Legal

Data Deletion Instructions

Last updated: June 21, 2026. How to ask us to delete the personal data we hold about you.

How to request deletion

Clients: the fastest route is the client portal — sign in, open Account → Data & privacy, and submit the deletion request there. Because you’re signed in, the request is verified automatically and enters the same 30-day workflow immediately.

Everyone else (or if you can’t sign in): email [email protected] from the email address on file with the subject line “Data deletion request”. Sending from the address we have on file lets us verify the request is yours; if you can’t, we may ask one or two questions to confirm your identity before we act. You do not need an account, and there is no charge.

What gets deleted

On a verified request we remove the personal information we hold about you from our operational systems — our lead, prospect and CRM records, any onboarding details, our outreach and messaging logs, and any free-teardown / audit inputs and contact correspondence tied to you. This includes your name and email address, and the company / website domain and competitor names you provided. We also request deletion of your subscriber record in our email / newsletter platform (MailerLite). Where a record is needed for aggregate accounting (for example a paid engagement’s revenue line) we anonymize it — the entry is kept but your identifying details are stripped — rather than leaving your data in place.

For clients, this also covers the materials you uploaded, any content we ingested with your consent, and the voice/brand profiles and deliverables we derived from them — deleted or returned within about 30 days of your request (or within 90 days of the engagement ending), subject to backup rotation. It also covers the communications we processed — the reviews, comments, messages and emails we ingested to route and answer — except the consent and opt-out suppression records described below, which we are required to keep.

Timeframe & confirmation

We action verified requests within about 30 days. When it’s done we email you a confirmation that lists what was deleted, what we were required to retain and why, and the completion date. Backups that contain your data are overwritten on our normal backup-rotation cycle (typically within 90 days), after which no copies remain.

Third-party processors

Where your data was shared with the service providers that help us operate, we instruct each to delete it as part of fulfilling your request. These are the same sub-processors listed in our Privacy PolicyMailerLite (email/newsletter), Resend (transactional email), Chatwoot (live chat, where enabled — we ask it to delete any chat conversation tied to you), Google Workspace (our correspondence/files), and Cloudflare (hosting/security). Stripe retains the payment and billing records it needs to meet its own legal and financial obligations as an independent payment processor. Plausible is cookieless and holds no personal identifiers to delete. Each provider acts under its own data-processing terms.

What we lawfully retain — and why

We are legally required to keep financial and tax records for completed paid engagements — invoices and ledger entries — for bookkeeping, tax-filing and audit purposes (the Canada Revenue Agency generally requires business records be kept for about six years). These are a recognised exemption from erasure (GDPR Article 17(3)(b); CCPA §1798.105(d)). When we keep them, the data is frozen, is never used for marketing, and we record that it was retained on this basis.

We also keep, as a separate legal hold, the minimum record needed to prove anti-spam compliance: the record that you gave (or withdrew) consent to receive commercial email, and your entry on our permanent do-not-contact suppression list. Canada’s CASL and PIPEDA (and equivalents such as CAN-SPAM and the GDPR/PECR) require us to be able to demonstrate that we had consent to contact you, or that you opted out — and the suppression entry is what lets us honour your opt-out and never email or re-add you. We retain these even after a deletion request, because deleting them would destroy the proof the law requires; they are frozen, used only to honour your opt-out and to answer a compliance challenge, and never used for marketing. Anonymized or aggregated data that can no longer identify you may also be retained.

Other privacy rights

This page covers deletion. Depending on where you live (EEA/UK GDPR, California CCPA/CPRA, or Canada’s PIPEDA), you also have rights to access a copy of your data, correct it, port it, and object to or restrict processing — and to confirm we do not sell or share your personal information. Those rights, and how to exercise them, are described in our Privacy Policy (see “Your privacy rights”). Email the same address for any of them.

Questions

Contact [email protected]. See also our Privacy Policy and Terms of Service. Clear Cited, 570 Hood Road, Unit 14, #1584, Markham, ON L3R 4G7, Canada.