, the name is Play Store.

It used to be called Market, but they changed it to Store.


Coming from developing iOS apps first I thought it was strange that I received these user details when they purchased my Android app. I assumed it had already been brought up though and was decided to not be an issue.


If you buy something from me, even via Google, you enter a mutual contract. And as such you have to provide sufficient information to identify yourself. Same with me. Pretty normal for any law protected contracts.


Its interesting to note that the email address wasn't always included, they used to be [random]@checkout.google.com before they made the switch to Google Wallet


Kinda like Paypal.


Yes, exactly like that service everyone hates. ;)


ZDnet interview with the guy who found the issue: http://www.zdnet.com/google-play-privacy-slip-up-sends-app-b...


It's not a "guy that found an issue". Nothing has every been hidden and it's not a privacy slipup. Come on.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: