How to accelerate revenue for SaaS startups(plainflow.com)
plainflow.com
How to accelerate revenue for SaaS startups
https://www.plainflow.com/blog/account-based-marketing-tactics/
4 comments
If you do it on demand instead of in bulk it isn't abuse. I could take your email and search Facebook myself, or could have before they removed the feature anyway
What if you do it on demand, and in an automated manner? I submit 1000 emails to Clearbit and they do 1000 automated lookups in FB.
Is that abuse?
Is that abuse?
[deleted]
Have you ever sent or received an email using that address?
If so the person on the other end may have given access to their address book/contacts.
If so the person on the other end may have given access to their address book/contacts.
But how would Clearbit know the Facebook profile linked to that email address?
The only way is:
1) Scraping Facebook by automating the process of searching for FB profiles based by email (most likely)
2) Having access to the same API Cambridge had years ago, where it's possible they downloaded the data from someone that had me in their friend's list (unlikely, this profile has ZERO friends :)
Of course if you ask Clearbit this, they'll hide behind the guise that they just look at publicly available data, or they bought it from a "trusted 3rd party". Where does the rabbit hole lead?
The only way is:
1) Scraping Facebook by automating the process of searching for FB profiles based by email (most likely)
2) Having access to the same API Cambridge had years ago, where it's possible they downloaded the data from someone that had me in their friend's list (unlikely, this profile has ZERO friends :)
Of course if you ask Clearbit this, they'll hide behind the guise that they just look at publicly available data, or they bought it from a "trusted 3rd party". Where does the rabbit hole lead?
That doesn't explain the link to Facebook at all though.
[deleted]
This really is a clickbait title.
One of the great things about GDPR is that this sort of thing will be flatly illegal. Want to use my IP address to look up information about me? Great, so long as you ask for, and get, my explicit consent.
Not at all.
If you're selling corporate targeted tools, you can assume that visitors represent a company and the lookup is a corporation. Facts about a company are not personal data per the GDPR. Note that a work email is certainly personal data, but the fact that a visitor works at corporation X isn't. As always, consult with your counsel. But that's what ours says.
If you're selling corporate targeted tools, you can assume that visitors represent a company and the lookup is a corporation. Facts about a company are not personal data per the GDPR. Note that a work email is certainly personal data, but the fact that a visitor works at corporation X isn't. As always, consult with your counsel. But that's what ours says.
Find new counsel. GDPR doesn’t consider the site’s intent at all, and the ECJ would - rightly - love to make an example of a company which “[assumed] that visitors represent a company” because they sell to companies.
Believe whatever you want, but a legitimate interest to match ip to company on a corporate targeted page is well within bounds.
And since you don't know what you're talking about, ok as per previous discussions with ICO.
And since you don't know what you're talking about, ok as per previous discussions with ICO.
I found some examples of consent (by Drip):
https://i.imgur.com/QPzXiWN.png
https://i.imgur.com/KiX2aCc.png
Although time will tell. My gut tells me that users will click decline and without any negative consequences (a redirect) and the dialog simply closes. Users will get used to doing that for all other EU sites and these startups marketing efforts will suffer.
Remember cookie law? Everyone I know is conditioned to click and not even look at the privacy policy.
That means overall, less profits for marketing and then lost sales.
It's going to be very interesting to see how competitive EU startups become verses US startups where in the US, GDPR doesn't exist (for now).
That said as well. Where US startups have much greater profits for marketing to non-EU regions, and EU startups cannot compete again due to less revenue due to regulations. EU startups will shrink against their US counterparts.
Again, all of this is my own speculation and lets see how things are in 2 years time.
Very interesting times ahead.
https://i.imgur.com/QPzXiWN.png
https://i.imgur.com/KiX2aCc.png
Although time will tell. My gut tells me that users will click decline and without any negative consequences (a redirect) and the dialog simply closes. Users will get used to doing that for all other EU sites and these startups marketing efforts will suffer.
Remember cookie law? Everyone I know is conditioned to click and not even look at the privacy policy.
That means overall, less profits for marketing and then lost sales.
It's going to be very interesting to see how competitive EU startups become verses US startups where in the US, GDPR doesn't exist (for now).
That said as well. Where US startups have much greater profits for marketing to non-EU regions, and EU startups cannot compete again due to less revenue due to regulations. EU startups will shrink against their US counterparts.
Again, all of this is my own speculation and lets see how things are in 2 years time.
Very interesting times ahead.
From our experience, that consent screen is wrong under the GDPR.
It asks for permission for 3 things, and while the first 2 could arguably be necessary for the "service", the third one (updates and promotions) clearly isn't. And it seems they refuse to provide service if you don't agree with everything in bulk.
This would be akin to an airline declining to sell you a plane ticket if you don't enroll in their promotional newsletter. Flat out illegal under the GDPR.
It asks for permission for 3 things, and while the first 2 could arguably be necessary for the "service", the third one (updates and promotions) clearly isn't. And it seems they refuse to provide service if you don't agree with everything in bulk.
This would be akin to an airline declining to sell you a plane ticket if you don't enroll in their promotional newsletter. Flat out illegal under the GDPR.
Isn't most of this stuff just managed with UX? Do people click "no" on cookie messages? or just "dismiss" which I assume means "whatever, just get this box out of the way"..
I found some examples of consent (by Drip):
Something tells me they collect more than "e.g. your name and email address."
Something tells me they collect more than "e.g. your name and email address."
Drift*, not Drip
IANAL, but company lookup by IP/DNS shouldn't fall under GDPR [0]:
"(14) The protection afforded by this Regulation should apply to natural persons, whatever their nationality or place of residence, in relation to the processing of their personal data. This Regulation does not cover the processing of personal data which concerns legal persons and in particular undertakings established as legal persons, including the name and the form of the legal person and the contact details of the legal person."
[0] http://eur-lex.europa.eu/legal-content/EN/TXT/?uri=uriserv:O...
"(14) The protection afforded by this Regulation should apply to natural persons, whatever their nationality or place of residence, in relation to the processing of their personal data. This Regulation does not cover the processing of personal data which concerns legal persons and in particular undertakings established as legal persons, including the name and the form of the legal person and the contact details of the legal person."
[0] http://eur-lex.europa.eu/legal-content/EN/TXT/?uri=uriserv:O...
European Court of Justice ruling confirmed that IP address can be considered personally identifiable information if a party can lawfully obtain information linking it to a natural person
But that is not the case there. SaaS's typically don't target a natural person, they target businesses (in EU, self employment is considered business as well).
That might work ok for Clearbit's customers - who can send an IP address and either get back a company name or nothing, but I suspect Clearbit have to have some solid legal advice for answers to questions like "What if a customer sends you a home/residential IP address?"
I live alone - my ip address is (and has been for a decade or more) static. It without doubt will qualify as Personally Identifying Information.
I live alone - my ip address is (and has been for a decade or more) static. It without doubt will qualify as Personally Identifying Information.
This is actually very well defined. If the IP address (the contract with ISP to be specific - thus every IP it might provide to the user) is used for business purposes (doesn't matter how much), then it's regarded as business even though it's residential and the businessman lives there.
Based on imhoguy's comment, it looks like only corporations (legal persons) count as businesses.
I didn’t knew something like ClearBit can transform an IP into personal data.
To be clear, Clearbit can only transform IPs into company data.
(Based on another reply, apparently David works for Clearbit)
How does Clearbit Reveal differentiate between a home/residential user browsing for business purposes, and that same person or their family browsing from the same IP (which may well be a business broadband subscriber) for entirely personal purposes?
From my own testing of a few Clearbit APIs, it seemed like your statement was, for all practical purposes, false. That said, maybe I’m wrong. I’d welcome an explanation or link to how Clearbit can tell commercial intent (or lack thereof) from, say, a shared IP.
Does a public site exist where an anonymous visitor can see the Clearbit Reveal response for their own IP?
How does Clearbit Reveal differentiate between a home/residential user browsing for business purposes, and that same person or their family browsing from the same IP (which may well be a business broadband subscriber) for entirely personal purposes?
From my own testing of a few Clearbit APIs, it seemed like your statement was, for all practical purposes, false. That said, maybe I’m wrong. I’d welcome an explanation or link to how Clearbit can tell commercial intent (or lack thereof) from, say, a shared IP.
Does a public site exist where an anonymous visitor can see the Clearbit Reveal response for their own IP?
The dubiousness of this statement aside, it's definitely good form to mention that you work for the company in question when you're making posts about that company (it was only a couple of clicks for me to figure this out and a couple more to confirm it, but still).
I've tried it with an email address I've never publicly disclosed anywhere, and amazingly it works. It found the FB profile linked to that email.
I always wondered how ClearBit knew that information. Were they the "malicious actors" Facebook was referring to in their announcement last month?[1]
[1] "Malicious actors have also abused these features to scrape public profile information by submitting phone numbers or email addresses they already have through search and account recovery": https://newsroom.fb.com/news/2018/04/restricting-data-access...