The CEO coming in here and trying to defend that this is actually a great idea is only making things worse.
I'm guessing they don't operate in Europe, because this would be a massive violation of many European and national privacy regulations.
Maybe they should take a hint from this - the fact that they can pull it off in the US doesn't mean it's morally acceptable.
Too many people think US citizen != EU resident (and therefore not a data subject covered by GDPR)