[w3c/browser-payment-api] Add Guidance Text for User Consent (#229)

This is a recommendation from the Security and Privacy Checklist review. See https://docs.google.com/document/d/1w7ginyzNg-xZUmITK4vzcGUKB4gbMOAvlkWWaRtX14k/edit?usp=sharing for additional detail

The privacy analysis highlights the importance for explicit user consent in providing payment or any information associated with payments to a requesting web site. We suggest including the following guidance in the spec: any mechanism that allows users to persistently grant information should take steps to inform users that doing so will allow various websites to positively identify and correlate a user, even across site owners.


---
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/w3c/browser-payment-api/issues/229

Received on Wednesday, 10 August 2016 20:08:34 UTC