Data Deletion Policy
This Data Deletion Policy explains how users and businesses can request deletion of their data from the Supa platform.
Supa provides clear and efficient mechanisms for merchants and customers to request deletion of their commercial data, including automated endpoints for third-party integrations like Meta. Data is securely purged or anonymized according to clear timelines.
1. Overview
Supa stores and processes data for businesses operating on our platform. This includes account data, business content, customer interactions, and integration data.
Each business operates in a separate isolated workspace (tenant), and data is logically separated across tenants.
Users have the right to request deletion of their data at any time, subject to legal and operational requirements.
2. What Data Can Be Deleted
Upon request, we can delete or anonymize:
- Account information associated with a Supa user or business.
- Business configuration workspace settings and custom preferences.
- Product and catalog data created within the platform.
- Customer messages and communication data processed through Supa.
- Invoices, orders, and transaction records generated within Supa.
- Integration data (such as connected messaging or payment services).
- Usage logs and activity logs associated with the account.
Some data may be retained where required by law, tax compliance, fraud prevention, or auditing purposes.
3. How to Request Data Deletion
Users and merchants can initiate a data deletion request using one of the following methods:
3.1 Email Request
Send a formal email request to:
support@usesupa.shop
Include your account email, business or account identifier (Tenant ID), and a clear request for data deletion.
3.2 In-App Deletion (if available)
If Supa provides an account settings page, users and merchants may initiate direct deletion and self-service account removal from within the administrative control panel.
4. Automated Deletion Endpoint (Meta Integration)
For integrations with Meta platforms (such as Facebook Login or WhatsApp Business), Supa may provide an automated data deletion callback endpoint when this feature is enabled.
Callback Endpoint (if enabled)
POST https://api.usesupa.shop/meta/data-deletionExpected Behavior
When a signed deletion request is received from Meta, Supa will:
- Validate the request digital signature provided by Meta.
- Identify the associated Supa account (user or business tenant).
- Queue deletion or anonymization of relevant data across Supa services.
- Return a confirmation JSON response containing a unique deletion request reference ID.
Example JSON Response
{
"status": "processing",
"message": "Data deletion request received",
"request_id": "del_123456789"
}Final deletion may be processed asynchronously depending on system load, databases sync, and backup retention policies.
5. Data Deletion Timeline
We aim to process deletion requests as quickly and transparently as possible:
- Standard manual user requests are processed within a reasonable timeframe following identity verification.
- Meta automated requests are processed instantly in accordance with required platform specifications.
- Some data may persist temporarily in encrypted system backups before full permanent removal.
6. Data That May Not Be Fully Deleted
We may retain limited data where required for very specific purposes:
- Legal and tax compliance obligations.
- Fraud prevention, security monitoring, and abuse auditing.
- Security monitoring and operational system logging.
- Financial and accounting transaction records.
In all such cases, retained data will be completely anonymized or strictly isolated from active business operations.
7. Confirmation of Deletion
Once a deletion request is fully processed and the data is purged from active servers, we may notify the user confirming:
- The completion of the data deletion process.
- Any limited data retained and the legal or regulatory reason for its retention.
8. Third-Party Services
If a Supa account is connected to third-party services (such as payment processors, social messaging platforms, or identity providers), deleting data from Supa **does not** automatically delete data held by those external third parties.
Users must contact those third-party providers separately for additional data deletion requests.
9. Contact
For questions, concerns, or technical inquiries regarding data deletion flows, contact our support team:
support@usesupa.shop
10. Summary
Supa provides transparent mechanisms for users and businesses to control their information and request its deletion, including automated deletion support for Meta integrations, maintaining privacy while upholding our security and compliance standards.