If Google insisted on being an option in the app it would be relatively fine. Users who prefer Googles payment system could chose it, but Google doesn't want users to have that choice.
If Google insisted on being an option in the app it would be relatively fine. Users who prefer Googles payment system could chose it, but Google doesn't want users to have that choice.
Google having my payment info is no worry at all to me. Google is on a very short list of companies whose defense against hacking and social engineering attacks I trust.
Google seeing every one of my purchases? Not a fan. I don't think that's the argument you're making here, though.
They get it directly from at least Mastercard.
https://www.bloomberg.com/news/articles/2018-08-30/google-an...
Even when I buy books from Kobo, I never stored my credit card with them. I always bought gift cards and loaded the balance onto my account. That would occasionally get cumbersome, since the only vendor for those cards in the US used to be Wal-Mart, until they discontinued their relationship. Now I think Kobo might sell them directly out of Amazon.com--but either way, for the odd $2 and $3 purchases that I do on impulse buys (because a book may be on sale), just having it go through Google Wallet is much easier.
Though I've never had the above happen. I've had a few times where my number was compromised but the bank found out and gave me a new card before whoever got the number was able to use it.
You can proactively decide when a card will expire and how much it can be billed ("Sure, NY Times, I'll take a subscription for the trial offer of $4 a month, so let's make sure this card only allows a charge of $4 every month and/or expires when that offer expires.")
Citation needed!
In 2014 I worked for a small, unimportant ecommerce retailer. We migrated at around that time to storing only a token, using our payment processor (Braintree at the time) - and no longer kept any card numbers in our database whatsoever. If someone had dumped our 'credit_cards' table after that migration, they'd have nothing but useless garbage (the token could only be used by our own merchant account). I think even Braintree didn't need to store the card number itself either, but I'm not so sure of their internals.
Storing a payment card number in your database is considered an incredibly bad practice, is not PCI compliant, and probably violates other important "compliance" things you have to regularly certify as well.