Policy
Privacy
A hardware-wallet reseller that harvests customer data is a target waiting to happen. We collect the minimum required to ship your order and support you, and we store it for the minimum time required.
What we collect
- Order details – email, name, delivery address, phone (optional, for courier), items, order id.
- Payment reference – a transaction id from our PCI-DSS acquirer. We never see or store card number, CVV, or 3-D Secure data.
- Server logs – IP address, user agent, referrer, timestamps. Retained 30 days for fraud and abuse defence, then purged.
What we don't collect
- No customer accounts. You can check out without signing up for anything.
- No advertising cookies. No Facebook Pixel, no Google Analytics on your card-entry flow.
- No wallet balances, no seed phrases, no keys. Anyone who asks for your seed phrase is trying to steal from you — that includes us. We will never ask.
Who we share with
- The courier (name, address, phone, tracking id).
- Our PCI-DSS acquirer (email, name, order amount, order id).
- Nobody else. We do not sell, rent, or license your data to marketers.
Retention
We keep order records for as long as legally required to comply with tax and consumer-protection law (typically 6–10 years, depending on jurisdiction). After that they are deleted. Server logs are purged after 30 days.
Your rights (GDPR / UK-GDPR)
You can request a copy of your data, correction of inaccurate data, or deletion (subject to legal retention obligations) by emailing care@coldkeys.shop from the address on your order. We reply within 30 days.
Contact
care@coldkeys.shop · Coldkeys, correspondence handled digitally.