Privacy Ratings

Virtual card privacy ratings

Virtual and masked payment cards.

4 virtual cards are rated against 9 public criteria, and 4 have enough evidence for a letter grade. Of the 4 with a known jurisdiction, 4 are based in a Five Eyes country, and 4 in the wider Fourteen Eyes.

Criteria for this category · Suggest an addition · Markdown

4 shown
Virtual cards privacy ratings, sorted by pick and then by grade
Name Grade Score Data Jurisdiction Open sourceNo trackers or telemetryNo ads or data salesIndependent auditTransparency reportTells users about requestsTLS configurationSecurity headersModern web standards
Privacy service formerly called Abine Blur that provides masked virtual payment cards, masked email addresses and masked phone numbers, along with password management.
Grade D 47 100% United States Five Eyes NoNoYesPartialPartialYesYesPartialNot tested yet
App for creating separate personas called Sudos, each with its own phone number, email address, virtual payment cards and encrypted messaging. Virtual cards require identity verification.
Grade F 34 100% United States Five Eyes NoNoYesNoPartialPartialYesNoNot tested yet
US service by Lithic that issues virtual Visa and Mastercard cards locked to single merchants or spending limits, hiding the real card number from merchants. Sign-up requires name, date of birth and a government ID number.
Grade F 19 100% United States Five Eyes NoNoNoPartialNoNoYesNoNot tested yet
Financial app offering accounts, payment cards, transfers and investing, including disposable and merchant-specific virtual cards. Accounts require identity verification.
Grade F 13 100% United Kingdom Five Eyes NoNoNoNoNoNoYesNoNot tested yet

Questions

What is the most private option among virtual cards?

No pick has been made yet. The table above is sorted by score, based on public evidence.

How are virtual cards rated?

Each entry answers 9 questions: open source, no trackers or telemetry, no ads or data sales, independent audit, transparency report, tells users about requests, TLS configuration, security headers and modern web standards. Answers need links to evidence. See the full criteria.

Does jurisdiction matter?

Jurisdiction decides which laws can compel a provider to hand over data. Each entry shows its country and whether it is in the Five, Nine or Fourteen Eyes. The data a provider can hand over depends mostly on what it stores and who holds the keys. Read about jurisdictions and the CLOUD Act.