Privacy.com Reissuing All Cards
support.privacy.com
support.privacy.com
In an attempt to stay current with changes in card network and bank requirements, we spent the better part of this year investigating product adjustments and determined that changing our cards from prepaid debit to charge cards is the best option to preserve the customer experience. I recognize reissuing cards can be a pretty big inconvenience - this isn’t a decision we took lightly. The silver lining is that this should improve merchant acceptance and provide a better overall customer experience.
Functionally, cards will continue to operate exactly as they always have - no fees, no interest, no selling of your data, and no impact to your credit score.
Reach out to our team at support@privacy.com and we'll be happy to take a look at your account and confirm.
Privacy.com is a wonderful service, but it already automatically locks to the first merchant the card is used on. If it's already working for that merchant, Why do I have to change the card number? Use the credit card updater mechanism (the same mechanism for when a CC gets stolen but my Netflix keeps working and they get the new number somehow) for all merchants that support that - that should keep the customer load down.
Just a minor correction: I'm able to use the same Privacy card for x merchant for any number of y merchants, so long as it stays under the charge limit I've set for that card.
I've only experienced this with Kickstarter and then a secondary payment collector (BackerKit, etc) where some extra charge had to be finalized, typically shipping or maybe I threw in some extra doodad, and then had it fail because that second charge wasn't technically the same merchant.
But this was fine and I was happy - working exactly as intended. I just created a new privacy card and updated payment.
We did explore the card updater[1] and were hoping to be able to use it. Unfortunately it’s not a viable option due to technical limitations. If we could do the updating for you we absolutely would! If you have questions or there's anything we can help with, please reach out to support@privacy.com
I have heard nothing of this problem until now.
Still nothing in the app.
WTF?!?
When forced to by customers, you sort of answered it here, but without details or transparency. The Web site FAQ doesn't even do that much - the question that every single customer will ask isn't listed. Needing to update dozens of cards and merchants for zero benefit is not an "Exciting Update" and Privacy ends up sounding dishonest and, well, stupid for claiming that.
If you were forced to do this by a processing partner, then that's what the FAQ and customer-facing popup should say (and explain why and why your partner agreements allow that with only a few weeks of notice).
I went from being a customer and fan to believing that I can't trust Privacy's decisions nor that those decisions will be described transparently.
[1]: https://support.privacy.com/hc/en-us/categories/441448782555... [2]: https://support.privacy.com/hc/en-us/sections/4414521336855-...
Also, I haven’t received any email about this change.
The pre-paid debit product was limited, but far from broken. This could and should have waited another month. And the news shouldn't break on HN.
oh yeah, well I have 167 bajillion!*
*I really don't; I do wonder what you're doing with hundreds of monthly payments though.
I'm super sorry for the inconvenience and for the limited lead time. Unfortunately, this change wasn’t fully within our control and was required by our card partners.
You tried to sugarcoat this - to pretend like forcing customers to change dozens of cards in December was exciting - and in the process, lost all trust. You could have simply described the problem honestly and transparently.
What I'm wondering is: why am I hearing about this over HN and not an official notification or email? Did I just miss it?
I logged in (to create a new card, so I could try out Oracle cloud), saw the notification and searched my email (saw nothing..) and searched HN (saw nothing..) then posted it.
I'm really kinda shocked I was the first, and, even more shocked it blew up as much as it did. I just checked back now (11 hours later -- it's been a busy day testing out that oracle cloud account, among other things) and this went crazy.
It's definitely inconvenient when it does, especially when that involves updating a bunch of different accounts/vendors.
As I commented in a thread below, I had started using your service connected to a debit card via my credit union. Then was required to attach a bank account/routing number as the source for funding and didn't receive an adequate answer as to why (which is fine, but it's slower to process and it requires that I provide more sensitive information). I get that Privacy is obligated to gather certain financial information for regulatory purposes and fraud prevention, but it feels like I'm widening my attack surface providing that info.
We do take customer privacy and security very seriously, and have worked hard to have similar data security safeguards as larger companies like Square and Stripe (both places I've worked, so I would know!). You can read more about some of our security practices here. https://privacy.com/security
Regardless all citizens are eligible and should be given an SSN if they apply.
It sounds like Privacy is falling into KYC territory and is not able to farm it off to the host banks. But then any limitations around requiring SSN are due to their implementation, and not to the KYC requirements.
I don't know if it's something you have to apply for, I was 20 when I moved to the US so my parent handled all the paperwork. Just wanted to float that SSN != citizenship.
I've tried putting mine in, but it says (rightly) that it's an invalid SSN.
This feels like a "you always become what you once hated" situation. Privacy.com was supposed to keep our private data private. With this change there is no way to use Privacy.com without providing even more private data.
This really should have been a choice for users. Do you want privacy or better compatibility? Considering Privacy.com's userbase and their freaking name, I would guess many users would choose privacy over that extra functionality.
With modern fraud prevention and financial regulation, we simply cannot expect actual privacy with payments or really any finance.
I agree that as a potential customer my main interest is about credit card theft/abuse.
(This does make me wonder if they are mis-marketting focusing on privacy, instead of controlling damange of credit card theft, and sketchy merchants who charge you reoccurring charges you didn't realize/have trouble canceling, etc. That's my interest).
Also fraud detection systems will often track the type of purchases associated with a particular card number, to detect anomalies. So I suppose your privacy is somewhat protected from that, but the e-commerce sites probably already know who you are.
What were the most important changes from the networks in banks that precipitated this?
Requiring an SSN is an important change. Did prior requirements not do enough to prevent abuse of their services?
It sounds like most people aren't aware, but recently merchants have been coming down hard on privacy.com. I've almost given up using it. Hetzner and GCP are the most problematic, but I've seen it elsewhere too.
I'm not happy about having to reissue, but I will be happy if this forces vendors to take my privacy.com card.
(Everyone else is complaining, so I thought I'd at least try to balance it out a little.)
EDIT: Well, never mind. Apparently their new cards are still getting rejected. https://news.ycombinator.com/item?id=29438181
I was really excited...
I posted this here originally, and wow this blew up, I think we've actually spoken over email as I was one of the earliest users of privacy. I've been using it for many years and abjectly love the service.
I don't object to you reissuing cards. Like I mentioned in my other comment, I actually see a lot of positives (no more prepaid issues!), however, only giving people 30 days to update their cards in dozens (I literally have 81 open privacy cards) is "not fun" and up until now, using your service has been smooth, painless and something which this change (mostly the timing of it) just completely deflated.
I updated like 4 or 5 cards so far, each one took me 5-10 minutes, on the outside I'm looking at (worst case) 13 hours of work I have to fit into the month of December (which with the holidays and year end biz items, is already the busiest).
Yesterday, your service was just a dream to use, today it is a burden I have to find hours of time to fix.
Sorry, I do truly love privacy and didn't post this to hurt you or privacy, but I hope you can extend the deadline.
Best of luck to you and all of the privacy team.
I suggested to support that if someone is able to log in, pass 2fa, that should be enough to prove it's not fraudulent. I don't think support ever responded to my suggestions.
Thank You
I've been with y'all since the very early days.
I have no idea how you all make money but I hope you all are around for many years to come.
We use DO as our provider, and we offer trials in our product offering, so if they attach a prepaid card to _our_ service (which people do, all the time), we're out that money, but it's $5 for us, so we eat it.
Then if they don't want that, don't be bill-after or companies like Privacy will just engineer around that prepaid card limitation.
With physical goods, there is always the possibility that the merchant could compel you to return the physical good, but with cloud computing, that's nearly impossible.
If you haven't preauthorized, you aren't guaranteed payment. That's why these services also have usage limits, of course--AWS doesn't want me to rack up a million dollar bill without seeing a past payment history that would indicate I can actually afford that.
https://support.privacy.com/hc/en-us/articles/4414521565719-...
> On December 31, 2021, we will close all Visa Privacy Cards that have not been updated. In order to continue using Privacy.com without interruption, we need you to complete a few simple steps. Visit our FAQs to learn more.
Via the popup transition tool when logging in.
Sad they couldn't keep existing cards open till they expire, but just recently their card expiration dates jumped to lasting till 2027 so I see why.
Actually, this reminder does make me feel slightly better about giving my SSN to Privacy.com.
Have you been asked to provide an SSN with the latest change?
We do take customer privacy and security very seriously, and have worked hard to have similar data security safeguards as larger companies like Square and Stripe (both places I've worked, so I would know!). You can read more about some of our security practices here. https://privacy.com/security
Thanks for responding to these questions. Very much appreciated.
There is no way around know your customer, but that doesn’t mean “requires SSN”. That’s just the easiest path from point A to point B and most businesses don’t care to support anything else.
[1] https://www.irs.gov/pub/irs-pia/id-me-pia.pdf (Pages 2-3)
The very first card that Privacy.com recommended I replace was the card I have for paying my Spectrum bill, which Spectrum is obviously already accepting. Privacy.com even linked me straight to Spectrum's billing page to replace the old card with the new "improved acceptance" card. Imagine my surprise when Spectrum rejects the new card with "Prepaid and gift cards are ineligible"
EDIT: I regenerated the card again and Spectrum accepted it no problem. No idea what happened there. Maybe there was something funky with that particular card number, or maybe I mistyped the previous number? Either way, it's working now and I've had no problem with the rest of my card replacements so far (though it has certainly been a bit of a slog).
I just posted a thank-you to Privacy, because I assumed it fixed this problem.
I guess I'll edit it. That's unfortunate.
I normally immediately end my relationships with companies that make a change that invalidates all the effort that I have already put into the company. Why? You just zeroed my sunk cost and made the cost of switching vs cost of staying the same.
I would like to stay with Privacy but I really want some assurance that you’re not going to do it again.
Wrapping up something that amounts to extra work for me in bubbly language is kind of infuriating but in keeping with a couple of my experiences with them.
I'm not sure if I'll continue as a user given my existing unease with how I feel their existing pitch and documentation are misleading.
I appreciate the service but I'm not sure it's worth it to me to switch the cards I have given the my other experiences.
Perhaps this re-issue will make them more useful - here's hoping, because I think the idea is brilliant.
That said, the only great thing about this, is that the new cards are re-classed as "charge card" and not "prepaid" card, so, they fixed it!
If only they did it with more than 30 days notice I would have been ecstatic.
So as I scanned through, my read was "oh, Privacy.com had a security incident", which it did not.
As such they have to use, presumably, a different set of card numbers/prefixes/whatever that the card issuers dictate. No security incident prompted this.
So the thing is, most of their customers are going to be connecting a debit card from a large bank (they don't allow credit cards as a funding source). A few will come from a Durbin-exempt institution like a small credit union or a community bank (including one issued by another fintech/bank partnership such as Chime). But on the whole, they will mostly be paying the low interchange and charging the high interchange.
Since the new cards are considered credit cards, not debit cards, they won't have to worry about Durbin amendment at all.
Emails are going out in phases. But if you log into your dashboard, you should be prompted to accept the new terms and re-issue any merchant locked cards.
Some folks will already be on the new product if they signed up during our public beta period, so if you don't hear from us you're likely already on the new card types.
I love your service, but, sorry, this was just a huge miss. You guys completely goofed on the messaging of this.
Unfortunately, everything is on autopay. I rarely access the app or browser extension, and almost never access the dashboard.
I hope folks over there are thinking about how many people will have fewer than 30 days to update their cards. Emails should have gone out much sooner. I'm guessing this was a rushed job, and I'm sympathetic toward the things vendors force on companies, but communication is 100% in a company's control and should have gone out much sooner (I still haven't received an email).
I’m finding out about this today from word of mouth, have 50+ cards and less than a month to react, still not a single email or notification from the mobile app to warn me.
I’ve used delete me which works well enough (from the people that make Blur), but I’ve ended up just using the Apple Card which has a tiny amount of the privacy guarantees without a lot of the hassle (and good software).
I’ve been tempted to switch to one of these services though, but I think your data still gets resold by the card processor?
Never had any issues with them. Not one. They always Just Work, their app doesn't change every six months, I hardly ever have to log in. Everything 'Just Works'. They've been great.
The card reset is a tad unfortunate but isn't really an issue since they're all named/branded accordingly.
My only quibble is that I wish I could generate a card that I could give to a someone else that had a limit cap but could be used at more than one site/vendor (the current method really wants you to use them at only a single vendor, which is generally exactly what I want). Like an allowance card basically.
However I am such a heavy user that this announcement is actually rather annoying. I didn't see an email about it yet either, and could have easily missed that I am going to need to update 10 or so subscriptions this month :/
Google was one of those merchants. I've been using this service for a few years now and it has saved me from so many headaches.
Pretty cool service.
A lot of my use case for Privacy.com was avoiding giving out my debit card (and thus, direct debiting against my checking account). If this switch means it no longer enables that (just replaces a credit card), my usage of them drops quite a bit. It's nice to be able to cap a charge against the card I guess, but the level of effort required doesn't really give me the peace of mind needed to warrant it.
The prior Privacy cards worked fine; that's what I had entered beforehand. It's just the new ones I reissued on Privacy that aren't being accepted.
I don't like either of those, so previously I used Privacy.com cards. Yes, that meant Privacy.com had access to my bank/debit card details, but they already did (and in general it means one place has my debit cards, rather than every place that eschews credit cards).
Affirm previously accepted cards created with Privacy.com just fine.
However, to prepare for the old cards no longer working (per the article), I just went and had new ones issued on Privacy.com. When I went to put those into Affirm, though, Affirm rejected them with "something went wrong". Multiple cards, multiple attempts, no further data given (both on the site and in the network request).
When I went "uh-oh; I need to actually make sure the Affirm loan gets paid off next month when it goes to bill again", and so inserted my bank's debit card details, it went through fine.
So, Affirm rejected the new Privacy.com cards for me. It accepted my personal debit card just fine.
They are a credit card company but don’t call the product a credit card. Can’t pay credit cards with credit cards.
Does the switch from a pre-paid cards to a charge cards affect the ability for a merchant to collect on balances over the configured limit in some way? Or will those still be declined as it currently is?
While some normal credit cards theoretically offer temporary/limited cards as a service, the software/support is so bad I've never been able to make it work with my existing cards.
Have HN'ers (without any financial relationships to the company!) used it? Any reviews? Any downsides?
As a side note, the integration with 1password (whom I have worked for but no longer) is just :chef_kiss: You can create a privacy card from the merchant’s checking form and it gets saved in 1Password.
I know this is not allowed in the USA.
I had a bunch of privacy.com cards expire (original customer here) and had to re-generate them. Those cards that I re-generated didn't need to be re-generated again this time.
I expect we will see events like this fairly frequently in the next decade.
I feel for them.
Privacy.com's mistake wasn't needing to change issuers; as you said, that's unavoidable. Rather, it was forcing customers to cut over existing cards in 3 weeks, then lying to customers by pretending this was an upgrade rather than something required by their issuer.
[0] https://www.goodreads.com/quotes/440683-explaining-a-joke-is...