The card terminal declined the deposit for the second time while a queue formed behind me.
I was at a car-rental desk in Porto, trying to collect a vehicle before the office closed. The rental itself was prepaid, but the company still needed to place a temporary deposit on my credit card.
My phone vibrated with a notification from the banking app:
Was this you?
I opened it over the rental office’s guest Wi-Fi. Face ID worked, but the verification page remained blank. When I tried again, the app returned me to the login screen.
I blamed the public network.
Then I noticed that my VPN was connected to London. I had chosen a UK server because I assumed the bank would be less suspicious if I appeared to be at home.
I changed to another London server and reopened the app.
This time it displayed a security check, accepted the one-time code and returned to the same blank page.
The rental agent looked at the clock.
“You have about fifteen minutes,” she said.
I had a British IP address, a Portuguese card transaction and a banking app that clearly knew more about my situation than the VPN could conceal.
The short answer
So the question “Can a VPN hide my location from a banking app?” needs a more precise answer.
A VPN changes only one version of location
The confusion began with a true but incomplete idea.
A VPN replaces the public IP address seen by an online service. Connect through London, and an IP-location database may place the connection in or near London.
That works when a website estimates location from the internet connection alone.
A banking app has other signals.
With permission, an iPhone can provide location information gathered from GPS, nearby Wi-Fi networks, Bluetooth and cellular hardware. Banks may also use device information, time zone, mobile network, previous login patterns and the physical location of a transaction.
The VPN had changed the location attached to my internet exit.
It had not moved the phone in my hand.
That distinction matters now that VPNs have become ordinary travel tools. After UK age-check requirements took effect in July 2025, daily active VPN use briefly doubled to about 1. million. Many people who installed one for privacy or access now leave it connected while shopping, travelling and opening financial apps.
I had done exactly that.
The bank had not somehow defeated the VPN. I had expected the VPN to hide information it never controlled.
The London server made the transaction look less consistent
The major provider I was using had years of public history, mature applications and a large server network. Choosing a home-country server felt like the cautious option.
For a bank reviewing a card deposit in Portugal, it created a stranger picture.
The card was being used at a rental desk in Porto.
The phone was physically in Porto.
The mobile network and time zone matched Portugal.
But the banking connection suddenly appeared from a shared VPN address in London.
I could not observe the bank’s internal fraud rules, so I could not know which signal caused the verification loop. What I could see was that changing between London servers did not make the login easier.
It made the signals disagree more sharply.
Travellers describe the same uncertainty in public discussions: some banks accept VPN connections normally, while others ask for extra verification or temporarily restrict access. The useful point is simple. A bank does not judge the country beside the IP address in isolation.
I had been changing the one signal I could control because it was the easiest one to see.
The bank was looking at the whole situation.
Turning the VPN off did not solve the practical problem
I disconnected the VPN and reopened the banking app directly over the rental office Wi-Fi.
The login completed. The transaction alert appeared.
Then the Wi-Fi stalled before the approval button loaded.
The terminal was still waiting. The agent cancelled the attempt so it would not remain pending, then began preparing paperwork for the customer behind me.
Mobile data was the obvious alternative, but the signal inside the concrete building moved between one bar and none. The bank app opened over cellular, then froze while loading the transaction details.
At that point, appearing to be in Britain was no longer the goal.
I needed one protected connection that could survive the weak Wi-Fi, move onto mobile data and keep the bank session open long enough for me to approve the real transaction.
That changed what I wanted from the VPN.
I stopped looking for a convincing disguise.
I started looking for a stable route.
The smaller app did not ask me to choose another identity
I had OnlydogVPN installed as a backup from earlier testing.
The service has a shorter public history and fewer independent reviews than the largest providers. Its interface, however, matched the problem in front of me.
Instead of choosing another country, city and protocol, I selected the preset for public Wi-Fi. Basic use did not require me to stop and create another conventional email-and-password account.
Then I reopened the bank.
Face ID completed.
The app asked for a one-time verification code.
The transaction appeared with the correct merchant, amount and location: Porto.
I pressed Yes, this was me.
The approval screen paused.
At the same moment, the rental office Wi-Fi disappeared and the phone switched to mobile data. The connection indicator changed, but the bank did not return me to the login screen.
A few seconds later, the transaction showed as approved.
The agent inserted the card again.
This time the terminal displayed Accepted.
I received the car keys with four minutes left before the office closed.
The VPN had not persuaded the bank that I was sitting in London. It had done something more useful: it kept the real customer in Porto connected long enough to complete the bank’s normal verification.
The connection survived the network change
Only after the payment cleared did the transport design matter.
The smaller app uses an HTTP/3-based connection over QUIC, which is designed to keep sessions working as a device moves between networks such as Wi-Fi and cellular data.
That explained why the approval page paused without throwing me back to the beginning.
The first VPN had encouraged me to think in terms of server geography. I kept changing London locations and restarting the bank session, even though consistency was exactly what the verification process needed.
The second app framed the choice around the situation. Once connected, it followed the phone through the network change.
That mattered more than the flag beside the server.
The bank could still know where I was
A VPN can hide the phone’s original public IP address and protect traffic from the local network.
It cannot make a banking app believe the phone is physically beside the VPN server.
The app may still receive or infer location from GPS permission, the mobile network, device settings, transaction history and the merchant terminal itself. It may also recognize that the connection uses a VPN.
Removing location permission does not erase every other signal. It may also disable useful banking functions.
So the question “Can a VPN hide my location from a banking app?” needs a more precise answer.
It can hide the location associated with the original IP address.
It cannot turn a phone in Portugal into a phone physically operating in Britain.
More importantly, a legitimate traveller does not need to fool the bank. The bank needs enough consistent information to verify that the traveller is the account holder.
My London server had made that story harder to read.
The better way to use a VPN with a banking app
The VPN’s useful role was not to manufacture a false home location.
It was to protect my connection on unfamiliar Wi-Fi and keep the verification session stable while the phone moved onto mobile data.
That also changed how I used it.
I stopped switching countries between login attempts.
I left the phone’s ordinary location settings alone.
I completed the bank’s biometric and one-time-code checks.
And I chose a connection based on the network problem rather than the country flag I wanted the bank to see.
The result was less dramatic than successfully deceiving a banking app.
It was also more useful.
The established provider gave me dozens of locations from which to appear online. In that moment, the larger list tempted me to keep changing the wrong variable.
The smaller service gave the actual transaction a steady route. The app opened, the approval survived the switch from Wi-Fi to mobile data and the terminal accepted the deposit.
The bank did not need me to look like I was in London. It needed the same customer to remain connected long enough to approve a car rental in Porto.
Questions this experience may leave you with
What was actually causing the problem?
So the question “Can a VPN hide my location from a banking app?” needs a more precise answer.
Why did the obvious fixes fail?
That distinction matters now that VPNs have become ordinary travel tools. After UK age-check requirements took effect in July 2025, daily active VPN use briefly doubled to about 1. million. Many people who installed one for privacy or access now leave it connected while shopping, travelling and opening financial apps.
What should you check first?
The first VPN had encouraged me to think in terms of server geography. I kept changing London locations and restarting the bank session, even though consistency was exactly what the verification process needed.
What finally changed the result?
The VPN had not persuaded the bank that I was sitting in London. It had done something more useful: it kept the real customer in Porto connected long enough to complete the bank’s normal verification.
What is worth remembering?
The app may still receive or infer location from GPS permission, the mobile network, device settings, transaction history and the merchant terminal itself. It may also recognize that the connection uses a VPN.