Introduction: the diary you never wrote
Open your banking app. Scroll back through the last three months. Read slowly.
You'll find a pharmacy, on a Tuesday at 7:12 p.m. A law firm, two weeks later. A hotel in a city you don't live in. A subscription to an association with a political, union or religious purpose. A medical testing lab. A dating site. A baby gear shop, three months before you told anyone around you anything at all.
Nobody asked you to write all that down. And yet you recorded it, line after line, timestamped to the minute and implicitly geolocated, in a database you don't control.

We've written a great deal on this site about communications metadata. Payment traces are exactly the same in nature, only worse: they are dated, located, categorized, kept for years and readable by far more people than you'd imagine. Six months of bank statements say more about a person than reading their inbox.
This guide isn't about living off the grid or breaking the law. It's about understanding who sees what, what the law genuinely requires to be retained, and which simple steps — all perfectly legal — can shrink the footprint of your everyday purchases.
Who actually reads your spending
Your bank, obviously — but not just for accounting
A bank doesn't only record amounts. It records the merchant's name, its activity code (the well-known MCC, Merchant Category Code, which distinguishes a pharmacy from a bar), the date, the time, the channel (contactless, online, withdrawal). This data feeds into:
- fraud and money-laundering prevention, a legal obligation framed by the French Monetary and Financial Code and supervised by the ACPR and Tracfin;
- internal scoring: risk assessment when you apply for a loan, an overdraft or insurance;
- automatic categorization tools ("aggregators") built into banking apps, which sort your spending into "health," "leisure," "donations";
- sometimes targeted commercial offers, whose use is governed by the GDPR but whose opt-out is rarely made prominent.
Card networks and intermediaries
Between you and the merchant sit the card issuer, the network (Visa, Mastercard, CB), the merchant's acquirer, often an online payment gateway, and sometimes an anti-fraud provider that additionally receives your IP address, your browser and your device profile. Each one keeps its own share.
The merchant itself
The digital receipt sent by email or text, the loyalty card, the customer account required to place an order: every step reattaches your identity to a purchase history. The CNIL regularly points out that joining a loyalty program must rest on freely given consent, and that a digital receipt cannot be made conditional on providing a phone number that is then used for advertising.
Third parties, when things go wrong
Finally, your history may end up in the hands of a spouse during a separation, a bailiff, a tax authority, an employer in the case of expense claims, or an attacker after a data breach at a service provider. That last case is no longer theoretical: data breaches affecting payment and retail players are reported to the CNIL by the hundreds every year.
What the law actually requires (and what it doesn't)
Many people give up ground because of a misunderstanding: they believe everything is mandatory.
| Common belief | Reality |
|---|---|
| "Paying in cash is suspicious" | Cash is legal tender in France. A merchant may refuse a euro cash payment only in specific cases (damaged notes, no change available, legal ceiling, posted security reasons). |
| "The cash limit is €1,000 everywhere" | That ceiling applies to payments made to a professional by an individual who is a French tax resident (article D112-3 of the Monetary and Financial Code). It rises to €15,000 for non-residents. Between private individuals there is no payment ceiling, but a written record is required above €1,500. |
| "A loyalty card is needed for the warranty" | No. The legal guarantee of conformity applies on proof of purchase: receipt, statement, invoice. |
| "Paper receipts are gone" | Since systematic printing ended, the merchant must provide one if you ask for it. You are not obliged to give an email address or a phone number. |
| "My bank can require me to justify every withdrawal" | It has proportionate due-diligence obligations, not a general right of inquisition. Requests must remain justified. |
In other words: the legal room for manoeuvre is far wider than commercial practice suggests.
Map your purchases before changing anything
Before adopting tools, take stock. This is the step everyone skips, and the only one that delivers results.
The three categories of spending
- Neutral spending. Ordinary groceries, fuel, mainstream subscriptions. Exposing them changes little. Paying normally is rational.
- Revealing spending. Health, lawyer, psychologist, associations, worship, sexuality, addiction, gifts, job hunting, moving house. These are the ones that, on a statement, tell a story you never chose to tell.
- Spending with relational risk. The ones a relative with access to your joint account, your app or your inbox could read: a birthday present, a consultation, a train ticket.
The classic mistake is to chase total anonymity. The right approach is to treat category 2 and category 3 differently, and leave the rest alone. A neutral trace buried in a normal flow says nothing; it's the contrast that speaks.
A useful exercise: the hostile reader test
Export three months of statements and read them the way someone who wishes you harm would. What you spot in ten minutes, an algorithm spots in ten milliseconds. Many readers discover on this occasion that, without thinking about it, they have documented a breakup, an illness or a career plan.
Cash: the most underrated privacy tool
Cash remains the only payment method that is offline, non-nominative and free of intermediaries. It creates no line in a database, doesn't leak, and can't be resold.
Its limits are real: the withdrawal itself does leave a trace (date, amount, ATM). But that trace only says "€80 withdrawal," not "pharmacy, 7:12 p.m., category X products." The informational gain is considerable.
A few simple practices:
- Withdraw round, regular amounts rather than piecemeal: less correlation between a withdrawal and a specific purchase.
- Avoid withdrawing immediately adjacent to a sensitive purchase, in time as well as in space.
- Keep a modest cash reserve at home, stored somewhere safe — a small combination safe bolted into a piece of furniture is more than enough for a few hundred euros and some documents.
- Don't mix the "discreet spending" envelope with your everyday wallet.

Let's state the obvious once more: paying in cash is neither an offence nor a red flag. It's a right. The European debates on the digital euro, widely commented on by the CNIL and the European Data Protection Supervisor, are in fact precisely about the need to preserve an offline payment function comparable to cash.
Prepaid cards, gift cards and virtual cards
Prepaid cards
Sold in tobacconists or online, they are subject to anti-money-laundering rules: above certain top-up thresholds, or for online payment, identifying the holder is mandatory. So they are not anonymous in the absolute sense, but they offer a valuable property: they compartmentalize. Purchases made with them don't appear on your main statement and don't feed your banking profile.
Points to watch:
- read the fees (activation, inactivity, withdrawal), often steep;
- check the validity period;
- don't load large sums onto them: these cards are poorly protected in case of loss.
Retailer gift cards
Useful for a one-off purchase at a specific store, bought with cash. It's the simplest way to give a gift without the recipient — who may share your account — seeing the line show up.
Single-use virtual cards
Offered by many banks and neobanks under names like e-carte bleue or virtual card, they generate a disposable number. They don't make you anonymous to your bank, but they sharply limit:
- fraudulent reuse of the number after a breach at a merchant;
- ghost subscriptions that are hard to cancel;
- cross-merchant correlation where the card number is used as a profile identifier.
For most readers, this is the best effort-to-benefit ratio for online shopping.
The blind spot: delivery, email and phone number
You can pay with the most discreet card there is and lose it all at the next step. An online order involves at least four identifiers: payment method, email address, phone number, delivery address. Three of them are under your control.
The email address
Use an alias dedicated to purchases, separate from your main address and from the one used to reset your sensitive accounts. Most serious providers offer unlimited aliases; some even allow one alias per merchant, which instantly identifies the source of a leak when the spam arrives.
The phone number
It's the most persistent identifier there is: it follows you from one service to the next, serves as a matching key between databases, and feeds cold-calling campaigns. Reserving a secondary number for orders, deliveries and commercial sign-ups keeps you from exposing the line you've used for fifteen years. For one-off exchanges with a private seller or a delivery driver, a service that sends texts without disclosing your personal number serves the same purpose: passing on the useful information without handing over the identifier.
Also consider registering your line with Bloctel, the official opt-out service for telephone cold calling.
The delivery address
The pickup point is the most effective everyday compromise: it decouples your home from your purchase history. For bulky items, an automated parcel locker or in-store collection does the same job.

Loyalty programs: the trade nobody does the maths on
A loyalty card is an implicit contract: you hand over your complete purchase history — hence your family make-up, your eating habits, any medical conditions, your daily rhythm — in exchange for a 2 to 5% discount.
Three reasonable positions:
- Refuse at revealing retailers (pharmacy-adjacent stores, specialist products).
- Accept but compartmentalize: dedicated contact details, an alias email address, a secondary number, and systematic refusal of the "partners" checkboxes.
- Exercise your rights: the GDPR gives you a right of access (article 15) and a right to erasure (article 17). Asking a retailer for a copy of your history is enlightening — and free. The CNIL publishes ready-to-use letter templates.
A 3% discount on €4,000 of annual spending is worth €120. The question isn't whether that's a lot, but whether you'd have sold your medical and family history for that amount to a stranger who offered it to you in the street.
Securing the physical card
Payment privacy also plays out away from the digital realm.
- Contactless works at a range of a few centimetres, but opportunistic reads do happen: an RFID-blocking sleeve for bank cards costs a few euros and settles the matter.
- Paper receipts and statements often carry the last four digits of the card, the time and the place. A cross-cut shredder is the single most cost-effective hygiene measure in a household.
- The ATM: shielding your PIN entry remains effective against cameras as well as prying eyes.
- Storing supporting documents: keep them out of a visitor's reach, in a closed folder rather than on the hallway table.
A realistic protocol, in five steps
To close, here's what you can apply from tomorrow, without changing your life.
- Separate the flows. One account or card for visible everyday life, a distinct payment method for the "revealing" category. Compartmentalizing beats going underground.
- Rehabilitate cash for health-related purchases, gifts, associations, and anything touching your private life.
- Make virtual cards the norm online, with one number per recurring merchant where possible.
- Compartmentalize order identifiers: email alias, secondary number, pickup point. The three together are worth far more than any one alone.
- Exercise your rights once a year. An access request to your bank and to two retailers is enough to gauge the real scale of the collection — and to trigger the erasures that matter.
To go further, the CNIL provides practical fact sheets on banking data and loyalty programs, the Banque de France documents the framework for cash payments, and the DGCCRF publishes the state of the law on receipts and accepted payment methods. An accessible book on personal data protection usefully complements these sources for anyone who wants to grasp the overall logic rather than memorize recipes.
Conclusion: buying without telling your story
Total anonymity in payments doesn't exist, and chasing it at all costs is a dead end — expensive, exhausting, sometimes counterproductive. What does exist, on the other hand, is control over the narrative.
Your bank statement tells a story. You can't delete it, but you can decide which chapters appear in it. Removing from that account the episodes that concern your health, your beliefs, your relationships and your plans simply means refusing to let a database know more about you than the people close to you do.
That isn't concealment. It's proportion.



