I guess strictly reading the CIP regulations it doesn’t specify the address has to be American, but I’m surprised you found a banking partner that doesn’t require this
What if I only need one card?
Our smallest personal plan starts at $12/month and doesn’t offer a single-card option. Multiple cards are core to how Halocard works — one for subscriptions, one for real-world spending, and one for online purchases you can instantly lock if compromised. Even if you start with one, you have more available when you need them.
So… if you have 3 suggested use-cases, have you considered a 3 card plan? That would be more competitive with MySudo.
Active cards? Like, I assume a disposable card doesn’t count after it is used?
@dddd I’m so sorry about that! We have a handful of US states (15 to be exact) that we’re still working on getting regulatory coverage for but are making steady progress.
We do check if a users’ state is ineligible before the identity verification step so we don’t submit any personal information to our verification provider and issuing bank that they have no use for.
If you specified in your account deletion request that you’d like to be notified when your state comes online, I’ll be personally emailing you when that happens.
@jonah Thanks for your feedback! This has more to do with licensing from Visa than it has to do with the issuing bank. We work with a non-bank member of the Visa Network with a broader distribution license than what Visa typically gives a domestic US bank, but because that entity is still US-based, CIP requirements apply.
We were cheaper to begin with but this attracted all the wrong types of users with higher prevalences of fraud and, in general, caused a strain on our support team. I would rather have fewer customers that I know we serve extremely well than the inverse.
We will likely actually increase our price in the next few months as we evolve Halocard to be more of a fully-functional global bank account, rather than just a virtual card provider (we will of course grandfather all our early users in).
For now though, if people want a cheaper plan, our referral program is paying $5 - $20 per referred user per month. So if you refer at least 3 people on our Core plan, you’re actually making money on your Halocard.
At the moment we’re working with an active card count because we noticed, interestingly, that the majority of our customers prefer to use cards multiple times rather than “disposably”, so we adjusted our plans accordingly. If this changes meaningfully, we’ll absolutely reconsider.
We appreciate companies who respect privacy, common sense or not. You’d be surprised common sense becomes a question of cost/benefit and effort analysis.
I have a question. I’m interested in obtaining a Halo card and while I understand that KYC requires SSN and other identifying information, it’s not clear to me if Halo card will appear on my Credit Report or a ChexSystems report?
Hey @Ipunxt! Thanks for your question. Halocard doesn’t share data with credit agencies and doesn’t perform any credit checks. It’s a secured credit card where you can spend only what you deposit. It works more like a traditional debit card with the added benefit of higher acceptance as a “credit card”.
Suppose my main goal is to protect myself from data brokers harvesting my transaction data via their agreements with my bank. I use halo card to mask purchase content from my bank, my bank only sees that I made a purchase with Halocard, therefore, when they sell my data, the data brokers only see that I use Halocard. However, VISA/MasterCard has the other end of the picture. And they can see what was purchased, the amount spent, and by who (halocard).
My bank doesnt respect my privacy and sells my transaction history to data brokers.Visa doesn’t respect my privacy and sells its data to data brokers. At this point I’m reaching, but assuming the ad/tracking industry is as advanced as i think it is – the likelihood that, given all the data (merchant, amount, product, time, currency, location, etc.), they can piece together the entirety of my purchase history, using Halo card for this threat model seems like a waste of time.
While I currently use Privacy.com for the fraud prevention aspect, the ‘privacy’ use case really seems futile given the current technical abilities of adversaries (data brokers). I’m definitely looking at worst case scenario here, but I don’t think that the above is very far fetched given the state of data science and the emergence of AI tools.
Your thesis seems plausible. The difference is mainstream consumer banks are known to monetize customer data for targeted advertising and selling personalized offers, whereas card networks are known to de-personalize and aggregate data to analyze spending trends and sell insights. If you had the choice to remove one of these from your payment stack, why wouldn’t you?
I would certainly prefer to eliminate both of those options, and I do try to with my current use of virtual cards. Either way, even if one side is primarily using data for personalized ads, and the other is using it for for overall market trends, it still seems trivial for the overall data picture to be captured and utilized.
I’m not against virtual cards at all i think they’re great. I’m just exploring the thought that our attempt at privacy via these cards may not actually be as effective as we think.
Hi Ed, thank you very much for responding. It’s good to know that Halo card will not affect my credit at all. However, I am still left wondering if it will show up on ChexSystems or other banking reports. Will Halo card look like I have opened a new bank account?
Admittedly, this is less of a concern than opening a line of credit, but I’d still like to know how it shows up.
I mean possibly? It ultimately comes back to your threat model.
Virtual cards are a data minimization and compartmentalization tool. Without an intermediary, your bank directly receives your complete merchant-level transaction history. With virtual cards, they don’t. Reconstructing and correlating that history from multiple different entities is materially harder when the datasets exist outside a single parties’ infrastructure.
If your threat model assumes an adversary can reliably combine granular data from across the entire payment ecosystem unencumbered, virtual cards are probably insufficient. But if it is to prevent your primary bank from seeing and monetizing your purchase history, and prevent merchants from storing your personal payment information and inadvertently exposing it, virtual cards can be effective.
@Ipunxt Thanks for the question! It doesn’t show up on a credit report. Halocard is not a US checking account and we don’t report to credit bureaus (nor are we legally required to).
@Grapeg Thank you for asking. They are two different approaches.
Contactless payments through Apple Pay or Google Pay tokenize your card, so the merchant does not see your actual card number. Your bank can still see the transaction, as with any card payment.
Virtual cards use a separate card number, so your main card is not exposed if a merchant has a data breach. You also have the added benefit of locking / cancelling them after use and/or pairing them with a custom billing address to restrict the data you share with online merchants.
For most people, the strongest setup is adding a virtual card to Apple Pay or Google Pay. You get both the added separation of a virtual card and the tokenization protection of tap to pay.
But do you even have an main card from the beginning? There is a virtual card directly from your account.
Other questions:
Is the security similar to what Cuve offers?
When you make the payment, do you leave the card number from the virtual card to the merchant?
For example if a tax agancy gets the virtual card number from a merchant can they then ask Visa who gives out this card like you or the bank you work with?
And if a 3rd part like an tax agency would contact you about a person if they have an account with you would you answer them or not?