How we had our Nectar Points stolen, and this is how yours will be too
kiphakes.com
kiphakes.com
The cashier was taking cards with a high points balance (she had the equivalent of over £100 on the card), and swapping them with a new, unregistered card.
We reported it to the store and they could see this happening on CCTV, so the cashier was fired. They gave my mother a Sainsbury's gift card for the monetary value stolen, plus a goodwill gesture.
Personally, my lesson learned from all of this is to spend loyalty points/rewards ASAP. While there are some "double up" offers every year that reward saving up, these are less common than they used to be. I think Sainsbury's ran a trial last year where only some people could use the "double up" promotion.
Customer service is more than useless across the board.
> Sainsburys DID send us a new card with our points back on it after a few weeks, and a thousand or so for the inconvenience.
And at a local shop (not a "customer service assistant" on the phone having to follow a script) people are usually quite helpful, especially when (potential) theft from an employee is involved, which tends to be taken quite seriously.
This is just generic undirected negativity and cynicism.
Further it goes like this: "But it meant that with our new card we were seen as ‘new’ customers, so all the carefully algorithmically picked shopping items that we buy regularly and got extra Nectar Points on, or Nectar Prices were forgotten. It’s taken MONTHS for us to get the new card to learn what we buy, and give us relevant offers based on it."
So clearly the customer service had no understanding of the issue and it suggest it took them weeks to issue a new card - from what I gather - after the author created a video, but that doesn't seem clear.
But that matches my comment - his problem has not been resolved and it took weeks.
It's astonishing that of all the software engineers involved in programming and reviewing this system, not one of them thought to lock the DB records to prevent this (or worse, someone ordered them not to for some reason). It's so simple to do and should be top consideration when dealing with financial transactions.
Each store would have a local copy of the card balances - but only for cards that had been used in that store in the past 12 months.
The first day you scanned your card in a store, you could only collect points (not redeem them).
By the next morning, your card would be included in the local database and you could redeem points - with the vulnerability that each store had its own database, and therefore you could redeem the points in multiple stores.
I thought this had been improved in recent years, but maybe not.
I am not sure, but I think you might need to register to redeem points.
All systems have trade-offs like these. It reminds me of the phase: "Anyone can build a bridge, but it takes an engineer to build a bridge that barely stands." That applies here. Any student can build a system with locking database records, but then when thousands of people's cards don't work for minute-long lockout periods, you aren't the one doing the CS calls or getting yelled at.
Only later it came to my mind that I'm not alone in not giving them my real phone and that they tracked us by phone numbers, not by cards. We all played a lottery: to whom a cashier would suggest to spend points earlier. I didn't care about that sort of money too much and decided to play fair. It was after half a year or so when another "win" happened. I moved and stopped visiting eventually, but I believe they are still playing this funny game. Software... software never changes.
"867-5309/Jenny" is a classic rock song by Tommy Tutone.
>> node devs looking at reflections of themselves, puzzled.
(From Wikipedia)
In case anyone else wonders.
But in return we get 10p off a pack of doughnuts.
... so when you have a baby? When else would you buy this?
I get the point you're trying to make, but this particular example seems somewhat strange.
> I hope you vote with your wallet to make these supermarkets go out of business.
I do -- not to make anyone go out of business, but because I prefer to shop at supermarkets that don't spy on me. At least in my part of the US, they do still exist and while they do, that's where I'll shop.
The point (for me) isn't to encourage or discourage any particular business practice. It's purely a self-defensive move on my part.
If you're not a zealot that preference probably melts as soon as you need it fast, or an exclusive price or item. Just from my observations the best performing supermarkets are in low crime areas with an ethnic minority as a majority. Supermarkets that try these tracking techniques aren't doing well, and I don't blame them for trying to survive and bring fresh food.
The problem is that stores that do use rewards programs hike up their prices so that the rewards programs are necessary just to get normal prices. This means it's not sufficient to just not use the program -- I need to use a store that doesn't have such a program.
It's also not just about rewards programs. It's about all of the various surveillance mechanisms these companies use. Going to a supermarket these days is like going into enemy territory.
But all of this isn't relevant to my comment. My comment was just that any business is responsible for the decisions it makes.
Using metadata and tracked information of known individuals can illuminate the lives of people who aren't tracked through process of elimination and correlation, which is why privacy rights are so crucial to legislate correctly. Right now, the US justice system is not at all equipped to properly handle the scale and scope of private industry's panopticon providing more or less total global surveillance.
We need to see some legislation with teeth, big and sharp enough to completely kill any business, no matter how large, if privacy isn't respected. But hey, let's all enjoy being tracked, logged, monitored, and surveilled every second of every day in the meantime.
For example, the US has a No Fly List with millions of algorithmically identified potential security risks. If you're on the list you can't get on a plane, but you are never notified or given a reason, and can't challenge the listing. Here's a paper that describes the issue I'm talking about: https://pure.uva.nl/ws/files/4284150/61150_Goede_M._de_Trans....
> This paper argues that the deployment of transactions data of many kinds has become the banal face of the war on terror’s preemptive strike. Because the failure to predict and prevent 9/11 is partly thought to be a failure to ‘connect the dots’ of available intelligence, post 9/11 policies seek to register, mine and connect ever more ‘dots’, or association rules, in the form of credit card transactions, travel data, supermarket purchases and so on. We argue that it is in these ordinary transactions that another spatiality of exception is emerging, one in which the traces of habits, behaviours and past practices become the basis of security decisions to freeze assets, to apprehend, to stop and search or to deport. As such, these developments constitute a relatively unacknowledged violence in the war on terror, which is in need of critical questioning.
Here's an article referenced by the paper: https://web.archive.org/web/20090101121831/http://www.indepe...
> Supermarket checkout staff are being trained by the security services in how to detect potential terrorists. MI5 has been secretly advising food retailers, including Asda and Tesco, on how to identify extremist shoppers. Measures include [...] being alert to mass purchases of mobile phones, which can be used as bomb detonators. The awareness training for staff also covers bulk sales of toiletries which could be used as the basic ingredient in explosives.
With a full supermarket loyalty database, you can just scan for anyone with suspicious toiletry purchases and an ethnic-sounding last name and bring them in for questioning.
My personal favorite was Tommy Tutone and the number I used was 8675309 with a zip code of 90210.
Lasted for a year and then they deleted it.
I'm a little less flippant now.
This is surprising because I would think you should be able to opt out of processing/marketing, while still having the loyalty/points aspect of the card. Particularly given non-member prices can be double to triple the price.
By contrast when I signed up for Tesco clubcard, even pre gdpr, I was easily able to opt out of tracking. I don’t get targeted vouchers, or any discount coupons, but I still get points and clubcard prices.
How do you know they stopped tracking and didn't just stop giving you vouchers and whatnot?
Never, ever, ever think cashback or points based sites as your money/savings. Take it out as soon as you hit the minimum threshold.
(Technically, exactly the same can be said about paper money, too, with "they are only cash once you have it in gold/silver coins".)
(All that said, I agree with you - only I find it funny that you don't trust some store but trust a banking system or a government. Yes, I know that trust(private company) < trust(bank) < trust(banking system) < trust(government), but neither is 100% (or even very, very close).
This is quite different. Banks have strict regulations regarding how they have to handle your money.
Now, of course, the banking system could collapse, but so could the state, in which case the cash in your wallet would loose validity, too. Gold would be valid, but only as long as you have people to trade to. For most states, though, this is a far smaller risk compared to some retailer shelving their cashback system.
EDIT: Responding to your edit:
> Yes, I know that trust(private company) < trust(bank) < trust(banking system) < trust(government), but neither is 100% (or even very, very close).
You are right, but reasonable trust in some unregulated cashback system of a private company is orders of magnitude smaller than the reasonable consumer trust in a bank (assuming we're talking about a stable country).
100% agree. Just shaking my fist at clouds when I hear people calling money in the bank "cash".
[0] to the point where, if your savings exceed it, you should have the ability to make some contingency plans yourself (like using multiple banks to spread risk and increase you total insured threshhold), or be able to hire someone to advise you on such things.
Unless there is an obvious incentive to purchase a giftcard -- critically for a store/vendor which you already have near-term plans to spend money at -- then avoid them. Eg. I recently purchased one which had an effective 20% savings due to some holiday promotion and will be done spending the balance some time next week. Even then I barely decided to do so.
I don't know how we got conned into trading our money for giftcard balances at par.
It ensured I bought a book with the £5 they sent, and it was redeemable at pretty much any bookshop, large or small — so it was relatively safe.
I see the system still exists: https://www.nationalbooktokens.com/
That's not what "non-plussed" means. I would suggest the word "blasé" as a better alternative.
Apologies for the pedantry.
Similarly, the definition of blasé has changed since Lord Byron first used it in 1819, since most people don't speak French and don't know exactly what it meant.
My guess at why would be that US high schools pretty much universally teach 1984 with 'plusgood' and 'doubleplusgood' which is the only use of the plus- prefix in the novel. And since it's a nonstandard prefix people associate the word with plus. Newspeak slang would absolutely use plussed to mean "feeling plusgood" and when you encounter the word in the wild you just assume that's what it means.
Non- is perfectly logical extension of newspeak because neither anteplusgood nor unplusgood quite capture absence.
I mean it's kind of dumb argument, we might as well say that all of English is "wrong" because it didn't exist when the first dictionaries were published.
But surely there has to be some agreed meaning of words? Otherwise in mathematics you might as well just claim that "addition" is the same as "division" because a bunch of people just defined it that way.
This redefining of words based on errors and ignorance just seems like one more example of the pernicious influence of post-modernism.
Yes you're right, and the dictionary documents that agreed meaning, but some of those meanings will gradually change over time. It's not new, and it certainly isn't post-modern. You can easily find examples, here's a short list: https://ideas.ted.com/20-words-that-once-meant-something-ver.... I think the first three here ("nice", "silly", "awful") are particularly noteworthy.
> redefining of words based on errors and ignorance
How else could they be redefined? Occasionally someone invents a word on purpose, but that's relatively rare, and none of the languages people actually speak were intentionally designed. For all of history, people just spoke to each other and sometimes they got a word wrong or said it a little weird. That's where all languages and almost all words came from.
There's nothing wrong with feeling annoyed by a particular word or usage, we all feel that sometimes, I just think it's useful to recognize that basically every word was in that transition phase at some point in the past. https://www.etymonline.com/ is fun to explore this stuff, it is often surprising.
More examples from this very comment:
- We make a distinction between "inventing" and "discovering", but "invention" used to mean "discovery"
- "phase" only referred to phases of the moon until the mid 19th century
- "weird" used to be a lot cooler, and mean something like powerful, magical, fate-determining
- "document" used to mean "to teach with authority"
etc.
So if you're a linguistic descriptivist then no problem.
>So if you're a linguistic descriptivist
Absolutely not.
See point about, "this will have also spilled into UK usage".
> So if you're a linguistic descriptivist
> Absolutely not.
This is a point where English lacks the distinction between a "singular you" and "collective you", I meant the 2nd interpretation, you (singular) took it at face value.
To be fair, I do understand somewhat where you're coming from. I hate the "common" usage of "could care less" in US English. It literally doesn't mean what it's trying to convey. However, I'm slowly learning to care less about it!
You can bet your bottom dollar that if you found a way to add points, they would lose their minds.
As this story explains, if you knew the 11 digit account code for those 2931 points you can just rock up to a Sainsburys store with the appropriate code on like a piece of paper, scan it with the reader, and it'll conclude you're me (that's my code after all, that's what I do when I shop with them although my code is printed on a little plastic card they gave me) and therefore you can "spend" my points, typically in lump sums of £5, so you could buy £12 of booze, take 2x £5 = £10 off the price and spend £2 on booze that costs £12.
You can't turn it directly into cash, but obviously goods like booze, electronics, jewellery which are all potentially available are very easy to turn back into cash at a discount.
There was a court case some years ago about an IT insider at Nectar assigning themselves points fraudulently and then spending them. He received a pretty hefty prison sentence: https://www.bbc.co.uk/news/uk-england-london-12189919
That is insane. Why would you stick with an irresponsible company? Unless it is a cultural thing and they are the Walmart of that local area?
I do not get it. https://www.youtube.com/watch?v=KjmjqlOPd6A
Many products are deeply discounted just by owning a card. You also cannot use certain features, such as scan-as-you-shop, without them.
They also have some personalised prices, where you get targeted special prices if you have a Nectar card.
Not using a Nectar card in Sainsbury's will mean paying more.
I found one on the floor. I use that one now.
(I’m not looking for someone to explain here, I already looked it up)
That gift card feature was three rest apis: load up, unload and status.
The backend code was like 5 lines of code.
I always thought 'we can't just do it like that. That feels stupid '.
Cash is truly the only de-facto standard that gives you privacy on expenditure.
Your face is regularly visible on CCTV when you swipe the card. If you drive to the shop, they could easily find the number plate of the car.
This also applies to anyone who sometimes accompanies you, e.g. children.
(I don't know if this is legal or whether the do it, but the data is available.)
If you're shopping in-store in the UK, the supermarket can't profile you based on your bank card without express consent, as it falls under personally identifiable information.
Am I willing to sell the correlation between this week's trip and last week's trip for $20? Absolutely.
If someone is going to offer discounts anyway, then I want discounts on things that I'm likely to buy.
I am quite happy to take the (low and theoretical) risk of harm in exchange for the (high and real) financial compensation.
You're welcome to either pay more or shop elsewhere. We each have a choice.
You really don't though. You can either pay more, or go to another supermarket with a similar scheme. Doesn't really seem cricket, am I really loyal for buying bread or cheese because I needed them and this supermarket is in my neighborhood?
Sainsbury's give you 1 nectar point per £ spent in store or in petrol. A nectar point's average value is a half penny, but annually they put on an offer to "double up" your points. That's a full percent off your annual petrol and shopping bills (more if you include the algorithmically generated offers).
The typical UK household spends £1,500/yr on petrol, and £6,500/yr on groceries, so the trade-off is that they give you £80/yr to profile you based on your preference of beans.