Articles on: Security

How We Handle GDPR Data Deletion Requests

Summary: When someone asks us to delete their data, we delete or anonymize what we can, and keep only what we're legally required to (mainly Stripe/financial records) — responding within GDPR's one-month window.


The right to erasure: Under GDPR's "right to erasure" (Article 17), individuals can ask us to delete their personal data when we no longer need it or they've withdrawn consent. This right isn't absolute — legal obligations, such as financial record-keeping requirements, can override it.


Our process: When we receive a deletion request, we:

  • Verify the requester's identity
  • Check what data exists across their account, campaign, and transaction records
  • Delete or anonymize what we can
  • Flag anything we're required to retain
  • Confirm back to the user what was done


What we can't delete: Stripe transaction and financial data must be kept for compliance reasons. Our Data Processing Agreement also states that data is deleted or returned upon termination, unless retention is required by law.


Response time: We aim to respond to deletion requests within one month, in line with GDPR requirements.

Updated on: 11/08/2026

Was this article helpful?

Share your feedback

Cancel

Thank you!