Anyone know of a way to know if one's credit card is classified this way? The author was using the corporate card they were issued... and presumably hadn't sought out a "privacy card", a term I never heard before today.
Brex has a feature where you can create vendor-specific cards, which I think is what's being referred to as the “privacy” feature. It makes it less disruptive to disable a card if a vendor leaks it, because it only interrupts payments to that vendor instead of having to update your card with every vendor.
I wasn't using that feature here, but it might be the case that the information that arrives at Google is just the issuer so they classify all Brex cards as “privacy” cards?
Well that will just cement my lack of relationship with Google and ensure that my business goes to AWS.
Considering that many banks are doing this sort of service to protect you against data breaches, I can't see how this is actually an appropriate policy.
AWS does the same thing. My account was randomly blocked until they went through the documents I had to submit. IIRC, I had to use a different payment method too just like the OP.
The solution is to use multiple clouds. Switching from one SPOF to another doesn’t help.
With AWS I know I can always get someone on the phone who can, or if they can't they will find someone who can, explain any billing or technical question.
I don't know your situation but unlike any of the Google stories, you found out that you needed to submit a document and then you gained access? Google refuse to tell people what the problem even is.
The article implies that the card issuer (Brex) triggered the fraud suspension and the comments above agree. It was the same issue I had with AWS (but with a different issuer) and they never told me that was the problem. The paperwork I had to submit was in addition to fixing the payment method.
Some comments in here imply that, but there is no evidence anywhere other than randoms on the internet. There isn't even any implication from those people that changing card providers at this point would resolve this.
> The paperwork I had to submit
Who told you to submit paperwork? It already sounds like you had a terrible but better experience.
> Well that will just cement my lack of relationship with Google and ensure that my business goes to AWS.
How can you run your ads through AWS? Or a better question, what other ad networks that are comparable to what Google offers are there? Because to me it seems almost like a monopoly in regards to how impactful Google's services are - sadly they aren't regulated as such.
I'm assuming OP here was referencing Google's cloud services vs AWS. As in Google's abysmal behavior in regards to AdWords has spoiled them against using any other Google services.
This is true, although I don't manage our ads. But the amount of articles from folks on a weekly basis where they broke some unspoken rule that got them banned with no recourse and any relationship point of contact ghosting them is unsettling.
Unless these are actually all astroturfing stories by Microsoft and Amazon, I will stick to the companies who will actually speak to me if I have problems. They have internal communications, so my support ticket will actually reach other teams, and even working in a start up I can get conversations with finance and technical employees to get problems solved.
Google can have the advertising dollars since they are the 80 ton gorilla, but I can't see how anyone can trust them with anything critical to the running of your business.
> Google can have the advertising dollars since they are the 80 ton gorilla, but I can't see how anyone can trust them with anything critical to the running of your business.
Well that's my point - you might end up in a situation where you cannot use them for advertising and where you won't have many viable alternatives.
And it seems like Google will just get away with automation like that, either due to manual support just not being possible at that scale, or for other reasoning of theirs, without mechanisms in place for you to bypass the automation and actually get a solution for your problem, unless you operate at a certain scale.
It can be a hard problem to solve, but it is frustrating. Google ads has a threshold billing system in place (based on their public docs). What this means is they probably track how much each payment method has spent, and charge that payment method when it reaches $X.
My theory is below, but I have not researched or looked into virtual cards.
The problem with virtual cards or privacy cards: What's stopping a single physical card from having multiple virtual cards generated for it? So if someone had a card they knew could only be charged $100 and googles threshold is at $200, they could make 10 virtual cards and add the physical card resulting in 11 payment methods. Now they can theoretically get $2200 worth of ads (if all ad campaigns reached the threshold at the same moment).
In other words, fraud risk can go up significantly.
For corporate cards (and I beleive gift cards and debit, no idea about privacy cards they didn't exist yet) when I wrote this sort of software way back you could identify by card ranges/format (that was the case in the past), just like how you identify if a card is Visa, Mastercard, Amex. A Visa subrange will be corporate, restricted purchase, etc. So for example, a trucker can have a corporate card that works to purchase gas outside but not the CStore inside.
If you know someone who write's merchant software they should be able to get you the ranges from their payment processor's specs.
One version of it that I have used is "virtual" prepaid cards. The way it works is that I can use my online banking account to create a new "virtual" card and load it with a fixed amount from my bank account. A new single-use credit / debit card number (by Visa or Mastercard) would be generated with CVV and expiry date that I can use online anywhere. It provides an easy and secure way of transacting online without providing the Primary Card / Account information to the merchant. Another version I wasn't aware, has been explained here in another comment - https://hackernews.hn/item?id=32238813 ...
I have unique cards generated for online transactions, and I see this feature with multiple banks here in the UK. It seems mad that this would be considered a bad thing.
It's due to fraud risk. If googles threshold billing is X, then their risk of revenue loss is X*(N+1) where N is the number of virtual card numbers that have been created for a single physical card. The +1 is for the physical card.
Visa/Mastercard likely don't supply a way to link a physical card to it's virtual card generations (that'd be a security risk), so Google doesn't know that virtual card A is associated with physical card B.
But if somebody steals your login, they can create multiple virtual numbers and spend a lot. And since these are virtual number, MC or Visa will not have tools to find problem or block it.
Can somebody which knowledge of this explain problems with "privacy" cards and why scammers love them?
Mastercard and Visa aren't the ones at risk by such activity, the issuing banks are, and as someone who works for a bank, yes, banks have tools to detect and stop account takeovers and assist card members in recovering from such incidents.
Scammers don't care about privacy cards. They'll use anything they can get their hands on, metaphorical or otherwise. If it doesn't have their details attached, it's fair game to them.