Data Deletion

This English version is provided for convenience. In the event of any conflict or inconsistency between the two versions, the French version prevails.

1. Who can request deletion?

  • You are a customer of a shop that uses Ekomy (you received an invitation to leave a review, or submitted a review): the shop is the controller of your data. You can:
    • request deletion directly from the shop — it has the necessary tools in Ekomy; or
    • write to us at privacy@ekomy.io — we handle the request or forward it to the shop concerned, and confirm the outcome to you.
  • You are a merchant using Ekomy: write to privacy@ekomy.io from the address associated with your account to request deletion of your account and the data in your workspace.
  • You interacted with a shop via WhatsApp, Messenger or Instagram: the same routes apply — through the shop or directly with us.

To process the request, state the email address and/or phone number concerned, and if possible the shop concerned. We may ask for an element of verification to prevent fraudulent deletions.

2. What is deleted

A deletion request covers:

  • your contact details (name, email, phone) in the customer records of the shop concerned;
  • the personal data linked to your orders;
  • the review-invitation records concerning you (the review submission links sent to you are immediately invalidated);
  • the identity attached to your reviews: by default, the review becomes “Anonymous” and its content remains published for the shop. On explicit request, the review is deleted in full (including text, rating and photos);
  • the conversations and contact details linked to the connected messaging channels (WhatsApp, Messenger, Instagram);
  • the associated technical data (analysis logs linked to your conversations).

After deletion, your identifiers are placed on a pseudonymized blocklist (cryptographic fingerprints) to prevent any re-import from the shop — this is a safeguard, not a retention of your data in clear form.

3. Timelines and confirmation

  1. Acknowledgement of your request.
  2. 7-day grace period, during which the request can be cancelled (for example if it was made in error). Immediate execution can be requested.
  3. Execution: deletion or de-identification in the active systems, channel by channel, with an execution log.
  4. Confirmation of execution.
  5. Residual copies present in encrypted backups expire no later than 30 days after execution. If a backup were to be restored, the deletions would be re-applied before the system returns to service.

Pseudonymized compliance records (fingerprints, log of the request) are kept for evidentiary purposes, in accordance with our privacy policy.

4. Deletion via Meta apps

When Ekomy’s Meta integrations (WhatsApp, Messenger, Instagram) are active, deletion of the data linked to these channels can also be triggered by removing the app from your Meta settings; the automated handling of these requests will be documented on this page as soon as it is activated. Until then, the instructions above are the deletion route for all data, including data from the Meta channels.

5. Contact

privacy@ekomy.io — we reply within 30 days at most. Version 1.0 — last updated 30 July 2026.