Final – A credit card built for the 21st century
getfinal.com
getfinal.com
-Hacked main street merchant, restaurant...
-Processor breach...
-Hacked point-of-sale service company/vendor...
-Hacked E-commerce Merchant...
-ATM or Gas Pump Skimmer...
-Crooked employee...(Most frequently committed by restaurant workers)...
-Lost/Stolen card...
-Malware on Consumer PC...
-Physical record theft [from] Merchant, government agency...
https://krebsonsecurity.com/2015/01/how-was-your-credit-card...
So of Krebs' top nine sources of leaks, Final addresses at most three. No thanks!
UPDATE: Re the downvotes, Maybe someone should tag posts about YC companies so we know when it's unacceptable to engage our critical faculties.
I mean, sure, but three is still better the status quo.
Unless your startup you haven't told anybody about solves all 9 issues, I'll take those 3 all the way to the bank! If they get enough traction with this MVP, they may move onto mailing out monthly physical credit cards which would handle a couple more on that list, but how about letting them learn to walk first?
https://www.bankofamerica.com/privacy/accounts-cards/shopsaf...
I was hopeful a "credit card built for the 21st century" would offer something genuinely new. I guess this has push notifications about charges, which is nice. And it can go in a digital wallet, but digital wallets are supposed to refrain from giving out CC #s anyway (or at least Apple Pay does that).
To be clear, I'm not casting judgment on Final's prospects as a business, just pointing out why I as a consumer would not want to go to the trouble of signing up. I do think the mission is a great one and hope they succeed (seriously).
Regarding mapgrep's post, I also have one of my accounts with Bank of America, and I have used the virtual card generation feature (in BoA branding it's "SafeShop") constantly for years (and regretted it wasn't more widespread). Nevertheless your implementation looks significant superior, and I think implementation improvements are usually far more significant in the context of a product like a credit card then "genuinely new". BoA's feature is clunky, available only through a tiny (and I mean that literally, it's a 467x300 fixed size window) Flash-based tool with a mediocre UI and poor virtual CC management. It has zero presence on mobile (despite that being the obvious way to use it, particularly combined with Touch ID), no notifications, etc. Despite that the advantages of a fixed limit virtual CC are great enough to make it worth it, but you doing a better job (and one that folks less paranoid then me might be willing to use more often) is a very strong feature for your product in my opinion.
One thing I may have missed on your site that I'd like to see for financial interactions in general: do you cryptographically sign your email communications (or at least allow customers to have that be a preference in their accounts)? I do see you list PGP keys for people to communicate with your security team specifically as is good practice, but I'd love to see more general use of at least signing email, which could dramatically reduce the ability of spammers, phishers and other malevolent actors to spoof legitimate sources. S/MIME at least has widespread native support without anyone needing to do anything else. PGP would probably need to be a selected option as it requires the installation of additional tools, but would be a nice bonus. You could even allow the customer to supply/request you fetch their own PGP key, thus allowing email to be encrypted as well as signed. While PGP support on mobile unfortunately looks to remain poor, since you have your own app for securely communicating in that area it shouldn't be as much of a problem.
Someday hardware mediated scheme's like Apple Pay or Google Wallet or whatever will hopefully make some of this redundant, but I suspect the old CC system will stick around as legacy for a long, long time, and better ways to securely make use of it will remain valuable. Best of luck to you!
You also didn't even say which three issues you think Final solves, making discussion about the issue even more difficult.
Anyway, in terms of constructively mentioning more specifics, I was thinking it can solve:
-Hacked E-commerce Merchant... [since they get a virtual number]
-Malware on Consumer PC... [since you would not be storing/entering the actual number any more]
Less so, now that I think about it:
-Physical record theft [from] Merchant, government agency... [Kinda - if you pay all government agencies and merchants virtually, you're fine, although those you pay physically are still vulnerable to theft]
(Processor breach is still going to catch your physical purchases, but using virtual numbers online could reduce the attack surface of that particualr vector... So I guess it's two clear solves and two half solves... depending how much online purchasing you do vs physical)
Also, anyone who thinks i'm completely dismissing the company is reading too much into my comment. By "no thanks!" I just mean it doesn't solve any problems for me right now. That's not a dismissal of the company's long term prospects, just because, IMO, the MVP is weak, for me. (As I said in another comment, I happen to bank at a national bank that offers free disposable CC numbers to all customers through standard online banking web login... not everyone has that, so maybe they'll sign up.)
https://www.cardbenefits.citi.com/Products/Virtual-Account-N...
https://www.bankofamerica.com/privacy/accounts-cards/shopsaf...
Annual Fee: $0 intro for the first year, $49 per year thereafter
And
Earn 1% cash back on all purchases
So you have to spend $5000 on this card just to break even and then I'm still only getting 1% back. As someone who has never really had an issues with my CC which averages me 2% back and is free and I can't start to justify this. I use Simple Bank and love the UI (mobile/web) and this UI looks nice but with Simple I didn't have to leave money on the table to switch over to it (or at least not how I use it).
That said, I do really want disposable card numbers; I've missed that service ever since Amex discontinued their version.
i always look for this before signing up to a financial service. if you aren't easy to reach from every page on your site(or only allow phone calls from 9-3 EST, kind of crap)... i don't trust you with my money, period. I know really good customer service reps are spendy, but hiding from the customer is unacceptable.
While the phone support number is not published on the marketing site, we make ourselves incredibly easy to reach for all current cardholders, both through the mobile app as well as by phone and email. Support is based onsite here at our HQ office in Oakland, and can be reached between 9am-5pm PST.
So what I am getting is virtual CC numbers (which is not really new) with package that is rather sub par. I mean, I get the technological end, it's very neat, but when I compare cold hard (plastic :) cash, this card does not look appealing to me.
As for CC breaches and changing numbers, yes, it's annoying, but for me not annoying enough to commit to a card that on relative calculation would cost me couple of hundreds of dollars per year.
- 18% APR? (interest rates are near 0%; my worst card is 17%) - 1% cash back (my worst card is 1.5% back, best is 5%) - $49 annual fee? (None of my cards have annual fees)
Great work on the features and UI for the service, but you need a better banking partner. The product is unremarkable.
[1]http://www.prnewswire.com/news-releases/mbna-introduces-the-...
None of this even addresses or ties who BoA uses as their core processor for CC, which is now TSYS, and typically have little knowledge a vCard was used.
The good thing for what we're doing at Final is that this goes beyond many credit card numbers, its rethinking what is a piece of plastic in hundreds of millions consumers pockets for how we shop and interact w/ merchants in this day and age.
1. logging in
2. clicking on your credit card's account
3. scrolling way down on the right hand side
4. knowing that "ShopSafe" is thing to click on
5. waiting for the little ShopSafe interface to load (it typically takes 10+ seconds)
6. clicking on either "Create a new number" or "Create a new number for recurring payment"
7. entering the security code from the actual physical card (probably a reasonable step)
8. actually filling out the details of the virtual number
That's just to create a number. And if you want to generate a number for something like Netflix or Github (fixed-cost, recurring) and not have to change it every 12 months, too bad -- BofA won't let you generate a recurring payment number that is valid for more than 12 months.
It may have been done before, but that doesn't mean it was done well. I think there's plenty of room for improvement in this area, whether it's done by BofA (who has apparently had 16 years to make something useful), or a new entrant like Final.
Re folks saying it's been done before, it makes me think of the William Gibson quote "The future's already here, it's just not evenly distributed."
Even if it has been done before (I have no idea) -- if something makes a new tech available to many more people, it's effectively new to them.
In terms of using the card, my wife and I have found it useful. It feels empowering to give the card to a service/person and know you remain in control. Yes, all cards let you do chargebacks, or recover from fraudulent charges, but I don't want to have to fight to recover my money.
I love the feeling of using a number and knowing no other charges can come - that number can never be used again.
This card is empowering.
I had this idea myself, I Googled it and found nothing. Visa has 3D Secure (which is really just a text-delivered OTP), but implementing the standard is completely optional. I've only come across it on a handful of websites.
Pity it's US only for now.
You generate a fake card number, this number is linked with an expiration date AND a maximal amount that can be charged.
AFAIK it's not possible to create a card with a monthly chargeable maximum amount, only to set the total amount for the card's lifetime, which limits the interest of the use for recurring payments.
I signed up 2/28/15. That day there were 40090 people ahead of me Jimmy. Now there are 40091 people ahead of me. So not only has one single person managed to cut in front of me, but the line hasnt moved since prior to February 2015.
That rant/inquiry aside, http://privacy.com/ gave me an account and I have been very happy with it. Seems like a good product.
Want to move up faster?
Share Final with your friends on social media through one of the links below and jump the line when they sign up.sounds to me like the signup was fake and only people who share get invited in.
https://www.bankofamerica.com/privacy/accounts-cards/shopsaf...
Having the ability to give them a completely different card # with a monthly limit for just them really provides an additional layer of protection without the threat of losing access to goods you legally acquired.
Chargebacks are the big problem for companies that operate like this.
That would be the CC company's job, not? IIRC, at least in US law, if you dispute a charge they can't make you pay for it and they can't also add interest to it. And in practice, no signature dispute is almost always decided for the consumer. That's why merchants are so drastic with compromised accounts - otherwise people would just buy stuff, use it and then claim fraud, and merchants would lose tons of money. They have to create disincentive to cheat.
This is a pretty useful feature. But does it run afoul of some mysterious rules that allow recurring charges to continue[1], when you have a tradtional card cancelled and reissued under a new number?
From[2]:
> Thanks to some under-the-radar rules that work out in favor of vendors who charge recurring card fees, most credit card carriers allow a "recurring indicator" to be included in vendor/customer credit card transactions. In layman's terms, that means there are data bytes in your credit card payment DNA that allows companies to bypass credit card expiration dates and keep charging you anyway, even if your card has expired.
> Worse, there are loopholes in credit card regulations that enable vendors to get new credit card information if the old card was closed due to fraud, or even if you switched cards for a better rate. In either case, the recurring charges continue.
[1] https://uncrunched.com/2012/08/01/recurring-credit-card-char...
[2] http://www.nasdaq.com/personal-finance/pull-the-plug-on-recu...
Think of them as a bank that has issued you a new credit card, except they're not actually giving you any credit, just a CC number/PAN.
Similarly, the lifespan of most other recurring contracts is independent of the lifespan of your credit card. The reality is that most merchants won't chase you for payments when the card expires because it is expensive and generates bad will, but they can.
What I don't understand with Final is how they can guarantee you won't have to make another payment after you cancel a number. They don't control your agreements with third parties.
Edit: though I'm in the UK so my understanding of the law is biased in that direction.
" Do you have rewards?
Yes - unlimited 1% cash back on every purchase.
The security and control benefits of Final go well beyond grocery points and miles, but we understand rewards are important.
So while it might not be the highest cash back rate available, our goal is to provide rewards that actually get used by our cardholders - and that means making it easy to redeem - two clicks easy."
So if you have a decent rewards card, you would be sacrificing quite a bit in rewards with this.
For instance, I just took a first class, round trip flight to Tokyo with my wife. The cost for each one way flight was a bit over $15k. So thats almost $60,000 in flights that I booked for 240k SPG points (transferred to AA with bonus, which then booked with Japan Airlines and Singapore Air). If I had used Final's 1% cashback program, I would have only received $2400.
Seems like a no brainer to skip out on the cooler features to get 25% more value from my purchases.
On the other hand I understand that saying "We slightly improved a 40-years old tool that is being replaced by totally different ideas and we are releasing it in what 10 years ago was the main market in the world, but today is only a part of the bigger picture and will be even less in the near future" sounds slightly less sexy.
I applied/heard about Final long, long time ago and they've done nothing since. So yeah...
I haven't used either service so I can't compare anything else.
This is something we've been working to improve over the past few months. If this happens again can you shoot us a note support@privacy.com with the details?
They're linked to a physical card and/or bank account that you never disclose, and you get an SMS notification for every transaction.
Not sure what's the novelty here?
The founders of the company couldn't use their cards because of Target breach. And they started Final based on that experience.
How is Final solving this problem for breaches involving in store transactions like that of Target? imo, the Final card would still need to be deactivated right?
If I understood their value proposition correctly, Final has the best UX for virtual card numbers unlike those provided by BoA and Citi, where the UX to generate and use them sucks, and to be used for online transactions.
w.r.t in store transactions, it continues to be the same. (correct me if I'm wrong)
[1] https://www.bankofamerica.com/privacy/accounts-cards/shopsaf...
So that's pretty impressive that they can still support and maintain code that old.
So if you are selling a card to the end users, individual cards for each transaction (which others do already) cannot be your first point. Its not convenient at all to go through an app to generate a new number every time. Sure there will be people using it but not sure it sells with the bulk of the users.
So while I wasn't out any money, I was definitely out my time and had to deal with excess stress, so I do care if it gets stolen in the future.
The one thing I would recommend is having a secondary card with a different provider kept as a backup, just to deal with the couple of days between cancellation and receiving the new card. Even better is if it's a different card type (Visa if you have a MC or whatever) for that once in a blue moon situation when a merchant doesn't accept that card. Finally, if you do this, put some regular, low value monthly payment on the backup card so it doesn't get cancelled for inactivity. Netflix is good.
As for customer service, we believe you can't tout that as differentiator, you just have to do a great job and your customers will speak for you. Amex did a great job over last 50 years, but is struggling to be relevant in this day and age (http://www.bloomberg.com/features/2015-how-amex-lost-costco/)
We agree there's nothing better than exceptional customer service and experience. We've built Final from the ground up as a new credit card issuer so that we can continue to enhance the technology, service, and experience. We need to make money somehow, and we think an annual fee is the best way to align with our customers.
We've spent 3 years to get to this point. We're now live and actively inviting people from our waitlist to apply for a card.
We talk to our customers often and ask them what they think about us. We will continue building and making it better. Here's what we've heard:
"The few people I’ve showed your service to so far have said “this is what we should have had all along” and I agree."
"Final just solved my XM radio problem. I've been trying to cancel XM for a year. Each month I dispute their charges, Amex credits my money back.. but Amex would never just BAN them from charging me. Generated new final number, added to XM, then froze account. Boom."
"Final is one of the best banking products I've ever used. You guys could have sat back on your haunches and only delivered the cool feature of generating cards, but the well-designed phone app, the card, and your great customer service make every other card I have in my wallet pale in comparison. I reach for the final card to make daily payments not because of rewards points, but because I see the receipt immediately and I'm able to instantly dispute the charge if necessary. I don't know if there's such thing as 'credit card anxiety', but something about that gives me so much peace-of-mind. Thank you for creating a great product!"
And our favorite: "You guys fking killed the UX experience. The site is a pleasure to use."
> The site is a pleasure to use.
The site is _annoying_ to use.Nav bar at the top reorders, or shifts width, or something - so I clicked something else instead 'FAQ' a couple of times; each time I had to wait several seconds while the navigation faded in...
Appreciate the thorough response. I definitely think you guys have a unique value proposition. I still wonder if it's enough to justify switching costs for a large enough # of customers (e.g. re-setup bill pays, stored cards on accts, etc) for one truly differentiating feature, but wish you guys best of luck with your launch!
So its 2/3rds BD to get setup, 1/3 enterprise engineering and a lot of integration work to get fully setup and running. Payments is the only trillion dollar industry where nothing is written down, we're working on changing that since we find a lot of the stories fascinating and so do most people we retell them to.
If anyone is in Oakland area and wants a primer, always happy to share, we spent 3 years learning industry and now its our time to start giving back.
Traditionally, we do it this way too, these piece of the payments ecosystem are all whitelisted IPs for access and MPLC circuits for connections.
The concept of Final is pretty awesome, as in theory this now allows me to identify who they were when I have to change out a particular number for a vendor. I then know they were a crap company, and likely would just never use them again. Finally.
I use BofA as the convenience at least here in Phoenix is great, but their disposable card numbers is no good for repeat transactions, which I do frequently. It is also highly inconvenient that it only exists for Credit Cards, and not my Debit that I use just as frequently. Final's solution fixes this (except my debit card) imho, definite perks I wish BofA had today.
With any luck, the banks will see what they are doing and at least copy them now that someone has shown them the methodology. This should be an industry standard solution in lieu of major PII breaches every 3 months these days.
The main thing to be careful about is not to use this to pay for things where you will be required to provide physical proof of card ownership later. For instance, some French railroad tickets can be withdrawn from machines where you must insert the card that has been used to purchase them.
Which I really feel that's insecure to even ask for the full number other than when you first order.
(It's impossible to reload a Revolut account from a US one now.)
As revolut uses a traditional bank their bank probably doesn't want to deal with it.
Did a quick google search to see if maybe they had the same co-founders but no dice.
[0] https://www.youtube.com/watch?v=w9Sx34swEG0
EDIT: Apparently the actor runs a production company that makes commercials for start ups and he stars in many of them[1]. It is actually quite surreal.
So I was going to comment along the lines of "surely it's actually a debit card, and I'm not sure I trust a company with such inaccurate copy with my money" - but comments here seem to suggest it's correct.
Anything can be put on a CC in the USA then? Do you also have DD? Why would you use DD if you can use your CC for such things?
The Wikipedia section on DD in the UK is very much longer than that for the USA. Funny, I never doubted that it was universal.
Almost everything in the US is done with a credit card (through VISA et al networks). Most people's debit cards go through the same networks. If by DD you mean direct debit through the banks, that's called ACH here and is pretty awful with respect to fraud since you have to give your bank account number, and transactions take several days to go through.
Direct Debit is very common, and is covered under legal guarantees --- companies using it must stand indemnity. There's frequently a discount for paying by direct debit.
Also, I'm not clear on why is giving your bank account number a problem with regard to fraud? At least here, you can't use it to do anything other than make deposits (and you still need a sort code number for that as well).
https://www.directdebit.co.uk/DirectDebitExplained/Pages/Org...
> Whilst the copy is being obtained you are entitled to an immediate refund of the amount debited from your bank under the Direct Debit Guarantee.
Usually in Europe it's the contrary; there is no separate fee for using a debit card, whereas the credit card fees are inflated and passed-on to the customer.
For example FlyBE, a UK airline charges, 3% of the transaction total for credit card but zero for debit. Ryanair and Easyjet charge 2% for credit cards.
Even worse, British Airways charges a fixed-fee per passenger.
Is it just completely the other way around in the US?
Unfortunately, the prevailing attitude in most UK banks that I've seen is one to look to profit from transactions rather than protect their clients. Unarranged overdrafts are fantastic money makers in that regard.
But parent commenter's point was that if you do this with a credit card you could be completely unable to pay - if, for example, you have a single bank account with:
(balance + overdraft) < minimum payment for credit card
This can't happen with a debit card, since it will decline the payment, in the same way it would if you tried to use it to pay off a credit card bill of the same amount per above.This isn't quite true. A lot of American companies in the UK (e.g. Netflix) now use recurring card payments rather than Direct Debits. I think Final would still be useful here.
Does anyone know of anything like Final in the UK?
> Does anyone know of anything like Final in the UK?
Monzo is an app-first soon-to-be current account (currently prepay debit card) with an API.Not quite the same, but depending on what attracts you to Final, might solve the same problem.
Not that I wish or think the founders can't make on their own, but CC market is rather commoditized, and I don't think they can compete on technology alone here. 1% + 49/year annual fee is not a superior offer. But a bank that can do 2%+no annual fee attached to it could do wonders with it I think. No financial pro, so maybe I am completely wrong :) but I'd switch to such offer right now.
How much info are you displaying on the various merchants that are billing via the individual card numbers? My credit card bill tends to have a transaction identifier, the name of the merchant & a reference number (along with transaction date & post date). Would be great to have merchant's address and additional information on it and flag if it's recurrent.
I don't think this was some kind of wordplay attempt around dealing a deck of cards. Hopefully they're just "dealing with" the information instead. Typos in statements proclaiming how safe and secure they are...
The concept seems fine, I think some of this is already possible with other card issuers. I doubt I would pay a $49 annual fee for the service when there are free cards available.
Citi also offers a card with no annual fee and 2% cash back, so if you use Final you're effectively paying $49 plus 1% of your spending each year for a trivial increase in piece of mind that you didn't need to begin with (because you're not liable for fraud).
aside from the obvious security benefit, the UX makes me never want to use another credit card. being able to see all of my merchant relationships in one place makes it easy to keep track of payments, paying my balance is effortless, the push notifications are seamless.
when final says they're making a credit card for the 21st century, one part of that is security, but a huge part of it is UX + customer support, too.
Walk into a Wal-Mart, as soon as I put the card in my phone rings (it's my bank) and card is denied.
AMEX likes to text and email me of things needing my confirmation.
If all else Privacy.com does the job just fine of generating new cards, burners, and etc.
The next time you hear about a big credit card breach, you can relax."
I don't actually agree with either of these statements. I think what is broken are practices of credit reporting agencies, theres really only the "Big 3" in the US = Transunion, Equifax and Experian." They are in control of your credit profile and not you the consumer/citizen/person. They are constantly selling your data. When you get a credit card offer in the mail it is because a third party bought a risk profile from one of these big three credit reporting agencies.
Their security practices and policies are also questionable. A recent example - last year Experian was breached and millions of customers data was stolen. Experian informed people weeks later via snail mail. Apparently they didn't think this was time-sensitive issue. They offered two years of free credit monitoring after which time they would start billing you for the service - talk about an inappropriate marketing opportunity.
This is so horribly broken on so many levels. You can not opt out of these agencies owning your credit profile.
Also I have had fraudulent activity on my credit card accounts before with two major credit cards and both times they have proactively informed me that there was suspicious activity and to contact them. I contacted them and they issued a new card and told me to not worry about the charges. This was the last I heard of it. Yes you need to go update your credit card number with people online but in my case only half a dozen places would have that and generally merchant will email you if there is a problem with the card such as you forgot to update them with the new one.
I am curious if anyone has tried this new card though, it looks interesting.
Work well done.
And not sure why someone reposted our website, but always happy to discuss the intricacies of human behavior and how it relates to payments.
Coin is a container for multiple existing card. Final is a new physical (credit) card which comes with an unlimited number of virtual sub-accounts.
Privacy is similar to coin in that it's just a wrapper over your existing payment methods.
Is this normal? It seems like a LOT to me
Edit: I misunderstood it since "Annual Percentage Rate" seems like just a group of English words together when it actually has a special meaning in economy
"Doing it wrong" does't really account for unseen or unplanned events in ones life.