Mint.com - promises to integrate your various banking sites and aggregate your financial data in handy charts with eye-popping flexibility. And it's free.
The idea of having all my banking, credit cards, insurance, and home expenses integrated in one interface kicks major butt.
The problem is, I have to give them all my banking website usernames and passwords to do this.
All of them.
Mint.com proudly tells you that they don't keep your data - which is true.
But Mint.com partners with a banking site called Yodlee.com to do all it's wizardy - and Yodlee.com most certainly keeps your data, because that's how they will pull data from your banking sites and give it to Mint.com.
Yodlee.com's privacy statement is - (to put it mildly) hard to find.
I pinged Mint.com to ask where I could find the privacy statement that applied to Mint.com users - and they responded with this:
Yodlee provides this same account aggregation service to many of the leading U.S. financial institutions (32 of 50 of the top financial services institutions to be exact), including, but not limited to, Bank of America and Fidelity Investments. As a result, you should be aware that Yodlee’s security technology and infrastructure is industry leading in the online banking sector, including hardware encryption. Yodlee is also in full compliance with all the important industry standards including:I suspect I'm not alone in wondering how much more my liability could be if I don't catch fraud within 60 days.
§ SAS 70 II;
§ ISO 17799 Compliance;
§ Visa CISP Level One Compliance
§ Multi-factor authentication – FFIEC compliance
In addition to the points above, your credit card company protects you in case of fraud and you would not lose this protection in any way by using the Mint service. But what you may not know is that Regulation E, which is a set of rules issued by the Federal Reserve governing electronic transactions (online banking, ATM withdrawals, debit card payments …) limits your liability in most cases to $50 in the event of fraud. Consumers must notify their bank of the fraud within 2 business days. On the third day the liability goes up to $500 and it can be more if notification occurs after 60 days. Regulation E rules are designed to encourage consumers to feel safe about electronic transactions. Even if a consumer has acted negligently and succumbed to a phishing or fraud attack and given away personal identification information that led to the fraud, they will be protected. In fact, one of the reasons the Mint service provides email and mobile alerts is so you don’t even need to log in to become immediately aware of any fraudulent activity.
Killer idea - not sure I'd be beating a path to their door, though.
1 comment:
...and since to protect yourself while using their service, you basically have to live with your hand on the pulse of every one of your accounts, there's not only 'no free lunch' - there's also no such thing as a real vacation.
entirely not worth trading peace of mind for convenience. and - they have to have your *passwords*? isn't that giving them de facto power of attorney? i wouldn't do that on a bet. giving them your password gives them power to *change your password*. sounds phar too phishy to me.
sincerely,
thorn
Post a Comment