/* Not legal advice. This page is research, not compliance guidance. */ /* */
Masked Payment-Card Comparison: Merchant Masking, KYC, Funding, and Limits
Status: active. The card class meets the frozen minimum of 3 distinct eligible vendors (4: Capital One Eno, Cloaked Pay, MySudo, Privacy.com), populated from the final, independently-validated p4 card tool cells. Not legal advice.
Short answer
This page compares masked payment-card products only through the frozen card-cell schema, for the four eligible vendors whose card products cleared the preregistered class-size gate. Every value below transcludes a specific vendor's own cited source; where a source does not address a field, that cell stays a typed unknown rather than an inferred answer.
What the masked card hides from a merchant
A masked or virtual card number is a merchant-facing credential that stands in for the underlying funding account or credit line. The merchant sees the masked card number, not the card or bank account that actually funds the charge. This boundary does not extend to the provider issuing the card, its issuing bank, the card network, the funding source, or a lawful requester -- all of whom can still hold identity and transaction information. See the comparison table below for what each eligible vendor's own documentation states about its specific card product. tool.card.masked_identifier The masked-card boundary is limited to the merchant-facing credential. It does not imply that a provider, issuer, network, funding source, or lawful requester lacks identity or transaction information.
Who still receives identity information
Each eligible vendor names its own operating entity and governing law in its primary terms or policy. See the comparison table's Identity recipients column, and the evidence ledger, for each vendor's own stated entity and governing law -- this is not collapsed into one cross-vendor fact. tool.card.operating_entity Jurisdiction slot: Incorporation jurisdiction is not disclosed in the captured primary-source terms or policies for any of the four eligible card vendors. Each vendor's stated governing law (not the same fact as incorporation) is reported in its own 'identity recipients' row of the comparison table. tool.card.entity_jurisdiction Issuer slot: The issuing bank or program partner differs by vendor, and is not disclosed at all for one of the four eligible vendors. See each vendor's Issuer column and evidence-ledger payment_card row. tool.card.issuer Network slot: The card network (for example, Mastercard) is stated for some eligible vendors and not separately disclosed for others. Network is tracked as its own column, never collapsed into the issuer statement, even where the only source discloses them together. tool.card.network Payment-method slot: No frozen card-class attribute separately tracks a vendor's supported in-app or wallet payment methods apart from its funding sources and card network. See Funding sources and Network in the comparison table for what the cited sources actually state. tool.card.payment_methods Provider, issuer, network, funding source, and payment counterparty remain separate fields.
Signup identifiers and later verification triggers
The identifiers a vendor collects at signup, before card access, vary by vendor and in some cases are not separately disclosed from later verification. See each vendor's Signup and later verification column and evidence-ledger row. tool.card.signup_identifiers Verification-trigger slot: Each eligible vendor's own documentation describes different events that can trigger an additional identity-evidence request after signup (for example, enabling a virtual card, adding a funding source, or a security review). See each vendor's evidence-ledger row for later_verification_triggers, quoted from its own primary source; this is not collapsed into one cross-vendor statement. tool.card.identity_verification_triggers KYC slot: None of the four eligible vendors' cited sources uses the literal term "KYC." Each describes identity-evidence collection at signup or before card access (name, address, date of birth, and in some cases a government ID number or SSN) consistent with standard bank-partnered identity-verification practice. See each vendor's Signup identifiers row; this page does not assert a formal KYC-program classification beyond what each source states. tool.card.kyc_required A signup identifier is not merged with a later verification event or a product eligibility constraint.
| Card roster row | Merchant-facing masking | Identity recipients | Signup and later verification | Retained data and duration | Lawful-request transparency | Claim label | Source origin | Fetch event |
|---|---|---|---|---|---|---|---|---|
| MySudo | MySudo virtual cards are US-only paid-plan cards funded by one linked US credit/debit card, with plan/card-count and transaction limits. | Anonyome Labs, Inc. | date of birth, government-issued ID, legal name, residential address | legal identity information supplied for card verification: duration of MySudo usage plus five years; legal identity verification data: 15 days; tokenized funding-card data: while active | law-enforcement request procedure only | vendor_stated | vendor_primary | 55da3a6b-f93f-4292-b999-7dd395b04351 |
| Cloaked Pay | Subscription + U.S.-resident KYC eligibility; U.S.-issued funding; one-time, ongoing, and custom controls. | Cloaked, Inc. for U.S. users; Cloaked International, Inc. for users outside the U.S.; Cloaked Pay, LLC named for Cloaked Card products/services. | Not disclosed | customer account and enabled-service information: for as long as the customer has an account and the service is turned on | Vendor states it responds to valid legal process and will notify the user when allowed. | vendor_stated | vendor_primary | 36b573ba-0cbb-573d-9eae-8163e54078ef |
| Privacy.com | Your Cards are charge cards, which access a line of credit provided by Bank. Your Cards are not debit cards or prepaid cards. | Lithic, Inc., doing business as Privacy.com | Date of birth, Name, Residential address, US phone number capable of SMS, driver license or other identifying document, identification_number (for most users, SSN) | Identity verification data: 5 years from the date of account closure; Payment card data: 5 years from the date of account closure; Funding bank account information: 6 years from the date of account closure; Audit logs: 3 years from date of creation; ACH transactions: 6 years from the date of an ACH entry | The policy describes possible sharing with government and law enforcement but publishes no request-count table in the fetched primary source set. | vendor_stated | vendor_primary | 70e7fa5f-8563-5114-9263-c3f43826f09d |
| Capital One Eno | Eligible Capital One cardholders can associate multiple virtual cards with one credit-card account, including general-use and merchant-specific numbers. | Capital One Financial Corporation; Capital One, N.A. | Not disclosed | personal information collected under the Online Privacy Policy: as long as reasonably necessary for the stated purposes and consistent with retention policies and applicable laws | Capital One says validly issued and served subpoenas may take approximately 30–45 days to complete, depending on request complexity | vendor_stated | vendor_primary | 4d5abd2f-0369-5060-927e-7c11d9c185a9 |
Data retained and retention periods
What is retained, and for how long, is stated per data category by each vendor's own policy. See each vendor's Retained data and duration column and evidence-ledger retention row. tool.card.data_retained Retention-period slot: Retention duration varies by data category and by vendor -- see each vendor's Retained data and duration column and evidence-ledger retention row for its own stated categories, durations, and exceptions. tool.card.retention_period Account-deletion slot: Account-closure mechanics and what is or is not erased on closure differ by vendor. See each vendor's evidence-ledger deletion row for its own stated initiation path, erasure statement, exceptions, and controller. tool.card.account_deletion Deletion initiation remains separate from completed erasure.
Portability and operational constraints
Supported platform scope is recorded per vendor in the comparison table and evidence ledger (for example, web and mobile, or iOS and Android), rather than asserted as one cross-vendor fact. tool.card.platforms Funding-source slot: What may fund the card (a linked credit or debit card, a bank account via ACH, or an existing credit-card account) differs by vendor. See each vendor's Funding sources column. tool.card.funding_sources Merchant-lock slot: Whether a vendor offers a card locked to a single merchant is stated for some eligible vendors and not disclosed as a distinct option for others. See each vendor's Merchant lock column; this is tracked separately from other merchant restrictions below. tool.card.merchant_locked Restriction slot: Category, geographic, and other merchant-use restrictions beyond a single-merchant lock vary by vendor. See each vendor's Other restrictions column. tool.card.merchant_restrictions Platform, plan, region, funding source, merchant lock, and other restrictions remain scoped to the source cell that states them.
Lawful-request process and transparency reporting
Each vendor's stated process for responding to lawful requests (subpoenas, legal process, or government and law-enforcement requests) is recorded per vendor in the comparison table and evidence ledger; none of the four publishes a request-count report (see request_counts_published). tool.card.lawful_request_process Request-count slot: None of the four eligible vendors' captured primary sources publishes a lawful-request count, reporting period, or jurisdiction breakdown for its card product. Absence of a published report is recorded here as a typed unknown, never rendered as a count of zero. tool.card.request_counts_published Absence of a published report is not rendered as zero requests.
Claim labels, sources, and capture dates
Every rendered card-class claim on this page is labeled vendor_stated: it comes from the vendor's own published documentation, not from independent testing (independently_tested claims are not permitted on this page in v1) or an unaffiliated public record. See the evidence ledger for the claim type recorded against every individual attribute. tool.card.claim_type Source-origin slot: Every rendered card-class source on this page originates vendor_primary: the vendor's own site, support article, terms, or policy. Claim type and source origin are tracked as separate labels and are never collapsed into one another. tool.card.source_origin Source URL slot: Each individual attribute's real source URL is recorded in the evidence ledger below, per vendor. tool.card.source_url Fetch-event slot: Each individual attribute's capture date is derived from its own fetch event, recorded in the evidence ledger below, per vendor. tool.card.fetch_event_id Schema slot: All card-class cells on this page are pinned to schema blob 5fb708ded8c1413319073d1b0d760aa8475674a0 (attributes-v1.json sha256 173db1cf3b307bf5a30358a028f2754c0911850728c97160b30095de5caa44cb). tool.card.schema_blob_sha No independently tested card claim is rendered in this scaffold.
Corrections and version history
No correction has been logged against any of the four eligible card vendors' cells as of this capture. The common correction procedure on the methodology hub applies if one is filed. tool.card.correction_log Schema slot: All card-class cells on this page are pinned to schema blob 5fb708ded8c1413319073d1b0d760aa8475674a0 (attributes-v1.json sha256 173db1cf3b307bf5a30358a028f2754c0911850728c97160b30095de5caa44cb). tool.card.schema_blob_sha The public correction procedure is maintained on the methodology hub.
Issuer, network, and funding sources
The issuing bank or program partner differs by vendor, and is not disclosed at all for one of the four eligible vendors. See each vendor's Issuer column and evidence-ledger payment_card row. tool.card.issuer Network slot: The card network (for example, Mastercard) is stated for some eligible vendors and not separately disclosed for others. Network is tracked as its own column, never collapsed into the issuer statement, even where the only source discloses them together. tool.card.network Funding-source slot: What may fund the card (a linked credit or debit card, a bank account via ACH, or an existing credit-card account) differs by vendor. See each vendor's Funding sources column. tool.card.funding_sources Issuer, network, and funding source are not collapsed into a brand-level statement.
Merchant locks and other use restrictions
Whether a vendor offers a card locked to a single merchant is stated for some eligible vendors and not disclosed as a distinct option for others. See each vendor's Merchant lock column; this is tracked separately from other merchant restrictions below. tool.card.merchant_locked Other-restriction slot: Category, geographic, and other merchant-use restrictions beyond a single-merchant lock vary by vendor. See each vendor's Other restrictions column. tool.card.merchant_restrictions Merchant-specific locking, merchant-category controls, plan scope, platform scope, and other limits remain separate.
Account eligibility and KYC requirements
Who may open or use the card product (citizenship or residency, age, an existing account relationship, a subscription, or a waitlist) is stated per vendor. See each vendor's Product eligibility column; eligibility is tracked separately from the KYC identity-verification facts above. tool.card.product_eligibility KYC slot: None of the four eligible vendors' cited sources uses the literal term "KYC." Each describes identity-evidence collection at signup or before card access (name, address, date of birth, and in some cases a government ID number or SSN) consistent with standard bank-partnered identity-verification practice. See each vendor's Signup identifiers row; this page does not assert a formal KYC-program classification beyond what each source states. tool.card.kyc_required Eligibility, geography, plan, funding source, and identity-check requirements stay separate from the masked-card capability.
| Card roster row | Issuer | Network | Funding sources | Merchant lock | Other restrictions | Product eligibility and KYC | Source origin | Fetch event |
|---|---|---|---|---|---|---|---|---|
| MySudo | Sutton Bank, Member FDIC; Mastercard license; powered by Marqeta | Mastercard | one active major US credit or debit card with a US billing address for all virtual cards | Not disclosed as a distinct card-locking option | US-based Mastercard merchants; US-dollar online or phone purchases; in-store and international transactions unsupported; additional prohibited categories in the terms | US-based users on paid plans after identity and funding-source verification | vendor_primary | 55da3a6b-f93f-4292-b999-7dd395b04351 |
| Cloaked Pay | Not disclosed in captured sources | Not disclosed separately from the issuer statement | U.S.-issued credit card; U.S.-issued debit card; U.S. bank account via ACH | A 'Custom card' can be configured to a specific merchant at setup; the help article does not describe the 'One-time' or 'Ongoing' card types as auto-locking to the first merchant used. | Cloaked Pay cards can also carry a spending limit and a merchant restriction as general card controls, independent of the merchant-locked card type specifically. | monthly or annual Cloaked subscription; U.S. citizen residing in the United States; 18 or older; passes identity verification; limited access/waitlist | vendor_primary | 36b573ba-0cbb-573d-9eae-8163e54078ef |
| Privacy.com | Patriot Bank, N.A.; the fetched support page says newly created Privacy Cards are Mastercard. | Mastercard | Checking accounts and debit cards from US banks/credit unions; credit cards are not supported as funding sources. | A Privacy Card can lock to a single merchant; a charge attempted at an unauthorized merchant is declined. | A Privacy Card also supports a per-card spend limit and can be paused or closed at any time, independent of the merchant lock itself. | US citizen or legal resident, age 18+, US checking-account holder, SMS-capable US phone number, and identification number. | vendor_primary | 70e7fa5f-8563-5114-9263-c3f43826f09d |
| Capital One Eno | The product page names Capital One but does not identify the precise issuing legal entity for every eligible card | Not disclosed separately from the issuer statement | an eligible Capital One credit card account; virtual cards are not available for debit cards and some credit cards | one general-use virtual card may be used at online merchants accepting virtual cards; merchant-specific virtual cards only work at the designated website | one general-use virtual card may be used at online merchants accepting virtual cards; merchant-specific virtual cards only work at the designated website | eligible Capital One cardholder; identity verification required before access; some users may need to wait about 30 days after account opening | vendor_primary | 4d5abd2f-0369-5060-927e-7c11d9c185a9 |
Evidence ledger
Every card-class attribute captured for each eligible vendor, with its own claim type, source origin, real source URL, capture date, and pinned schema blob. Claim type and source origin are tracked as separate fields and never collapsed into one another.
| Vendor | Attribute | Claim type | Source origin | Source | Capture date | Schema blob |
|---|---|---|---|---|---|---|
| MySudo | signup_identifiers | vendor_stated | vendor_primary | source | 2026-09-30T11:19:18Z | 5fb708ded8c1 |
| MySudo | later_verification_triggers | vendor_stated | vendor_primary | source | 2026-09-30T11:19:18Z | 5fb708ded8c1 |
| MySudo | retention | vendor_stated | vendor_primary | source | 2026-09-30T11:19:22Z | 5fb708ded8c1 |
| MySudo | deletion | vendor_stated | vendor_primary | source | 2026-09-30T11:19:21Z | 5fb708ded8c1 |
| MySudo | payment_card | vendor_stated | vendor_primary | source | 2026-09-30T11:16:54Z | 5fb708ded8c1 |
| MySudo | operating_entity | vendor_stated | vendor_primary | source | 2026-09-30T11:16:57Z | 5fb708ded8c1 |
| MySudo | source_availability | vendor_stated | vendor_primary | source | 2026-09-30T11:19:16Z | 5fb708ded8c1 |
| MySudo | audit_report | vendor_stated | vendor_primary | source | 2026-09-30T11:16:55Z | 5fb708ded8c1 |
| MySudo | request_reporting | vendor_stated | vendor_primary | source | 2026-09-30T11:21:52Z | 5fb708ded8c1 |
| Cloaked Pay | signup_identifiers | vendor_stated | vendor_primary | source | 2026-09-30T06:43:49-04:00 | 5fb708ded8c1 |
| Cloaked Pay | later_verification_triggers | vendor_stated | vendor_primary | source | 2026-09-30T06:43:47-04:00 | 5fb708ded8c1 |
| Cloaked Pay | retention | vendor_stated | vendor_primary | source | 2026-09-30T06:43:49-04:00 | 5fb708ded8c1 |
| Cloaked Pay | deletion | vendor_stated | vendor_primary | source | 2026-09-30T06:43:44-04:00 | 5fb708ded8c1 |
| Cloaked Pay | payment_card | vendor_stated | vendor_primary | source | 2026-09-30T06:43:47-04:00 | 5fb708ded8c1 |
| Cloaked Pay | operating_entity | vendor_stated | vendor_primary | source | 2026-09-30T06:43:50-04:00 | 5fb708ded8c1 |
| Cloaked Pay | source_availability | vendor_stated | vendor_primary | source | 2026-09-30T06:43:50-04:00 | 5fb708ded8c1 |
| Cloaked Pay | audit_report | vendor_stated | vendor_primary | source | 2026-09-30T06:43:50-04:00 | 5fb708ded8c1 |
| Cloaked Pay | request_reporting | vendor_stated | vendor_primary | source | 2026-09-30T06:43:49-04:00 | 5fb708ded8c1 |
| Privacy.com | signup_identifiers | vendor_stated | vendor_primary | source | 2026-09-30T10:42:13Z | 5fb708ded8c1 |
| Privacy.com | later_verification_triggers | vendor_stated | vendor_primary | source | 2026-09-30T10:37:54Z | 5fb708ded8c1 |
| Privacy.com | retention | vendor_stated | vendor_primary | source | 2026-09-30T10:37:54Z | 5fb708ded8c1 |
| Privacy.com | deletion | vendor_stated | vendor_primary | source | 2026-09-30T10:41:36Z | 5fb708ded8c1 |
| Privacy.com | payment_card | vendor_stated | vendor_primary | source | 2026-09-30T10:39:33Z | 5fb708ded8c1 |
| Privacy.com | operating_entity | vendor_stated | vendor_primary | source | 2026-09-30T10:37:54Z | 5fb708ded8c1 |
| Privacy.com | source_availability | vendor_stated | vendor_primary | source | 2026-09-30T10:37:56Z | 5fb708ded8c1 |
| Privacy.com | audit_report | vendor_stated | vendor_primary | source | 2026-09-30T10:39:33Z | 5fb708ded8c1 |
| Privacy.com | request_reporting | vendor_stated | vendor_primary | source | 2026-09-30T10:37:54Z | 5fb708ded8c1 |
| Capital One Eno | signup_identifiers | vendor_stated | vendor_primary | source | 2026-09-30T16:14:35.886Z | 5fb708ded8c1 |
| Capital One Eno | later_verification_triggers | vendor_stated | vendor_primary | source | 2026-09-30T16:11:09.552Z | 5fb708ded8c1 |
| Capital One Eno | retention | vendor_stated | vendor_primary | source | 2026-09-30T16:11:10.114Z | 5fb708ded8c1 |
| Capital One Eno | deletion | vendor_stated | vendor_primary | source | 2026-09-30T16:11:09.793Z | 5fb708ded8c1 |
| Capital One Eno | payment_card | vendor_stated | vendor_primary | source | 2026-09-30T16:11:09.552Z | 5fb708ded8c1 |
| Capital One Eno | operating_entity | vendor_stated | vendor_primary | source | 2026-09-30T16:14:34.908Z | 5fb708ded8c1 |
| Capital One Eno | source_availability | vendor_stated | vendor_primary | source | 2026-09-30T16:11:10.349Z | 5fb708ded8c1 |
| Capital One Eno | audit_report | vendor_stated | vendor_primary | source | 2026-09-30T16:11:10.114Z | 5fb708ded8c1 |
| Capital One Eno | request_reporting | vendor_stated | vendor_primary | source | 2026-09-30T16:14:35.356Z | 5fb708ded8c1 |
Sources
The companion sources.json records the card roster, every card-class cell transcluded above, and the full evidence ledger. Each cell binds to the vendor's own cited source URL, a fetch event, a capture date, and the pinned schema blob (5fb708ded8c1).
Not legal advice
Masked-card provider policies, issuer relationships, funding rules, merchant controls, and verification flows can change. This page is a source-bound comparison scaffold and not operational, legal, financial, or compliance guidance.