Online shopping generates a detailed behavioral record. Most uses are ordinary commercial ones, and a few settings meaningfully reduce what is collected.

What Is Actually Collected
A retailer records what you viewed, in what order, for how long, what you added and removed from a cart, what you searched, what device you used and where you appeared to be. Purchase history is only a small part of it, and the browsing record is considerably more detailed. Identifiers tie this together across visits. Account logins are the strongest, followed by cookies, device fingerprints and email addresses used at checkout. This is why a retailer can recognize you across devices and why advertising for a product follows you after a single visit.
Third parties receive a share of this. Advertising networks, analytics providers and payment processors each see part of the picture, and data brokers aggregate across sites to build profiles that no single retailer holds. The scale of this is routinely underestimated.
The uses are mostly commercial rather than sinister. Recommending products, timing offers, retargeting advertising, pricing experiments and inventory planning. None of that is objectionable in itself, and the aggregate detail is still more than most people assume they have agreed to.
How It Is Used Against Your Interests
The clearest case is price sensitivity inference. Behavior reveals whether you buy regardless of discount, and customers who do receive fewer discounts because the model predicts they will buy anyway. This is a direct consequence of how targeting works rather than a policy anyone announced. Urgency and scarcity messaging is tuned on the same data. Which prompts work on which segments is measured continuously, and the version of a page you see is selected to maximize the chance of a purchase. The personalization that surfaces a relevant product is the same mechanism that surfaces a persuasive pressure tactic.
Timing is the third application. Offers arrive when the model predicts a purchase is due, based on your own replenishment pattern, and marketing notifications land at the times of day when decisions are least deliberate.
None of these require unusual behavior from the retailer. They are the normal output of a system optimized for conversion, which is worth knowing because the defense is behavioral rather than technical.
Settings That Actually Reduce Collection
Turning off marketing notifications for every shopping app is the highest value change, and it protects against the timing effect directly. Nothing useful is lost, since you can open an app deliberately when you want to buy something. Reviewing app permissions is the second. Location, contacts, photo access and background activity are rarely needed for shopping and were usually granted by tapping through a prompt. Revoking them costs nothing and removes a meaningful amount of collection.
Browser level controls handle the rest. Blocking third party cookies, which is now default in several browsers, substantially reduces cross site tracking. A tracker blocking extension does more. Using a browser rather than apps for occasional shopping also reduces what is gathered, since apps have access to device level identifiers that websites do not.
Where available, opting out of personalized advertising and data sharing within each retailer account is worth the few minutes. These settings exist because regulation requires them in many markets and they are usually buried rather than absent.
The Email and Payment Layer
Using a dedicated email address for shopping separates that activity from the rest of your correspondence and makes it easy to see what each retailer sends. It also limits the usefulness of your email as a cross site identifier, since the address appears in fewer places. Email aliasing, where supported by your provider, goes further by giving each retailer a different address. That makes it obvious which company shared or leaked your details when unexpected mail arrives, and it allows disabling a single alias without affecting anything else.
Payment details are worth keeping out of retailer accounts. Deleting stored cards reduces the exposure in any breach and, as a side effect, adds friction that reduces impulse purchases. Virtual card numbers where your bank offers them go further, since each merchant holds a number that works only for them.
Guest checkout avoids creating an account at all, which is appropriate for one off purchases. The tradeoff is losing order history and any member pricing, which for a single purchase is usually not a loss.
A Proportionate Position
Complete avoidance is not realistic and not necessary. The sensible position is to accept the trade at the retailers where you genuinely benefit from the relationship, and to minimize collection everywhere else. That means accounts and loyalty programs at two or three places and guest checkout with blocked tracking at the rest. Pay particular attention to categories that are personally sensitive. Health related purchases, anything medical, and anything you would not want inferred or shared deserve more care than a clothing order, and in those cases guest checkout and a separate payment method are reasonable precautions.
Check what rights you have, since in many markets you can request a copy of your data and ask for deletion. Making one such request to a retailer you use heavily is informative, because the volume of what comes back is usually more persuasive than any description of it.
The practical summary is that the data question and the spending question have the same answer. Fewer accounts, fewer apps, no stored cards and no notifications reduce both what is collected about you and what you buy without meaning to, which makes the privacy changes worth making even if privacy is not your main concern.
