Could have been worse I guess. Still...there are no second chances in this game - confidence once damaged can never be made truly whole again.
I'm also a bit alarmed at me hearing this from mybb instead of AH.
That being said I am impressed that AH is attempting to analyze customer geographic distributions.
Steam has an option to disable storing of credit card info. (AH I hope your taking notes)
We don't store credit card info - that is stored offline by our carrier so there would never be a danger of that data being compromised. We were well aware of what information was being used, and we would have definitely not used payment or identity information (like they do on some public records) as firstly it would yield no value for GIS and secondly because we were extremely cautious (even though we still ended up on the wrong side of this)
It could have been worse - agreed. But we're glad that it wasn't and we fully believe that once explained and any risks have been mitigated, we will win back the trust of all our clients