19 ms·
I have background here and can take a pretty good guess at what happened. You used a Brex card, which Google sees as a “privacy card.” These are often used by s
by ericabiz 4y ago
I have background here and can take a pretty good guess at what happened. You used a Brex card, which Google sees as a “privacy card.” These are often used by scammers trying to circumvent Google blocking their credit card account numbers.
The solution here is to never use a hidden or “privacy” card number with Google, although of course Google will never tell you that or confirm or deny this. I only know this due to working with clients in this area.
You can try removing that card and adding a regular hard card number and asking for a reinstatement again, but it may be too late for this account.
Hopefully this helps folks reading this to not make the same mistake (although it’s incredibly frustrating that stuff like this has to be learned by trial and error or knowledge from those of us who have dealt with this previously.)
- kylecordes 4y agoAnyone know of a way to know if one's credit card is classified this way? The author was using the corporate card they were issued... and presumably hadn't sought out a "privacy card", a term I never heard before today.
- happymellon 4y agoI still don't understand what a "privacy card" is.
- webmobdev 4y agoOne version of it that I have used is "virtual" prepaid cards. The way it works is that I can use my online banking account to create a new "virtual" card and load it with a fixed amount from my bank account. A new single-use credit / debit card number (by Visa or Mastercard) would be generated with CVV and expiry date that I can use online anywhere. It provides an easy and secure way of transacting online without providing the Primary Card / Account information to the merchant. Another version I wasn't aware, has been explained here in another comment - https://news.ycombinator.com/item?id=32238813 https://news.ycombinator.com/item?id=32238813 ...
- happymellon 4y agoI have unique cards generated for online transactions, and I see this feature with multiple banks here in the UK. It seems mad that this would be considered a bad thing.
- tlogan 4y agoBut if somebody steals your login, they can create multiple virtual numbers and spend a lot. And since these are virtual number, MC or Visa will not have tools to find problem or block it. Can somebody which knowledge of this explain problems with "privacy" cards and why scammers love them?
- nulbyte 4y agoMastercard and Visa aren't the ones at risk by such activity, the issuing banks are, and as someone who works for a bank, yes, banks have tools to detect and stop account takeovers and assist card members in recovering from such incidents. Scammers don't care about privacy cards. They'll use anything they can get their hands on, metaphorical or otherwise. If it doesn't have their details attached, it's fair game to them.
- Brystephor 4y agoIt's due to fraud risk. If googles threshold billing is X, then their risk of revenue loss is X*(N+1) where N is the number of virtual card numbers that have been created for a single physical card. The +1 is for the physical card. Visa/Mastercard likely don't supply a way to link a physical card to it's virtual card generations (that'd be a security risk), so Google doesn't know that virtual card A is associated with physical card B.
- paulgb 4y agoBrex has a feature where you can create vendor-specific cards, which I think is what's being referred to as the “privacy” feature. It makes it less disruptive to disable a card if a vendor leaks it, because it only interrupts payments to that vendor instead of having to update your card with every vendor. I wasn't using that feature here, but it might be the case that the information that arrives at Google is just the issuer so they classify all Brex cards as “privacy” cards?
- happymellon 4y agoWell that will just cement my lack of relationship with Google and ensure that my business goes to AWS. Considering that many banks are doing this sort of service to protect you against data breaches, I can't see how this is actually an appropriate policy.
- KronisLV 4y ago> Well that will just cement my lack of relationship with Google and ensure that my business goes to AWS. How can you run your ads through AWS? Or a better question, what other ad networks that are comparable to what Google offers are there? Because to me it seems almost like a monopoly in regards to how impactful Google's services are - sadly they aren't regulated as such.
- ajford 4y agoI'm assuming OP here was referencing Google's cloud services vs AWS. As in Google's abysmal behavior in regards to AdWords has spoiled them against using any other Google services.
- happymellon 4y agoIt just feels like a massive risk to my business that they could take my business and essentially shut it down, and block any communications. Surely they should be able to see that OP is an actual customer and not some sort of scammer.
- ROTMetro 4y agoFor corporate cards (and I beleive gift cards and debit, no idea about privacy cards they didn't exist yet) when I wrote this sort of software way back you could identify by card ranges/format (that was the case in the past), just like how you identify if a card is Visa, Mastercard, Amex. A Visa subrange will be corporate, restricted purchase, etc. So for example, a trucker can have a corporate card that works to purchase gas outside but not the CStore inside. If you know someone who write's merchant software they should be able to get you the ranges from their payment processor's specs.
- setgree 4y ago> The solution here is to never use a hidden or “privacy” card number with Google The author regularly uses the same CC with many other google services > The same credit card on the account, a corporate Mastercard from Brex, is attached to Google Cloud, Google Workspace, and Google Domains. Collectively, Google services have successfully charged that same card over $2,000 since that email.
- Jasper_ 4y agoGoogle Ads is a separate division with separate policies, separate payment infrastructure, and separate fraud detection systems. Don't try and make sense of it; it's inscrutable on purpose.
- oarsinsync 4y agoIf everything about it is separate, that makes it pretty easy to split out into an independent organisation too.
- derefr 4y agoIf Google Ads was a separate company, then the rest of Google wouldn't have an income source. Google is one breadwinner (Ads) + N loss leaders for it. (They're trying to grow a second revenue generator — GCP — but it's not been the success they've hoped; especially compared to Azure. Microsoft had the B2B relationships already in place, while Google has mostly been a B2C company, so they've been struggling to win clients.)
- elcomet 4y agoOf course they would have an income source. They would sell space on their pages to Google Ads or any competitors, like most websites or media companies (newspaper, tv).
- rainsil 4y agoSo they'd split off Google Ads then create another ad platform to sell ads on their properties? Why would anyone use the independent Google Ads?
- mousetree 4y agoWe've been using Brex virtual cards with Google Ads and Google Cloud for more than 3 years with no issues.
- jandrese 4y agoYou probably have enough history with Google to get away with it. What they likely do is have several flags that push an account closer to being autobanned, so it's not just one thing, but a combination that gets you knocked out. I'd imagine a list like: Using scammer friendly credit card: -10 points Used a TOR exit node: -20 points Account age < 2 years: -15 points Account spend < $1000US: -10 points Service being advertised is not well known to Google's data mining: -10 points etc... Get enough demerits and your account is toast, and since people are expensive once a bot flags the account you don't really have a recourse. Ironically if you want your ad to continue to run the best people to talk to probably isn't Google's tech support but black market scammers who have built and industry around understanding and circumventing these protections.
- toddh 4y agoI use a normal credit card that I use everyday and they canceled my account for no reason that I can see at all. No reason. No appeal. And they keep sending me email to create ads! This is despite paying for google domain, apps, and google drive space forever.
- s17n 4y agoIsn't Brex basically the standard for bay area startups now? Hard to believe that Brex cards in general would be getting flagged.
- tlogan 4y agoBrex privacy feature is used by a lot of scammer / spammers. Simple as that.
- powerhour 4y agoCurious how this works. Google surely verifies things like business addresses, DUNS numbers, company principals (CEO et al), etc, eh? So what if the card is "private" if the rest is legit?
- tlogan 4y agoThat is a good question. Maybe verification of the above data is "weak" so Brex privacy feature wins. I do not how Google fraud system works but I know that Brex privacy feature is signal which is not good (from my experience in our company). Sidenote: I also noticed that PayPal doe not like Brex privacy CC for subscriptions.
- sam0x17 4y agoExperience has taught me they have no such qualms when keeping advertiser money whether or not they revoke publisher earnings. As a teen (back in '09), I ran a domain parking network that was used by a modest number of users (about 50 users with ~300 domains total). At the time the Google AdSense TOS allowed any site that had "content" (there was no stipulation about it being original), so my network worked by displaying random wikipedia articles that are relevant (using a very simple algorithm) to the domain in question, along with several adsense blocks and a few other features. Each domain was also a fully functional wikipedia mirror, and content was properly attributed etc.. Anyway, most months I would get a payout of around $800 that I would then distribute to my users (I took a 20% cut). At 11:30 PM the night of payouts one month, they decided to change the TOS, revoke all of my earnings, and suspend my AdSense account. I sent an email to my users explaining the situation and I actually paid them all out-of-pocket for the missed earnings because I had the money to do so from doing random web design for local businesses and I felt quite bad -- some of my users were in dire rent situations, etc., and I was in regular contact with them so I wanted to make them whole even if it meant I would lose a good bit of money since I was a teenager without these sorts of problems. Anyway, one of my friends ran his own online service (a network of web proxies) and he actually specifically advertised on my network because for some reason the traffic converted well for his particular service. I had him check his AdWords spend several weeks later and we discovered that he was never refunded for the ads that ran on my network, even though those earnings were taken away from me. In other words, at least back then Google probably didn't refund advertisers in cases of clickfraud, etc., unless the advertister specifically knew they were being defrauded. At least that's what appeared to happen based on the info I had access to haha. They are super shady.
- jandrese 4y agoCan you imagine a company treating you like this in person? Like say you walked into Wal*Mart and selected some merchandise from the shelf, then walked to the register and paid using a Vanilla Visa card, as you noted there was a Visa sticker on the door when you entered. While you are picking up your bag from the bagging area a security guard roughly picks you up and throws you out the door and tells you to never come back. You ask why but their only response is "You were being suspicious." The customer is left bewildered, angry, and hurt.
- ev1 4y agoI have actually seen this multiple times - a very common thing, at least in the US, is using gift card magstripes for cloning stolen card track data onto. This is mostly irrelevant in countries that use chip and pin.
- kornhole 4y agoI have had similar problems using many platforms. I use virtual cards whenever I can to achieve better security and control of expenses (compartmentalization). I have given some companies my real name and address but used a virtual card, and then they locked my account later. This situation seems to be ramping up due to the escalating financial war with Russia. It would certainly be helpful if companies would tell us up front that if we use a payment card that cannot be firmly tied to our identity, they will lock the account afterwards. This would allow us to go somewhere else without wasting all the time to setup the account.
- navigate8310 4y agoI've had a similar experience but with IBM Cloud. So, I've started using LibreFox recently. Signed up for IBM Cloud after verifying my credit card and lo and behold, an account suspension letter was delivered after an hour. I guess it has something to do with their algorithm triggering accounts signed up using privacy focused browsers.
- mattl 4y ago> I guess it has something to do with their algorithm triggering accounts signed up using privacy focused browsers. What's the user agent for LibreFox?
- navigate8310 4y agoPretty sure Librewolf sets the same user agent that the Tor browser uses in its librewolf.cfg and locks the setting.
- m463 4y agoPeople don't understand that google is first and foremost an identification service.
- antioppressor 4y agoNobody cares. Google, a 1,3 trillion company, a gargantuan gatekeeper, the 3 letter acronym factory can't give you a proper error message :D. And they smear it right into your face. They don't care about you. Just give them your money and shut the F up. That's all. And people try to sort it out. I mean what's wrong with people? :DDDD Just give your money to someone else.
- figmaheart255 4y ago> although of course Google will never tell you that or confirm or deny this this sounds like security by obscurity. Why are people ok with this?
- deleted 4y ago[deleted]
- vesinisa 4y ago> although it may be too late for this account Aren't bans from Google services always eternal in the sense that trying to circumvent them by e.g. creating different accounts just gets you in even hotter water? Plus, it is very easy to detect when someone reinstates an ad (or Play Store app / YouTube channel) for something that was already banned under a different account.
- londons_explore 4y agoThis isn't the case... If you make a new account just make sure the recovery phone number and email address aren't ones which have a bad history. If you want to make a new ads account make sure in addition the postal address doesn't match a bad one. If you want to make a new payments account, make sure none of the credit card numbers in the account match a bad one. Note that because different teams within Google don't talk to one another, you don't for example need a new postal address if the issue is on the payments side.
- vesinisa 4y agoThen the rules are quite different for AdWords. For Google Play Store accounts, "termination" means that your primary account, as well as any "related" account (what Google's algorithms determine to be operated by the same person/company), are all eternally banned from the Play Store. Attempts to open any new account will be subjected to the same algorithm and get automatically rejected if determined to be "related" to the previously banned account. I am not making this up. Some indie Android developers have ended up in pretty Kafkaesque situations with their livelihoods (Play Store accounts) terminated without any explanation or human recourse, and with any attempts to circumvent the ban only leading to more trouble.
- oarsinsync 4y ago> any attempts to circumvent the ban only leading to more trouble Is this a figure of speech, and not a literal situation? If you’ve already been banned, failing to circumvent that ban ultimately only leads to the same outcome: still being banned? Or is there further punitive actions taken?
- koheripbal 4y agoThe issues exist with normal non-anonymous cards also. I'm currently having an issue because I used the same amex card on multiple Google accounts (within a corp gsuite instance), and I must have triggered something because now that card won't work anywhere with Google. And it fails with a useless "try again later error". Same then happened with a standard visa card. These corporate cards haven't worked for over a year. I wish they would just do some extra bit of verification rather than blacklist the cards without explanation.
- deleted 4y ago[deleted]
- kyrra 4y agoGoogler, opinions are my own. Corporate cards have some of extra handling to deal with them. I know I tried to buy a WASD keyboard using a corp card, and their payment processor didn't let me use it either. Looking around, it looks like when a Corp Card is issues (Capital one example[0]), they can lock the card to only be allowed with certain MCC (merchant category code). These are the codes that say what kind of product is being purchased. So it's possible the issuer of your corp card locked your card to certain MCCs. If your card in MCC locked, the merchant and processor likely won't know this until the payment has been tried, and there is a good chance the network/bank didn't send back a useful error code. [0] PDF: https://www.capitalone.com/commercial/decomm/media/doc/treasury-management/commercial-card.pdf https://www.capitalone.com/commercial/decomm/media/doc/treas...
- ROTMetro 4y agoYou should be able to handle for this by card type? When I wrote merchant software way back, we could separate restricted corporate cards from standard cards prior to processing, because we had to send itemized purchase records for corporate cards in a special format as part of the approval request. I believe corporate cards had their own card ranges and it was trivial to determine if you have the card number. A funny story. Because they shoehorned this functionality into a fixed length messaging spec instead of repeating segments, we could only send like 12 items. Anything after that was just approved. If I remember correctly the same spec applied to EBT purchases as well. I'm sure they use a different message format now and you totally can't get away with buying 12 things and then beer with an EBT card.
- deleted 4y ago[deleted]
- b3lvedere 4y ago"The solution here is to never use a hidden or “privacy” card number with Google" Okay. I get the why, but not put that in your TOS or just block it by default then? Should save a huge amount of time/trouble on both sides.
- kmeisthax 4y agoGoogle has an internal policy of not talking about anything related to enforcement. They've banned and ghosted their own business partners, not to mention their own employees' husbands, with zero explanation. This isn't anything new either; you can find examples of it going all the way back to the company's founding. The underlying logic seems to be to lay traps and pitfalls for bad actors to fall into rather than having a transparent and evenly-enforced set of rules. i.e. if we tell scammers they can't use privacy cards, instead of just silently banning anyone who uses them, then how can we tell scams apart from real users?
- TimTheTinker 4y agoThat's a pretty cynical outlook on their part. All of this is just a further reminder to me to avoid doing business with Google.
- MintPaw 4y agoBecause any card they banned would probably go out of business as such a policy spreads.
- 4y ago
- justsomeguy33 4y agoThis is your best bet, because you used a some kind of burner/debit card. Google does indeed discriminate on your payment method. Most likely due to them having too much data to process they analyze the data from abusers and these kind of cards seem to stick out like a sore thumb.
- AtNightWeCode 4y agoBurner/single use. Maybe it is different in different countries but Google do allow debit cards. Company credit cards are not standard in large parts of EU for instance.
- TimTheTinker 4y ago> too much data to process That's not true, it's their choice not to process the data manually. Google loves to leverage developers and code to fix every problem, including (especially?) customer service. In particular, they hate manual labor and seek to automate everything -- which is a horrible approach when it's applied unilaterally to all aspects of business relationships and customer service. At some point, Google needs to grow up and learn that being clever only takes you so far. As it is, Google leaders seem to love computers and money, not people. I'd wager 20:1 that anyone at Google reading this thread takes action by tweaking algorithms, not by restructuring the company to help customers in person.
- TimTheTinker 4y agoGoogle gained a tremendous amount of goodwill early on because they provided incredibly powerful free tools - search, web mail with 1GB of space, etc. -- which was so much better than what stingy incumbents offered (Yahoo Mail's free tier offered 10 MB of email storage at the time). But the rest of the industry has (mostly) caught up technically with them. But cleverness and free tools will no longer be enough, since they're invading people's privacy (as ad revenue motivates them) and failing in customer service.
- babypuncher 4y ago
- mrtksn 4y ago> of course Google will never tell you that or confirm or deny this This is my problem with de facto utilities that are not regulated like utilities. Google can have enormous impact on your business and personal life but you cannot get proper communications with them. If something goes wrong you can't fix it, even if it's your fault because often you don't know what you did wrong. If it's their mistake, you might get a chance if your issue gets attention by a large audience. It feels like there should be a legal recourse where you get compensated for damages due to service design choices of the utility. I'm sure in many places you can get compensated if the energy company cuts your electricity and doesn't clearly say the reason and what you can do about it. You can lose your business, you can loose access to your digital assets that you built all your life and for what? So that some employees at Google can have easier time managing an issue(not disclosing the reason for account restrictions probably makes the scammers life harder too and you are just a collateral damage that doesn't even show up in the analytics). Can you imagine E.ON cutting off the energy of the English futbol fans because it's easier for them to internally manage the surges during the games due to the tea kettles and not give them any explanation whatsoever? Edit: Interestingly, UK GDPR seems to have some protections agains automated decision making[0]. [0] https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/automated-decision-making-and-profiling/what-does-the-uk-gdpr-say-about-automated-decision-making-and-profiling/ https://ico.org.uk/for-organisations/guide-to-data-protectio...
- srcreigh 4y agoThere's a latent assumption here that big tech isn't already regulated by the US government, albeit in a hidden manner or a manner you don't like.
- jopsen 4y ago> This is my problem with de facto utilities that are not regulated like utilities. I totally see that. But on the flip side we see utilities like phone companies unable to block abusive robocalls and scammers. (My thoughts are my own, and they are rarely well-formed)
- 4y ago
- nunez 4y agoThat is extremely frustrating. I use a "privacy" card (issued by privacy.com) to containerize my monthly subscription spend, as I don't feel comfortable with any company having the ability to charge my actual card (which is a legit card). I'm using one with YouTube TV. I'll be pissed if they suspend my account because of this. There has to be a better way.