Data Deletion Instructions
Last updated: August 2026
Nerja AI provides multiple pathways for data deletion, in compliance with Shopify’s mandatory privacy webhooks, GDPR, and CCPA requirements.
1. Uninstall the App (Shop-Level Deletion)
When you uninstall Nerja AI from your Shopify admin, Shopify sends a shop/redact webhook to our servers. Within 30 days of receiving this webhook, we permanently delete:
- All customer profiles and associated data
- All event data (browsing, cart, checkout events)
- All order data synced from Shopify
- All campaign execution history
- All suppression records (unsubscribes, bounces)
- All audience segments
- Your tenant configuration and settings
Provider credentials (API keys, tokens) are deleted immediately upon uninstall.
2. Customer Data Request (GDPR Access)
When a customer submits a data access request through Shopify’s privacy portal, Shopify sends a customers/data_request webhook. We compile and return the following data about the customer within 30 days:
- Profile information (email, phone, name)
- Event history (page views, cart activity, purchases)
- Campaign messages sent to them
- Suppression status and reason
- Segment memberships
3. Customer Data Deletion (GDPR Erasure)
When a customer requests data deletion through Shopify’s privacy portal, or when a merchant initiates deletion, Shopify sends a customers/redact webhook. We permanently delete all data associated with that customer:
- User profile and identifiers
- All tracked events
- Campaign execution records
- Suppression records (added to a permanent block list before deletion to prevent re-import)
- Segment memberships
Deletion is completed within 30 days of the webhook receipt. The customer’s email/phone is added to a suppression list before deletion to ensure they are never re-imported or messaged again.
4. Manual Deletion Request
Merchants can also request data deletion manually by contacting support@nerja.ai with the subject line “Data Deletion Request” and including the shop domain. We process manual requests within 30 days.
5. Data Retained After Deletion
The following data may be retained after deletion for legal or operational reasons:
- Suppression records: Email/phone hashes are retained to prevent re-messaging (required for CAN-SPAM/GDPR compliance).
- Billing records: Transaction records required for tax and accounting purposes are retained as required by law.
- Aggregated/anonymized data: Statistical data that cannot identify an individual (e.g., aggregate campaign performance metrics) may be retained.
6. Questions?
For any questions about data deletion, contact us at support@nerja.ai or see our Privacy Policy.