Stated carefully, this is a question about record-keeping rather than about secrecy, and reframing it that way makes it tractable.
Public blockchain transactions are permanent, globally readable and linkable. Chain analysis routinely deanonymises addresses through exchange on-ramps, and the record does not expire.
Keep your own record of every transaction regardless of method: date, amount, reference, and what was ordered. This is the documentation you will need if anything requires resolving.
Customer identification requirements at regulated exchanges create the identity linkage that makes on-chain analysis effective.
The caveat is that legal exposure varies enormously by jurisdiction and nothing here is legal advice.
A chargeback is the only recourse mechanism in this space. Price that in.