Consumer Law LibrarySearchBy decadeBy respondentBy topicBy outcomeDataAbout

Upromise, Inc.

Volume 153 · 153 F.T.C. 600

Citation
153 F.T.C. 600
Docket
C-4351
Complaint
2012-03-27
Decision
2012-03-27
Document type
consent order
Case type
consumer protection
Statutes
FTC Act (section 5)
Industry
college savings membership service
Outcome
consent order entered
Relief
affirmative_disclosure; recordkeeping; compliance_reporting; other
Order term (years)
20
Source
Original volume PDF
Original PDF
This decision as a PDF

privacy data securityonline internetdeceptive advertising

Cite this decision

Upromise, Inc., 153 F.T.C. 600 (2012). Consumer Law Library, https://consumerlawlibrary.org/decisions/v153-0012

Report an error in this record (decision id v153-0012)

Order status: active_until:2032-03-27. Sunset may be extended by the latest qualifying federal-court complaint alleging an order violation; complaints, dismissal/appeal outcomes, and respondent-specific extensions are not fully tracked.

Cited by 0 later FTC decisions

Cites

Text (OCR of the scan at left; may contain errors)

IN THE MATTER OF UPROMISE, INC.

CONSENT ORDER, ETC. IN REGARD TO ALLEGED VIOLATIONS OF SECTION 5 OF THE FEDERAL TRADE COMMISSION ACT Docket No. C-4351; File No. 102 3116 Complaint, March 27, 2012 – Decision, March 27, 2012 This consent order addresses Upromise, Inc.’s advertising, marketing, and operation of an optional feature of that Toolbar, the “personalized offers” feature. The complaint alleges that the Targeting Tool collected the names of all websites visited; all links clicked; information that consumers entered into some web pages such as usernames, passwords, and search terms; and, from July 2009 through mid-January 2010, consumers’ interactions with forms on secure web pages. The complaint further alleges that Upromise engaged in a number of practices that, taken together, failed to provide reasonable and appropriate security for the personal information it collected and maintained. The consent order requires Upromise to disclose to consumers – before the download or installation of software that records or transmits information about any activity occurring on a computer involving the computer’s interactions with websites, services, applications, or forms – the types of information collected and how the information will be used. Participants For the Commission: Katrina Blodgett and Ruth Yodaiken. For the Respondent: J. Beckwith (“Becky”) Burr, Wilmer Cutler Pickering Hale and Dorr LLP.

COMPLAINT The Federal Trade Commission, having reason to believe that Upromise, Inc. (“Upromise” or “respondent”), a corporation, has violated the Federal Trade Commission Act (“FTC Act”), and it appearing to the Commission that this proceeding is in the public interest, alleges:

1. Upromise is a Delaware corporation with its principal office at 95 Wells Avenue, Suite 160, Newton, Massachusetts 02459.

UPROMISE, INC. 601 Complaint 2. The acts and practices of respondent, as alleged herein, have been in or affecting commerce, as “commerce” is defined in Section 4 of the FTC Act.

RESPONDENT’S BUSINESS PRACTICES AND REPRESENTATIONS TO CONSUMERS 3. Upromise offers a membership service to consumers. A consumer who is a member of Upromise and purchases products and services from Upromise partner merchants can receive cash rebates. Upromise places these cash rebates into a college savings account for the consumer.

4. Since 2005, Upromise disseminated or caused to be disseminated through its website, www.upromise.com, a software toolbar referred to as the Upromise TurboSaver Toolbar (the “Toolbar”) for consumers to download and install onto their computers. Among other things, the Toolbar highlighted Upromise partner companies in consumers’ search results, so that consumers could more easily determine which companies were Upromise partners. (See Exhibit 1).

5. The Toolbar incorporated a “personalized offers” feature that, when enabled, would collect and transmit information through the consumer’s browser. The personalized offers feature used consumer browsing information to provide targeted advertising to consumers through the browser. Upromise engaged a service provider to develop the Toolbar and the personalized offers feature.

6. During the download process for the Toolbar, where the personalized offers feature was offered users were presented with one of several versions of a pop-up window that contained a check-box next to text stating “Enable Personalized Offers,” (See, e.g., Exhibits 2- 4). Until mid-January 2010, Upromise provided the following description of the personalized offers feature, either directly in the pop-up window or if the consumer clicked on a hyperlink labeled “Show”:

By enabling the Personalized Offers feature, information about the web sites you visit will be VOLUME 153 Complaint collected. This information is used to provide college savings opportunities tailored to you. See, e.g., Exhibit 2, Exhibit 3 (operational from approximately July 2009 to January 2010), and Exhibit 4 (operational from approximately October 2008 to May 2009).

In some instances, the check-box to “Enable Personalized Offers” was pre-checked to enable the personalized offers feature by default. (See, e.g., Exhibit 2, operational from approximately July 2009 to January 2010).

7. When the personalized offers feature was enabled, the feature modified the Toolbar to collect extensive information about consumers’ online activities and transmit it to the service provider for analysis. (Hereafter this modified version of the Toolbar with the personalized offers feature enabled is referred to as the “Targeting Tool.”) The Targeting Tool collected the names of all websites visited, all links clicked, and information that consumers entered into some web pages such as usernames, passwords, and search terms. The Targeting Tool’s data collection occurred in the background as a consumer used the Internet, and there was no way for consumers – without special software and technical expertise – to discover the extent of the data collection. Moreover, from July 2009 to mid-January 2010, the Targeting Tool was reconfigured to include consumers’ interactions with forms on secure web pages, which companies such as banks and online retailers provide to safeguard consumer data. The Targeting Tool was enabled on at least 150,000 consumers’ computers.

8. The Upromise TurboSaverTM Privacy Statement, which was available on the Upromise website and at times through a link during the download process, stated that the Toolbar might “infrequently” collect some personal information. It further stated that a filter, termed a “proprietary rules engine,” would “remove any personally identifiable information” prior to transmission. (See, e.g., Exhibit 5, operational from approximately October 2008 to September 2009). The TurboSaverTM Privacy Statement also stated that “every commercially viable effort” would be made UPROMISE, INC. 603 Complaint “to purge their databases of any personally identifiable information.”

9. In fact, although a filter was used to instruct the Targeting Tool to avoid certain data, the filter was too narrow and improperly structured. For example, although the filter was intended to prevent the collection of financial account personal identification numbers and would have prevented collection of that data if a website used the field name “PIN,” the filter would not have prevented such collection if a website used field names such as “personal ID” or “security code.” 10. The Targeting Tool transmitted the information it gathered – including in some cases credit card and financial account numbers, security codes and expiration dates, and Social Security numbers entered into web pages, including secure web pages – over the Internet in clear text. Tools for capturing data in transit, for example over unsecured wireless networks such as those often provided in coffee shops and other public spaces, are commonly available, making such clear-text data vulnerable to interception. The misuse of such information – particularly financial account information and Social Security numbers – can facilitate identity theft and related consumer harms.

11. On approximately January 21, 2010, Upromise halted all data collection through the Targeting Tool after a security researcher disclosed the scope of the information collected and the fact that it was transmitted in clear text. 12. In addition to the representations made in the download process and in the Upromise TurboSaverTM Privacy Statement, respondent has disseminated or caused to be disseminated the Upromise Privacy Statement, which was available on the Upromise website and through a link in the TurboSaverTM Privacy Statement. The Upromise Privacy Statement stated: Upromise is committed to earning and keeping your trust. We understand the need for our customers’ personal information to remain secure and private and we have implemented policies and procedures designed to safeguard your information.

VOLUME 153 Complaint Exhibit 6 (operational from approximately June 2008 to January 2010).

13. Similarly, the Upromise Security Statement, also available on the Upromise website, stated:

Our members’ security and privacy are critically important issues for Upromise. We are proud of the innovations we have made to protect your data and personal identity throughout the Upromise service. Upromise protects your data by... SSL, Data, and Password encryption technology.... Using the Secure Sockets Layer protocol (SSL), Upromise automatically encrypts your sensitive information in transit from your computer to ours. * * * Upromise security architecture and security procedures are audited and inspected by industry leaders specializing in security processes and technologies.

Exhibit 7 (operational from approximately January 2008 to January 2010).

14. Respondent engaged in a number of practices that, taken together, failed to provide reasonable and appropriate security for consumer information collected and transmitted by the Targeting Tool. Among other things, respondent:

a. created unnecessary risks of unauthorized access to consumer information by the Targeting Tool transmitting sensitive information from secure web pages, such as financial account numbers and security codes, in clear readable text over the Internet; b. failed to use readily available, low-cost measures to assess and address the risk that the Targeting Tool would collect such sensitive consumer information it was not authorized to collect. For example, UPROMISE, INC. 605 Complaint respondent did not test the Targeting Tool before distributing it to consumers or monitor the Targeting Tool’s operation thereafter to verify that the information it collected was consistent with respondent’s policies;

c. failed to ensure that employees responsible for the information collection program received adequate guidance and training about security risks and respondent’s privacy and security policies; and d. failed to take adequate measures to ensure that its service provider employed reasonable and appropriate measures to protect consumer information and to implement the information collection program in a manner consistent with the respondent’s privacy and security policies and contractual provisions designed to protect consumer information.

VIOLATIONS OF THE FTC ACT Count 1 15. Through the means described in Paragraph 6, respondent has represented, expressly or by implication, that the Targeting Tool would collect and transmit information about the websites consumers visit. Respondent failed to disclose that the Targeting Tool would also collect and transmit much more extensive information about the Internet behavior that occurs on consumers’ computers, and, for the period between July 2009 and January 2010, information consumers provided in secure sessions when interacting with third-party websites, shopping carts, and online accounts – such as credit card and financial account numbers, security codes and expiration dates, and Social Security numbers consumers entered into such web pages. These facts would be material to consumers. Respondent’s failure to disclose these facts, in light of the representations made, was, and is, a deceptive practice.

VOLUME 153 Complaint Count 2 16. Through the means described in Paragraph 13, respondent has represented, expressly or by implication, that information transmitted by the Toolbar would be encrypted in transit. 17. In truth and in fact, as described in Paragraph 10, information transmitted by the Toolbar was not encrypted in transit. Therefore, the representation set forth in paragraph 13 was, and is, false or misleading and constitutes a deceptive act or practice.

Count 3 18. Through the means described in Paragraphs 12 and 13, respondent has represented, expressly or by implication, that it employs reasonable and appropriate measures to protect data obtained from consumers from unauthorized access. 19. In truth and in fact, as described in Paragraph 14, respondent did not implement reasonable and appropriate measures to protect data obtained from consumers from unauthorized access. Therefore, the representations set forth in Paragraphs 12 and 13 were, and are, false or misleading and constitutes a deceptive act or practice. Count 4 20. As described in Paragraphs 9, 10, and 14, respondent’s failure to employ reasonable and appropriate measures to protect consumer information – including credit card and financial account numbers, security codes and expiration dates, and Social Security numbers – caused or was likely to cause substantial injury to consumers that is not offset by countervailing benefits to consumers or competition and is not reasonably avoidable by consumers. This practice was, and is, an unfair act or practice. 21. The acts and practices of respondent as alleged in this complaint constitute unfair or deceptive acts or practices in or affecting commerce in violation of Section 5(a) of the Federal Trade Commission Act.

UPROMISE, INC. 607 Complaint THEREFORE, the Federal Trade Commission this twentyseventh day of March, 2012, has issued this complaint against respondent.

By the Commission.

Exhibit 1 VOLUME 153 Complaint Exhibit 2

VOLUME 153 Complaint Exhibit 4

UPROMISE, INC. 613 Complaint Exhibit 6 Upromise Privacy Statement Protecting your privacy is a top priority at Upromise. We want you to understand how we handle the personal information about you that we may obtain, and how we may and may mot share it, This statement covers all of our information handling practices for Upromise, Inc. and its subsidiaries, including Upramise Investments, Inc. and Upromise Investment Advisors, LLC, for the benefit of current and past customers. Please also see our separate statement, Privacy of Upromise Rewards Service, for additional information about our practices relating to our Rewards service. Information We May Obtain.

As part of providing you products or services, we may obtain personal information from the following sources:

* Information you provide to us on applications and other forms, that you otherwise enter on our web site, or that you provide to us in writing or by telephone, such as when you contact aur customer service staff, This information may include items such as your name, address, telephone number and social security number. In addition, please see Use of Cookies and other Technologies below for information we receive automatically when you visit our web site.

* Information from your transactions with us, our affiliates or nonaffiliated third parties such as account activity and your purchase information in our Rewards service. * Information from third parties, including public sources, such as verification services and consumer reporting agencies (to comply with regulatory requirements, ensure the accuracy of data and prevent fraud, for example), or from other sources (such as fromother institutions like a bank or broker you use to transfer funds into a Upromise account, or public sources).

We use the information we obtain in order to develop, offer and deliver our products and services, to offer products and services of our affiliates, participating companies, marketing partmers and other companies, to process transactions in your accounts, and to fulfill legal and regulatory requirements.

Please note that information you voluntarily include in bulletin boards, chat rooms and other online forums, such as the Upromise Community, may be viewed and used by anyone with access to those forums. Upromise is unable to control any use of such Information. Sharing Information With Our Affiliates As a subsidiary of SLM Corporation, commonly known as Sallie Mae, our affiliates are the family of companies controlled by SLM Corporation. Our affiliates include, among others, Sallie Mae, [nc., Upromise Investments, Inc., Upromise Investment Advisors, LLC, Student Loan Funding Resources, Nellie Mae Corporation, Southwest Student Services Corporation, Student Loan Finance Association, Academic Management Services Corp,, SLM Financial Corporation, and Sallie Mae Bank. Our affiliates offer a broad range of products and services including education loans, private loans, mortgage loans, 529 college savings plan administrative services and debt collection services. By sharing your personal information with our affiliates, we and our affiliates can better understand and meet your college savings and other needs by letting you know about products, services and promotional offers in which you are most likely to be interested. For example, if you have a Rewards account that has accumulated sufficient funds, you may be interested in opening an account with the Upramise Callega Fund, or if you have a high school student, you may be interested in learning more about Sallie Mae student loans.

Unless you tell us not to, we may share with our affiliates all of the information we obtain about

VOLUME 153 Complaint Please remember that you also play a valuable part in data security. You should never share your Upromise password with anyone. If you feel your password has been compromised, you should change it immediately, After you have finished using our site, you should log out of your Upromise account and exit your browser so that no unauthorized persons can use our site under your name and account information.

Collection of Information from Children. None of Upromise's products or services are intended for purchase by children. Accordingly, Upromise does not knowingly collect, either online or offline, personally identifiable information from children under the age of 13.

State Laws In addition to the rights described in this policy, please note that you may have additional rights under state law, For example, if your address on file with us is a California address, we will not share personal information about you with a financial institution with whom we have a joint marketing relationship unless we provide you the required notice under California law and you do not opt-out of that information sharing. In addition, if your address. on file with us is a Vermont address, we will not share consumer report Information about you with our affiliates unless you expressly consent to that information sharing. Changes to This Privacy Statement If we materially change this statement or our information-handling practices as described in this Statement, we will notify you by email and/or through a notice on our web site at least 30 days prior to their implementation, Privacy of Upromise Rewards Service What information does Upromise collect, and why? Enrollment Information. To set up your membership with the Upromise Rewards service, you will need to provide certain contact Information, such as your name, mailing address, email address, phone number, username, and password. This information will also allow us to contact you about new college savings opportunities, unless you opt out of receiving these messages. Purchase Information. As a Rewards service member, you can save for college by shopping with our participating companies. We may require additional information in order to keep track of and collect your contributions. For example, if you use a credit card to make a purchase, we may use your credit card number to identify the transaction. A phone company might require your telephone number, while an airline might require your frequent flyer account number, To take part in our grocery service, you may need to provide a grocery loyalty card number. [n order to keep track of and collect your contributions, Upromise collects from some participating companies, grocery retailers or third party processors details of your transactions such as the date and armount of your transaction.

Rewards Account Information. We will maintain records bo keep track of the contributions you aarn from your purchases with our participating companies, You can use aur website to view your Rewards service account balances and recent account activities, update your account profile, establish college savings qoals, add new future college students, or contact 2 customer service representative, Student Information. [in order to link an eligible investment account or student loan account to the Rewards oeivice oa that we inay direct your savings from your Rewards service account to the Investment oF student nan adeceunt you will Weed to provide certain information about the students or future students for whem you are saving such a5 Lhe name, date ef birth and social security

VOLUME 153 Complaint Use of Information from Third Parties. We may obtain information about you from our participating companies and other third parties in order to provide you with college savings opportunities tailored to your interests. You may opt out of receiving these offers by updating your account profile at any time on our website, or by contacting a customer service representative at 1- 800-877-6647, We may also use information obtained from our participating companies and other third parties in conjunction with member account and enrollment information for analytical and audit purposes.

Use of Non-Personally Identifiable Information, We may also provide aggregated, nonpersonally identifiable information about our members and their future college students to third parties for audit, marketing and other purposes. Because aggregated data is not associated with any particular person, these third parties will not have access to any personally identifiable information about you or your future college students, What are my choices regarding the receipt of marketing messages? We reserve the right ta send you specific administrative notices that are required by law, regulation, or as needed to service your account. You may choose whether or not to receive messages from Upromise and our participating companies that may better suit your interests based on your preferences and transaction history. [F you do not wish to receive these messages from Upromise and/or our participating companies, you may opt out by sending us an email at [email protected] containing your name, address, account number and request, or by calling the following toll free number: 1-800-877-6647. You may also opt-out of receiving marketing emails from Upromise and marketing messages from our participating companies by updating your Upromise account member profile opt-out preferences on our web site. Our participating companies reserve the right to contact you using information from sources other than Upromise, How can I access and update my Upromise data? You may access and update information stored in your account profile by visiting the Upromise site. Please keep your contact, account, and preference information up-to-date. Doing so ensures that your contributions are property tracked and received. It also helps us inform you of new Participating companies who may help you boost your college savings. What about links to other sites and participating companies' use of information? Through our various online offerings, we may provide links to third-party websites, such as those of our participating companies or your investment manager. Each of these sites may have separate privacy and different data-collection practices fram Upromise, and we are not responsible for the actions or practices of these third parties, nor for the content on these sites. We encourage you to - review the privacy policies of their sites. In addition, our remindU service and the Personalized Offers feature of the Uprornise Toolbar are provided by third parties, which also have separate privacy policies and data-collection practices which can be accessed when you down-load the remindU and Upromise Toolbar software. To learn more about privacy and the Upromise Toolbar, please read the Toolbar Privacy Statement. Finally, please remember that when you shop or do any other business with any of our participating companies, any information you provide to them is subject to their own privacy and data collection practices, for which Upromise is not responsible, What is TRUSTe and why is it so important? Upromise, a wholly-owned subsidiary of Sallie Mae, is a licensee of the TRUSTe Privacy Program. TRUSTe is an independent, non-profit organization whose mission is to build users’ trust and confidence in the Internet by promoting the use of fair information practices. TRUSTe has agreed to review the practices of www.upromise.com because this website wants to demonstrate its commitment to your privacy. Please note that the TRUSTe program does not cover the privacy practices of Upromise, Inc. affiliates. Please also note that the TRUSTe program covers only information that is collected through this wabsite, and dogs nat cover information that may be collected through software downloaded fram the site. IF you have questions or concerns regarding this statement, you should first contact Upramise (see hallow). [FP you do not rroeive acknowledgment af your inquiry ar your inquiry has not been Hauisfactonly aciiressed, you should then contact TRUSTe. |RUSTe will then serve as a liaison with Jproumise Lo resolve your concerns

VOLUME 153 Complaint Exhibit 7 UPROMISE, INC. 621 Decision and Order DECISION AND ORDER The Federal Trade Commission, having initiated an investigation of certain acts and practices of the Respondent named in the caption hereof, and the Respondent having been furnished thereafter with a copy of a draft of Complaint which the Bureau of Consumer Protection proposed to present to the Commission for its consideration and which, if issued, would charge the Respondent with violation of the Federal Trade Commission Act; and The Respondent and counsel for the Commission having thereafter executed an agreement containing a consent order, an admission by the Respondent of all the jurisdictional facts set forth in the aforesaid draft complaint, a statement that the signing of the agreement is for settlement purposes only and does not constitute an admission by the Respondent that the law has been violated as alleged in such complaint, or that any of the facts as alleged in such complaint, other than jurisdictional facts, are true, and waivers and other provisions as required by the Commission’s Rules; and The Commission having thereafter considered the matter and having determined that it had reason to believe that the Respondent has violated the Federal Trade Commission Act, and that a complaint should issue stating its charges in that respect, and having thereupon accepted the executed consent agreement and placed such agreement on the public record for a period of thirty (30) days for the receipt and consideration of public comments, and having duly considered the comment received from an interested person pursuant to Section 2.34 of its Rules, now in further conformity with the procedure prescribed in Section 2.34 of its Rules, 16 C.F.R. § 2.34, the Commission hereby issues its complaint, makes the following jurisdictional findings, and enters the following order: 1. Respondent Upromise, Inc., is a Delaware corporation with its principal office at 95 Wells Avenue, Suite 160, Newton, Massachusetts 02459.

2. The Federal Trade Commission has jurisdiction of the subject matter of this proceeding and of the VOLUME 153 Decision and Order Respondent, and the proceeding is in the public interest.

ORDER DEFINITIONS For purposes of this order, the following definitions shall apply:

A. “Affected Consumers” shall mean persons who, prior to the date of issuance of this order, downloaded and installed the TurboSaver Toolbar and had the Personalized Offers feature enabled.

B. “Clearly and prominently” shall mean as follows: 1. In textual communications (e.g., printed publications or words displayed on the screen of a computer or a mobile device), the required disclosures are of a type, size, and location sufficiently noticeable for an ordinary consumer to read and comprehend them, in print that contrasts highly with the background on which they appear;

2. In communications disseminated orally or through audible means (e.g., radio or streaming audio), the required disclosures are delivered in a volume and cadence sufficient for an ordinary consumer to hear and comprehend them;

3. In communications disseminated through video means (e.g., television or streaming video), the required disclosures are in writing in a form consistent with subparagraph (A) of this definition and shall appear on the screen for a duration sufficient for an ordinary consumer to read and comprehend them, and in the same language as the predominant language that is used in the communication;

UPROMISE, INC. 623 Decision and Order 4. In communications made through interactive media, such as the Internet, online services, and software, the required disclosures are unavoidable and presented in a form consistent with subparagraph (A) of this definition, in addition to any audio or video presentation of them; and 5. In all instances, the required disclosures are presented in an understandable language and syntax, and with nothing contrary to, inconsistent with, or in mitigation of the disclosures used in any communication of them.

C. “Collected Information” shall mean any information or data transmitted from a computer by the TurboSaver Toolbar as a result of the Personalized Offers feature being enabled prior to the date of issuance of this order to any computer server owned by, operated by, or operated for the benefit of respondent.

D. “Commerce” shall mean as defined in Section 4 of the Federal Trade Commission Act, 15 U.S.C. § 44. E. “Computer” shall mean any desktop or laptop computer, handheld device, telephone, or other electronic product or device that has a platform on which to download, install, or run any software program, code, script, or other content and to play any digital audio, visual, or audiovisual content. F. “Covered Online Service” shall mean any product or service using or incorporating a Targeting Tool. Covered Online Service includes, but is not limited to, the TurboSaver Toolbar with the Personalized Offers feature enabled.

G. “Personal information” shall mean individually identifiable information from or about an individual consumer including, but not limited to: (a) a first and last name; (b) a home or other physical address, including street name and name of city or town; (c) an VOLUME 153 Decision and Order email address or other online contact information, such as an instant messaging user identifier or a screen name; (d) a telephone number; (e) a Social Security number; (f) a driver’s license number or other government-issued identification number; (g) prescription information, such as medication and dosage, and prescribing physician name, address, and telephone number, health insurer name, insurance account number, or insurance policy number; (h) a bank account, debit card, or credit card account number; (i) a persistent identifier, such as a customer number held in a “cookie” or processor serial number, that is combined with other available data that identifies an individual consumer; (j) a biometric record; or (k) any information that is combined with any of (a) through (j) above.

H. “Personalized Offers feature” shall mean the component of the TurboSaver Toolbar that Upromise has offered under the name of “Personalized Offers.” I. “Respondent” shall mean Upromise, Inc., and its successors and assigns, and its officers, agents, representatives, and employees.

J. “Targeting Tool” shall mean any software program or application distributed by or on behalf of respondent that is installed on a consumer's computer, whether as a standalone product or as a feature of another product, and used by or on behalf of respondent to record or transmit information about any activity occurring on that computer involving the computer's interactions with websites, services, applications, or forms, unless (a) the activity involves transmission of information related to the configuration of the software program or application itself; (b) the activity involves a consumer's interactions with respondent's websites, services, applications, and/or forms; or (c) the activity involves a consumer's interactions with respondent's member merchants and that information is collected, retained, or used only as necessary for the purpose of UPROMISE, INC. 625 Decision and Order providing the consumer's reward service benefits for transactions involving those merchants.

The TurboSaver Toolbar when configured to collect consumer data, for example, with the Personalized Offers feature enabled, is a Targeting Tool. K. “Third party” shall mean any individual or entity other than respondent, except that a third party shall not include a service provider of respondent that: 1. only uses or receives personal information collected by or on behalf of respondent for and at the direction of the respondent and no other individual or entity, 2. does not disclose the data, or any individually identifiable information derived from such data, to any individual or entity other than respondent, and 3. does not use the data for any other purpose. I.

IT IS ORDERED that respondent, directly or through any corporation, subsidiary, division, website, or other device, in connection with the advertising, promotion, offering for sale, sale, or distribution of any Targeting Tool, in or affecting commerce, shall, A. Prior to the consumer enabling (by downloading, installing, or otherwise activating) any Targeting Tool: 1. Clearly and prominently, and prior to the display of and on a separate screen from, any “end user license agreement,” “privacy policy,” “terms of use” page, or similar document, disclose: a. all the types of data that the Targeting Tool will collect, including but not limited to, if applicable, a statement that the data includes transactions or communications between the VOLUME 153 Decision and Order consumer and third parties in secure sessions, interactions with shopping baskets, application forms, online accounts, web-based email accounts, or search engine pages, and if the information includes personal, financial or health information.

b. how the data is used, including if the data is shared with a third party, other than as reasonably necessary: (i) to comply with applicable law, regulation, or legal process, (ii) to enforce respondent’s terms of use, or (iii) to detect, prevent, or mitigate fraud or security vulnerabilities.

2. Obtain express affirmative consent from the consumer to the enabling (by downloading, installing, or otherwise activating) and to the collection of data.

B. For those TurboSaver Toolbars installed by consumers before the date of issuance of this order, prior to (1) enabling data collection through any Targeting Tool or (2) otherwise making any material change from stated practices about collection or sharing of personal information through the TurboSaverToolbar, provide the notice and obtain the express consent described in subparts A(1) and (2) of this Part.

II.

IT IS FURTHER ORDERED that respondent shall: A. Notify Affected Consumers: a) that they have or had the Personalized Offers feature enabled, and that from 2005 through January 2010 use of this feature resulted in collection and transmission of data to or on behalf of respondent, listing the categories of personal information that were, or could have been, transmitted; and b) how to permanently disable the Personalized Offers feature and uninstall the TurboSaver Toolbar. Notification shall be by each of the following means: UPROMISE, INC. 627 Decision and Order 1. Beginning within thirty (30) days after the date of service of this order and for two (2) years after the date of service of this order, posting of a clear and prominent notice on its website.

2. Beginning within thirty (30) days after the date of service of this order and for three (3) years after the date of service of this order, informing Affected Consumers who complain or inquire about the privacy or security of the TurboSaver Toolbar.

3. Within sixty (60) days after the date of service of this order, providing direct, clear and prominent notice to Affected Consumers who have the Personalized Offers feature enabled.

B. Provide prompt, toll-free, telephonic and electronic mail support to help Affected Consumers disable the Personalized Offers feature and, if requested, uninstall the TurboSaver Toolbar.

III.

IT IS FURTHER ORDERED that respondent shall, within five (5) days after the date of service of this order, delete or destroy, or cause to be deleted or destroyed, all Collected Information in respondent’s custody or control, unless otherwise directed by a representative of the Commission. IV.

IT IS FURTHER ORDERED that respondent, directly or through any corporation, subsidiary, division, website, or other device, in connection with its advertising, marketing, promotion, or offering of any service or product in or affecting commerce, shall not make any representation, in any manner, expressly or by implication, about the extent to which respondent maintains and protects the security, privacy, confidentiality, or integrity of any personal information collected from or about consumers, unless the representation is true, and non-misleading. VOLUME 153 Decision and Order V.

IT IS FURTHER ORDERED that respondent, directly or through any corporation, subsidiary, division, website, or other device, in connection with its advertising, marketing, promotion, or offering of any product or service, in or affecting commerce, shall maintain a comprehensive information security program that is reasonably designed to protect the security, privacy, confidentiality, and integrity of personal information collected from or about consumers. This section may be satisfied through the review and maintenance of an existing program so long as that program fulfills the requirements set forth herein. Such program, the content and implementation of which must be fully documented in writing, shall contain administrative, technical, and physical safeguards appropriate to respondent’s size and complexity and the nature and scope of respondent’s activities, and the sensitivity of the personal information collected from or about consumers, including:

A. The designation of an employee or employees to coordinate and be accountable for the information security program;

B. The identification of material internal and external risks that could result in the unauthorized disclosure, misuse, loss, alteration, destruction, or other compromise of personal information and an assessment of the sufficiency of any safeguards in place to control these risks. At a minimum, this risk assessment should include consideration of risks in each area of relevant operation, including, but not limited to: (1) employee training and management; (2) information systems, including network and software design, information processing, storage, transmission, and disposal; and (3) prevention, detection, and response to attacks, intrusions, account takeovers, or other systems failures;

C. The design and implementation of reasonable safeguards to control the risks identified through risk assessment, and regular testing or monitoring of the UPROMISE, INC. 629 Decision and Order effectiveness of the safeguards’ key controls, systems, and procedures;

D. The development and use of reasonable steps to select and retain service providers capable of appropriately safeguarding personal information such service providers receive from respondent or obtain on respondent’s behalf, and the requirement, by contract, that such service providers implement and maintain appropriate safeguards; and E. The evaluation and adjustment of respondent’s information security program in light of the results of the testing and monitoring required by subpart C, any material changes to respondent’s operations or business arrangements, or any other circumstances that respondent knows or has reason to know may have a material impact on the effectiveness of its information security program.

VI.

IT IS FURTHER ORDERED that, in connection with its compliance with Part V of this order, for any Covered Online Service respondent shall obtain initial and biennial assessments and reports (“Assessments”) from a qualified, objective, independent third-party professional, who uses procedures and standards generally accepted in the profession. Professionals qualified to prepare such Assessments shall be: a person qualified as a Certified Information System Security Professional (CISSP) or as a Certified Information Systems Auditor (CISA); a person holding Global Information Assurance Certification (GIAC) from the SysAdmin, Audit, Network, Security (SANS) Institute; or a similarly qualified person or organization approved by the Associate Director for Enforcement, Bureau of Consumer Protection, Federal Trade Commission, Washington, D.C. 20580. The reporting period for the Assessments shall cover: (1) the first one hundred and eighty (180) days after service of the order for the initial Assessment, and (2) each two (2) year period thereafter for twenty (20) years after service of the order for the biennial Assessments. Each Assessment shall:

VOLUME 153 Decision and Order A. Set forth the specific administrative, technical, and physical safeguards that respondent has implemented and maintained during the reporting period; B. Explain how such safeguards are appropriate to respondent’s size and complexity, and the nature and scope of respondent’s activities, and the sensitivity of the personal information collected from or about consumers;

C. Explain how the safeguards that have been implemented meet or exceed the protections required by Part V of this order; and D. Certify that respondent’s security program is operating with sufficient effectiveness to provide reasonable assurance that the security, confidentiality, and integrity of personal information is protected and has so operated throughout the reporting period. Each Assessment shall be prepared and completed within sixty (60) days after the end of the reporting period to which the Assessment applies. Respondent shall provide the initial Assessment to the Associate Director for Enforcement, Bureau of Consumer Protection, Federal Trade Commission, Washington, D.C. 20580, within ten (10) days after the Assessment has been prepared. All subsequent biennial Assessments shall be retained by respondent until the order is terminated and provided to the Associate Director of Enforcement within ten (10) days of request.

VII.

IT IS FURTHER ORDERED that respondent shall, for a period of five (5) years after the last date of dissemination of any representation covered by this order, maintain and upon request make available to the Commission for inspection and copying: A. All advertisements, labeling, packaging and promotional material containing the representation; UPROMISE, INC. 631 Decision and Order B. All materials relied upon in disseminating the representation;

C. All tests, reports, studies, surveys, demonstrations, or other evidence in its possession or control that contradict, qualify, or call into question the representation, or the basis relied upon for the representation, including complaints and other communications with consumers or with governmental or consumer protection organizations; and D. All acknowledgments of receipt of this order, obtained pursuant to Part IX.

Moreover, for a period of three (3) years after the date of preparation of each Assessment required under Part VI of this order, respondent shall maintain and upon request make available to the Commission for inspection and copying all materials relied upon to prepare the Assessment, whether prepared by or on behalf of the respondent, including but not limited to all plans, reports, studies, reviews, audits, audit trails, policies, training materials, and assessments, for the compliance period covered by such Assessment.

VIII.

IT IS FURTHER ORDERED that respondent shall, in connection with this action or any subsequent investigations related to or associated with the transactions or the occurrences that are the subject of the Commission’s complaint, cooperate in good faith with the Commission and appear at such places and times as the Commission shall reasonably request, after written notice, for interviews, conferences, pretrial discovery, review of documents, and for such other matters as may be reasonably requested by the Commission. If requested in writing by the Commission, respondent shall appear and provide truthful testimony in any trial, deposition, or other proceeding related to or associated with the transactions or the occurrences that are the subject of the complaint, without the service of a subpoena. VOLUME 153 Decision and Order IX.

IT IS FURTHER ORDERED that respondent shall deliver a copy of this order to: (1) all current and future principals, officers, and directors; and (2) all current and future managers who have responsibilities with respect to the subject matter of this order, and shall secure from each such person a signed and dated statement acknowledging receipt of the order, with any electronic signatures complying with the requirements of the E-Sign Act, 15 U.S.C. § 7001 et seq. Respondent shall deliver this order to current personnel within thirty (30) days after the date of service of the order, and to future personnel within thirty (30) days after the person assumes such position or responsibilities. X.

IT IS FURTHER ORDERED that respondent shall notify the Commission at least thirty (30) days prior to any change in respondent that may affect compliance obligations arising under this order, including but not limited to, a dissolution, assignment, sale, merger, or other action that would result in the emergence of a successor company; the creation or dissolution of a subsidiary (including an LLC), parent, or affiliate that engages in any acts or practices subject to this order; the proposed filing of a bankruptcy petition; or a change in respondent’s name or address. Provided, however, that with respect to any proposed change about which respondent learns less than thirty (30) days prior to the date such action is to take place, respondent shall notify the Commission as soon as is practicable after obtaining such knowledge. Unless otherwise directed by a representative of the Commission, all notices required by this Part shall be sent by overnight courier (not the U.S. Postal Service) to the Associate Director of Enforcement, Bureau of Consumer Protection, Federal Trade Commission, 600 Pennsylvania Avenue NW, Washington, DC 20580, with the subject line FTC v. Upromise. Provided, however, that, in lieu of overnight courier, notices may be sent by first-class mail, but only if an electronic version of such notices is contemporaneously sent to the Commission at [email protected]. UPROMISE, INC. 633 Decision and Order XI.

IT IS FURTHER ORDERED that respondent shall, within sixty (60) days after service of this order, and at such other times as the FTC may require, file with the Commission a true and accurate report, in writing, setting forth in detail the manner and form in which respondent has complied with this order. Within ten (10) days of receipt of written notice from a representative of the Commission, respondent shall submit additional true and accurate written reports.

XII.

This order will terminate on December 31, 2031, or twenty (20) years from the most recent date that the United States or the Commission files a complaint (with or without an accompanying consent decree) in federal court alleging any violation of the order, whichever comes later; provided, however, that the filing of such a complaint will not affect the duration of: A. Any Part of this order that terminates in less than twenty (20) years;

B. This order’s application to any respondent that is not named as a defendant in such complaint; and C. This order if such complaint is filed after the order has terminated pursuant to this Part.

Provided, further, that if such complaint is dismissed or a federal court rules that the respondent did not violate any provision of the order, and the dismissal or ruling is either not appealed or upheld on appeal, then the order will terminate according to this Part as though the complaint had never been filed, except that this order will not terminate between the date such complaint is filed and the later of the deadline for appealing such dismissal or ruling and the date such dismissal or ruling is upheld on appeal. By the Commission.

VOLUME 153 Analysis to Aid Public Comment ANALYSIS OF CONSENT ORDER TO AID PUBLIC COMMENT The Federal Trade Commission has accepted, subject to final approval, an agreement containing a consent order applicable to Upromise, Inc.

The proposed consent order has been placed on the public record for thirty (30) days for receipt of comments by interested persons. Comments received during this period will become part of the public record. After thirty (30) days, the Commission will again review the agreement and the comments received, and will decide whether it should withdraw from the agreement and take appropriate action or make final the agreement’s proposed order. Upromise offers, among other things, a membership service through which consumers who join can receive cash rebates for making online purchases from merchants who participate in the Upromise program. To take part in the program, consumers download and install software, the Upromise TurboSaver Toolbar (“Toolbar”), from Upromise that modifies the consumers’ Internet browser to highlight Upromise member merchants. The Commission’s complaint involves the advertising, marketing, and operation of an optional feature of that Toolbar, the “personalized offers” feature. That feature modified the Toolbar to provide targeted advertising to the consumer based upon the consumers’ online behavior (the modified version is referred to here as the “Targeting Tool”). Upromise engaged a service provider to develop the Toolbar and the personalized offers feature.

According to the FTC complaint, while Upromise represented to consumers that the Targeting Tool collected information about the web sites consumers visited, its failure to disclose the full extent of data collected through the software was deceptive. The complaint alleges that the Targeting Tool collected the names of all websites visited; all links clicked; information that consumers entered into some web pages such as usernames, passwords, and search terms; and, from July 2009 through mid-January 2010, consumers’ interactions with forms on secure web pages. The complaint further alleges that Upromise misrepresented its UPROMISE, INC. 635 Analysis to Aid Public Comment privacy and security practices, including misrepresenting that consumers’ data would be encrypted. The complaint alleges that these claims were false and thus violate Section 5 of the FTC Act. In addition, the FTC complaint alleges that Upromise engaged in a number of practices that, taken together, failed to provide reasonable and appropriate security for the personal information it collected and maintained. Among other things, Upromise: (1) transmitted sensitive information from secure web pages, such as financial account numbers and security codes, in clear readable text; (2) did not use readily available, low-cost measures to assess and address the risks to consumer information; (3) failed to ensure that employees responsible for the information collection program received adequate guidance and training; (4) failed to take adequate measures to ensure that its service provider employed reasonable and appropriate measures to protect consumer information.

The complaint alleges that Upromise’s failure to employ reasonable and appropriate measures to protect consumer information – including credit card and financial account numbers, security codes and expiration dates, and Social Security numbers – was unfair. Tools for capturing data in transit, for example over unsecured wireless networks such as those often provided in coffee shops and other public spaces, are commonly available, making such clear-text data vulnerable to interception. The misuse of such information – particularly financial account information and Social Security numbers – can facilitate identity theft and related consumer harms.

The proposed order contains provisions designed to prevent Upromise from engaging in the future in practices similar to those alleged in the complaint.

Part I of the proposed order requires Upromise to disclose to consumers – before the download or installation of software that records or transmits information about any activity occurring on a computer involving the computer’s interactions with websites, services, applications, or forms – the types of information collected and how the information will be used. The disclosure must be clear and prominent and separate from other notices. The company must also obtain consumers’ express affirmative consent VOLUME 153 Analysis to Aid Public Comment before the consumer downloads, installs, or otherwise activates such software. In addition, the company must provide this clear and prominent notice, and obtain express affirmative consent, before enabling data collection through any previously installed TurboSaver Toolbar and before making any material change from stated practices about collection or sharing of personal information through the Toolbar.

Part II of the proposed order requires Upromise to provide notice to consumers who, prior to the issuance of the order, had the Personalized Offers feature enabled. The notice must inform consumers about the categories of personal information that were, or could have been, transmitted by the feature, and how to disable the Personalized Offers feature and uninstall the Toolbar. Part III of the proposed order requires the company to destroy data it collected during the years covered by the complaint unless otherwise directed by the Commission.

Part IV of the proposed order prohibits the company from making any misrepresentations about the extent to which it maintains and protects the security, privacy, confidentiality, or integrity of any information collected from or about consumers. Part V of the proposed complaint requires Upromise to maintain a comprehensive information security program that is reasonably designed to protect the security, confidentiality, and integrity of such information (whether in paper or electronic format) about consumers. The security program must contain administrative, technical, and physical safeguards appropriate to Upromise’s size and complexity, the nature and scope of its activities, and the sensitivity of the information collected from or about consumers and employees. Specifically, the proposed order requires Upromise to:

• designate an employee or employees to coordinate and be accountable for the information security program; • identify material internal and external risks to the security, confidentiality, and integrity of personal information that could result in the unauthorized disclosure, misuse, loss, alteration, destruction, or other compromise of such information, and assess the UPROMISE, INC. 637 Analysis to Aid Public Comment sufficiency of any safeguards in place to control these risks;

• design and implement reasonable safeguards to control the risks identified through risk assessment, and regularly test or monitor the effectiveness of the safeguards’ key controls, systems, and procedures;

• develop and use reasonable steps to select and retain service providers capable of appropriately safeguarding personal information they receive from Upromise or obtain on behalf of Upromise, and require service providers by contract to implement and maintain appropriate safeguards; and • evaluate and adjust its information security programs in light of the results of testing and monitoring, any material changes to operations or business arrangements, or any other circumstances that it knows or has reason to know may have a material impact on its information security program.

Part VI of the proposed order requires Upromise to obtain within the first one hundred eighty (180) days after service of the order, and on a biennial basis thereafter for a period of twenty (20) years, an assessment and report from a qualified, objective, independent third-party professional, certifying, among other things, that: (1) it has in place a security program that provides protections that meet or exceed the protections required by the proposed order; and (2) its security program is operating with sufficient effectiveness to provide reasonable assurance that the security, confidentiality, and integrity of sensitive consumer, employee, and job applicant information has been protected. Parts VII, VIII, IX, X, XI, and XII of the proposed order are reporting and compliance provisions. Part VII requires Upromise to retain documents relating to its compliance with the order. For most records, the order requires that the documents be retained for a five-year period. For the third-party assessments and supporting documents, Upromise must retain the documents for a period of three years after the date that each assessment is prepared. Part VIII requires the company to cooperate with the FTC in VOLUME 153 Analysis to Aid Public Comment connection with this action or any subsequent investigations related to or associated with the transactions or the occurrences that are the subject of the FTC complaint. Part IX requires dissemination of the order now and in the future to persons with responsibilities relating to the subject matter of the order. Part X ensures notification to the FTC of changes in corporate status. Part XI mandates that Upromise submit a compliance report to the FTC within 60 days, and periodically thereafter as requested. Part XII provides that the order will terminate after twenty (20) years, with certain exceptions.

The purpose of this analysis is to facilitate public comment on the proposed order. It is not intended to constitute an official interpretation of the proposed order or to modify its terms in any way.

LONG FENCE & HOME, LLLP 639 Complaint

← 153 F.T.C. 458 · 153 F.T.C. 639 →