So I went there and cancelled my account, and they even sent me a "sorry to see you go" message. They definitely got it.
Then they went and charged my card anyway. But it was declined, because I'd closed the privacy.com virtual card I'd given them.
That's why you do this.
If you're receiving a service at cost but agreeing to pay for it later, then yes they could send you to collections if you refuse to pay it, but that model is only really used for a select few services (some phone plans come to mind). The vast majority of online services are prepay.
It’s not unique to Apple though. I think it’s this standard from EMVCo
https://www.emvco.com/emv-technologies/payment-tokenisation/
> EMV Payment Tokenisation enhances transaction security by removing the most valuable data to a fraudster within a transaction, the primary account number (PAN), and replacing it with a unique alternative value, a payment token.
> This reduces the value of payments information stolen in the event of a data compromise, as a payment token should not be able to be used beyond the environment in which it was intended. Payment tokens support both face-to-face (F2F) and remote payment transactions.
Basically, if Amazon leaks my credit card data, thieves can’t use it because the number is associated with my Amazon account only. That one token can be cancelled and the next time I buy something a new one is issued and I don’t have to replace my credit card just because one merchant leaked my info.
Ignore them. Just give a virtual credit card to any subscription service, and set a credit limit on it. Problem solved. If they try to keep charging your card: too bad, the charges are declined.