Is that meant to be a real reply? I'll answer it like it is, giving you the benefit of the doubt - your thumbprint is only used to unlock the data store on the device, where the credit card token is kept. Note token, not actual credit card number or CVV code. The data stolen from Target and Home Depot was the real number, where ApplePay will use a one-time token, so even if it's stolen, it's useless once the transaction is complete. But that wasn't a real reply, was it?