The short version: every method leaves a record somewhere, the records differ in who holds them and for how long, and none of them is anonymous.
Merchant data breaches are the realistic exposure for most people, and the mitigation is minimising what the merchant holds rather than choosing an exotic payment rail.
What a cold pack actually holds, and for how long
| Packing | Ambient | Time below 10 °C | What that means on a 12-day lane |
|---|
| One phase-change pack, thin-walled box | 25 °C | 1–2 days | At ambient for roughly ten of the twelve |
| One phase-change pack, thin-walled box | 35 °C | under 1 day | At ambient for essentially the whole lane |
| Two packs, insulated liner | 25 °C | 2–3 days | Buys a day; does not change the conclusion |
| Lyophilised solid, no pack | 25 °C | not applicable | Dry powder is chemically stable at ambient |
| Anything in solution | 25 °C | not applicable | A different risk entirely; hydrolysis proceeds |
A liquefied pack on arrival is the expected outcome rather than evidence of a problem. A single-use logger, not a heavier pack, is what turns this from speculation into a record.
The part that matters: using a dedicated email address per merchant makes any subsequent breach traceable to its source and costs nothing to set up.
Card scheme chargeback rules are published and provide a defined dispute mechanism with time limits, which no other common method offers.
Decide what you are protecting against first. Most of this question dissolves at that step.