Is your credit card sharing your phone number with vendors?
Receiving unwanted store messages explained.

Image by Cybernews
- After a Redditor raised concerns about tap-to-pay devices sharing their phone number to merchants, experts said that's not the case.
- Customers may receive texts if they previously gave a phone number to a payment platform, loyalty program, or another merchant.
- Some payment data must be shared to approve purchases, prevent fraud, move funds, and handle disputes.
- Consumers can request stored data deletion, change receipt settings, unlink contact details, or use privacy rights where state laws apply.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
“The little ‘tap to pay’ machines are tracking you,” shared one Redditor after making a purchase at the shop they were in for the first time.
The user said that after they paid for their goods, they received a text from the store, together with the receipt for their recent purchase.
“How did the system know my cell number?” the Redditor pondered, suggesting that the machine they used to pay is somehow tracking them.
It might sound strange, but how else could you explain suddenly receiving such information on your phone after visiting a particular shop for the first time?
With facial recognition technology and dynamic pricing already raising privacy concerns, could your credit card really be telling merchandisers everything they need to know about you?
Only cash can’t betray you?
The question prompted an online discussion, with users offering explanations for how this could have happened.
“Any time you use any payment method other than cash, yes, you’re being tracked. It’s very lucrative to do so, and it’s one of the driving business reasons for loyalty programs,” wrote one user.
“The card doesn't have your number. The processor does. They build profiles from transactions and offer merchants automated texting as a 'feature,’” noted another netizen.
Who holds customers' contact details?
In situations like these, which are quite common, users shouldn’t blame the card issuer or the payment device.
“Card issuers and payment networks maintain significant customer information as part of providing financial services, but they operate under strict financial privacy regulations,” Brent Johnson, CISO at payment and data security firm Bluefin, told Cybernews.
“They generally do not provide a customer's personal contact information to a merchant simply because a card was used for a purchase.”
When a user makes a payment by card, the card provides the information needed to authorize the purchase and a security code unique to that transaction. This information, however, doesn’t include the user's name or phone number.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
Nevertheless, the customer receiving the receipt may be due to the business using a third-party payment platform that also handles digital receipts, customer profiles, loyalty programs, or messaging.
“The customer may have supplied a phone number during an earlier interaction with that platform, possibly while requesting a receipt from another business. Some platforms can store that number and associate it with the customer’s card or payment profile,” explained C. Jordan Howell, a criminologist with the University of South Florida, to Cybernews.
Can you opt out?
“I used my husband's credit card to pick up coffee at a local place once, but I am the one who has the loyalty account with them. So now I get text receipts whenever he uses that card at certain merchants,” one Redditor shared their experience.
“I hate that it's another thing I have to opt out of,” they added.
Is it possible to opt out, and how can one do it?
When it comes to card payments, customers can’t just disagree to share all information, explained Howell.
“The store, processor, card network, and issuing bank must exchange certain information to approve the purchase, prevent fraud, transfer the funds, and resolve disputes,” said the expert.
Nevertheless, they do have control over information that is not needed to complete the payment process, as this data is often used for marketing purposes.
Depending on the provider, users can ask what information is stored and request its deletion, change their receipt settings, or request to unlink their phone number or email address.
How to protect your data?
“Turn on Global Privacy Control in your browser, since in the states that recognize it, that signal is a binding opt-out, and you don't have to write to anyone,” Gage said, adding, “and treat your phone number as the key it has become. Hand it to a store, and you have joined yourself to every other record that already carries it.”
Global Privacy Control (GPC) is a browser signal that informs websites you visit not to sell, share, or use your personal data for targeted advertising.
When it comes to legislation, one of the most well-known examples is the California Consumer Privacy Act (CCPA), which provides California residents with the right to access, delete, correct, and limit certain uses of their personal information collected by businesses.
Howell noted that besides California, 18 more states have introduced consumer privacy laws.
The list includes Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia.
“Florida has a narrower privacy law and is sometimes counted as the twentieth,” shared the expert, adding, “Alabama, Louisiana, Oklahoma, and Vermont enacted additional privacy laws in 2026, but those laws will not take effect until 2027 or 2028.”