• Ask the Community
  • Bunq.me shares IBAN before paying

@Aram-Pink-Zebra#58985 And what can you do with that IBAN? Send him money? I guess he would be OK with that ;-)

    @jho#58986 You can enter an amount and click the iDEAL button. Then the IBAN is revealed

      @Roeshimi#58987 Ha, I know. I guess the risk is not as apparent as with the phone number IBAN combination. It seems like a privacy issue?

        @Roeshimi#58988 ah... i see ;)

        Someone could pay with this iban, but since we can decline a direct debit it's not really a problem, i think.
        You would need the Passphrase/Logincode to login to the app or together as well.

          @Aram-Pink-Zebra#58990 I think so too, that it's a bit of a privacy problem. It should be possible to perform iDEAL payments just like SOFORT payments, i.e. without showing an IBAN before being logged in.

            @Aram-Pink-Zebra#58980 Hi Aram,

            That is a good question. The fact is that bunq does share you IBAN if you are using IDEAL and also if you are using SOFORT.

            But fortunately, you can create 25 accounts at bunq. So if you want to lower the risk tremendously, make sure your bunq.me is always connected to an account that for that is used for that purpose alone. So in that regard, the risk of becoming a fraud victim by using bunq.me is farrrr less than with Tikkie.

              @jho#58986 Also Sofort shows the IBAN number of the connected bunq account :)

                @JohnDo#58999 i could not see my personal iban anywhere @ sofort.

                The only way i could see my personal iban was at the sending bank in the description.

                  @jho#59002 Maybe we are taking about the same thing

                    @Aram-Pink-Zebra#58980 Bunq has said (I think even Ali) that this is on purpose to prevent fraud. He did't exaclty say how this should work though.

                    I guess it's for that when someone creates a bunq.me link like bunq.me/PimFortuin people can check where the money goes.

                    I think it's a privacy leak, and don't really see how showing the IBAN helps. If people know the IBAN (or look it up) to see it's not actually the account of PimFortuin they could just enter the IBAN in their own banking app, right?

                    However, in the Terms & Conditions of bunq.me it clearly states that you give them permission to share your name and IBAN. Note that someone has to know your bunq.me-link for this to work anyway

                    If you don't want anyone to know your IBAN you can remove your bunq.me page and then it won't work anymore.

                      Agree, this is a privacy hole that ought to be plugged. Didn’t know about it either (then again, I never use it), not happy about it. Fortunately I had linked it to a separate IBAN, but all the same...

                      Besides, if the argument is fraud prevention: isn’t that easily negated by creating a disposable IBAN? :P Show after payment is something that can be OK, but without even making a payment? That makes it an easy target for scrapers as well.

                      Whilst we’re on the subject anyway, also be advised that people can find your IBAN if you have your phone number or email set as Alias. (Settings of the bankaccount -> Aliasses) If you value your privacy, disable that (check each account) as well.

                        @JohnDo#59003 in german(y) it looks like that :-) this iban is not from me

                          Maybe it is bank specific what you see

                            @jho#59031 You don't see this icon in the first screen, above the country field?

                              @Bastiaan#59069 Never noticed it 🤣

                                @Bastiaan#59069 Just tried it and the last digits of the IBAN are hidden behind black dots

                                  Using sofort, it doesn't show indeed. But when choosing iDeal, it shows before the payment starts. the 'fraud prevention' argument is a bit strange if it doesn't show before using with sofort.

                                  But apart from all, I think nos/nu.nl are making this issue too big. What does it matter if someone knows my iban? I couldn't think of anything that someone could do with it, without different info.

                                    @Petervdv#59103 ( ͡° ͜ʖ ͡°)( ͡° ͜ʖ ͡°)( ͡° ͜ʖ ͡°)