Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Lately I've been thinking that this should be part of the login process. Enter username and password. Just below the "Login" button there's the "If you click on this button..." text with a link to the TOS. Every time someone logs in they are accepting the TOS. If your login events are recorded you even have a record of when each user logged-in and, effectively, accepted the TOS.


American Express does this when you pay your bill on-line. I hate it --- that was one of the reasons, after decades with AmEx, that I switched all our household spending over to a Southwest Airlines affiliate-program Visa.


I would not consider that to provide adequate notice of a change in the TOS. If it's just a link that never changes, you won't have been notified if it updates.


According to the article:

  Using Clickthrough Agreements.  Zappos had an easy way to 
  form a clickthrough agreement.  As shoppers are checking
  out of the store with their shopping cart, Zappos could
  say "By clicking the 'purchase' button, you agree to the
  Zappos terms of use" with a link to the document.  It's as
  easy as that.  No custom coding, no interstitial web
  pages, no real risk of abandoned shopping carts.
Considering that the author is a professor of Law at Santa Clara University, I would think that the TOS in the login dialog would hold water in court.

http://www.ericgoldman.org/biography.html


What if it included the date of most recent update? Worst case, you could store the user's most recent TOS agreement version or date identifier, and force them to agree after logging in if they want to continue. This seems to be how Apple operates for the App Store.


When I was at Yahoo years ago, and we handled billing for premium servies, we'd explicitly store the version of the TOS the user had indicated express consent to as an extra precaution (express consent in this case meant the user had ticket a checkbox to confirm they agreed and then submitted the form).


First of all, the login experience should not change if the TOS is the same as before.

If the TOS has changed, you could accept-reject the login (lock the credentials in the fields) and say "to continue, please read the TOS change and press 'accept' to continue". Or just have this as a separate screen after the login.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: