>forward to 3rd party
Already this screams "security nightmare". Why the fuck would you not just handle the data yourself after what keeps happening every year with companies left and right getting hacked because some dumb fuck clicked an email they weren't supposed to?
So the token is meaningless to hackers. O.K. and? That third party still has people's information. How reliable is this 3rd party that you would trust them with said information to where they wouldn't just sell it to marketing spammers? Do they follow GDPR standards too or fuck them, because america?
I hope to hell people are grilling him on this shit and not just going "WOW JOSHY VERY SMART, HE KNOWS THINGS!!!" (who am I kidding, they most likely are)