Privacy · Threat model
Your address is your identity: close the privacy gap
You can rotate an email alias in thirty seconds. You cannot rotate the apartment you live in. That asymmetry has quietly turned your shipping address into a critical identifier.
Short answer
Your shipping address is the most persistent data point in your entire profile. Every physical order writes it into a shop database, a payment processor, one or more carriers, and eventually a data broker. Unlike an email or a phone number, you cannot rotate it. The fix: don't hand out the address you actually live at. Use a receiving address that sits between you and the sender: the shop learns where to ship without ever learning where you live. Below are nine ways to get there. Each option comes with different trade-offs. We take a closer look at them in this article.
Why is an address harder to protect than an email?
An address is harder to protect than an email because you can't throw it away and mint a new one. Privacy tooling has spent a decade solving the rotatable identifiers, and it solved them well. You already do the obvious things:
- Email: Proton, Tuta, SimpleLogin or Addy aliases, a fresh address per service.
- Browsing: Mullvad or IVPN, Tor for ultimate privacy.
- Payments: cash, Lightning, Monero, disposable virtual cards.
- Devices & identity: GrapheneOS, Linux, pseudonyms, compartmentalisation.
Every one of those is designed to be replaceable. Alias leaked? Burn it. Browser fingerprint? Reset it. But there is one field in every checkout that none of those tools touch, and it's exactly the field you can't reset.
Why the address is so critical: the join
An address is dangerous not as a single data point but as the join key that connects all the others. The corporations you already worry about, and the data brokers behind them, aren't dangerous because they collect data. They're dangerous because they correlate it.
Rotate the email, rotate the card, rotate the browser: the address still ties this year's you to last year's you, this pseudonym to that one. The address is the longest-lived data point, and the hardest one to change.
Where does your address go after you click "buy"?
After checkout, your name and address don't sit in one place: a single order fans out into seven or more independent databases, most of which you never chose and none of which you can audit:
Now recall the data-breach headlines of the last five years. Almost every one of them had names and postal addresses in the dataset. The address you typed into a shop in 2021 is still circulating, and it still points at your door, long after you've forgotten the order.
Aside: why should Bitcoiners and self-custodians be especially careful?
Self-custodians should worry more because self-custody flips your threat model: there's no exchange or custodian left for an attacker to breach. You are the vault. That's the point of self-custody, and it's also the attack surface. A potential attacker who wants your coins needs three things:
- Identity: your name is already public somewhere: registers, a leaked email, an old forum post.
- Interest: you ordered a hardware wallet, a Coldcard, a Bitaxe. That order trail exists in the many databases above.
- Location: your shipping address connects the first two to a physical door. The correlation is the attack surface.
This is where the "$5 wrench attack" stops being a meme. The wrench needs an address to show up at. Ordering Bitcoin equipment to the place you sleep invites the conclusion: "self-custodied value stored here." Breaking the link between your coins and your doormat is not paranoia: it's the same OpSec hygiene as not reusing on-chain addresses. Bitcoin is pseudonymous, not anonymous, and that holds off-chain too.
Possible ways to protect your shipping address
There is no silver bullet: every option has a different trade-off profile across convenience, cost, coverage, trust and privacy. The most important step is knowing these trade-offs, so you can derive your personal privacy mix:
| Method | Coverage | Cost | Scales? | Main catch |
|---|---|---|---|---|
| 1 DHL Packstation | DE only | free | somewhat | DHL shipping not always selectable; DE only |
| 2 Third-party parcel lockers | regionally limited | varies | somewhat | low coverage; often full; not all carriers |
| 3 Poste restante | DE – inconsistent abroad | free | no | staff often unaware and refuse without ID |
| 4 Alias on your own mailbox | local | free | no | address is merely masked |
| 5 Rented neighbour mailbox | local | low | no | single point of failure, rarely possible; parcels can be awkward |
| 6 Trusted kiosk / corner shop | local | low | no | depends on the owner's goodwill |
| 7 Hotel / hostel / coworking | global | varies | no | reception rotates; not persistent |
| 8 Family & friends reshipping | global | free | no | shifts the risk onto people close to you |
| 9 Professional mail service | persistent | paid | yes | you trust the provider |
1 DHL Packstation
Automated parcel lockers with a personal Post-Nummer.
DE only- Free, nationwide coverage in Germany
- Discreet use possible via the Post & DHL app
- Only DHL knows the address
- DHL only; size limit per locker
- 9-day pickup window: miss it and it bounces
- Only DHL knows the address :)
2 Third-party parcel lockers
Automated parcel lockers with a pickup code.
Regional- Sometimes usable without registration
- Flexible use with multiple carriers
- Low coverage, often full
- Availability varies strongly by region
- Sometimes paid
3 Poste restante (Postlagernd)
Pickup at a post branch under a name you choose.
DE- Officially offered by Deutsche Post in Germany
- Minimal setup, no contracts
- Works for letters and small items
- Staff are often unaware and refuse without ID
- Hard to claim as "Donald Duck" in practice
- Not always reliable abroad
4 Alias on your own mailbox
A temporary name label next to your own.
Local- Zero cost, zero third parties
- Effective for one-off shipments
- No registration anywhere
- No legal protection; the carrier may refuse
- Tied to your real address; defeats the purpose
- Looks suspicious with systematic use
5 Rented mailbox in the neighbourhood
A small monthly tip or a personal favour.
Local- Cheap; a very personal trust relationship
- Bypasses corporate intermediaries entirely
- Resilient to data breaches
- The owner is a single point of failure
- Letters mostly; parcels get awkward
- Depending on distance, emptying it takes effort
6 Trusted kiosk / corner shop
A personal arrangement with a local merchant.
Local- Reliable receiving through a person you trust
- Parcels often fine, long opening hours
- Builds local goodwill
- Fully dependent on the owner's discretion
- No SLA, no contract, no scale
- Won't survive an ownership change
7 Hotel / hostel / coworking
Use your current stop as a temporary drop.
Global- Works anywhere you happen to be
- Quick setup; just ask reception
- Useful for time-boxed orders
- Reception staff rotates
- Not suitable for sensitive shipments
- No permanent solution
8 Family & friends reshipping
A trusted person receives, then forwards.
Global- Maximum trust, zero corporate exposure
- Very good privacy
- Free
- Shifts the risk onto someone close to you
- Doesn't scale; effort for family & friends
- Manual reshipping required
9 Professional mail service
A flexible, permanent solution.
Persistent- Persistent address, accessible from anywhere
- Forward letters or just read them digitally on demand
- Parcels are forwarded, the provider never knows the contents
- Significantly better privacy and reduced risk
- Not free
- Some degree of trust in the provider required; always check the privacy concept
- Processing time instead of instant pickup
What ProxyHub does, and what it is not
ProxyHub is a professional mail service, built in Germany, focused on flexibility and privacy. The design in one line:
We know where it goes, but not what's inside.
A German receiving address that stands between you and the shop. Letters and parcels arrive at our facility, get recorded and photographed, and land in your personal portal. You decide, per shipment:
- Letters: destroy free of charge, open and scan, or forward worldwide unopened.
- Parcels: we never open parcels. We store them for at least 7 days, up to 10 depending on your plan. Within that window you choose: forward across the EU or send back.
- Minimum retention: defined windows per data type, automatically deleted within the legal retention requirements. What isn't stored can't leak.
ProxyHub is self-hosted in Germany, under some of the strictest data-protection laws in the EU. Privacy is a design constraint at every layer, not a footnote. Protecting your home address is the top priority.
Registered-address use. Using ProxyHub e.g. for an Impressum address is available as an add-on in all subscription plans. All we need is an additional receiving authorisation and proof of identity.
You can start for free, there is no base fee. All plans can be cancelled monthly.
What ProxyHub is not
Trust-minimised means: we tell you exactly where you have to trust us, and where you don't.
Three things to walk away with
You can't rotate it the way you rotate a phone number or an email alias. Treat it accordingly.
No single tool covers every scenario. But a sensible combination of measures, matched to your use case, can improve your privacy significantly.
There is no trustlessness in shipping. Pick providers that minimise the trust you have to extend.
Order to an address that isn't your front door.
A German receiving address for letters and parcels that nobody can connect to your home. Start free, no base fee, cancel monthly.
