The Personal Information I Never Hand Over to an Online Store
The Personal Information I Never Hand Over to an Online Store
I've written elsewhere about my full routine from search to delivery but that routine assumes I'm already comfortable with the retailer itself. This is the layer underneath it: the actual personal information I do and don't hand over once I've decided to buy, because the checkout page is where casual browsing turns into pieces of my identity sitting in someone else's database, and most of what gets asked for there isn't actually required to complete the order.
Why I Default to Guest Checkout Whenever It's an Option
Every account I create with a retailer is another database holding my name, address, phone number, and order history, sitting there indefinitely long after I've forgotten the site exists. Guest checkout completes the exact same purchase without creating that permanent record, and I use it by default unless I'm actually going to order from a site regularly enough that saved details are worth the tradeoff. I've lost count of how many "member accounts" I've created over the years for a single one-off purchase, most of which I never logged into again, and every one of them is still sitting somewhere with my address and order history attached whether I remember creating it or not.
The Payment Details I Never Let a Site Save
Retailers ask to save card details "for next time" at almost every checkout now, and I decline by default, typing the card number in fresh each time even though it costs an extra fifteen seconds. A saved card sitting in a retailer's system is only as safe as that retailer's security, and small and mid-sized online shops are exactly the kind of target that doesn't make headline news when they're breached, unlike the big-name breaches that actually get reported. I'd rather deal with that fifteen seconds of extra typing every single time than find my card number sitting in a database I have no visibility into and no real way to check.
Why I Give Deliberately Vague Answers to "Optional" Profile Fields
A lot of checkout and account-creation forms ask for a date of birth, a phone number, or a "tell us about yourself" field that has genuinely nothing to do with completing an order, and marks itself optional while still sitting right there asking anyway. I skip anything actually marked optional without exception, and where a field is presented as required but clearly isn't, a date of birth for a clothing order, for instance, I've stopped assuming I have to answer it accurately, since that data point usually exists for marketing profiling rather than order fulfilment. The pattern I watch for is a request for information that has no plausible connection to shipping me a physical item.
Why I Don't Use "Sign In With Facebook" to Speed Up Checkout
The one-click social login options at checkout are genuinely convenient, and that's exactly why I avoid them. Signing in with an existing social account doesn't just save me typing a password, it usually hands the retailer a slice of whatever profile data that platform is willing to share, and it links a purchase history I'd rather keep separate to an account that already knows a great deal about me. A separate email and password through a password manager takes a few seconds longer at checkout and keeps the two entirely apart, which matters more the day one of them gets breached and I need to know exactly what was exposed rather than guessing how many services quietly had a copy. It also means a compromised shopping account never becomes a door into the social account it was signed in through, which is exactly the kind of chained access I've seen catch people out with accounts they thought had nothing to do with each other.
The Marketing and Data-Sharing Boxes I Always Opt Out Of
Somewhere near the bottom of most checkout pages sits a pre-ticked box agreeing to marketing emails, and often a second one agreeing to share my details with "trusted partners," a phrase that could mean almost anything. I go through and untick both every single time, since a pre-ticked box is a default written to work in the retailer's favour, not mine, and "trusted partners" is rarely defined anywhere I can actually check before I've already handed the information over. It costs a few extra seconds per order, and it's the difference between one retailer having my email address and an unknown number of others acquiring it without my ever agreeing to that directly. I've traced more than one wave of unfamiliar marketing emails back to a single order where I skipped past that box without reading it, which is usually enough motivation to actually read it properly the next time.

Why the Information I Withhold Matters as Much as the Password I Choose
A strong unique password protects an account after it exists, but it does nothing about the data I chose to hand over while creating that account in the first place. Every optional field I skip, every account I don't create, every card number I don't let get saved is one less thing sitting in a database somewhere waiting for the next breach notification email. The NCSC publishes guidance on shopping safely online if you want a second source to check your own habits against, and my free Safety Toolkit covers the account-level basics that make the rest of this easier to keep up. I'd rather spend an extra minute at checkout now than spend an afternoon later working out which of my old accounts got compromised.
