I'd like to continue my quasi-useful unhinged ramblings by killing something that many of you love.
P411, aka Preferred411. TL;DR; don't use it, if you do use it, stop using it and tell them to delete your data. Do it now, tell your friends. Here's why:
Now now, I can hear you already "No sauce, P411 is cool, they're legit, no way they'd cause us any harm", to which I'll reply, surely you realize that, someone not meaning to harm you can indeed end up harming you... right?
I have no doubt that, the folks behind P411 have the best of intentions. I mean that in earnest, if there were going to be issues with them, there would have already been issues with them. My objection, and, what your objection should be, is the storage of PII, so let's have a look shall we? https://preferred411.com/privacy
P411 requires that you send them, digitally, your full name, e-mail address, telephone number, website url, etc, use your imagination in terms of what "etc" means. Basically they have, initially, the full monty, all of your PII, But they delete that, or say they delete it, and, well, they seem trustworthy so, what don't they destroy? What do they gather after the fact? Well they define that as well.
They keep, "P411 Id, email address, user name, security questions, and partial phone number", additionally, as you use their website, they keep "All communications made through Preferred411", "all communications with Preferred411", " All activity within accounts", your IP address, geolocation, browser type, HTTP referrer information, and track you via their login cookie via uniqueID, and in addition to that, for the ladies, they store photos of your government-issued ID.
Additionally, they disclose "This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply", which means that, your communications with P411 directly are likely directed to a google apps account, so google has access to them. Additionally, any time they serve you a reCAPTCHA, google has access to your information as well. Google, of course, packages and sells that information to advertisers, who then package and sell it to other advertisers, etc etc. That's because reCAPTCHA as a service, is Google's code, running on their website. That code knows what website it's running on, and that you're interacting with it.
Now, if you've been paying attention, you can see the problem here.
For those that don't, it's simple. They say they delete your information, but, they then store and continue to collect enough information that, you could easily be identified by them or anyone else with access to their databases, and, they're sharing enough information with google that it would cost somewhere around $25 to reveal your real name via access to any number of marketing data services. A VPN will not protect you from this, if you've been using the site, you're already exposed, and will remain exposed for awhile even if you cancel your P411 membership and request they delete your data (which they require you to do so via email).
That's not really even the worst part. See, a website isn't infallible. P411 even admits this "we are unable to make any guarantees that our measures (security measures) will prevent an illegal hacking, which could result in the data on our servers being compromised.", and boy howdy do I have a treat especial for you, their site currently has a rank of "C" on the Mozilla Observatory (MZO). That's, pretty good, however, and this is a big however, their site on April 11, 2016 had an "F", a hard "F", a **zero**, on MZO, on November 23, 2020, another "F", with a score of 10, and it wasn't until recently, within the last year, that they got things secure enough to earn a "C". I now consider it safe enough to report this to you, as in their current state, they're likely as secure as most websites you use, and revealing this to you, and the world, presents no additional risk to anyone as this data is already public elsewhere.
But it gets worse, see, MZO isn't a well known tool outside of security researchers and hackers. It also doesn't just go scanning websites willy-nilly, one has to request that they scan a site. That means, some interested party, in 2016, scanned P411, and found it wildly insecure, it was scanned again four years later, maybe by the same person, maybe not, and again found wildly insecure, and it remained as-such until recently, all the while, those scan results were available to the public, searchable, findable, and there's no guarantee that any of those interested parties were at all affiliated with P411, nor is there any guarantee that those results were used in a benevolent manner. I've linked those results below so you can see for yourself.
I'll wrap this up with, if you have used P411, they've betrayed your trust, they've sold themselves as one thing, and delivered you another by remaining massively insecure for years, and allowing Google, a 3rd party, to run code on their website that deanonymizes their users. They likely have no idea if they were compromised between 2016 and now, and neither do you, nor do they have to disclose a breach to you (as per their TOS). The best move was to never use them, the second best thing is to stop using them today.
disclosure: I've never used P411, I have no interest, personal or otherwise, in P411, or any competing ventures. I simply like you and want to try and help keep you safe.