A lot of companies are going to cause you grief if you try to checkout via
any kind of system which purports to offer anonymity. PayPal for instance
will likely kill your account. Merely having your IP come from a different
location than the billing address may get you flagged- so VPN's aren't
necessarily going to work either.
The real question is who/what are you trying to protect against. If it is a
specific ISP or country you might be able to thwart spying at that level by
using a VPN. However if the VPN is located in or the company has people
located in the same country as you all bets are off. The same can be true for
countries which are cooperative with your country. VPN providers will succumb
to at least government pressures if pressed to reveal your 'identity' (real
public IP address anyway) where there is some connection. The United States
is a difficult country to thwart for example As it is tangled in many many
other nations affairs.
If your trying to buy something your government doesn't permit you to then
VPN + Tor is probably the answer. Tor was designed for anonymity. However if
you reveal who you are or leak little clues via what you say all bets are
off. For example if your the only Tor user around they'll be able to identify
you more easily after you've let out some detail of location. Just look at
how the FBI agents tracked a Harvard bomb threat suspect down despite the
user posting via Tor. They didn't need absolute proof to suspect the person
they identified as a probable suspect. The FBI simply sought the records that
Harvard kept of all users activities on its network. I'm taking an educated
guess here, but Harvard probably kept a log of IP addresses that users
connected to and timestamps of these connections. The FBI then merely
searched for IP addresses of Tor nodes and identified the user who had been
on Tor at the university (as it was a threat toward the university there was
a good chance it was made by someone attending the university). After which
they could get a search warrant and/or question the one or two suspects tied
to that IP address. The solution to this problem would have been to use VPN +
Tor or a Tor bridge. The government will have a much harder time connecting a
user as they'll first have to identify all VPN users at the university and
then seek the IP logs from the VPN provider to identify weather or not the
VPN user connected to Tor. Now if the user had used VPN + Tor + a Tor bridge
there would be a significantly more difficult time as the information held by
the VPN provider would not be a public Tor node. The same would be true if
the user had merely used a Tor bridge. However the student might have been
identified still as a Tor user merely by the fact he had connected to the Tor
project's web site to download Tor. If it wasn't done immediately (that is
the threat around the time of the Tor download) then there would probably be
a lot more students that the FBI would have had to interview in order to
narrow down a suspect. It would probably also have been more difficult had he
downloaded Tor via another means like through Debian's repository. There
would then be no tie to him having downloaded Tor (probably- this assumes
they only logged the IP addresses- and were not retaining other info linke
URLs).