Trezor asked for written confirmation the data was deleted. It got it. The data was still there.
Trezor makes hardware wallets, the little devices people buy so their savings aren't sitting in a browser. On 13 August it told customers that its fulfilment partner ShipMonk had been broken into three days earlier, and that about 13,689 people who ordered between May and August were affected. Unpleasant, contained, over.
On 2 September ShipMonk came back with more. Order records from an earlier partnership, running from November 2019 to August 2021, were also in the stolen set: another 67,000 US customers, with names, email addresses, phone numbers, shipping addresses and order numbers. Trezor's own retention policy is 90 days. Its statement is worth reading twice: "Throughout our entire relationship with ShipMonk, we repeatedly requested and received written assurance confirming the deletion of the data." It wasn't deleted. Roughly 81,000 people are now in the total, and the wallets themselves are not affected in any way.
Here is why the address field is the ugly one. A list of home addresses belonging to people known to have bought a crypto wallet is useful to two very different sorts of criminal, and only one of them works online. Expect phishing that quotes your real order number, because the sender genuinely has it. Trezor's advice reduces to a single rule that never expires: your wallet backup phrase does not get typed into anything, ever, no matter who is asking or how correct their details are. That principle generalises well beyond crypto. Knowing your order number proves nothing anymore.
If you're taking stock of which companies hold your details, Tendvane's Privacy and accounts check is a reasonable place to see what's signed in on your PC and what's connected to it.