My Phone Said Yes, the Register Said No

My Phone Said Yes, the Register Said No

Personal apple-pay currentc cvs mcx mobile-payments

My Phone Said Yes, the Register Said No

So I tried to pay for a bag of pretzels and a bottle of NyQuil at the CVS on the corner with my phone last night, and the terminal just sat there. No beep, no little checkmark, nothing. Not because my phone did anything wrong. Because CVS switched the reader off on purpose.

Apple Pay's only been out a couple weeks now (it launched October 20th) and for the most part it's been working exactly like Apple said it would: hold the phone near the reader, feel the little buzz, done. I used it at the Whole Foods on 5th without a hitch the other day and felt very smug about it, honestly, like I was living in the future a few months early. Then CVS and Rite Aid both quietly killed tap-to-pay at the register, and it turns out a bunch of other big retailers are about to do the same thing, all at once, all for the same reason.

The reason is a thing called CurrentC. It's a mobile payment app being built by a retailer group called MCX — Walmart, Target, Best Buy, Kohl's, a bunch of others — and instead of tapping your phone, you open the app and scan a QR code off the register, and it pulls money straight out of your checking account. No card networks in the middle, which means no interchange fees for the retailer. I get why they want that. Visa and Mastercard take a cut of every swipe and it adds up when you're Walmart. But I don't love what it costs me as the person standing there with pretzels in one hand. Scanning a QR code is slower than tapping a phone, and skipping the card networks means skipping the fraud protections that come bundled with them. If somebody drains your checking account through CurrentC, that's a very different phone call to make than disputing a charge on your Visa.

And here's the part that actually got under my skin. CurrentC isn't even out yet (it's still in a limited pilot with a waitlist) and a few days ago the emails of people who'd signed up for that pilot got grabbed by somebody outside the company. Not credit card numbers, thankfully, just email addresses, but still. This is an app whose entire pitch is "trust us with your bank account," and before it's even public it's already had a breach. That's not a great first impression! I don't think that's a minor thing to shrug off either, when the whole reason retailers say they need this system is to be more secure than what we've already got.

Anyway, back to CVS. The cashier was a younger guy, seemed almost embarrassed about it, said "yeah we can't take that right now" in the tone of someone who's had to explain this forty times that shift already. I ended up digging my actual physical debit card out of my wallet like some kind of caveman, which, fine, it's not a hardship, I've been doing it my whole life. But there was something almost funny about standing in a CVS with a phone that can do this genuinely clever trick, being told no by a company that would very much like me to download a different app instead, one that isn't finished, and that already leaked some people's emails before I even had the chance to sign up for it.

Small tangent, but this whole thing reminds me of the ExtraCare keychain fob wars of a few years back, when I refused on principle to carry one more piece of plastic on my keyring just so CVS could track what shampoo I buy. I held out for probably two years out of pure stubbornness before I caved and just used the app instead, muttering the whole time. I have a feeling this is going to go the same way eventually, some kind of surrender after enough friction, except this time the stakes are my checking account and not my loyalty points.

For now I'm just going to walk the extra block to the Walgreens, which as far as I can tell hasn't shut anything off yet. It's a longer walk for pretzels. Worth it, for the moment, not to feel like a guinea pig in someone else's payments experiment.