Skip to content

Data retention and deleting a person's data

How long data is kept and how privacy requests are handled.

2 min read
  • Raw events, sessions, inactive visitor profiles, popup/spin activity and link clicks are deleted automatically every night once they are older than your plan's retention period (default 14 months). Leads and contact records stay until you delete them.
  • Consent records are kept for 5 years as legal proof.
  • IP addresses are not stored with analytics: only a salted hash for abuse protection. (If your own database is down, tracking batches: including the IP: are held for at most 72 hours until they can be written.)
  • Emails and phone numbers are encrypted at rest.

Deleting a person's data (right to erasure)

When someone asks you to delete their data under DPDP / GDPR, open their profile (Visitors → the person) and click "Delete this person's data" at the bottom of the left column. You'll confirm with your 2FA code first.

  • Deleted: their events, sessions, visitor profile, popup and spin-wheel activity, and leads.
  • Their contact record (email, phone) is deleted too: or, if it is linked to other devices, just this device is unlinked. Delete linked devices from their own profiles.
  • Consent records are kept as legal proof, but the visitor id is removed from them.
  • It can't be undone, and every deletion is recorded in the audit log.
  • Only Admins can do this by default (permission "Delete a person's data"). Developers can call DELETE /api/v1/orgs/{orgId}/sites/{siteId}/visitors/{visitorId} from a signed-in session.

Tip: Find the person on the Visitors page: you can search by visitor id.