Just assume everybody harvests your data. There’s no way to prove that they’re not liars and just doing it anyway.
There are several examples of companies and government agencies that have been caught doing things and retaining data they shouldn’t - only after a breach released all the info.
Home Depot wasn’t supposed to store credit cards but they did it anyway in violation of PCI, for example.