I’m pretty sure that Halocard never gets the ID you upload for KYC. When I did the KYC process, all I had to give Halocard (before they sent me to Sumsub to do actual KYC (like with my passport and whatnot) was my full name, email, phone #, address (for billing/tax) and SSN (tax ID number). Halocard never had my ID documents themselves, and I’m sure they’re legally required to collect the info they collected.
In most of Europe you can trust the banks to not sell your data to random companies because of GDPR, PSD2 and other laws.
and
You can find the same in European banks with more safeguards and higher fines.
Now, I’m no lawyer (especially not an EU lawyer), but or people covered by the GDPR, your protections dont magically go away because you use Halocard. Halocard isn’t exempt from the GDPR (or any other EU regulation). I’m unsure where the “more safeguards” and “higher fines” appear from.
For people who are not protected by a privacy law like the GDPR (see: all of America) or have weaker privacy laws in their region, companies like Halocard are the way to protect their data from being sold and shared to data brokers. Just because YOU don’t see a value-add, doesn’t mean one does not exist. Having a company with the value of respecting your pricacy is a step up from the companies who really don’t care and will only do the bare minimum to get the legal people to stop yelling at them. I’m unsure why you’d rather (from purely a privacy perspective) use a company that only does the minimum to comply over a company with the explicit purpose of being more private.
Additionally, the privacy-focused aspect of the company means they are significantly more likely to engage in practices and make new technology that further the goal of privacy. “Not sell your data” is an amazing first step, however it will never beat a company actively trying to improve the situation.
What I’m saying is that most (if not all) of their promises are contractual and not hard, technical facts.
Yes, that is how privacy in these industries (ie ones that are heavily regulated against it) tends to happen. The accountability shifts from legal to reputational. There’s not much you can do about that, without reforming the law. Governments seem to really like their ability to send some paperwork to banks and get back a full ID of the user, so I don’t see that happening anytime soon. Again, a company who explicitly improves the privacy of a user will always be better (in my mind) than a company that’s just checking the compliance box and calling it a day. The threat model here is less of the government getting my data, and more of 5 billion companies 1) getting my data and/or 2) having an unique ID to tie me across sites (ie name, billing address, payment info). Im sure the GDPR protects you from some of this, but it certainty does not protect everyone from all of it (which is what companies like this are trying to push towards).
the whole vibe also feels a bit like a honeypot
(from this comment)
To add onto my previous comment addressing this, if we’re throwing around baseless accusations, I may as well accuse you of trying to spread doubt and push people toward less private institutions so you and your government buddies can spy on us easier.
See how baseless accusations work? No? Great, that’s cause they don’t >:P
I’d ask that you please continue criticizing Halocard, but for you to do it in a manner that 1) has evidence backing a privacy harm and/or 2) allows Halocard to learn and improve. Throwing around baseless accusations gets us all nowhere, causes division in our community, and doesn’t allow anyone to learn / grow from critical feedback.
PS: While typing all of above I couldn’t stop thinking about this XKCD rofl