JPMorgan to sell customer transaction data to advertisers
media.chase.com
media.chase.com
"Card-linked offers" have existed for a while now, and I know they are supported by at least the Mastercard, Visa and AmEx networks. How it works is:
1. A company that provides the card linked offers goes out and markets to brands that they should provide an offer. The idea is that someone who uses their card at this brand will then get cash back or some discount (e.g. "Sign up to get 10% cash back when you buy from Whataburger.") For the brand it's basically just a new marketing channel.
2. Importantly, the way I've always seen it work is the user must sign up for the discounts, or otherwise sign up for something that says "I want to be eligible for any discounts your platform offers". That is, the cardholder sees a list of promotions, and they then must tap on each one that they want to subscribe to. After that they will get discounts if they shop at those stores.
3. The card-linked-offers provider then gets notified by the card networks when there is an intersection of (a) a cardholder that signed up and (b) shopped at a store that offered a discount.
So to me it looks like Chase is essentially just taking this in house. Whether you think that's a good or bad thing is up to you, but just know that lots of other companies already did this, and these card-linked offers have been enabled by the major card networks for some time.
This is IMHO an important distinction. AFAICT Google doesn't sell data to advertisers, they target the ads for the advertisers. It's still annoying, but it's way less offensive than all the data sharing/selling that goes on.
IIUC, it's a much more vetted system than most online advertisers do. Chase has some screenshots [2] which would imply they're not grabbing data at runtime from a 3rd party and it seems very similar to their experiences "adverts" [3].
I think PayPal's Offers is probably the best parallel. [4]
[1]: https://support.google.com/domains/answer/13689670?hl=en
[2]: https://www.chase.com/mediasolutions/solutions
Also, there is no indication that Squarespace has received any user data that is not required for them to take over Google Domain operations (so they would get a user's domains, billing info, etc but not their Google Maps location or their search history).
It’s an old and big business that even uses the same terms as other ad platforms (banks are publishers, advertisers buy placement, etc).
I’ve been involved in the industry for a while and I’m not seeing a single “new” thing in this announcement.
This seems to be a first, though a lot of transaction data is already leaked to wallet providers (Google, Apple, Samsung) when you add your cards to those digital wallets in exchange for added convenience or offers. Note that these wallets get access to ALL card transactions, including physical card swipes, and not just those conducted via their platform.
That’s not true at all for Apple Pay: “Apple Pay doesn’t collect any transaction information that can be tied back to the user. Payment transactions are between the user, the merchant and the card issuer.”[1]
The system is designed such that transactional information goes directly from the bank’s server to your device, and doesn’t pass through Apple’s servers (unless you’re using Apple Card)
[1]: https://support.apple.com/en-gb/guide/security/sec82e7bc3f8/...
As they are only bound to providing a interpretation of "that can be tied back to the user" that is "technically correct", like how a monkey paw only needs to technically grant your wish, all they have to do is not link the transaction to your name and they have technically fulfilled their end of the bargain. That their highly paid legal team deliberately did not disclose higher standards means we should not engage in wishful thinking. They can tighten up their legally binding language if they want some trust.
Do you have a citation for this? I see no evidence of this in the user-facing parts of the Google Wallet app, nor do I see something like that in the terms.
Are you sure you’re getting alerts through Apple Wallet and not just the bank app?
No, this is from my personal understanding. Please feel free to correct me if you think this is incorrect.
This announcement doesn't seem like it's anything new on the consumer side, instead it's a platform for brands to access the data from their ads/offers, create campaigns, etc.
(work in financial services, so I am familiar with the product landscape)
If I spend $2k a month on my card and get 1.5% back, that’s $30 a month. It adds up.
That changed a few weeks ago
"Both card networks also agreed to cap rates for five years and remove anti-steering provisions. Merchants will have more discretion to offer discounts, or impose surcharges on cards with higher interchange fees."
https://www.reuters.com/business/finance/mastercard-visa-rea...
That’s not to say they do have programs like this but only that they have the capability, usually just by making a phone call to their account manager.
And now using that trust to make even more money.
Any way to opt out?
It seems unlikely to be covered by the existing privacy controls which just promise to "limit" the information shared with third parties, without detailing what those "limits" are.
I don't have high hopes, tbh.
Leave your Chase cards at home
From their FAQ page, you need to call them: https://www.chase.com/digital/resources/privacy-security/pri...
Anyhoo, other than privacy concerns, my issue with this is a scenario like buying a UTI kit at the drugstore for a family member and suddenly getting all manner of urinary and kidney health ads nonstop. Like, I certainly don't LOVE 99.9% of Brands I interact with regularly, because most of them, from clothes to meds, are things I buy because I have to. Even my favorite Brands run the risk of the "oh god the Thai restaurant knows my takeout order before I place it because I come here too much so now I have to stop coming here for at least 6 months" effect if they get too clingy, and anyone else is basically instant "NOPE."
Amazing how openly CEO's like Dimon will fear-monger about start-ups, when in reality they're just not satisfied with their own team's progress in doing the same exact thing. But of course it's OK when they eventually launch the product.
[0]https://www.finextra.com/newsarticle/37293/dimon-scared-shit...
Remember their original use case was to offer third-party services something with a little more guiderails than "enter your ACH info and cross your fingers" and a little less clumsy than "we'll take that info and make some test deposits that you have to read back to confirm it's your account."
Seriously though, the opt out mechanism for this will probably be required under CA law.
If Chase does this successfully, we can expect every other bank to follow suit.
It didn't take a genius to figure out that banking data is quite valuable.
Honestly, I assumed given those meetings that this was already common practice with selling to data brokers.
Those "how to do this" meetings were not technical. "How to do this without causing a PR shitstorm" would have been a working meeting title. I guess it was all shelved until the 2000lb gorilla bank said lets do it. Or it was just being done quietly previously.
With JPM moving on this a bank will not be able to afford to not.