Privacy
The Privacy tab is the record of every data-subject request your account has handled — someone asking for a copy of the data you hold about them (an export), or asking you to delete it (an erasure). Under GDPR you have one calendar month to respond to a request like this, so each one is tracked here with its due date and exactly how far it's got. Only admins can view this tab; if you're not an admin, you'll see a message explaining that access is restricted.
Steps
Request an export or erasure
- Go to Contacts, open the contact the request is about, and click the ⋯ menu on their record.
- Choose Export data for a copy of everything the account holds about them, or Erase data (GDPR) to permanently remove it.
- For an erasure, type the contact's email address to confirm — this is a deliberate extra step, since the action can't be undone. There is no confirmation step for an export.
- The request now appears in Settings → Privacy, running in the background. Leave the page or come back later; you don't need to wait for it to finish.
Check on a request
- Go to Settings → Privacy. Requests are listed newest first, each showing its type (Export or Erasure), who it's about, who asked for it, its due date, and its status.
- Status moves from pending (queued) to running (in progress) to completed. A request that couldn't finish shows failed, with the reason on the row. If the due date passes before a request completes, it's marked Overdue so it doesn't get lost.
- Click a row to expand it and see the full timeline: when it was requested, when it completed, and an event-by-event audit trail you can point to if you're ever asked to show that you acted on the request.
Download a completed export
- Once an export shows completed, a Download button appears on its row.
- It gives you a ZIP file of the contact's own data — their contact record and the activity associated with them (things like emails and texts sent, form submissions, and imported data) — which is what you send them to satisfy the request. It does not include the app's internal scheduling or processing records, since those aren't the person's data.
- The download link expires after a period shown on the row. After that, raise a fresh export if you need the file again.
What happens when you erase a contact
Erasing a contact is permanent. There is no undo and no recycle bin — once you confirm, the data is gone.
A suppression record is kept on purpose, and this is not a bug. To reliably never contact this person again, the system has to remember, in some form, who they were — otherwise a spreadsheet import next quarter or a new campaign next year could add them right back. What's kept is a scrambled, one-way fingerprint of their email and phone number, not their email and phone number themselves: it can't be read back into the original address, and it isn't personal data you or anyone else can look up. Its only job is to recognize "this person asked to be erased" the next time that email or phone number shows up — in a spreadsheet import, in a sync from a connected CRM, or in a campaign about to go out — and block it.
Past reporting numbers don't change. A campaign you sent to this contact last quarter still shows the same total sent — the person just isn't identifiable in that count anymore. This is expected: aggregate and de-identified numbers are allowed to survive an erasure, and it's the only way your historical reporting stays accurate.
A connected CRM record is deactivated, not deleted. If this contact also exists in a CRM you've connected (like HubSpot or Salesforce), erasing them here deactivates that record rather than removing it. That's deliberate: inside your own CRM, you — not this app — are responsible for that record, and it may carry deal history, invoices, or other information this app has no business destroying on your behalf.
This reaches the CRM you have connected now. If the contact also carries links from a CRM you've since disconnected or migrated away from, those records aren't touched — this app no longer has a way in. The erasure report counts them so you can see there were links it couldn't reach, and you can deactivate the person in that system yourself.
A CRM sync won't bring the contact back. Erasure closes every route by which someone can re-enter this app: they can't be re-added by a spreadsheet import, they can't be sent to again, and an inbound sync from a connected CRM won't recreate them either. If the record still exists on your CRM side, each sync simply skips it — the contact is not created here, and everything else in that sync goes through as normal. The skip is recorded and counted rather than passed over quietly, so if you ever need to account for why a CRM record has no contact on this side, the answer is there.
It's still worth removing or suppressing the person in your CRM if you want them gone everywhere — this app declines to import them, but it deliberately doesn't delete anything inside a system you own (see above).
If an erasure stops partway through
Occasionally the system finds a piece of data it can't clean up automatically. When that happens it stops rather than continuing, and the request is marked failed with an explanation on the row.
The contact still exists afterwards, and that's on purpose. Stopping early keeps enough information to finish the job later, so the erasure can simply be run again once the problem is sorted out. If it carried on regardless, the leftover data would be stranded with no way left to reach it — and a later attempt would report a clean success while that data quietly stayed put. A request you can retry is far better than one that looks finished and isn't.
The person is protected either way. The suppression record is written before anything else is touched, so from the moment the request starts they can't be contacted or re-added — by a spreadsheet import, by a CRM sync, or by a campaign — even while the erasure is incomplete. A stopped erasure means unfinished cleanup, not an unprotected person.
What to do: run the erasure again from the contact's record. If it stops in the same place a second time, send the reason shown on the request to your administrator — it points at exactly which data couldn't be cleaned up.
Why a second attempt shows different numbers
When you retry, the counts on the second run are usually smaller than on the first, and some items that had a number the first time show nothing at all. That's expected and it isn't a sign the retry did less work: most of the cleanup already happened on the first attempt, so there's simply less left to remove. The retry finishes what was outstanding rather than starting over.
What tells you the erasure is done is the status reaching completed — not how big the numbers are.
Tips
- Raise the request from the contact's own record, not from the Privacy tab — the Privacy tab is where you track requests, not where you start them.
- Read the request through before closing it out, especially for an erasure. Once it's confirmed there's no way to reverse it.
- If a request is close to its due date, check its status rather than waiting — a running request just needs more time, but if it looks stuck, that's worth investigating before the deadline passes.
- A failed erasure is meant to be retried, not replaced. Run the erasure again on the same contact rather than raising a fresh request, and don't worry that the person is exposed in the meantime — they're already suppressed.
FAQ
Q: Can I undo an erasure? A: No. There is no undo and no recycle bin. Confirming an erasure is final.
Q: The erasure failed and the contact is still there. Did anything happen? A: Yes. The suppression record was created, so the contact can no longer be contacted or re-imported, and everything the system could clean up has been cleaned up. It stopped before the final step deliberately, so the erasure can be completed by running it again. If it fails a second time, ask your administrator to look at the reason shown on the request.
Q: I ran the erasure again and the numbers were much smaller. Was anything missed? A: No — that's the normal picture on a retry. The first attempt already removed most of the data, so the second one has less left to do and reports smaller counts. Go by the status: completed means the erasure finished.
Q: Why do old campaign reports still count someone I erased? A: Aggregate totals (like "sent to 4,200 contacts") are allowed to survive an erasure — the contact themselves is no longer identifiable in that number. Only de-identified, aggregate data is kept this way; their personal record is gone.
Q: If the person is still in my CRM, will a sync bring them back? A: No. An erasure blocks re-entry by spreadsheet import, by CRM sync, and by any future send. When a sync runs into a record for someone who's been erased, it skips that record and carries on with the rest — nothing is recreated here, and nothing else in the sync is affected. The skip is counted, so it isn't a silent disappearance.
Q: Should I still delete the person in my CRM? A: That's up to you. This app won't recreate them from a sync either way, so nothing is going to slip through. But the record does still exist in your CRM, and this app deliberately won't delete anything inside a system you own — so if you want the person gone everywhere, remove or suppress them there as well.
Q: Does erasing a contact here delete them from my CRM too? A: No. The CRM record is deactivated, not deleted. You remain the owner of that data inside your own CRM, so this app won't hard-delete it on your behalf.
Q: How long do I have to respond to a request? A: One month from when it's raised, per GDPR's response window. The due date is shown on every request, and it's flagged Overdue if it passes before the request completes.
Q: Who can see this tab? A: Admins only. Everyone else sees a message explaining that access is restricted.