# Amazon.de mystery concerning my privacy

**URL:** <https://boards.straightdope.com/t/amazon-de-mystery-concerning-my-privacy/570003>\
**Category:** Factual Questions\
**Created:** [February 3, 2011, 9:48am UTC](https://boards.straightdope.com/t/amazon-de-mystery-concerning-my-privacy/570003 "2011-02-03T09:48:42Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![EinsteinsHund](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/einsteinshund/32/8400_2.png) [@EinsteinsHund](https://boards.straightdope.com/u/EinsteinsHund)\
**Post date:** [February 3, 2011, 9:48am UTC](https://boards.straightdope.com/t/amazon-de-mystery-concerning-my-privacy/570003/1 "2011-02-03T09:48:42Z")

</div>

I’m a long time customer on [amazon.de](http://amazon.de) (German), and considering their well matching recommendations, fully aware about them storing and tracking my personal data. I’m okay with that, as long as it’s restricted to my personal account.

But then this happened:

A friend of mine wanted to order from [amazon.de](http://amazon.de) and asked me if there was something I’d like to have he could add to his order (to save shipping fee). So I checked my wish list on amazon and emailed my friend three direct links to items (one book, two CDs) from the list he should order for me. He did so, the items were sent, and everything went the usual way.

A few days after the order had been processed, I checked my amazon wish list, and to my big surprise, two of the articles now are marked as purchased items, although the whole transaction was done outside of my account.

How the heck do they know I got the articles via a friend? The only possibility I can imagine is that they tracked my email with the links to the items, but that would have bee an extreme invasion of my privacy.

Does anybody know what was going on here, or maybe had a similar experience?

---

<div class="post-metadata">

**Author:** ![Mops](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/mops/32/16494_2.png) [@Mops](https://boards.straightdope.com/u/Mops)\
**Post date:** [February 3, 2011, 9:59am UTC](https://boards.straightdope.com/t/amazon-de-mystery-concerning-my-privacy/570003/2 "2011-02-03T09:59:16Z")

</div>

WAG: you followed the links from your wish list, and the resulting URL (that you mailed to your friend) still contained a parameter connecting it to your wish list.

---

<div class="post-metadata">

**Author:** ![EinsteinsHund](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/einsteinshund/32/8400_2.png) [@EinsteinsHund](https://boards.straightdope.com/u/EinsteinsHund)\
**Post date:** [February 3, 2011, 10:24am UTC](https://boards.straightdope.com/t/amazon-de-mystery-concerning-my-privacy/570003/3 "2011-02-03T10:24:03Z")

</div>

**Mops** , that’s a possibility I hadn’t considered. Indeed, I followed the links from my wish list, copied the URLs and pasted them into the email to my friend. So if he followed them directly from the email and then put the articles in his shopping cart, there could have been a continuous passing on of any information that was part of these URLs.

Okay, that’s a good explanation, and better than spying my emails, but still, I would find it borderline invasion of privacy.

---

<div class="post-metadata">

**Author:** ![Telemark](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/telemark/32/372_2.png) [@Telemark](https://boards.straightdope.com/u/Telemark)\
**Post date:** [February 3, 2011, 12:30pm UTC](https://boards.straightdope.com/t/amazon-de-mystery-concerning-my-privacy/570003/4 "2011-02-03T12:30:18Z")

</div>

> [@EinsteinsHund](#):
>
> Okay, that’s a good explanation, and better than spying my emails, but still, I would find it borderline invasion of privacy.

It’s inevitable when information is put on the URL. It’s pretty standard usage, not something I would consider an invasion of privacy at all. If anything, it works against Amazon and they would like to avoid it.

---

<div class="post-metadata">

**Author:** ![EinsteinsHund](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/einsteinshund/32/8400_2.png) [@EinsteinsHund](https://boards.straightdope.com/u/EinsteinsHund)\
**Post date:** [February 3, 2011, 12:42pm UTC](https://boards.straightdope.com/t/amazon-de-mystery-concerning-my-privacy/570003/5 "2011-02-03T12:42:51Z")

</div>

> [@Telemark](#):
>
> It’s inevitable when information is put on the URL. It’s pretty standard usage, not something I would consider an invasion of privacy at all. If anything, it works against Amazon and they would like to avoid it.

My point is that this way, my personal handle is encoded to these URLs and later decoded in a transaction that doesn’t involve my own account, just to be used afterwards by amazon to assume changes to the personal data in my account, e. g. my private wish list. It’s not that big a deal, but I’m still uncomfortable with this kind of process. If they want to avoid it, why do they use the information to manipulate my data?

---

<div class="post-metadata">

**Author:** ![Ferret\_Herder](https://avatars.discourse-cdn.com/v4/letter/f/e47774/32.png) [@Ferret\_Herder](https://boards.straightdope.com/u/Ferret_Herder)\
**Post date:** [February 3, 2011, 1:21pm UTC](https://boards.straightdope.com/t/amazon-de-mystery-concerning-my-privacy/570003/6 "2011-02-03T13:21:50Z")

</div>

The wish list feature is designed to let other people buy you presents off of it, without the risk of you getting multiples of the same item. Many people just point friends and family to their wish list if they’re asked about gifts.

---

<div class="post-metadata">

**Author:** ![EinsteinsHund](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/einsteinshund/32/8400_2.png) [@EinsteinsHund](https://boards.straightdope.com/u/EinsteinsHund)\
**Post date:** [February 3, 2011, 1:44pm UTC](https://boards.straightdope.com/t/amazon-de-mystery-concerning-my-privacy/570003/7 "2011-02-03T13:44:08Z")

</div>

> [@Ferret\_Herder](#):
>
> The wish list feature is designed to let other people buy you presents off of it, without the risk of you getting multiples of the same item. Many people just point friends and family to their wish list if they’re asked about gifts.

Yeah, I know, but the default setting for the wish list is _private_, so you have to actively set it to public to make it available to others. My use (and I’m sure that of many others) for the wish list is to keep track of items I’m interested in, but don’t want to buy immediately.

---

<div class="post-metadata">

**Author:** ![Nava](https://avatars.discourse-cdn.com/v4/letter/n/da6949/32.png) [@Nava](https://boards.straightdope.com/u/Nava)\
**Post date:** [February 3, 2011, 1:55pm UTC](https://boards.straightdope.com/t/amazon-de-mystery-concerning-my-privacy/570003/8 "2011-02-03T13:55:52Z")

</div>

**EinsteinsHund** , did the shipment go directly to your address?

If your friend used the same address that amazon has on record for you (not only that, but with your name on it) that seems like something the dumbest of code monkeys should be able to identify as being for you.

---

<div class="post-metadata">

**Author:** ![Omar\_Little](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/omar_little/32/269_2.png) [@Omar\_Little](https://boards.straightdope.com/u/Omar_Little)\
**Post date:** [February 3, 2011, 2:00pm UTC](https://boards.straightdope.com/t/amazon-de-mystery-concerning-my-privacy/570003/9 "2011-02-03T14:00:52Z")

</div>

There was nothing nefarious here. Your wish list is not private. Your friend purchased items from **your wishlist**.

---

<div class="post-metadata">

**Author:** ![EinsteinsHund](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/einsteinshund/32/8400_2.png) [@EinsteinsHund](https://boards.straightdope.com/u/EinsteinsHund)\
**Post date:** [February 3, 2011, 2:19pm UTC](https://boards.straightdope.com/t/amazon-de-mystery-concerning-my-privacy/570003/10 "2011-02-03T14:19:51Z")

</div>

> [@Nava](#):
>
> **EinsteinsHund** , did the shipment go directly to your address?

No, the whole shipment went to my friend’s address, the only connection between my wish list and my friend’s order were the links to the items in the mentioned email to him.

And **Omar Little** , please see post #7. I didn’t set my wish list to _public_, and my friend didn’t add the articles directly from my wish list. I assumed that by mailing him the links, it would be the same as if I had told him my wishes over the phone or in a direct conversation.

But anyway, I didn’t want to make a big deal about it, I was mostly curious how this all worked. I just assumed that by setting the wish list to private, there wouldn’t be a mechanism to register changes that happened outside of my own account.

---

<div class="post-metadata">

**Author:** ![Telemark](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/telemark/32/372_2.png) [@Telemark](https://boards.straightdope.com/u/Telemark)\
**Post date:** [February 3, 2011, 2:50pm UTC](https://boards.straightdope.com/t/amazon-de-mystery-concerning-my-privacy/570003/11 "2011-02-03T14:50:11Z")

</div>

> [@EinsteinsHund](#):
>
> I assumed that by mailing him the links, it would be the same as if I had told him my wishes over the phone or in a direct conversation.

Clearly, that is not the case. It’s hard to know exactly what information is being stored in the URL unless you take a close look at it, so emailing links generated by a site is a possible way for your information to get out. Is there a “Mail this item to a friend” link on the site? That may (or may not) strip identifiable information out of the URL based on your privacy settings.

---

<div class="post-metadata">

**Author:** ![EinsteinsHund](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/einsteinshund/32/8400_2.png) [@EinsteinsHund](https://boards.straightdope.com/u/EinsteinsHund)\
**Post date:** [February 3, 2011, 7:05pm UTC](https://boards.straightdope.com/t/amazon-de-mystery-concerning-my-privacy/570003/12 "2011-02-03T19:05:45Z")

</div>

> [@Telemark](#):
>
> Is there a “Mail this item to a friend” link on the site? That may (or may not) strip identifiable information out of the URL based on your privacy settings.

No, that doesn’t seem to be the case, but I will be more cautious in the future when mailing or posting links from sites I’m currently logged in to.

I think I now fully understand what happened. There seems to have been a flag encoded in the URL from when I was logged in that tells the site’s software:

```auto

 IF (this.article is_purchased_ following this.URL) THEN
    EinsteinsHund.wishlist.article.purchased = TRUE 

```

Am I thinking right? In this case, there really was nothing dubious going on. It was just my carelessness.

Thanks to all for clearing my confusion.
