In August 2026, Trezor disclosed on its own blog that a data exposure at its fulfillment vendor affected 13,689 customers: 11,742 with full exposure (name, email, phone, address) and 1,947 with partial exposure (name, city, email). The fully exposed orders shipped between May 10 and August 8, 2026; Trezor says the timeframe for the partially exposed records is still being verified and may include older orders. No Trezor system, product, or service was affected; the exposure was limited to the fulfillment side of the order chain. Neither company has published a root cause.
Four things worth asking before you sign: how long they retain customer PII after an order ships, who inside the company can access full unredacted records, what breach-notification timeline is in the contract, and which subprocessors (carriers, software vendors, printers) touch your data downstream.
No. No fulfillment provider, including Simpl, can promise zero breach risk. What you can evaluate beforehand is whether a partner has deliberate, written policies for data retention, access control, and breach disclosure, rather than deciding those things after something goes wrong.
A subprocessor is a third party your fulfillment partner shares your data with to do its job: a shipping carrier, a warehouse management system, a returns platform. Depending on where you and your customers are located, data-protection law can require that an additional processor receive the same data-protection obligations set out in the 3PL's own contract with you, but that requirement applies to specific roles under specific laws, not automatically to every downstream vendor. Ask your fulfillment partner to name its subprocessors, confirm each one is under contract, and have counsel confirm what that contract needs to cover for your business.