Genies Pay / In the hand / Cards

Three shapes, one account.

A virtual card that exists in the same minute the account opens. A digital card tokenised into the phone's own wallet. A physical card in the post. All three draw on the same balances and obey the same controls.

VIRTUAL

Issued in the app, now

A number, an expiry and a CVV, usable online immediately. The details sit behind a biometric check, and single-use cards can be created for one merchant and one amount.

DIGITAL

Tapped from the phone

Provisioned into the phone's own wallet as a token. Any contactless terminal takes it — the merchant sees a token, never the real number.

PHYSICAL

Ordered from the same screen

Personalised and delivered, then activated in the app. It is a third form of the same card record, not a separate account.

Currency cards

Which balance pays, and who decides.

A customer holding four balances should not have to think about which one a card touches. Two behaviours, chosen per card.

PINNED

One card, one balance

The card is tied to a single currency. A payment in any other currency converts at the quoted rate, and the conversion is shown on the transaction.

MATCHING

One card, whichever balance fits

At authorisation the card picks the balance that matches the transaction currency, and falls back to the primary balance if there is none. No conversion where none is needed.

What each shape can do
VirtualDigitalPhysical
AvailableImmediatelyImmediately, once provisionedOn delivery and activation
Online paymentYesYes, where the platform supports itYes
Contactless at a terminalNoYesYes
ATM withdrawalNoWhere the platform supports itYes
Number visible to the merchantReal numberToken onlyReal number
Replace if compromisedInstantly, in the appRe-provision, in the appReissue and post
Drawn on a crypto balanceYesYesYes
Controls

Change a switch, and the next authorisation obeys it.

Every control here takes effect on the next authorisation — not overnight, not at the end of a batch. Turn the switches and run a test payment.

Per-transaction cap AED 500

Run a test authorisation

Turn switches on the left, then run one.

The response codes shown are the real ISO 8583 field 39 values the switch would return. The amounts and the card are invented.

Keeping the number out of harm's way

Four places a card number could leak, and what stops it.

Exposure and control
WhereThe riskWhat is in place
On the phone screenShoulder-surfing, screenshotsDetails revealed only behind a biometric check, masked by default, and a rotating CVV on virtual cards
At the terminalThe merchant's systems hold a real numberThe digital card presents a token; the real number never reaches the terminal
On a websiteStored card details in a breachSingle-use virtual cards scoped to one merchant, and 3-D Secure approved in the app rather than by SMS
Inside your own appYour code touching a PAN brings it into scopeThe SDK returns a result, never a number — the same boundary the Payment SDK draws at the counter
The other side of the card

Who issues it, and where that is explained.

HERE

The card in the customer's hand

Issuing it into the app, provisioning it to the phone, the controls, the limits and the way it behaves at a terminal. That is this page.

CARD PRIME D 3.0

The card lifecycle behind it

Product and BIN setup, personalisation, the embossing bureau, HSM key management, PIN services and the issuing switch live in the issuing platform — cardprime.us.

Also in the hand

The rest of the app.

IN THE HAND

Wallet

Balances, five ways in, conversion with the clock, the ledger.

IN THE HAND

Crypto

Accept, hold, spend and settle — with the caveats in place.

And the other half of the site is the counter this money arrives at — Smart POS, QR, the SDKs and attestation.