Louis Rossmann Cancels Privacy.com: Halocard's Founder Reacts
10:36Published Watch on YouTube
Summary
Louis Rossmann stopped recommending Privacy.com after it asked him to verify his identity with biometrics through Persona, a third-party provider.
Halocard's founder responds to excerpts of his video: what identity verification card issuers are legally required to carry out, why selfie and liveness checks are a fraud control rather than a legal requirement, and why a private payment is not an anonymous one.
- Why card issuers must verify who their customers are
- Documentary and non-documentary identity checks
- Biometric retention as a provider policy, not a legal requirement
- What Halocard is asking of its own verification provider
- Private payments versus anonymous payments
Transcript
Edward Taylor: A few days ago, Louis Rossmann, who's a prominent YouTuber in the privacy space, uploaded a video denouncing his recommendation for Privacy.com, a virtual card provider. I wanted to provide some context and some initial thoughts and reactions to his video.
Louis Rossmann: Today, I want to apologize for a service that I endorsed in the past and that I suggested that you all use. I used to talk about a website called Privacy.com. Privacy.com is a website that allows you to create virtual credit cards. And the reason this is really cool is because there are a lot of companies that make it very, very difficult to cancel your charges.
Edward Taylor: This is absolutely a problem, and one of the main problems that our customers also use Halocard for. So, 100% agree on the frustration.
Louis Rossmann: One of the things that I'll do when a vendor makes it almost impossible to cancel is I will just swap in a virtual credit card, immediately cancel it, and then they have nothing to bill. So for me, that's the cancellation.
Edward Taylor: It sounds like Louis doesn't use virtual cards exclusively, but I really like his trick of swapping in a virtual card just before renewal. That's a good trick. I might use that.
Louis Rossmann: Now, I logged in and it said that my account is currently paused. And there was a pop-up that came up and it said, "We need some information to help us confirm your identity. By clicking the button below, you consent to Persona…"
Edward Taylor: Persona is an identity verification provider that's typically used by banks, card issuers, etc. to verify the identity of people who are making online applications.
Louis Rossmann: "…collecting, using and utilizing its service providers to process your biometric information to verify your identity, identify fraud and improve Persona's platform in accordance with its privacy policy."
Edward Taylor: So, the biometric information is typically part of the second step in identity verification. The first step is scanning your identity document: passport, driver's license, whatever the approved document is for your country. And then secondarily, you'll typically be asked to do a selfie, where you look in a camera and you do this 360-degree rotation of your head. That selfie is also known as a liveness check, where they're creating biometric markers on your face and verifying with an algorithm that the person in front of the camera is the same person on the document that you uploaded. It's important because otherwise, without that, you wouldn't really be able to verify that the person behind the camera is the same one on the ID document, which would cause all sorts of issues.
Louis Rossmann: Your biometric information will be stored for no more than 3 years, which means if I'm lucky they'll only keep it for 3 years, and if I'm not lucky, that's probably much longer than that and they won't tell me.
Edward Taylor: Okay. So there's a difference between what the legal requirements are for identity verification when providing a financial product, and what an identity verification provider does with your biometric or residual information.
Edward Taylor: Identity verification requirements are set in stone. It's been that way since 2001, and it was an immediate response to September 11, in the form of the Patriot Act. So in the US, basically, the Patriot Act prescribes ways that all banks and financial services providers need to verify their customers, in order to limit money laundering and also terrorist financing.
Edward Taylor: There are typically two ways you can verify an individual. There is a non-documentary method and a documentary method. Non-documentary obviously doesn't require you uploading any form of identity document, but they would typically use, like, your SSN, and compare that to a government database to confirm that you exist and you are a real and natural person. And a secondary check to that would be a check that goes through to your financial institution.
Edward Taylor: So in Privacy.com's case, Louis likely created an account. I'm not going to speak on his behalf or Privacy.com's behalf, so I'm speculating here, but Louis likely created an account with a non-documentary method. So he entered his SSN, they confirmed he was a real and legitimate person in the US, and then he likely connected his checking account via Plaid, which is a financial services platform. And because Plaid connects to your bank account, your checking account, it would be able to also verify the account, the transaction history and what financial institution it belongs to, as a secondary supporting piece of evidence. So it sounds like, again, I'm speculating, that he signed up in a non-documentary form, and there was some change in either his account or in Privacy.com's policy that is now requiring him to verify with an external third-party vendor.
Louis Rossmann: I don't want you to keep my data for 3 years. I don't want you to use my data to improve your services. That's kind of the opposite of what somebody goes to a website like Privacy.com for. And when I go to Privacy.com, I don't expect you to use one of the worst identity verification services, that is funded by Peter Thiel, to… Yeah, this, we're not doing that.
Edward Taylor: This is a really tricky predicament. What Louis is explaining is absolutely right and completely legitimate. He is concerned that his data is being used for purposes that are outside of what he was originally intending the service for, which is virtual credit cards, in order to control who can charge his cards and when.
Edward Taylor: I think the challenge from a banking and a provider perspective is that we absolutely need to employ identity verification in order to be able to issue anyone cards or financial products, as per the Patriot Act. In order to do that, we do need to employ the services of an identity verification provider, because this is a very complex and a very specific function that needs to be solved. So you can typically really only choose from a handful of different verification providers. And in all honesty, none of them are spectacularly great. All of them need to collect large amounts of information to identify different signals that individually may not mean much, but that together help them identify whether there is a fraudulent person doing an application.
Edward Taylor: One of the biggest challenges that these providers have to deal with is AI. It's now mainstream and ubiquitous, and anyone with a laptop and a connection to ChatGPT can actually deepfake anyone else. So the number of people that are applying, and the number of false applications that are using AI deepfakes, has grown exponentially in the last two to three years. There really is no other way to stay ahead of this threat unless you collect lots of data, and unless you are employing your AI algorithms to be one step ahead.
Edward Taylor: That said, again, the collection of biometric information is not strictly required by law. It's a fraud control, to make sure no one can upload anyone else's document and then be approved immediately.
Edward Taylor: So this has given us pause at Halocard to also go back to our vendor. We use an identity verification vendor called Sumsub, and we're now having a conversation with them to understand: break down all the data you collect for our customers as part of the onboarding process, and help us understand what signals you use to determine whether it is a pass or a fail in terms of the identity check. But then, for anything residual, can we have that flagged and either immediately deleted, or flagged so it's not used for any training or unrelated uses in the future?
Edward Taylor: I think what Louis is raising here is an extremely valid point. These providers collect large amounts of information that, in my mind, is justified to help them ensure that we are only onboarding true and legitimate people. That's our legal and our fiduciary duty. But what is also brought to bear is how much of that data is actually serving that specific purpose, and how much of it is being used for the identity verification provider's benefit. That's a conversation we're having with our identity verification provider now, and we hope to announce in the near term some changes that we'll make to our process, to make sure that there is a clear delineation between what we collect that is necessary, and what is collected that is not necessary and can be deleted or purged and no longer used in any, let's call it, privacy-exposing way.
Louis Rossmann: As of recently, if you want to be able to use their services, you will see this, and this is not the Privacy.com that I was suggesting you use. Just so we're clear: when I was recommending people use Privacy.com, I was not suggesting you use a Privacy.com that was using Persona for ID verification. I was not asking you to use a Privacy.com virtual credit card service that takes your biometric info, uses it to improve a third party's platform, and saves the data for three years. That's not a thing. That's not what I wanted. That's not what I agreed to. That wasn't what I was telling you about. And I will no longer be utilizing or recommending their services into the future. It sucks.
Edward Taylor: It seems like Louis is pretty clear in his thoughts and beliefs here, and I think he's raised a really good point. Signing up for a virtual credit card will require identity verification, and for the most part you'll likely eventually have to do a documentary form of evidence, which would require the primary document and then also a selfie or liveness check, which includes that biometric data. Your card issuer and your card network, so Visa or Mastercard, will know who you are.
Edward Taylor: The real benefit of a virtual card is creating privacy around the data that you give to merchants when making online purchases. You can use whatever name or billing address you wish, and you can also create customized controls on those cards to make sure that they cannot be charged by different merchants, over a certain amount or beyond a certain date. That's the primary benefit of a private payment, which is fundamentally different from anonymous payments, where you completely remove your identity and delink yourself from a purchase.
Edward Taylor: The only way to achieve true anonymity in payments is if you were to use a form of tender like cash, a crypto token like Monero, or purchase prepaid and gift cards, which don't work everywhere that debit and credit cards do, but don't require any form of identity verification when you buy them and get them from Walmart, Target, wherever.
Edward Taylor: So for everyone out there: if virtual cards and private payments are your objective, they absolutely still play a role, but just know that there are requirements in order to be eligible, and identity verification, and unfortunately using identity verification providers, is part of that requirement. But that's very different from anonymous payments. Everyone is free to choose which option works best for them, but just make sure you know the difference between both.
Related articles

Best Privacy.com Alternatives: 15+ Options Compared (2026)
Halocard is the best Privacy.com alternative: a US-issued Visa credit card with no bank account to link. Compare it with 15+ alternatives including Wise, Revolut, IronVest, and Cloaked.

Privacy.com vs Revolut Virtual Card vs Halocard
Halocard is the better choice for most people and the best Revolut virtual card alternative: a US-issued Visa credit card that US merchants treat as domestic. Compare it with Privacy.com and the Revolut virtual card on availability, acceptance, and fees.

Are Virtual Credit Cards Safe?
Yes, virtual credit cards are safe, and Halocard is the safest choice for most people: a US-issued Visa credit card with a separate card for each merchant and no bank account to link. Here's what virtual cards protect against, what they don't, and how to evaluate a provider.


