← all articles

Paying online without spreading your details

Why your card number is the least of it

When people worry about online payment privacy, they usually picture a hacker stealing their card number. That happens, but it’s not the main leak. Every time you check out, you’re handing a merchant your name, billing address, email, and purchase history, and that merchant keeps it, often indefinitely, often shares it with payment processors, analytics vendors, and marketing partners, and sometimes gets breached years later when you’ve forgotten you ever bought anything from them.

The card number is one data point. The bundle around it, tied to your real identity and stored by a company whose security you have no visibility into, is the bigger surface. Reducing what you spread means thinking about both.

What actually happens when you type your card into a checkout page

A standard checkout sends your card’s primary account number (PAN), expiry, and CVV to the merchant’s payment processor, which routes it to the card network and your bank for authorization. Depending on how the merchant is set up, that raw PAN may pass through their own servers first, and many merchants store it (or a processor-generated reference to it) so you don’t have to re-enter it next time.

That stored data is what shows up in breach dumps. It’s not usually because someone cracked your bank, it’s because a mid-sized retailer with mediocre security kept your card on file for a year and got compromised. The PAN itself doesn’t expire on its own, so a stale record from a store you used once can still be live years later.

Tokenization: the mechanism behind Apple Pay and Google Pay

This is where tokenization actually helps, and it’s worth understanding the mechanism rather than just trusting the badge. When you add a card to Apple Pay, Google Pay, or a similar wallet, the card network doesn’t hand the merchant your real PAN. It generates a device-specific token, a substitute number that’s only valid for transactions from that device, tied to a cryptogram that changes per transaction.

If a merchant’s database with your tokenized payment gets breached, the token is close to useless outside that specific device and merchant relationship. The attacker doesn’t get your real card number, and they can’t replay the transaction elsewhere. That’s a real, mechanical reduction in blast radius, not a marketing claim. It doesn’t make you anonymous to the merchant (they still see a name and shipping address if you’re buying a physical good), but it does close off the “stolen card number reused everywhere” failure mode.

Virtual card numbers and why they narrow the blast radius

A separate but related tool is the virtual or single-use card number, offered by some banks and by dedicated card-issuing services. The mechanism: instead of giving a merchant your real PAN, you generate a substitute number linked to your actual account, often scoped to one merchant or one transaction, with a spending cap you set.

The benefit is containment. If that merchant is breached, the exposed number is only useful against that specific merchant relationship, and you can kill it without touching your main card or having to call your bank to reissue everything tied to it. It also stops the quiet subscription creep that happens when a free trial auto-converts to a paid plan on a card you forgot was saved somewhere, since a merchant-locked virtual number simply won’t authorize charges from a different biller.

Virtual cards don’t hide your billing address or your name from the merchant, and they don’t stop the merchant from linking your purchase to an account you’re logged into. They solve the “my card number spreads to servers I don’t control” problem specifically, not the whole picture.

The other channel: your billing details feed data brokers

Card security is one leak. The identity bundle is another, and it moves through a different pipe. Your name, email, shipping address, and purchase category get shared, sold, or leaked to data brokers and marketing platforms constantly, sometimes through an explicit “share with partners” checkbox you didn’t uncheck, sometimes through analytics pixels the merchant embedded without much scrutiny of who receives that data downstream.

This is why using a unique email alias per merchant is a genuinely useful habit, not because it hides your identity from the merchant you’re transacting with (they know who you are, you’re paying them), but because it lets you see exactly which company leaked or sold your address when spam starts arriving at that specific alias, and lets you kill that one alias without touching your main inbox. Most email providers support plus-addressing ([email protected]) or dedicated alias services that forward to your real inbox while keeping the receiving address disposable.

Guest checkout, where available, does something similar on the account side: it avoids creating a persistent account record that a company retains and can later be breached, sold during an acquisition, or repurposed for marketing you never opted into. You still complete the purchase and the merchant still has your order details, but there’s no login-linked profile accumulating history over years.

Cryptocurrency is not the private option people assume

It’s worth addressing directly because it comes up whenever payment privacy is discussed: paying with cryptocurrency is not an anonymity solution. Most cryptocurrencies, including Bitcoin and Ethereum, run on public ledgers where every transaction is permanently visible to anyone who looks. The privacy people assume comes from the address being a string of characters rather than a name, but that’s pseudonymity, not anonymity, and it breaks down fast.

The break point is usually the exchange. To convert cash into crypto or crypto back into cash, most people use an exchange that requires identity verification, which links their real name to their wallet address in that exchange’s records. From there, any transaction from that wallet is traceable back to that identity by anyone with access to the exchange’s records or sufficiently patient blockchain analysis, which is now a mature commercial industry. Using crypto for a purchase can avoid handing your card number to a specific merchant, but it does not make the payment untraceable, and treating it that way is a mistake with real consequences if you’re relying on it for privacy you don’t actually have.

A realistic checklist, not a silver bullet

None of the tools above work alone, and none of them make you private on their own, they each close off one specific leak:

  • Use a mobile wallet (Apple Pay, Google Pay, or your bank’s equivalent) where accepted, so merchants get a tokenized number instead of your raw PAN.
  • Use a merchant-locked virtual card number for subscriptions and one-off purchases from sites you don’t fully trust, so a breach or a forgotten auto-renewal doesn’t touch your main card.
  • Use a per-merchant email alias so you can trace and kill leaks at the source instead of abandoning your main inbox to spam.
  • Use guest checkout when you don’t need a returning relationship with the merchant, to avoid a persistent account record you’ll forget exists.
  • Periodically check which merchants still have a saved card on file and remove the ones you don’t actively use.

Each of these narrows a specific, mechanical exposure. Stacked together, they meaningfully reduce how much of your data ends up sitting on servers you don’t control, without pretending you can make a purchase invisible to the company you’re buying from.

If you want more breakdowns like this, of what’s actually happening under the hood rather than what a product page claims, check out the rest of the site here.

from the team
Want a real mobile IP, not a datacenter VPN endpoint?

Shared VPN exit nodes get flagged and blocked. Singapore Mobile Proxy runs real 4G/5G mobile IPs that give you a residential-grade address carriers still trust.

see how it works →
read on
More from The Privacy Wire

VPN and tool reviews, realistic opsec guides, and privacy news for people who want to protect their data.

browse all articles →