Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Retailers barred from asking for zip code in California credit card purchases (ericgoldman.org)
30 points by grellas on Feb 11, 2011 | hide | past | favorite | 24 comments


Wait a minute. Does this mean stores are not supposed to ask to see ID like a license to be sure it's your credit card?


Technically, this is against most merchant agreements anyway. I've often wanted to create an "I have to adhere to my credit card contract and so do you" tearsheet to hand out to merchants who require insane minimums (like bars and their $10-$20 minimums) and require ID for verification.


I read the article as making a distinction between using it in the transaction and storing it for use in postal spam.


I hope so. I mean, if finding out my zipcode is a big deal, then all the stuff printed on my driver license must be HUGE.


No. http://www.cardreport.com/laws/california/1747-1748-7.html They can check your ID and verify it matches the card, they just can't record anything from your ID.


But as techtalsky pointed out above, the merchant agreements between the credit card company and merchant often prohibit requiring ID for a signed, valid card and your matching signature.


Why is there a Song-Beverly Credit Card act making it unlawful to ask for corroborating identification for credit cards in California? What is the societal benefit to this law?


No, that is absolutely not what the law says. http://www.cardreport.com/laws/california/1747-1748-7.html

The law prohibits recording personally identifiable information, unless it's absolutely required for the transaction (for instance if your CC contract requires it, another law requires it, you're delivering something, etc).

In particular, it explicitly allows checking ID:

  (d) This section does not prohibit any [retailer] from requiring the cardholder, as a
  condition [blahblah], to provide reasonable forms of positive
  identification, which may include a driver's license [...], or [...],
  another form of photo identification, provided that none of the
  information contained thereon is [...] recorded [...].


All I have is wild speculation, but I'll attempt an answer.

I believe there was quite a bit of concern about providing any identification along with a in-person CC purchase. The idea was that by providing identifying information, plus a credit card number, you were making it extremely easy for someone to lift your identity. The clerk could pick up the phone immediately after you left the store and order whatever he wanted using your card.

So the theory was: ID check in person -> bad. ID check by internet or phone -> good.


That seems so backwards to me. I've had physical cards stolen before, and they get used, in person, immediately. I write "ASK ID" on the back of all my cards and thank clerks when they ask me.


I'm not a security guy, so I'm at a loss with analyzing whether it makes sense or not.

It did occur to me, though, that I would not want to be the clerk asking for ID if the guy on the other end of the counter had just mugged somebody at gunpoint and was now looking to buy something so he could go down the street and pawn it to purchase drugs.

But I can definitely see the other side of the argument too.


That works 99% of the time for me. The other 1% are people that point out the NOT VALID UNLESS SIGNED right above the signature block.


The article talks about the plaintiff being asked for their zip code, but not ID. I don't see in the article or in the snippets of law it references where proof of ID is unlawful. Perhaps its perfectly fine to ask for proof of id to authenticate the credit card holder, but not ok to record the ID info into the company's marketing database.


I've always just told them I'm from Canada (which I am) and that normally just gets a pass. Sometimes the checkout person can be quite forceful and require me to tell them my 'zip code', ok, V5J 021. There systems only accept numbers, so not alot of good that is going to do them.

The only place this is annoying is at gas stations where I have to go inside and give them my cc card to hold while I fill up. Hopefully this new law means that gas stations can't do that anymore.


The Song-Beverly Credit Card Act is a California-only animal. Having said that, it is unenforceable in interstate commerce. The only people who need to worry about this for their online stores are retailers with a business presence in California.


I've always wondered why they asked you for this information. Best Buy has been doing this for years. The article points out that online retailers have access to this a lot of info, but when you shop online you expect it. I actually hate purchasing for William Sonoma online because after I bought a wedding gift they spammed me from here in to 2027.

It's amazing to me how merchants feel entitled to your information and will be so aggressive in their procurement of it.


They do it precisely because they have less info than they get online.

How do you determine the response rate of a newspaper insert? You insert it into one zipcode one weekend and a different zipcode a different weekend.

How do you track unique vs repeat customers? You ask them for a uniquely identifying number.

Around these parts, I believe it's referred to as A/B testing and analytics.


I understand the basics of marketing, but asking a customer for their zip code isn't going to tell you much about them personally. It's the reverse engineering that is the real key and problem with this strategy. I'm pretty sure that when any internet user with half a brain goes to a website they know they're giving up info of some sort, what page they came from, IP addy, etc. My only point is that you don't expect that same level of privacy invasion (if you will) when you go buy some headphones from Best Buy.


I doubt that most people expect the site owner to find their IP address (let alone what an IP address even is and what we can do with it) or what page they came from. When I bring up analytics with normal people, they tend to be a bit shocked.


And Radio Shack used to ask for your phone number when buying batteries (maybe they still do, it's been a while). In both cases, you can just say no.


It's much more fun to put a bit of research in, and find out the store's phone number before buying batteries. When they ask for your number, give them theirs. They'll start typing it in, then pause in confusion, which you are then free to enjoy!


The person at the desk doesn't really care, I often just say "it's the same as the store's" -- it's that or 867 5309, their choice.


True, but most people won't think twice and will just give it to them.


When people ask for my personal information with a transaction, I just say politely, "No, Thanks."




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: