When a vendor has your ID documents or your home address

Updated Corrections

September 18, 20267 min read

Financial firms must verify who you are, and anyone shipping you a package needs an address. The risk isn't that they hold it, it's that the copy outlives the order and reaches vendors you never chose. Identity documents usually can't be deleted, so the work is hardening the accounts around them.

Sources

Why a fintech has your passport selfie

Anti-money-laundering rules require it. In the US, 31 CFR 1020.220 says a financial institution must collect your name, date of birth, address, and an identification number before opening an account, and keep that identifying information for five years after the account closes1.

Worth knowing precisely: the rule requires a description of the document they relied on, not a photograph of it. Firms keep scans and selfies by choice, or to satisfy other obligations, not because that specific rule compels it.

Why a shipper has your home address

Because a parcel has to arrive. What surprises people is how many companies sit behind one order. The store takes your order, a fulfillment provider picks and packs it, a carrier delivers it, and an email platform sends the confirmation. Each one holds a copy of some of it, and your relationship is only with the first.

Retention is the other half. An address you gave a retailer years ago can still be sitting in a vendor's system long after the order, sometimes after deletion was promised.

What it looks like when this goes wrong

Two 2026 incidents show both halves, and neither was a break-in of the company customers had heard of.

A fintech handed data to someone posing as a government. In September 2026, Revolut confirmed that an unauthorized party used a legitimate government agency's email domain, with valid authentication, to submit fraudulent requests for customer information, and the company fulfilled them. Revolut's notice to customers lists dates of birth, postal and email addresses, phone numbers, and copies of identity documents such as passports and driving licences, and says verification selfies, statements, and transaction histories may also have been disclosed. The Financial Times reported that about 680 customers were contacted34. Revolut says its systems were not breached and customer funds were unaffected, and it reported itself to the UK's Information Commissioner's Office, which said it is looking into the matter.

A shipping vendor leaked addresses, and scam mail followed. In August 2026, the hardware-wallet company Trezor disclosed that its fulfillment provider, ShipMonk, had been breached through a critical flaw in a third-party analytics tool. Exposed fields included names, email addresses, phone numbers, shipping addresses, and order numbers for about 13,700 customers5. In September, Trezor said roughly 67,000 more US customers were affected, from orders placed between 2019 and 2021 that the provider had given written assurance were deleted7. Trezor's own systems, devices, and keys were not compromised, and the contents of parcels were never exposed.

What came next is the part worth studying. Customers reported printed letters arriving at their homes, dressed up as Trezor communications, carrying a QR code that led to a page harvesting wallet recovery phrases6. Others got phone calls from strangers who knew their name, their address, and what they had bought. A separate incident involving Trezor's email provider produced a wave of phishing messages around the same time.

An address plus a product tells someone what you own and where you keep it. That combination is what makes a scam letter land.

Can you make them delete it?

Usually not, at least not the identity documents.

In the UK and EU, the GDPR right to erasure does not apply where a company must process the data to comply with a legal obligation2. Anti-money-laundering recordkeeping is exactly that, so while the retention clock runs, a request to delete your passport scan will normally be refused. US state privacy laws work similarly, with exemptions for data a business is legally required to keep.

Shipping data is a better bet. It usually carries no retention mandate, so asking a retailer to delete old order records is a reasonable request, even if enforcement is uneven.

What you can do

  • Ask before you upload. Where an ID check is optional, or a lower-friction option exists, take it. The copy you never send is the one that can't leak.
  • Use a delivery address that isn't your home for high-value or identity-revealing orders. A parcel locker, a work address, or a mailbox service breaks the link between what you bought and where you sleep.
  • Treat physical mail as an attack surface. A letter with a QR code, a bank's logo, or a "security alert" deserves the same suspicion as an email. Type the address yourself; never scan the code.
  • Treat a call that already knows your details as a red flag rather than proof. Knowing your address and your recent purchase is exactly what a leaked shipping record provides.
  • Never enter a recovery phrase, seed, or backup anywhere except the device it belongs to. No legitimate company asks for it, by mail, phone, or email.
  • Turn on two-factor authentication on the accounts tied to a leaked email address, and prefer an authenticator app over SMS.
  • If your notice named a Social Security or financial account number, freeze your credit at all three bureaus. IdentityTheft.gov is the reference if something has already happened.

If you received a notice from a company, what to do when a company emails you about a breach covers verifying it and the first moves. For an ID scanned at a counter rather than uploaded to an app, see when a store or rental scans your driver's license. If a Social Security number was involved, our data breach recovery guide has the longer checklist.

What this has to do with what's findable about you

None of the above puts your passport on a people-search site. Those are separate pipelines, and we explain the difference in dark web data versus data brokers.

They intersect at the address. A leaked order record ties your name to one address at one point in time. People-search sites publish current addresses, phone numbers, relatives, and previous addresses, continuously and to anyone. That's what turns a stale record into a working profile, and unlike a vendor's archive, it's the part you can actually get taken down.

See what's listed, free

What Delist does here

Delist scans the open web for listings that publish your personal details, people-search sites, public records, data brokers, and breach-source signals (signals are not live listings, and this is not removing you from a dump), and shows you what's there. The free scan is the look. A paid plan files the removals we're authorized to file and re-checks them afterward, because brokers repost profiles.

What Delist does not do is retrieve or delete identity documents held by a bank or an ID-verification vendor, remove order records from a shipping provider's systems, or pull anything out of a leaked archive. Nobody can do that, and a service that says otherwise is selling you something that doesn't exist.

Frequently asked questions

Can I ask a bank or fintech to delete my passport scan?

Usually not while anti-money-laundering retention applies. In the US, identifying information must be kept for five years after an account closes, and in the UK and EU the right to erasure is disapplied where a company must keep data to meet a legal obligation. You can still ask what's held, and ask them to delete anything kept beyond the requirement.

Why does a company I've never heard of have my shipping address?

Because retailers outsource fulfillment, delivery, and email. Your order details flow to those vendors as a matter of course, so a breach at one of them exposes customers of brands that were never touched themselves.

Is a leaked shipping address dangerous on its own?

It's most dangerous in combination. An address plus a product record tells someone what you bought and where it went, which is why leaked retail data is followed by convincing scam letters and calls rather than ordinary spam.

Was Revolut hacked in September 2026?

No, and the distinction matters. Revolut says an unauthorized party submitted fraudulent information requests from a legitimate government agency's email domain, and the company fulfilled them. Its systems were not breached, and it reported the incident to the UK Information Commissioner's Office.

Can Delist remove my ID documents or order records from a vendor?

No. We have no access to a bank's KYC files, an ID-verification vendor's systems, a shipping provider's databases, or any leaked archive. What we remove is the open-web listings that publish your name, address, phone number, and relatives.

What should I do with a letter that arrives in the mail with a QR code?

Treat it as phishing until proven otherwise. Don't scan the code. If it claims to be from a company you use, reach that company through an address or number you look up yourself, and never enter a recovery phrase or password on a page reached from printed mail.

More guides

Find out what data brokers know about you

A free scan shows which sites are exposing your name, phone, address and email, and Delist files the removals for you.

Start your free scan No card required