Accepted answer
Answer first: the practical privacy question is what a payment record reveals and to whom, and the answer differs by method more than most people assume.
Public blockchain transactions are permanent, globally readable and linkable. Chain analysis routinely deanonymises addresses through exchange on-ramps, and the record does not expire.
In practice, merchant data breaches are the realistic exposure for most people, and the mitigation is minimising what the merchant holds rather than choosing an exotic payment rail.
Card scheme chargeback rules are published and provide a defined dispute mechanism with time limits, which no other common method offers.
No payment method makes an unlawful act lawful, and privacy is not a defence.
Public chains are permanent and searchable. Pseudonymous is not anonymous.
edited 19 Nov 2025 by w_okoye — reworded for clarity after a comment