My payment for 1 unit is here:
http://blockchain.info/tx/381324dc4925b62e6eb7391904e22f5dfa06bfcd488f90a0f27648cd7f5a0641
My shipping address is:
XXXX XXXXXXXX
XXXX XXXXXXXXXXX
XXXXXXXX, XX XXXXX
======================
Signature of the text between the === lines above using one of the
sending addresses (1LWkDUVtMVUvgojDhhqDfuGu8YJCv7p2dn):
IEajXyxbq414bkBiw+GRuuIBCCfJQh7Y5d12Mjx1vRmQIuGs4RYuyNPEXCSUBEdM+PY6wiExmAvmbShrfERjzQ0=
Obviously, the signature doesn't actually match in the example above, because I X-ed out my actual shipping address.
The above proves that a) I own the address that sent the payment and b) that the shipping address hasn't been tampered with.
This was done with the Sign Message / Verify Message functionality built into bitcoin-qt: http://imgur.com/a/nUmZ0