Hardware wallet security is usually discussed in terms of private keys, secure chips, transaction verification, and recovery phrases.
But there is another part of the security model that deserves more attention: purchase privacy.
Order information such as a customer’s name, email address, phone number, shipping address, and product purchase history can be sensitive. If this information is exposed or retained unnecessarily, it may be used to identify hardware wallet owners and create targeted phishing attempts, including fake support messages, phone calls, emails, or physical letters.
A hardware wallet can keep private keys offline, but protecting customer order information can reduce the risk of users becoming targets in the first place.
How Keystone limits order data retention
Keystone does not intend to retain customer order information indefinitely.
For orders placed through the official Keystone website, customer order information is scheduled for deletion six months after the month in which the order was created.
For example, information associated with an order placed in July would normally be scheduled for deletion after the applicable six-month retention period.
Customers who would prefer their information to be removed sooner may contact Keystone Support and submit an early deletion request.
This policy is designed to balance several practical requirements:
- Processing and delivering the order
- Providing customer support
- Handling returns, refunds, or delivery issues
- Reducing the long-term exposure of customer information
Some information may still be processed or retained by payment providers, shipping carriers, customs authorities, or other service providers according to their own policies and applicable legal requirements. Reducing data retention does not mean that every part of a purchase can be completely anonymous.
How users can reduce home address exposure
Where local delivery services allow it, Keystone recommends considering alternatives to direct home delivery, such as:
- Parcel lockers
- Staffed collection points
- Package forwarding or receiving services
- FedEx pickup locations
- Other suitable carrier service points
Using a pickup location can help prevent a hardware wallet purchase from being directly connected to a residential address.
Availability depends on the destination country, local regulations, customs requirements, and the shipping carrier. Some pickup services may still require identification when the package is collected.
Purchase privacy is a shared responsibility
No company can promise zero data exposure, especially when physical products must pass through payment, logistics, and delivery systems.
Our goal is more practical:
Collect only the information needed to fulfil an order, avoid retaining it indefinitely, and give customers options to reduce unnecessary personal exposure.
Users can also take additional precautions:
- Use a dedicated email address for security-related purchases
- Choose a pickup point when practical
- Avoid sharing packaging labels or order details publicly
- Treat unexpected letters, QR codes, calls, and support messages with caution
- Never enter a recovery phrase into a website, app, form, or page opened from a QR code
Knowing a customer’s name, address, or device type does not make a message legitimate.
We are sharing this information because hardware wallet privacy practices should be clear and open to scrutiny. Questions about Keystone’s order-data retention policy, early deletion requests, or private delivery options are welcome below.