A hardware wallet can be flawless and the purchase record still creates a targeting list. Retention policy is the control that bounds it. Five of eight manufacturers state a number. Three do not. Among those that do, the range runs from 30 days to ten years.
The Purchase Record: Customer Data Retention as a Custody Risk Input
The Linkmerica Research Team August 17, 2026
Executive Summary
A hardware wallet can be flawless and the purchase record still creates a targeting list. Name, address, phone number and purchase detail identifies a person who holds cryptocurrency and where they live. That is the input for phishing at scale and, in documented cases, physical coercion. Retention policy is the control that bounds the exposure window—determining whether a breach surfaces three months of orders or ten years. It is rarely stated as a number.
Three manufacturers experienced material customer data incidents between 2020 and August 2026. One entered its breach with a 90-day deletion policy contractually extended to fulfilment partners; the exposure window matched. Another entered with more than thirteen months of retained order history; the affected population was roughly three times larger. A third experienced the most severe documented downstream consequences—phishing, ransom demands, and threats of physical violence—from a breach of approximately 272,000 detailed records, with data retained for ten years under accounting obligations after three-month segregation.
Five of eight manufacturers assessed disclose a numeric retention period. Three do not. The range runs from 30 days to ten years.
What the Purchase Record Contains
The purchase record identifies someone who owns cryptocurrency hardware and documents where they live. At minimum: full name, shipping address, phone number, email address, and the fact of purchase. In some implementations: device serial numbers, order value, and payment method detail.
This information is not custody in the technical sense—it does not grant access to private keys or seed phrases. It is custody risk in the targeting sense. It constructs a list of individuals known to hold digital assets, sorted by home address. The use cases for that list, at scale, are adversarial: phishing campaigns that leverage the credibility of knowing what the recipient bought, extortion via ransom demand, SIM-swap attacks that begin with a phone number tied to a confirmed hardware wallet owner, and physical coercion at a documented address.
The risk is not theoretical. It has been realised.
Case 1: Ledger, 2020
In 2020, Ledger's e-commerce database was breached. Approximately 272,000 detailed records were exposed, including names, postal addresses, and phone numbers. Downstream consequences included phishing campaigns, ransom demands, and threats of physical violence against named individuals at their home addresses. This remains the best-documented evidence that customer data breach translates directly into targeted harm.
Ledger's response, published on the company's own blog, described the control environment. E-commerce order data moves to a segregated environment three months after shipping, with strictly limited access. It is then retained in that segregated database for ten years under accounting obligations, after which it is removed. The distinction is material: segregation is not deletion. The data exists, access-restricted, for a decade.
Orders placed on ledger.com are processed through Global-e, which acts as an independent data controller. Global-e was itself breached in January 2026, exposing Ledger customer names and contact data. That was a separate incident from the 2020 breach of Ledger's own database, and the second occasion on which Ledger customer data was exposed through a commerce system.
Case 2: Trezor, August 2026
On August 10, 2026, Trezor was notified that its fulfilment provider, ShipMonk, had been breached via a Metabase SQL injection zero-day. Trezor disclosed the incident publicly three days later, on August 13. The breach affected 13,689 customers: 11,742 with full records including name, email, phone number and shipping address; 1,947 with partial data. The exposure window covered orders placed between May 10, 2026, and August 8, 2026.
Trezor's own systems, devices, and firmware were not compromised.
The control worked. Trezor's 90-day data retention policy, contractually extended to fulfilment partners, meant that older records had already been deleted and were not available to the attacker. The exposure was bounded to roughly three months of orders rather than the full order history. This is a finding in Trezor's favour. A rated manufacturer experienced a partner breach via an external zero-day exploit, and its disclosed retention control measurably limited the population at risk.
ShipMonk holds SOC 2 Type II certification and was breached regardless.
Case 3: SafePal, August 2026
On August 16, 2026, SafePal disclosed that an authorization flaw in an order-tracking plug-in had allowed one customer to access another customer's order record. The incident affected 39,798 customers. The exposure window covered orders placed between March 2, 2025, and April 11, 2026—a period of more than thirteen months.
Exposed data included name, email address, shipping address, phone number, and purchase details. Not exposed: seed phrases, private keys, wallet passwords, bank information, payment cards, or government identification.
SafePal's remediation statement, verbatim: "Tightened the retention period for personal information in the relevant order-processing environment to 90 days, subject to applicable legal requirements." The company also engaged an independent third-party security firm, notified all affected customers individually, took down over 30 fraudulent websites and phishing links, and contacted third-party logistics partners to confirm the issue had not spread. SafePal stated in its disclosure that affected order information may be used for targeted phishing and impersonation.
The Variable That Separated Them
Both the Trezor and SafePal incidents belong to the same failure class: a third-party component in the order pipeline was compromised. The affected populations differed by roughly a factor of three. The apparent difference in exposure scope is the presence or absence of a disclosed retention control at the time of the incident.
Trezor entered its breach with a 90-day deletion policy already in place and contractually extended to partners. SafePal entered with more than thirteen months of retained order history and adopted a 90-day retention period as part of remediation, landing on the same figure Trezor had implemented in advance.
The claim requires precision. These were different failure mechanisms: an external zero-day exploitation of a fulfilment partner versus an authorization flaw in a plug-in. The affected populations are not directly comparable, and multiple variables influenced breach scope. The claim is not that retention policy alone caused the difference in scale. The claim is that retention policy is the control that bounds how much history is available when a breach occurs, and that one manufacturer had that control in place and one adopted it afterward.
What Eight Manufacturers Disclose
Linkmerica reviewed published customer data retention policies for all eight LISR-scored manufacturers and the pipeline manufacturers tracked for potential inclusion. Policies were checked between August 14 and August 17, 2026.
BitBox02 (Shift Crypto): Order data is anonymised after 30 days internally. Third-party fulfilment platform order data is anonymised after 180 days. The company also states that Bitcoin payments are processed through a self-hosted BTCPay server storing only anonymised invoice metadata, that the company avoids referencing cryptocurrency terms in submitted data to reduce inference risk, and that servers either do not log IP addresses or anonymise them before writing. This was the most detailed disclosure found.
Trezor: 90-day deletion policy, contractually extended to fulfilment partners.
Ledger: Order data is segregated three months after shipping and retained for ten years under accounting obligations. Contact and support data is retained for three years from last contact. Marketing data is retained for 25 months.
Coinkite (Coldcard): 120-day standard practice. This policy was suspended on August 6, 2026, to preserve records for expected litigation following a firmware entropy defect. A device security failure produced a legal obligation that reversed a privacy control.
SafePal: 90-day retention in the order-processing environment, adopted August 16, 2026, as part of incident remediation.
Tangem: A retention policy exists but states no numeric period. The policy states that data is kept "only for the period necessary" and explicitly notes that data related to orders may be kept longer due to tax and commercial law.
ELLIPAL: A retention policy exists. No period was found in the text reviewed.
Foundation: The policy effective May 21, 2026, states no numeric period, only that retention "varies depending on the nature of the information" and that records in Shopify, payment, fulfilment, logistics, tax, accounting, and customer-support systems may be retained for different periods. An earlier version of the policy, no longer live, stated that name, address, phone number, and email were purged automatically 60 days after shipping, that the order number was retained but disassociated from identity, and recommended purchasing pseudonymously via a remailer service, work address, or PO Box. A company moving its commerce onto Shopify cannot promise a 60-day purge across systems it does not control. The finding is that a specific disclosed control became a general commitment. The reason for the change is not documented and is not imputed here.
Five of eight manufacturers state a numeric retention period. Three do not. Among those that do, the range runs from 30 days to ten years.
What Assessable Disclosure Would Look Like
For retention policy to be assessable rather than asserted, four elements are required.
First, a stated number—not "as long as necessary" or "for the period required," but a defined maximum expressed in days, months, or years.
Second, a stated scope. Retention in the order-processing environment is a different claim than retention company-wide. Data segregated after three months but retained for ten years is a different posture than data deleted after 90 days.
Third, whether the policy binds fulfilment and logistics partners contractually. A manufacturer's own deletion schedule is distinct from the retention practices of the third parties that touch the data.
Fourth, the endpoint action: deletion, anonymisation, or segregation. These are three different things with different risk profiles. Deletion removes the record. Anonymisation removes the identifiers but retains the structure. Segregation moves the data to a restricted environment but leaves it intact.
Only when all four are disclosed can the control be assessed as stated.
Limits of This Analysis
This brief assesses disclosed policy, not verified practice. Linkmerica has no visibility into whether any manufacturer executes the policy it publishes. A stated 30-day deletion that is not performed is worse than a stated ten-year retention that is honoured. What is assessable is what is disclosed, and that is the limit of this analysis. This is consistent with the standing methodology statement that LISR assesses documented and disclosed controls and cannot detect undisclosed implementation defects.
LISR v1.0's six categories do not include customer data retention as a scored input. The supply_chain_risk category assesses manufacturing concentration, tamper-evidence, and distribution controls—not the retention of order records. Three of the seven LISR-scored wallets have now experienced a material incident in this area that the framework cannot score. Linkmerica is treating that as a framework question under review, not as a silent omission. Whether and how customer data retention policy integrates into future LISR versions is an open question.
The case comparison in this brief is limited by differences in failure mechanism, affected population, and remediation timing. The claim is not causal. The claim is that retention policy is the disclosed control that bounds exposure scope when a breach occurs, that one manufacturer had it in place and one did not, and that both landed on a 90-day standard—one before the incident and one after.
Linkmerica is a trade name of CASPO LLC. LISR scores and research are for informational purposes only and do not constitute financial or investment advice. This brief is based on publicly available information as of August 17, 2026, drawn from each manufacturer's own published policies and disclosures.
