- Use Tor or VPN when registering to website and install ad blocking extension like uBlock.
Using Tor or a VPN isn't really necessary. It wouldn't have protected you from a database leak at all.
Regardless of whether it is ledger or any other website.
All the information they potentially can get from that is your geo location in a 100km radius. Given they really store your IP address used.
Using an ad blocker and additionally a javascript blocker (e.g. NoScript) should always be done. Not only when ordering a hardware wallet..
- Use alternative or disposable e-mail address and new random password for registration.
This should also be always done.
- Use alternative prepaid phone number and not your real phone number for registration.
I have a 2nd mobile number here just for that purpose. Using for registering when necessary.