Chris@O2
Many thanks for once again revisiting this.
I think what you are saying is that the part of Bango which handles your contract (our data) is utterly separate to the part of Bango that provides and thus profits from billing and analytical services to such delights and gambling and `adult service` industries.
I'm not sure I fully understand the link between the privacy policy and your paragraph
We’ve chosen to use Bango for reporting on usage of our mobile portals only (including O2 Active) and the information is presented as overall usage and trends. Reporting on individuals isn’t available and we don’t collect any information from the use of non-O2 sites. Any data that Bango collects belongs to O2, not Bango – they don’t pass on any of it to anyone other than O2, unless required to do so by law. |
Keeping in mind that the policy permits the collection of explicit (exact, not pornographic) web activity data quote]browsing history (including web sites you visit) (
section 6 of "Information We Collect")
I can not but help but think a company like Bango would do a sterling job of
aggregate information about you, your spending and your use of the Services with information about other users of the Services in order to identify trends ("Aggregated Data"). We may pass Aggregated Data to third parties, such as advertisers, content providers and business partners or prospective business partners, to give them a better understanding of our business and to bring you a better service. Aggregated Data will not contain information from which you may be personally identified. |
(
section 20 of "How We Use")
and (
here's the bit that bothers me a bit)
analyse information about you including your calling, searching, browsing and location data on a personalised or aggregated basis. We may pass this data to the third parties mentioned in (xx) above and we may use this information to provide you with targeted O2 or third party offers, promotions, adverts or commercial communications. |
(section 21 of the same)
And there lies the rub. This section 21 appears to contradict what you said about aggregated data being the only kind....
I'm not sure that I personally am comfortable with the later being held by a company who's reputation is (in my view) ethically tarnished the nature of some of their revenue streams. I'm also not certain what transparently audited data controls they have in place (I looked but couldn't find).
You mentioned
Bango are PCI-DSS compliant |
- I'm not sure what credence that is meant to give - it's pretty much the minimal framework (I can't think of an incident of either internal or on-line credit card fraud that occurred within / to a company that wasn't PCI-DSS) that has to be in place for any company handling a reasonable quantity of card data and is typically rarely audited independently. That's not to say that there's a better accreditation (at least I'm not aware of one) but it would be nice to have some statements which offer reassurance if about card handling, if at all.
However, their ability to handle credit card information securely wasn't in doubt. My personal concern was two fold:
multiple billing as inspired by https://ageverification.o2.co.uk/
Please note that each time you age verify, your credit card will be charged £1. You will only receive £2.50 credit when you use this service for the first time. |
You see, Chris, If
Firstly, just to clarify, once a customer’s age has been verified there should be no reason to process the verification again. |
is correct, I can't help but wonder why the "each time" clause was written (to age verify multiple children using a single credit card, perhaps :mansurprised: )
Fear of cross charging to their `other` business (anyone want to seed their foes with a script on a WinMo or Android phone to repeatedly visit site x to click through an advert or worse as a `hidden` background process? It's not that hard). If Bango held card data for any other purpose, this would become possible. I think? your response alleviates that fear.
Regarding the continued (not fixed?) problems with the WAP gateway equipment - I looked at http://status.o2.co.uk/ when I started seeing such disgraceful sites as child friendly forums and the wonderful Google Translate site (I still haven't worked out how to exploit that, btw) but didn't (and haven't) seen any notifications about the problems which you allude to. Whilst not doubting that the legion of server errors that us customers have been experiencing are related to this, I'm mindful of the positive power of external transparency (hark back to when the Plusnet engineer pulled the de constructed the drive array on the `live and good` mail server rather than the one with the failed array and how their openness was seen as being so positive) - I can't help but think that it would be wonderful if O2 could learn from this in their communications with customers (although, as we've seen, some openness and transparent communications to customer facing staff would do wonders for, say, Net Promoter Scores).
You mentioned the internet being a huge place and not all categorisation being correct - that's understandable. However, you said previously
If you find an example of this please let us know, and we’ll do our best to unblock the site quickly. You can either let us know here on the O2 Forums, or via Twitter (@O2) |
- I've tried this both in this thread and on Twitter - it appears to fall on deaf ears (for example translate.google.com)
Finally, this feels like a bit of an essay, I gave up whilst attempting to search Hotukdeals to see if I could beat a store price whilst Christmas Shopping (Hi, Bango...) earlier in the week and on Friday I went into the local O2 store and requested the ability to access `over 18 year old` websites. You should have heard the decibel levels drop when I said that and a couple of sniggers as I detailed some of the sites that were barred (not sure if they were perceived as hate sites, pornographic or what)... Once customer had a penny drop moment when I described the problem and she followed suit soon afterwards and I'm pleased to say that the general mood in the store became far more good humoured. The staff were lovely and the process, without card, was utterly painless.
Chris - Thanks for listening to us and stepping up to answering the concerns.
P.S. The certificate on the age verification site is expired.