Credit cards have a privacy problem
washingtonpost.com
washingtonpost.com
Companies need to start thinking of this less in the lens of "evil" and more principle of least astonishment. Would users be surprised and angry to learn you do this? Then don't.
How do they connect my credit card data to my Google activity? My Google account isn't connected to my personally identifiable information in any way. I.e. they don't have my phone number, nor do I use Google Pay.
Most people have a phone number with google for gmail (you didn't need one in the beginning, but do now). There's also their wallet, app store, voice, broadband, phone plan, etc.
Some people will dodge all of that, but most won't.
> Since 2014, Google has flagged for advertisers when someone who clicked an ad visits a physical store, using the Location History feature in Google Maps. Still, the advertiser didn’t know if the shopper made a purchase. So Google added more. A tool, introduced the following year, let advertisers upload email addresses of customers they’ve collected into Google’s ad-buying system, which then encrypted them. Additionally, Google layered on inputs from third-party data brokers, such as Experian Plc and Acxiom Corp., which draw in demographic and financial information for marketers.
I just created a new Google account without a phone number 10 seconds ago. Phone number was optional and of course I didn't provide it.
If you try to sign up using Tor, for example, it's not optional.
Google makes sure that if you don't hand over your data to them, someone else will.
I guess I would need enough people to do a sybil attack on Google.
I bet this is how Places data and other stuff is hacked. How does one prevent a coordinated attack like this? Machine learning ensuring voting rings can only be used once or twice?
Linking offline purchases is harder but still doable if they buy CC data in bulk.
There are 2 pieces of information that need to be joined.Google have your cookie and email and MasterCard have your address and probably email. If both sides have your email then job done. If not then they can use your physical address via a data broker. All it needs is some e-commerce sites that allow cookie syncing and have a privacy policy that allow them to sell that part of your data.
Which personally identifiable information?
The time of day you use your devices? Which languages you use? Which websites you visit? The type of medical conditions you search for?
Information being PII or non PII isn't binary. It's relative shades of how shannon entropic it is. You need about 33 bits to identify someone, you likely have leaked 33 bits of entropy.
EFF's Panopticlick help show this: https://panopticlick.eff.org/
It is binary in Google's data structures (marked as annotations on protobufs), and in law. Things you listed aren't considered PII.
I'm pretty sure they use that to feed their models.
And 4 data points would be a lot more than usually required.
Not Google does X, but there is a market that sells X, and X can be linked to you personally by Y, Z
So
* A market exists for reselling credit card transaction data. Your card provider (ie Barclaycard) sells to companies such as $FOO who will aggregate same data from different providers and sells it for marketing purposes. The size of the market is $Billions
* Google can link the purchase history to you personally by multiple means including - reading your gmail, and looking for purchase confirmations using last 4 digits
* There is a market for reselling your mobile location and call history. your cell provider ...
I would love to see this - I honestly need reminding of this and it seems like a great press expose.
Doesn't this already exist since nobody wants to piss off shareholders?
We'll eventually have regulations cracking down on the privacy shitshow the web is today. But how many billions of dollars were made on the abuse to date, and how many more will be made still?
* https://marketingreportoptout.visa.com/OPTOUT/request.do
* https://www.mastercard.us/en-us/about-mastercard/what-we-do/...
Perhaps there's opportunity here for someone to be Robinhood here and improve the privacy of a lot of people...
How about instead of fraudulently providing someone else's credit card because "we know best", we just make sure to spread the pages as much as possible where appropriate, and let people make their own educated choices (and hopefully it opens their eyes to other places in their lives they can do so as well).
I understand the impetus to help, but it's important to consider that what one person views as helping another might view as terribly invasive in itself.
This is a sense of decency that the surveillance companies didn't share. People didn't make any sort of educated choice to be surveilled - the surveillance companies arrogantly "opted" them in. Opting them out is much lesser transgression onto their will.
I do agree from the practical perspective - surveillance companies will parry any legible bulk activity into an excuse to continue surveilling. Fine point white text at the bottom of the homepage: "Due to an attack from scary hackers, all opt out requests from 2019 have had to be discarded. If you had submitted a request during that time, please resubmit your request. To protect yourself in the future, buy our nonsensical "identity insurance" for only $10/mo."
So, that makes it okay? They've been abused before, so what what's the big deal if we do it too? That's a troubling perspective to me. Two wrongs don't necessarily make a right.
I think this is very straightforward. You, as a third party, have no place making decisions for me without my consent in this case. If I have a relationship with Visa or MasterCard, please stay out of it. The appropriate way for this to change is for a) me or someone I've authorized to request it, b) the company in question deciding not to do it anymore, or c) a legislative body with jurisdiction mandating a change through law or regulation.
If you have access to my credit card number and I haven't given it to you, the only appropriate things you should do with it are to notify me, the company providing it, or the authorities that it's been exposed and should probably be changed. If I have given it to you to authorize a payment, you are authorized to use it for that payment (and possibly later payments that I agree to), not to keep it to use as you see fit later on without my consent.
If you have my card because I've given it to you and you show me a dialog letting me know you can opt me out and give me the choice, that's acceptable. But I view any action taken on my behalf without my consent with regard to this as a violation of my trust, privacy, and personal information. We are in a very scary place if we as random third partied think we're allowed to make decisions for people just because we think it's better for them.
It's okay to acknowledge this as a vulnerability of your personal paradigm but still hold yourself to it. Just don't act like it's the only permissible way to interpret the situation, when the present state of affairs has been created by the surveillance companies not following the same moral requirement - already "[making] decisions for [everyone] without [our] consent".
More generally, a sense of right and wrong cannot mean simply following low level axiomatic rules, but rather requires judging constructive behavior. I'd say an action that mainly undoes a wrong is a lot closer to being right than another wrong.
You can label them surveillance companies all you want, and in some contexts it might be the most fitting description. In this context, I would say it's more fitting to say they are contractual partners abusing the looseness of the contract for their own benefit.
Just in case you missed where this particular thread started, the top level comment is about the opt out forms for data collection at Visa and MasterCard, and the reply's (possibly somewhat in jest) suggestion that since the CAPTCHA is so simple, someone just use whatever card numbers they have access to to opt people out automatically. All my comments are specifically in that context, which is one of random third parties using card numbers they shouldn't have direct access to anyway to alter the business relationship of others without authorization.
Furthermore, I do not view a person's associating with Visa/MC in today's society to be in any way voluntary - opting out is only possible at significant personal expense. So the mere existence of a business relationship also cannot be a basis for general consent. (As an aside: people generally do not contract with Visa/MC directly)
Taken together, these put "abuse" of a "business relationship" is in the exact same category as interjected actions by "third" parties - unwanted transgressions. They only feel different because we've become fatigued to accepting these transgressions when they pad someone else's bottom line.
And yes I am aware of the context of the discussion. I wouldn't personally do such a thing, but that doesn't mean I wouldn't applaud someone who did.
Hardly. There are other creditors, and if you aren't worried about credit at all (and there are other ways to build credit), then you can use cash, buy gift card variants of their products which don't link to you, use some other provider (paypal), or some other form of payment entirely in some cases (e.g. cryptocurrency). There are more choices now than ever before.
> Taken together, these put "abuse" of a "business relationship" is in the exact same category as interjected actions by "third" parties - unwanted transgressions. > I wouldn't personally do such a thing, but that doesn't mean I wouldn't applaud someone who did.
The only way I can read this is as you condoning additional violations of someone's privacy just because you think it's for the best this time. As I've noted, I don't think your value judgements have any place in my life, nor my interactions with other parties.
This has nothing to do with whether the whether the credit card company was justified in doing what they did, it has to do with people minding their own business and not violating other people's privacy. If you think the credit card companies are going too far, then calk to the authorities for legal action or legislative remedy. I applaud that action, but I don't want your vigilante activism, and I don't condone breaking the law by people that think they're more special than other people because they're doing it for "a good reason" or because "it's really just helping people".
I guess it's nice that you wouldn't do it yourself, but why would you applaud someone doing something that you wouldn't do yourself? It's real simple, if you can't or don't want to ask for permission to do something for someone else, then you shouldn't be doing that thing.
> additional violations of someone's privacy
I've agreed that flipping that surveillance preference flag is a type of violation, just of territory that has already been trodden on. It's like if someone breaks into your house while you're away, then a neighbor comes along to put a tarp over your window before it rains, and you're complaining that the neighbor has trespassed. In a sense you'd be technically correct, but most people would consider that action to have been reasonable.
There is also the aspect where someone leaving this preference flag unmaintained is contributing to a larger attractive nuisance.
> why would you applaud someone doing something that you wouldn't do yourself?
Because I simply wouldn't want to take on the legal risk.
> To opt-out from our anonymization of your personal information...
Uh, I'm no lawyer, but the wording really gets my attention here.
> Depending on your country, you may have the right or choice to: Opt out of some collection or uses of your Personal Information, including the use of cookies and similar technologies, the use of your Personal Information for marketing purposes, and the anonymization of your Personal Information for data analyses.
[1] https://www.mastercard.us/en-us/about-mastercard/what-we-do/...
Am I the only one thinking there might be some Clapper-level double-speak going on here? Why would these company share admittedly valuable data without being compensated?
A question for contract lawyers: can I sell something (say an API or quarterly report) that "incidentally" includes customer data and get away with saying I'm not "selling customer data"?
No different than if I sell to you knowledge of the fact that cardholder XYZ lives at 123 Main St, has phone number 555-867-5309, and shopped at Giant Dildos, LLC 3 times in the summer of 2019.
$corp provides it's marketing partners with insights gleaned from aggregated transaction data. And allows select partners to query an api for derived information about $corp's cardholders using a marketing identifier that tracks across multiple agencies including credit reporting, social media monitoring and customer intelligence analytics.
Additionally $corp uses it's transaction stream to feed information about aggregated spending per retailer to both their internal trading desk and to select financial markets partner firms.
Your personal transaction information is never exposed to anyone outside of $corp.
So for example when I attempted to link based upon routing/account number at Simple, it told me I can't continue because I should hand over my account information for the other bank to Plaid instead.
I've done it, and then immediately changed my account info. So yes, technically Plaid has my historical data, but at least they won't get it going forward. It really sucks though, because it locks my money into a singular bank otherwise.
My understanding of the ACH system is that it's best used in a "pull" manner, as if you're writing a check. Link your Simple account from another bank and initiate the pull from there. (Then work on transitioning your activity to the better bank while you're at it).
So, it's a virtual debit card, not a virtual credit card.
Now, they do let you set transaction limits, and daily/weekly/monthly limits, as well as either locking the card to the first merchant to use it or to make it a "burner" one-time only card.
So, there's lots of additional controls there.
They don't give you a good way to export any of that financial information, so if you want to use a budgeting program to try to help you track what is going where, then privacy.com doesn't help you there.
Overall, I like privacy.com very much. I do want to be able to tie in multiple back-end payment sources, including credit cards, and I'd be fine taking the 2% or whatever fee on my end. And I do want more transparency in terms of being able to easily export my data where I want to use it. But those are both relatively minor problems, compared to the ones they do help you solve.
Arbitration agreements are bad in general, but not necessarily uncommon. What makes privacy.com different is that they have access to your bank account. They're in a position where they have direct access to your funds, and you can't bring them to court if they wrong you.
I've had people suggest that I link privacy.com to a limited bank account and manually transfer money. That's a good suggestion, I'd probably do that no matter how they were set up. But that's not going to help if privacy.com takes you to arbitration over a bogus overdraft charge, or if they leak your credit card numbers, or if they start selling data behind your back. My bank doesn't have an arbitration agreement tied to my checking or savings account. I don't think it's justifiable for privacy.com to claim that they have more customer risk than my bank does.
If a business includes an arbitration agreement in your terms of service, I immediately assume that they don't respect their customers. There are some businesses where I tolerate that, but I need a heck of a good reason -- especially if that business is going to be managing my bank account.
Binding arbitration agreements are underhanded. The only reason to have one is because you want to make sure right from the start that you're not accountable to your customers.
In my understanding, they have the account numbers and can do ACH withdrawals - just like someone who has your debit card number (but against a checking account, not a card). So I believe it's like every other transaction (or check) - there's an intentional (as I get it) processing period for a day or two, and you can always call your bank and request to not honor it. I could be wrong though.
And actually, they can be associated with a debit card instead of a bank account - they've failed to associate with my bank, so I have had to go this route (and there's no way to switch it afterwards).
Oh, and I totally agree that arbitration clauses without a way to opt out are disrespectful to say the least.
They likely won't, being still subject to the court of public opinion. But it doesn't bode well that they're trying to escape the more direct avenue of accountability.
(IMO the FAA is blatantly illogical and should be judicially nullified. But until that happens, we're stuck being on guard for these offensive customer-hostile terms)
> Cookies and Tracking Technologies: We and our partners use cookies or similar technologies to analyze trends, administer the website, track users’ movements around the website, and gather information about our user base, such as location information based on IP addresses
They also transfer data in the case of a query about a sale.
This would be a bit less awkward if the name of the company wasn’t “privacy”
I would trust Apple a lot more since they already make money, and their reputation is something that they would be more likely to value more than a startup would be.
> We noticed you’re browsing in private mode. Private browsing is permitted exclusively for our subscribers. Turn off private browsing to keep reading this story, or subscribe to use this feature, plus get unlimited digital access.
Disabling JS bypasses for now.
But what they're saying is: We won't let you read our stuff unless we can track you (and see exactly what you read how long from where using which device, etc.)
I don't want to volunteer personal & payment details (which is more info than their tracking can get, considering I block it all) to find out.
Also, a lot of folks end up carrying a balance in spite of their best intentions.
I suspect this happens relatively often even for folks with a long history of not doing so - e.g. maybe you get fired for the first time and start running up a balance, not long before you've run up some significant interest charges.
And then there's huge credit card bonuses like $150 for Chase Freedom which is like $7.5k of spending's worth...
But again, that doesn't really answer my question. I very much realize lots of people do pay interest. But there are also people who don't, and possibly never have, for many years. I'm asking why do they keep those people around as customers if they're literally losing money on them? To me the obvious answer is they're still bringing value, and the only realistic form that can take as I see it seems to be their transaction data.
https://www.magnifymoney.com/blog/best-of/10-best-5-cash-bac...
This way they'll make money after the limit takes effect. My assumption is that they are hoping the consumer will forget there's a hard limit to the amount they can save and always go with their "5% cash back card" when making purchases.
And that assumption is exactly what I'm saying isn't universally true. My entire point is there are customers who just rotate cards instead of still using it for lower cash back. Who do this for years. Without racking up any interest. Why do those customers' accounts get kept open?
If that's the case, and you can't predict who exactly that subset is going to be, you keep all of them around.
Fun fact: you can pay your US tax return with a credit card for a ~1.5% fee.
I would imagine the number of people who only purchase things that are in the 5% category on their card is extremely small.
That's the answer to the question "why are these cards offered at all", which was not my question.
My question was, "why are even the accounts of people who consistently cause them a loss still kept open?", which this doesn't answer.
2. I bet government regulators might be a bit peeved by a company that systematically cancels customer accounts for behavior which is within the advertised terms of the agreement. Usually regulators frown upon luring customers in with an advertisement for a product/service and then purposefully sidestepping said product/service.
3. It’s probably such a small number of customers that’s it’s just not even worth their time.
2. It need not be against their terms though? They could easily specify hyper-optimized usage in their agreements as something that might result in account closure. This is already done in a lot of other cases; they could do the same here.
3. I don't know about that. Just look at the sheer number of sites that explain how to maximize your credit card rewards/cash back/bonuses. They wouldn't seem to be there if the audience for them was so vanishingly small?
If you believe so strongly that it is worthwhile for them to do this, then perhaps you have an idea for a lucrative career.
But as long as credit card fraud in the US is measured in billions, I’m going to guess that any manpower which can be assigned there is way more lucrative than any manpower assigned to demonizing their honest customers.
Think about an all-you-can-eat buffet. Some poor soul is gonna starve themselves so they can splurge and have a "good deal" on a lot of food. Most people will not, and the business would be in trouble otherwise. They still have to serve the patron who's eating a lot, because what kind of buffet would it be if it was "all you can eat, until you're eating so much that we're no longer making enough money"?
Or, some retailers sell items at a very low price, just to get people into the store in hope of them starting to buy more. Nothing stops you from getting into the store, getting the deal on those items and not buying anything else. The store may be losing money on you but they can't stop you from purchasing the item at the advertised price.
People who choose to spend their time and energy chasing deals to hyper-optimize the benefits on their credit card savings are entitled to their savings. Companies (credit cards or otherwise) are just interested in the total outcome of their operations anyway, not on making money off of every single customer. (Besides, even just defining what is a "profitable customer" is a hairy problem.)
These companies have very, very smart people working for them, analyzing all the data they have to come up with a product and its limits. They know x% will not be profitable, and they include that in the profit calculations.
Why dont they simply cut off the non-profitable customers? Because people don't like this and they'll quickly tell their friends "Don't sign up for Discover, they cancel your account if you don't make them money." It wound be all over Slickdeals and blogs. No credit card is going to survive cancelling accounts for using their credit line in totally normal ways.
Just like a store could say "for every 10 sale priced items you buy you must buy a full priced item" - but then nobody would shop there.
The people churning enough to actually cost the issuer money are extremely rare and there are a lot of people making sure it stays that way.
And then there are folks who get hit with interest and late fees that subsidize the big churners.
Because, churners, are a very small portion of the 20B in revenue Visa generated last year, of which it generated a ~50% profit margin.
The system works so well already, why rock the boat by closing the accounts of a few thousand individuals? It would probably cost more to enforce any such rule than they lose in revenue.
I was sure this couldn’t be right... but it absolutely is.
https://s1.q4cdn.com/050606653/files/doc_financials/2018/q4/...
They don’t even take any risk lending money, just a % fee for owning the network, that one has to be on to do business with most people with money nowadays.
So, by encouraging the use of credit cards for smaller and smaller transactions, the credit card companies take a bigger and bigger bite from the merchant.
That's all on top of any annual fees and interest charges that the credit card companies hit the customer with.
https://www.investopedia.com/articles/personal-finance/04071...
> When merchants accept payment via credit card, they are required to pay a percentage of the transaction amount as a fee to the credit card company. If the cardholder has a participating cash back rewards program, the credit card issuer simply shares some of the merchant fees with the consumer
And some is paid by interest being paid by other customers
http://www.bos.frb.org/economic/ppdp/2010/ppdp1003.pdf
> Because credit card spending and rewards are positively correlated with household income, the payment instrument transfer also induces a regressive transfer from low-income to high-income households in general. On average, and after accounting for rewards paid to households by banks, the lowest-income household ($20,000 or less annually) pays $21 and the highest-income household ($150,000 or more annually) receives $750 every year
I also have a vague memory that some cards from the same issuer (mostly American Express) charge the merchants more for the higher-level cards, and prevent the merchant from treating those customers any differently. I can't find a source for that, but some starting points might be https://www.washingtonpost.com/business/economy/supreme-cour... and https://about.americanexpress.com/press-release/american-exp...
The credit card issuer fees can be the worst because of these high reward credit cards.
I'm very aware of this when shopping at a local small business. I'll pay either in cash or with my debit card, because the credit card fees are seriously squeezing small merchants.
I'm also not aware of any across-the-board 5% rewards cards, and most have an "up to $x,000 annual spend" on the categories that are that high.
Yes. I understand this. I'm asking, why do they keep the others' accounts open?
> I'm also not aware of any across-the-board 5% rewards cards
I'm not either, but many people just rotate to a different card instead of using the same card for less cash back. And who never miss a payment or rack up interest. Meaning they always use those cards at a loss for the company. I'm asking why do these peoples' accounts get kept open.
It's a loss leader.
On the flip side, Mint has all the rest of the credit card data for the person (across potentially many different cards and card networks), savings and checking accounts, brokerage accounts, mortgages, car loans, student loans, and tax returns if you use TurboTax.
I think that balances out the equation pretty handily - that amount of linked, collated data should easily be worth more than a single CC can garner.
Intuit's a public company, making both their revenue and the number of Mint users publicly available. They're not making anywhere near what they'd need to make off their extensive data holdings to make your theory work.
These sites are mostly blogspam that push referral links.
Some rewards cards let you select "online shopping" as your high rewards category. You can extend that to in-store shopping at Walmart by enrolling that card in Walmart Pay and then paying in-store via that.
For a lot of people, "online shopping" and Walmart together will cover 95+% of their credit card use.
The base card is 3% in your selected category (online shopping; gas; dinning; travel; drug stores; or home improvement and furnishing), 2% in grocery and wholesale clubs, 1% everything else. The 3% and 2% are limited to $2500 per quarter.
The base rate is multiplied by 1.25, 1.5, or 1.75 if your total at BofA and Merrill Lynch is at least $20k, $50k, or $100k, respectively.
https://squareup.com/guides/credit-card-processing-fees-and-...
"The card that’s used
Debit cards with PINs are lower risk than credit cards, so they typically have a lower interchange rate. And rewards cards (travel, triple points, etc.) and business cards typically have have higher interchange rates."
Of course the badly implemented EU changes which in theory should have benefited the consumer did not - the merchants just took the reduction in interchange fees and didn't cut prices at all for the end consumers
The reason credit card companies are willing to give customers rewards/cashback is that they’re competing, primarily for interchange revenue. Most cards are guaranteed to be profitable for the issuer (ex-credit risk); some models (5% rolling category up to $75 back, etc) are not strictly guaranteed to be profitable, but they’re running a portfolio strategy.
You don’t need to make money on every account. You need to make money on every pool of, say, 100,000 accounts. One could conceive of rebate schemes poorly designed enough to not do that, but the industry broadly doesn’t ship them.
There are people who make hobbies off of attempting to get the financial industry’s sweet sweet marketing dollars. The financial industry can afford an infinite number of business analysts and geeks. The marketing dollars are still on offer. What does this suggest to you as to the portfolio-wide impact of hobbyists who exploit the offers?
I dont personally care that some marketer knowns I purchased toilet paper then went to the tacorita on Tuesday; I'll gladly give that information away for $4.
Banks and lenders are heavily regulated in this area and often times the financial institution has absolutely no insight into the line-item level of the purchase. That data is at the prerogative of the merchant to disclose.
If $RESTAURANT offers cash back on certain purchases made with them on a certain card, the merchant already has the data of the purchase and can determine if purchase qualifies for some cash back and notify the lender (at the expense of $RESTAURANT). Cards also follow patterns in the number scheme which would allow a merchant to determine card type and map that to current incentive offerings. By card type I mean more than just credit provider, down to the specific type of card (i.e. Sapphire Reserved vs Sapphire Preferred, etc).
Approach ATM, insert Mondex card. Feed ATM bills and coins, Mondex card gets loaded. Spend card, swipe as normal. Works offline, no connection to a bank account necessary, the money is deducted from your local card's 'account' to the 'account' on the POS/business. Your card records a transaction date/time/merchant for debits, theirs records the same for a credits.
You can transfer funds from one card to another, cash out the card offline at supporting ATMs, be used for building access/RFID cards, hold up to 5 digital wallets on one card, and more.
It was tried in the UK back in the 90s and NYC right in 2000 and worked about as well as you'd imagine in that world. But today, it would probably work much better. HK has the Octopus card which is conceptually similar and works well.
I'd certainly give either a shot so I don't have to carry physical cash but also aren't worried about having my money in someone else's hands who can lose it all due to bank fraud or have IT issues preventing payment processing.
Additionally I imagine this data is available for marketers to target buyers of Product X with Accessory Y.
Finally, marketers may use purchase data to build suppression lists; ie. Stop retargeting people that already purchased Product X. I don’t know if this happens very often in practice. It’s very hard to do well in general, and generally cheaper to spam people than buy data to shrink your list.
None of this is well-disclosed to consumers, not one bit of it is right. It just is, and it has been for going on for 8+ years.
> Something went wrong
> We're sorry. This page failed to Outline.
And more generally, credit cards have been around a long time. Shouldn't there be more evidence by now if anyone is being harmed by sharing data about consumer purchases?
This is typically infeasible for online transactions.
Anyway, some years ago banks opened for the possibility to get your receipts electronically. I opted into that, not thinking about privacy at the time, and they certainly have the data to track us in ways we that make Facebook look harmless, because Facebook doesn’t know your pharmacy purchase history.
I’ve never seen an impact of this that I was aware of, so maybe banks don’t actually use the data. It’s certainly not their business model to sell advertising, but who knows.
It doesn't go far enough (or at all, really) to explain that the credit card issuer doesn't see the data. They see a transaction amount. There's no banana.
The current top comment about Google linking online to B&M purchases isn't a leak of privacy: it's strictly private both to Google and the merchant. You are being tracked, but not in a privacy-revealing way, just in an uber-annoying I'm-still-being-targetted so-it's-creepy-and-annoying way.
That retail merchants are tracking you is a huge, huge problem. The CC facilitates this by linking all your purchases into a single history, but it isn't the CC per se that is the problem. eg the store's own rewards card specifically does this. They don't even care if you give your actual PII up to signup for the rewards card, all they care about is that they can [even anonymously] identify the purchase stream tied to an individual.
They should go to length to better distinguish this problem because then they can get to the fact that every Apple Pay transaction is tokenized and not linkable to prior or future Apple Pay transactions.