What a disappointment. They should just use their own provider or make one for their ecom and shipping rather than relying on irresponsible third parties.
However, this doesn't offer a 100% guarantee of secure data storage. That said, I agree that a proprietary solution from trezor would benefit their clients: in the event of a leak, trezor would not be able to shift the blame to others, the full responsibility would rest with them, thereby compelling them to take a very serious approach to implementing their own e-commerce solution.
And instead of a 90-day data retention policy, they should make it lower.
Trezor has floated the concept of anonymous delivery. We are awaiting the full announcement (it will be interesting to see how this is actually implemented). However, I have doubts that this "feature" will be supported in all countries where delivery is available.
It seems to me that shortening the data retention period from 90 days to, say, 45 or 30 days would be entirely feasible (without compromising the service provided), as most typical disputes (such as refund requests) can be resolved within that timeframe. With a 90-day window, buyers have no choice but to hope that their personal data won't be leaked before it gets wiped.
Anyway, another set of phishing emails, smishing is on the way. smh
It would be good if it were limited to just that, rather than a "visit from guests with a $5 wrench".