Our position, up front: we are Geonode and we sell proxies, so the honest version matters more than usual here. A proxy does not make a payment private. When you check out, you supply your name, your billing address and a card issued by a bank that knows exactly who you are. The merchant learns all of it. The IP address is the least identifying thing in that transaction, and changing it does not change the rest. Worse — and this is the practical point most articles miss — a mismatch between your apparent location and your billing country is a well-known fraud signal, so routing a genuine purchase through a proxy is a good way to have it declined. We would rather tell you that than sell you a plan for it.
We are also not covering evasion of bans, sanctions screening or identity verification, and none of what follows is a route to that. Those uses are illegal in most places and out of scope.
Two Tools That Cover Different Halves of the Problem
Think of an online purchase as leaking information along two channels.
The network channel carries your IP address, and from it an approximate location and your ISP. It also carries your browser fingerprint, cookies and referrer. This is what a proxy affects.
The payment channel carries your card number, your name, your billing address, and — via the card's BIN — your issuing bank and its country. This is what a virtual card affects.
Neither tool touches the other channel. That is the whole reason they get recommended as a pair, and also the reason pairing them badly causes problems: the two channels are cross-checked against each other by every fraud system in the payments industry.
What a Virtual Card Actually Hides
A virtual card is a real card number issued against your actual account, with restrictions attached. Privacy.com, one of the better-known providers, describes it as "a unique 16-digit card number with a CVV code and expiration date that can be generated instantly", acting as "a secure layer" between you and the merchant.
The controls are the substance:
Merchant locking. Cards "automatically 'lock' to the first merchant they're used at and can never be used anywhere else if they're stolen." This is the single most useful property. A merchant breach yields a number that works nowhere else.
Spend limits. "Set a spend limit on any Privacy Card so you won't be charged for more than you authorize", with transactions over the limit declined automatically.
Instant termination. You can "pause or close a Privacy Card anytime" without touching your real card or any other virtual card.
Single use. One transaction, then dead.
What it genuinely protects you from:
- A merchant data breach exposing a number that is useful elsewhere
- Subscriptions that are easy to start and hard to cancel — close the card and the charge fails
- A trial that silently converts to a paid plan
- The need to reissue your real card, and update it everywhere, after one merchant is compromised
What it does not hide:
- Your name. Merchants and card networks still have it.
- Your billing address, which most merchants require and verify.
- Your identity from the card issuer, who performed identity verification before issuing.
- The transaction from your bank, which sees everything.
- Your identity from law enforcement with proper process.
So the accurate description is compartmentalisation, not anonymity. You are limiting how far a single merchant's knowledge and a single merchant's breach can travel. That is genuinely valuable and it is a much smaller claim than the one usually made.
One practical constraint worth noting: availability is regional. Privacy.com states it is "currently available to US citizens or legal residents with a checking account at a US bank or credit union, and who are 18+". Its plans run $5, $10 and $25 per month across three tiers, checked September 2026. Elsewhere, virtual cards are commonly offered by challenger banks and payment apps rather than by dedicated providers, and the controls vary — some offer merchant locking, many do not.
What a Proxy Actually Hides
Our own product, described accurately.
What it changes: the IP address a website sees, and therefore its estimate of your location and your network operator. That is the complete list.
What it does not change:
- Cookies and local storage already in your browser
- Your browser fingerprint — fonts, canvas rendering, screen dimensions, time zone
- Account logins, which identify you directly
- Anything you type, including your name and address
- Payment details, which travel through a different channel entirely
The last point deserves emphasis because it is the crux of this article. The payment does not go through your proxy in any meaningful sense. Your browser sends card details to the merchant over TLS; the merchant sends them to its payment processor over its own connection. Your IP address is metadata attached to the checkout session, not part of the payment authorisation path. Changing it changes one field in a fraud model and nothing else.
There are also leaks that undo a proxy entirely, and they are common: DNS queries going to your own resolver while traffic goes through the proxy, WebRTC exposing local addresses, a time zone that contradicts the exit country, and IPv6 traffic bypassing an IPv4-only proxy. We covered testing for these in our guide on how to test proxies.
The Mismatch Problem: Why Combining Them Naively Fails
This is the section that saves people from declined transactions and locked accounts.
Every card transaction is scored for fraud risk, and one of the standard signals is consistency between the network channel and the payment channel. A payment where the IP geolocation, the billing address country and the card's issuing country all agree looks ordinary. One where they disagree looks like a stolen card being used from abroad — because that is very often exactly what it is.
So a proxy applied to a genuine purchase produces a genuine problem:
Your transaction is declined, and you have no way of knowing why, because fraud decisions are not explained.
Your account is flagged, and subsequent legitimate transactions face extra scrutiny.
The merchant asks for verification — identity documents, a phone call — which is precisely the opposite of what you were trying to achieve.
Your card issuer freezes the card, because from their side an unfamiliar location is exactly what they are watching for.
Address verification makes this concrete. Merchants routinely check the billing address you supply against the one the issuer holds, and a mismatch there is a much stronger signal than IP geolocation. A virtual card does not change your billing address; it is still your address, attached to your account at your bank.
The practical rule: for a genuine purchase, do not use a proxy. Consistency is what you want. If your goal is to reduce what a merchant learns about you, the virtual card does that; the proxy adds risk without adding privacy, because the merchant is about to learn your name and address anyway.
Where This Is Genuinely Useful
Cases where each tool earns its place.
Virtual cards, for almost everyone. Merchant-locked cards mean a breach at one retailer does not compromise anything else. Subscription control means a cancellation you cannot be argued out of. Spend limits catch billing errors. These benefits require no proxy, no unusual behaviour, and no explanation to anyone. If you take one thing from this article, this is it.
Proxies, for research rather than purchasing. Checking regional pricing and availability before you buy — as research, from a browser that is not logged in and is not about to check out. Comparing what a service costs in different markets is legitimate market research, and doing it from a clean session avoids polluting your own account history.
Proxies, for separating browsing from buying. A genuinely coherent pattern: research with a proxy in a session with no accounts and no payment details, then purchase normally without one. The privacy benefit is in the browsing, which is where behavioural profiling actually happens. Checkout is not where you are anonymous; it is where you identify yourself by design.
Proxies, for network restrictions. Reaching a site your network filters. Unrelated to payments.
Both, for legitimate business testing. If you operate a shop, testing your own checkout from different regions with test cards is normal quality assurance. This is a business use with the merchant's own consent, which is a different situation entirely.
Where It Is Not, and Where It Is Illegal
Stated plainly, because this search term attracts a certain amount of wishful thinking.
Buying region-locked goods or services from outside the region. The billing address and issuing country give you away regardless of the IP. It generally breaches the merchant's terms, and where it works it works unreliably.
Evading a ban or a suspension. New card, new address, same person. Platforms correlate on far more than payment details, and the attempt is usually detectable.
Circumventing identity verification, sanctions screening or anti-money-laundering checks. Illegal in most jurisdictions, and the virtual card issuer performed identity verification on you before issuing anything. There is no anonymity to be had here; the compartmentalisation is between you and merchants, never between you and your bank.
Anything involving deceiving a merchant about who is paying. That is fraud, and the tools discussed here do not change that characterisation.
Free trial cycling. Merchants detect this through email, device fingerprint and behavioural patterns as much as through card numbers, and it breaches the terms you agreed to.
We will not help with any of the above, and none of it is what virtual cards are designed for.
Regulation Working in Your Favour
Three frameworks give you more than most people realise, and they cost nothing to use.
Strong Customer Authentication. Under PSD2, Article 4(30) defines SCA as authentication using two or more elements from the categories of knowledge, possession and inherence, "that are independent, in that the breach of one does not compromise the reliability of the others". For European consumers this means a stolen card number alone is usually insufficient to complete an online payment — which is a substantial protection that arrived without anyone having to configure anything.
PCI DSS governs how merchants handle card data. The standard "was developed to encourage and enhance payment card account data security", and applies across "merchants, processors, acquirers, issuers, and service providers". Note the limit the PCI Security Standards Council states about enforcement: whether an entity must comply or validate compliance "is at the discretion of organizations that manage compliance programs, such as a payment brand, acquirer, or other entity". It is a contractual regime rather than a law, and compliance is not uniform — which is a reasonable argument for merchant-locked cards.
GDPR and equivalents give you rights over the data a merchant holds: access, correction, erasure, and objection to processing for marketing. Exercising those rights removes data that was already collected, which no technical measure does. A subject access request is slower and less exciting than a proxy, and it acts on the actual problem.
The pattern across all three: the strongest privacy protections available to an ordinary consumer are legal rather than technical, and they are underused because they are boring.
Practical Setup That Does Not Backfire
If you want the benefits without the declined transactions.
Use merchant-locked virtual cards as the default. One per merchant, spend limit set to slightly above expected. This is the highest-value change and it has no downside.
Use single-use cards for trials. The card dies with the trial, and the conversion charge fails.
Do not proxy your checkout. Consistency between IP, billing address and issuing country is what keeps a genuine transaction from being flagged. The merchant is receiving your name and address anyway.
Separate your sessions properly. Research in one browser profile with a proxy and no accounts; purchase in another with neither. Half-measures — a proxy with your usual logged-in browser — give you the fraud-score penalty and none of the privacy benefit, because the cookies already identify you.
Use a dedicated email address per merchant if your provider supports aliasing. Email is the identifier most commonly used to link accounts across services, and it is easier to compartmentalise than payment details.
Keep your billing address accurate. Falsifying it to match a proxy location is a bad idea legally and practically, and address verification will fail anyway.
Exercise your data rights on the merchants you use most. Deletion requests act on data that already exists. Nothing technical does.
People Also Ask
Do virtual credit cards make me anonymous?
No. They compartmentalise — a merchant gets a number that works nowhere else, and a breach at that merchant compromises nothing further. Your name, billing address, issuing bank and identity are all still known to the merchant, the card network and your bank. The right word is compartmentalisation, not anonymity.
Should I use a proxy when buying things online?
Generally no. Fraud systems check consistency between IP geolocation, billing address and card issuing country, and a mismatch is a standard indicator of a stolen card. Using a proxy on a genuine purchase increases the chance of a decline, a flag or a verification request, while adding no privacy because you are supplying your name and address anyway.
Can a proxy hide my payment information?
No. Card details travel from your browser to the merchant and from the merchant to its processor. Your IP address is metadata attached to the session, not part of the payment authorisation path. Changing it alters one input to a fraud model and nothing about the payment itself.
What is the best privacy setup for online shopping?
Merchant-locked virtual cards with spend limits, a dedicated email alias per merchant, a browser that blocks third-party tracking, and periodic data deletion requests to merchants you no longer use. No proxy at checkout. The unglamorous combination is the effective one.
Are virtual cards available outside the US?
Dedicated providers such as Privacy.com are US-only — it requires US citizenship or legal residency, a US bank account and being over 18. Elsewhere, virtual cards are commonly offered by challenger banks and payment apps, though the controls differ and merchant locking is less universally available.
Will a virtual card let me buy something not available in my country?
Usually not, and it is a poor plan. Merchants check the billing address and can see the card's issuing country from the BIN. Both point at where you actually are, regardless of the card number or your IP address. It also generally breaches the merchant's terms.
Do virtual cards work with subscriptions?
Yes, and this is one of their best uses. A merchant-locked card handles recurring charges normally, and closing it makes future charges fail — a cancellation that does not require a retention conversation. Just remember to update the card for services you actually want to keep.
Is it legal to use a proxy with a virtual card?
Using either tool is legal in most places. Using them to deceive a merchant, evade identity verification, circumvent sanctions or bypass a ban is not, and no configuration changes that. The legitimate use is limiting what a merchant learns and how far a breach travels.
Wrapping Up
The two tools solve different problems, and the useful conclusion is that only one of them belongs at checkout.
Virtual cards are genuinely worth adopting. Merchant locking means one retailer's breach stays with that retailer, spend limits catch errors, and closing a card is a cancellation nobody can argue with. None of that requires unusual behaviour or explanation, and it works for essentially everyone in a market where the cards are available.
Proxies belong earlier in the process, if at all. They help while you research, in a session that carries no accounts and no payment details, which is where behavioural profiling actually happens. At checkout they hurt: fraud systems specifically look for disagreement between your apparent location and your billing details, and creating that disagreement on a genuine purchase is a good way to have it declined.
And the least technical measures are the strongest. Strong Customer Authentication already makes a stolen number insufficient across much of Europe, and data protection rights let you remove information that was already collected — which is something no proxy and no card can do.