Halocard (Virtual Credit Cards)

I genuinely appreciate you taking the time to read the privacy policy and look for the facts. I interpret it the same way, but having employees or being born in Israel still does not provide evidence to support the original comment.

To be clear I’m not defending them or their founder – I see several shortcomings in their KYC platform (and the industry at large) that I would love the opportunity to change. I just don’t believe origin-bias should be used to draw absolute conclusions about any one individual. If evidence to the contrary exists and poses a genuine threat, I’m very open to reconsidering that position.

Anyway, I shan’t wish to belabor this point or take this further off-topic. Thanks for your perspective and your input :blush:

Having an office in Tel Aviv isn’t enough to support the original comment that you should be ok with the company sending whatever data you give them to Tel Aviv? What?

Or are you still trying to claim the person you replied to said something about Mossad? Because I would agree it doesn’t support that, but that’s not what they said. They factually said the founder is based in Israel, and it seems fine if you’re ok with your data being sent to Tel Aviv. I don’t know what isn’t supported by the facts here. Yeah they claim they don’t normally process data in Tel Aviv, but do you seriously think it’s out of the question that it may happen in the future considering they do have a presence there?

I think @ed-halocard and Halocard as a whole are trying to build something good but the problem is that I feel like the whole product idea is just flawed? It feels like a privacy.com alternative for non-US citizens without a lot of benefits and with the disadvantage that your data is at yet another company (or two, or three) in yet another country (or two, or three).

I don’t blame Halocard, they’re just following the law but I don’t really see a reason for most people to use this? Also the whole vibe also feels a bit like a honeypot. I’m not saying it is but it feels a bit like it

I’m glad you’re in a place where you can trust your bank to not sell all your data :slight_smile:
Halocard is cool because they’re at least trying to be privacy focused in an industry where this is almost unheard of.

Also, for the “honeypot” thing: I work for Cape, the privacy focused MVNO. Go and google “Cape honeypot” and see how much we’re called a honeypot :stuck_out_tongue:

Just because a company is trying to do privacy in a field that’s heavily regulated and primed against it, it doesn’t mean the thing is automagically a honeypot.

The way I think about it is, when trying to do privacy in banking, it can’t get much worse than the default, therefore it’s not really possible to make it a honeypot in the traditional sense.

All banking is flawed. I don’t think this is any more flawed than privacy.com, though.

@ed-halocard Does stripe correctly label your cards as prepaid?

@ed-halocard Does stripe correctly label your cards as prepaid?

Stripe (the payment processor) doesnt label cards, the issuer issues a type of card (ie prepaid credit / “real” credit). Halocard’s cards are “real” credit cards, not prepaid (however Halocard also doesn’t give you a line of credit, so you can’t go into debt (and, as such, they don’t have to report your transactions to credit bureaus)).

In most of Europe you can trust the banks to not sell your data to random companies because of GDPR, PSD2 and other laws. Users must give clear and informed consent otherwise the penalty is quite high (a few percentage of you yearly global turnover). Proving a user gave clear and informed content is VERY hard when it comes to court.

What I’m saying is that most (if not all) of their promises are contractual and not hard, technical facts. They have contractual promises not to sell data, they promise the KYC data being forwarded to Sumsub and “deleted” from Halocard’s servers and they promise minimal data retention claims.

You can find the same in European banks with more safeguards and higher fines.

I’m pretty sure that Halocard never gets the ID you upload for KYC. When I did the KYC process, all I had to give Halocard (before they sent me to Sumsub to do actual KYC (like with my passport and whatnot) was my full name, email, phone #, address (for billing/tax) and SSN (tax ID number). Halocard never had my ID documents themselves, and I’m sure they’re legally required to collect the info they collected.

In most of Europe you can trust the banks to not sell your data to random companies because of GDPR, PSD2 and other laws.

and

You can find the same in European banks with more safeguards and higher fines.

Now, I’m no lawyer (especially not an EU lawyer), but or people covered by the GDPR, your protections dont magically go away because you use Halocard. Halocard isn’t exempt from the GDPR (or any other EU regulation). I’m unsure where the “more safeguards” and “higher fines” appear from.

For people who are not protected by a privacy law like the GDPR (see: all of America) or have weaker privacy laws in their region, companies like Halocard are the way to protect their data from being sold and shared to data brokers. Just because YOU don’t see a value-add, doesn’t mean one does not exist. Having a company with the value of respecting your pricacy is a step up from the companies who really don’t care and will only do the bare minimum to get the legal people to stop yelling at them. I’m unsure why you’d rather (from purely a privacy perspective) use a company that only does the minimum to comply over a company with the explicit purpose of being more private.

Additionally, the privacy-focused aspect of the company means they are significantly more likely to engage in practices and make new technology that further the goal of privacy. “Not sell your data” is an amazing first step, however it will never beat a company actively trying to improve the situation.

What I’m saying is that most (if not all) of their promises are contractual and not hard, technical facts.

Yes, that is how privacy in these industries (ie ones that are heavily regulated against it) tends to happen. The accountability shifts from legal to reputational. There’s not much you can do about that, without reforming the law. Governments seem to really like their ability to send some paperwork to banks and get back a full ID of the user, so I don’t see that happening anytime soon. Again, a company who explicitly improves the privacy of a user will always be better (in my mind) than a company that’s just checking the compliance box and calling it a day. The threat model here is less of the government getting my data, and more of 5 billion companies 1) getting my data and/or 2) having an unique ID to tie me across sites (ie name, billing address, payment info). Im sure the GDPR protects you from some of this, but it certainty does not protect everyone from all of it (which is what companies like this are trying to push towards).

the whole vibe also feels a bit like a honeypot

(from this comment)

To add onto my previous comment addressing this, if we’re throwing around baseless accusations, I may as well accuse you of trying to spread doubt and push people toward less private institutions so you and your government buddies can spy on us easier.

See how baseless accusations work? No? Great, that’s cause they don’t >:​P

I’d ask that you please continue criticizing Halocard, but for you to do it in a manner that 1) has evidence backing a privacy harm and/or 2) allows Halocard to learn and improve. Throwing around baseless accusations gets us all nowhere, causes division in our community, and doesn’t allow anyone to learn / grow from critical feedback.

PS: While typing all of above I couldn’t stop thinking about this XKCD rofl

To be fair, every cointry, regardless of location, is at the whim of requests by a given government.

For most “day to day” operations, the question is what impact this really results in. However given Isreal companies aren’t aligned with respect for human rights, as seen here with the UN blacklisting 68 companies due to human rights violations, I’d be particularly sour if my KYC date was routed through Isreal, and would view my KYC data at more risk of malicious use against me should I not align or be in a situation that is not preferred.

But at any point the Isreal gov gets involved, I would also be very upset. And given Isreal is a large supplier of essentially hackers for hire (NSO group), and I’d just assume by the time it funnels to the government, I’d consider myself worse off than if a different external government had it.

No country is perfect, and we don’t get to choose where we are born, but privacy and security is about risk. Perhaps its more politicol, but Israel is the on my blocklist of where I put my money, and most assuredly where I want my PII data to route through. And of course, privacy is politics, and given the nature that privacy is about human rights, human rights violating countries blends with privacy like oil and water.

Actually, it does not. They’re incorporated the UK. They process data in Germany. They don’t appear to have any legal entity in Israel, however 6 marketing professionals (according to LinkedIn) are located there. The extent of their obligations to the Israeli Government likely extend to payroll tax for those employees. The suggestion being made here, based on the birth country of the founder, however plausible in theory, is still unfortunately absent any evidence.

I appreciate the perspective. If what you’re saying stands to be true, I hope you or anyone else don’t put their money in a major US bank like BoA, Citibank, Chase, Goldman Sachs or Morgan Stanley because they’re all incorporated and have licensed branches in Tel Aviv. By this logic, half of the US banking sector could already be compromised and “at the whim of requests” by the Israeli government.

tl:dr; I fully appreciate the implication the Israeli Government shouldn’t be trusted and if there’s evidence to suggest a supplier is sharing information with them, it’s serious and should force an immediate re-assessment. Unfortunately there isn’t any evidence to substantiate this is the case and while I empathise with circumstantial theories, you can’t run a sustainable business on those alone.

We’re going to continue to focus on our vision of building the most private banking alternative we can, for the largest number of people we can, who also share this vision. We’ll continue to do this transparently, and would love to continue taking this community’s feedback into consideration. I truly hope at least a few members of the community appreciate what we’re trying to do – That’s what ultimately makes this (very difficult) path worth it.

Saw this mentioned on TWIP. I use this service and it certainly would’ve been helpful if this was listed in the Privacy Tools section last year when I was looking for virtual cards. I fundamentally object to services like Plaid (yet another vector) and if you’re not in the USA, there is no one to recommend and a definite absence of licensed and reliable virtual card services outside Privacy. There should also be something said for companies engaging in our community and actively taking user feedback into account. This is very rare and I like the idea of having a say in the products we use and trust. Based on the Payment Masking Service criteria, Halocard objectively meet both.

  1. Allows the creation of multiple cards which function as a shield between the merchant and your personal finances.
    Is Halocard anonymous? | Halocard
  2. Cards must not require you to provide accurate billing address information to the merchant.
    Can I use a custom name and billing address on Halocard? | Halocard

There’s already a warning in the Payment Masking Services section about the KYC requirement which I also think is essential to emphasize for these tools since they do involve divulging sensitive information to a 3rd party.

It’s important to note that these financial services are not anonymous and are subject to “Know Your Customer” (KYC) laws and may require your ID or other identifying information.

Given Revolut didn’t qualify for this list and there have been multiple threads across the forums requesting recommendations for non-US Privacy alternatives, it would seem Halocard is a worthwhile addition.

Halocard seems better than privacy dot com.

My issue with them, is that they said they removed Google Analytics. When actually they just removed it from their privacy policy + homepage, but kept recording user events on the account pages (where it matters most). I reviewed them here.

They didn’t day they removed analytics, they said they switched to Plausible, which likely has its own analytics engine.

I’d assume they don’t want 2 analytics running at the same time, so benefit of doubt is they forgot to remove Google tag manager. A cynical take would be they lied and kept using Google all along.

We removed Google Analytics from our marketing site (it was never used on our card platform) and replaced it with Plausible, which we recently replaced with PostHog because they support anonymous, first-party analytics, allow us to identify and respect GPC (Global Privacy Control) signals and allow us to now run a single analytics platform across both the marketing site and card platform.

Hi @lissy93! My apologies, I wasn’t aware you had an issue with us. Please allow me to clarify a few things for you here.

We did remove Google Analytics from our marketing site as I previously mentioned, and it has never been used on our card platform. We use PostHog on our card platform to understand how people use our service, where they get stuck and proactively identify bugs and usability issues. These usage analytics are a part of how we constantly improve our customer experience and make the platform better.

Separately to this, our team have been testing different marketing channels and payment processors (Stripe). Google Tag Manager (GTM) was implemented as part of this testing to identify which marketing campaigns are the most effective. Our team have already come up with alternative approach that doesn’t require GTM in the middle and we’ll move to this once our testing is complete.

Also, you gave us quite a lot of homework to do in our PR last week. We’ve applied all the fixes to our marketing site and are working through the requests made for our card platform. Because we handle card payments and funds on behalf of thousands of people, we take a little longer to implement, test and publish changes to the card platform, but I’ll definitely re-open the PR and publish a breakdown of all the changes we’ve made as soon as they’re live.

I’m not sure if your aware, but you are still sending events to GTM for logged in accounts. I can send you more details if you need?

I’ve decided to vote in favor of adding Halocard

In light of recent discussion around Privacy[.]com and their usage of Persona for KYC, I feel providing an option that does NOT use Persona adds meaningful value to the category - whether or not Persona is significantly worse than other KYC providers, users will have the option to avoid it

While I do remain skeptical of the whole KYC-compliant tool category, they do ultimately provide unique value to the privacy toolchest. @nateb just posted a video that articulates the value, limitations, & scope of these tools quite well

Last but not least, @ed-halocard has been an active participant on the forum in the past weeks. That matters imo. Direct comms between providers & users yields a stronger product & ecosystem

Keep in mind this may not always be true. KYC providers are an internal aspect not guarantees to be unchanging. Contract negotiations can easily swap a KYC provider.

This is a good point, but I don’t figure it’s any more true for the KYC payment tools than it would be for the remainder of our recommendations - dev teams could implement any arbitrary code in a future update, change their privacy policies, leak our data, etc

As proponents of privacy, the people of PG have to stay vigilant and continually reassess our tools. Thus far, we seem to do a decent job. And at the very least with Halocard, we can angrily tag Ed & demand an explanation, should such a change be spotted