Coldcard has suspended the automatic deletion of customer data due to a security incident and will retain relevant records in accordance with the law
The cryptocurrency hardware wallet manufacturer Coldcard has released an update on its customer data retention policy. Due to legal compliance requirements arising from the security incident disclosed on July 30, the company has temporarily suspended its original automatic customer data deletion mechanism.
Previously, Coldcard's standard practice was to automatically clear customer records after 120 days, retaining only the user's email address and country information, while allowing customers to request early deletion of data at any time after product delivery. Coldcard stated that due to the security incident involving ongoing and potential legal proceedings, the company is obligated to retain records that may be relevant to litigation. Therefore, customer data that was originally scheduled for deletion will be temporarily retained until the law permits the resumption of normal processes.
However, users can still request Coldcard to handle their personal information according to the original data retention policy. If users wish for their data not to be included in this legal retention scope, they can contact official customer service to make a request. Coldcard emphasizes that the retained data will be strictly protected, accessible only to authorized personnel, and will not be used for any purposes other than fulfilling legal obligations. The company will restore the previous automatic data deletion mechanism once legally permissible.






