- Tell people up front what you will do with their data
- Let them opt out
- Track what services your own service uses (Ex: your website -> google analytics)
- If people want to know what data you have about them tell them
- If people want you to delete their data (and there is no legal obligation to keep it) delete their data
- Take reasonable steps to keep user data safe
In this case Grindr was passing (per the article): advertising ID, IP address, GPS, location, gender, age, device information and app name to a bunch of Ad Services with "no control".
So beyond just "handling data" Grindr was getting paid (ads) for sharing your data to companies that could then also turn around and do whatever they wanted with that data.