First, you need to understand, that no business can access a user's data without a user's consent. It's doesn't matter there won't be passwords for authentication, we use biometric authentication instead which is more convenient and safe for users.
Second, when a business wants to get your data it sends you a request with its targeted offer (i.e. mortgage offer for students). You receive it, see details of the offer, what personal information it requests and decide either it's interesting and looks safe for you or not. If you decide to share, then you earn tokens and a business gets just requested personal data, not more.
Is it more clear or needed more clarifications?
Is there a way of knowing that the businesses on the platform are genuine and this aren't on the platform to steal user data for their personal gains??Because from what I'm reading,I could just push my data around the ecosystem without the need for passwords but what if there are unscrupulous people in the ecosystem,how does the platform weed them out?