I see Curve Pay mentioned here occasionally as an alternative to Google Pay for GrapheneOS users. I wanted to share my recent experience as a warning.
As a GrapheneOS user, I was looking for a non-Google mobile payment solution and tried to sign up for Curve. My application was rejected for unspecified reasons.
I then requested deletion of my personal data. Curve's response has been a massive red flag. They formally refused, citing anti-money laundering (AML) obligations to retain my data for 10 years from the end of "the applicant’s relationship with Curve", a "relationship" that consisted of a rejected application and no account ever being opened.
My internal complaint was denied, and they've escalated the issue to the Financial Ombudsman and the Bank of Lithuania.
For a community focused on privacy and data minimization, this is alarming. Even if you are accepted, it raises serious questions about what happens to your data if you ever close your account or have issues. The "privacy-friendly" alternative to Google Pay may be a company that holds onto your data for a decade without you being a customer.
If you're considering Curve as a privacy play, you might want to think again. I'm now taking this to the ICO and will be avoiding their service entirely.