> Whether you have Zoom account or not, we may collect Personal Data from or about you when you use or otherwise interact with our Products. We may gather the following categories of Personal Data about you:
> - Information commonly used to identify you, such as your name, user name, physical address, email address, phone numbers, and other similar identifiers
> - Information about your job, such as your title and employer
> - Credit/debit card or other payment information
> - Facebook profile information (when you use Facebook to log-in to our Products or to create an account for our Products)
> - General information about your product and service preferences
> - Information about your device, network, and internet connection, such as your IP address(es), MAC address, other device ID (UDID), device type, operating system type and version, and client version
> - Information about your usage of or other interaction with our Products (“Usage Information”)
> - Other information you upload, provide, or create while using the service ("Customer Content"), as further detailed in the “Customer Content” section below
So, all this doesn't sound great, but... the specific accusation in the tweet is that they're tracking other applications that are open. Their privacy policy does not say they do that, and the Zoom twitter account says they don't either[0]. Now, it's a matter of trust, of course (and after [1] I wouldn't blame people for a lack of trust), but to state authoritatively that Zoom tracks other open applications seems like completely unsubstantiated fear-mongering.
Sure, as I said, the privacy policy isn't great, but the tweet specifically accused Zoom of tracking and recording what other applications people are running. There seems to be no evidence of that.
> your name, user name, physical address, email address, phone numbers, and other similar identifiers
My problem with this isn't the info they collect, it's how they would collect it, which this privacy policy doesn't seem to clarify.
As it stands, this policy technically gives them the right to crawl through all my personal files or even listen using the microphone to search for and collect this information.
I'm not saying they are doing this, but the policy is not reassuring. I wish there was enforced legislation (so GDPR is excluded, as regulators don't give a fuck) to curb this. There should be a legal requirement describing exactly the information collected, how is it collected, transmitted, sorted and which third-parties it is given to, if any.
This is standard language to cover everything in normal use. Billing details is obvious. Profile info is provided when you signup and use the service. The system info is used to run and optimize the calls.
Zoom isn't actively scraping your info, and there's 0 evidence of anything in the Tweet.
Sure! Except it was mandated by your boss. Or you have a choice between a bunch of offerings with the exact same screwball terms. This might not actually be true for videoconferencing now that it's getting somewhat democratized and competitive.
Point is: "just boilerplate" is just rationalization. An honest person would never present it as comforting and a knowledgeable person would never find it comforting. Of course, the world is full of dishonest people, so it gets used all the time. Hence "lawyerspeak."
Do you refuse to use any other software mandated by your company? What's the difference?
It's standard policy to cover any potential personal data that they might receive. What is your concern exactly? That they shouldn't spell it out? That would be illegal under current data regulations.
Let me tell work that I can't collaborate remotely anymore on video because I am using my agency to refuse to use Zoom even though everyone else at the whole company does. Then they can use their agency to put me on a PIP because my choice hindered my ability to do my job.
I'm sure you realize it's not as easy as you say, but I suppose it's easier to assert that situations don't have nuance because then you can make blanket statements like you did.
There is an incentive to do so and they have taken measures to legally protect themselves if they do. That's grounds enough for alarm, even without evidence of them actually doing it.
Alarm for what? It's enterprise video conferencing tech. They make their money from subscriptions. Your personal data is rather useless to them and now a liability under data regulations.
Worrying about Zoom here (and I'm not sure the tweet is accurate) seems to ignore all context of the product and business.
That privacy policy is a clear indication that Zoom is only concerned about protecting themselves at all costs. They may not be acting maliciously, but they clearly aren't dedicated to acting ethically either.
I'm not saying it's an emergency, but a privacy policy like that should at least set off some warning flags for a privacy-concious user.
> They make their money from subscriptions. Your personal data is rather useless to them...
I don't care if the data os valuable to them as long as it's valuable to someone.
Every company will protect themselves. Why is this controversial? Please list the companies that open themselves up to litigation and show me how that's ethical.
"as long as it's valuable to someone"
This is so vague as to be meaningless. What about your browser, ISP, OS, phone, and the million other services that you use? Context matters.
"The liability is worth it if the price is right."
Are you claiming that a company selling enterprise video tech for 100s of millions and operating under all the latest data regulations is somehow trying to squeeze out a few pennies by selling some worthless data while risking massive lawsuits?
These don't look that bad, but what's describe in a tweet (tracking focus app etc) is much worse, it doesn't seem to be in the privacy policy though (or they masked it?). So where's the information about focused window come from?
Your name, physical address, email address, phone number, employment, credit card, Facebook profile, IP address, MAC address, device ID...is not that bad?
These are technical details for normally working with the app. They charge you, so they need you name and credit card. You ask for a support, so they need your ip etc. They list what they may gather, because privacy policy should cover everything, doesn't mean they require all that info at once. I also didn't provide them many of these items.
They have to name every possible thing they can potentially receive. Mac addresses are available as part of networking details if you're using their desktop software. Zoom is enterprise video conferencing that only recently gained attention for average consumers.
That's not how PII is defined nor how privacy policies work. They list potential PII received in standard categories with normal product usage and backend processing.
Otherwise every server on the internet can be sent data by you at anytime which effectively makes listing things pointless.
No it's not. As I explained, it's well developed legal structure that's used by several countries for major legislation and has decades of precedence. There's also further complexity on how data is submitted, stored, and processed.
Any random file is not considered PII. It doesn't automatically identify you and it's still your responsibility if you send your private files everywhere.
How do you know that? These statements leave other possibilities open:
It covers all Personal Data that you affirmatively provide during your interactions with us, information that we automatically collect when you interact with our Products, and information that we collect about you from third parties
Whether you have Zoom account or not, we may collect Personal Data from or about you when you use or otherwise interact with our Products.
It says "when you use or otherwise interact with our Products."
It's not unreasonable. I'm not sure what your claim is here, because you'll find this language in every single online business. You realize Zoom sells enterprise video conferencing right? They have no use for your data otherwise.
The GDPR’s specific, granular and informed clauses for opt-in couldn’t have been more timely. I wonder how long it is before Zoom have to stop providing services to the EU?
Is that a technical question? All of that information is immediately available because you typed it in when you made your account, or because of the nature of the internet.
Seriously, you've given this information to any service you've ever signed up for and / or ran.
> Whether you have Zoom account or not, we may collect Personal Data from or about you when you use or otherwise interact with our Products. We may gather the following categories of Personal Data about you:
> - Information commonly used to identify you, such as your name, user name, physical address, email address, phone numbers, and other similar identifiers
> - Information about your job, such as your title and employer
> - Credit/debit card or other payment information
> - Facebook profile information (when you use Facebook to log-in to our Products or to create an account for our Products)
> - General information about your product and service preferences
> - Information about your device, network, and internet connection, such as your IP address(es), MAC address, other device ID (UDID), device type, operating system type and version, and client version
> - Information about your usage of or other interaction with our Products (“Usage Information”)
> - Other information you upload, provide, or create while using the service ("Customer Content"), as further detailed in the “Customer Content” section below