What personal data is sent when paying?
Privacy policy says "other information requested by the merchant, such as ... account number, your shipping address, or email address, is also provided".
Does that mean silent supermarket checkout profiling?
Privacy policy says "other information requested by the merchant, such as ... account number, your shipping address, or email address, is also provided".
Does that mean silent supermarket checkout profiling?
Apple only receives encrypted data and does not have the key to decrypt the data. Unless Apple is the merchant, and then they receive shipping address (likely on file) and the details necessary to fulfill the order. The supermarket already knows what you’re purchasing and will do whatever is required to meet federal and state requirements. Apple can’t supply the notification you’d like, because they do not know what you’re purchasing if they are not the merchant, because the data is encrypted. Merchants have their own privacy policies in regard to how they handle the data they receive.
Apple only receives encrypted data and does not have the key to decrypt the data. Unless Apple is the merchant, and then they receive shipping address (likely on file) and the details necessary to fulfill the order. The supermarket already knows what you’re purchasing and will do whatever is required to meet federal and state requirements. Apple can’t supply the notification you’d like, because they do not know what you’re purchasing if they are not the merchant, because the data is encrypted. Merchants have their own privacy policies in regard to how they handle the data they receive.
The request would be if it’s an order being shipped. Normally, address, phone number and email would not be provided to the merchant. However, if the purchaser requests/requires shipment, Apple Pay must provide address, email and phone number so merchant can contact purchaser if there is a delay in shipment or delivery etc.
Customer name and partial card details, depending on the type of purchase and the type of business. Some businesses are required to have additional information, such as purchase of firearms, some prescriptions, etc. If the purchase is for shipping, name, address, email and/or phone number to contact the purchaser.
Not sure what silent supermarket checkout profiling is. My experience is more on the financial side.
The information being shared was already entered by the account holder or authorized user in their iPhone at this path,
iPhone > Settings > Wallet &Apple Pay > Transaction Defaults > this information includes name, address, email and phone number.
That’s what happens, as best as I can confirm. I have a merchant account and I accept Apple Pay. I know the data I get when I do a transaction and when I accept an order for shipment.
Yes, Apple would not be in the position to verify the lawfulness of a request. But Apple Pay privacy policy mentions "other information requested by the merchant". This looks like a request from the merchant (or third parties employed by the merchant) to the Apple Pay service to provide the user information, so Apple would be able to do a user confirmation dialog before sending user data like the "Transaction Defaults" for Apple Pay.
I will try to be more precise: If I pay at a supermarket checkout, can the involved third parties receive personal details from Apple Pay without me having to confirm it per pay event?
Regarding the firearms/prescriptions use case, I would want a dialog like "This transaction service has requested to get your name & address. Send it?"? For example, if I pay in online stores with Apple, I get asked whether an Apple account postal address should be used to fill in the form for the shipping address.
That's what I'd hope. Transaction Defaults sent for shipment – or as you said, firearms and specific use cases – not sent for every purchase simply because requested, at least not without a dialog.
What personal data is sent when paying?