Couldn't a card number be tokenized in some way so as to allow for tracking?
I'm asking because I saw a lot of in-house tokenizer with hashes or deterministic encryption that could get reversed in a few seconds by brute force since the space to cover is so small.
https://stripe.com/docs/api/tokens/create_card (notice the request has no charge, but the response contains a fingerprint).
To state the obvious: it's not determinstic outside of Stripe, and there's no way to revert it, or even iterate over all CC numbers and brute force the space. You'd need Stripe's secret, e.g. assuming they use HMAC.
It’s fine with PCI DSS as long as it is not reversible.
[1] https://gist.github.com/epixoip/a83d38f412b4737e99bbef804a27...