Data Deletion
Last updated: July 21, 2026
This page explains, in plain terms, how and when your data is deleted from WapShopAI — both automatically and on request — in line with LGPD and GDPR. For the full picture of how we handle data, see our Privacy Policy.
1. If you're a merchant: automatic deletion on uninstall
When the app is uninstalled from your store, Shopify notifies us automatically. After the safety window required by Shopify itself (typically 48 hours, in case of an accidental uninstall), we permanently remove from our database:
- The catalog index (products, attributes, embeddings) built for your store.
- The agent's and widget's persona and settings.
- The operational information you configured (shipping, payment, contact, location).
- The conversation history and usage metrics tied to the store.
- The store's identifiers and access token.
2. If you're a merchant: requesting earlier deletion
You don't need to wait for uninstall: you can request immediate deletion of all your store's data at now@sysflow.me, from the email address associated with the account, or by providing the store domain for verification. We confirm the request and the deletion within a reasonable time, without undue delay — typically within 15 days.
3. If you're a customer/visitor of a store using WapShopAI
We do not collect your name, email, or address from your order for recommendation or attribution purposes — we only use a conversation identifier and the order line value (see Privacy Policy, section 2). Because of that, Shopify's customer data deletion webhook (customers/redact) already finds no personal data of yours retained on our end to delete through that flow.
Your conversation with the agent is tied to an anonymous token stored in your browser, not to your identity — unless you yourself typed personal data into the conversation. If you'd like a specific conversation's history deleted, write to now@sysflow.me with the store name, the approximate date, and, if possible, a snippet of the conversation to help us locate it; we'll delete the matching record.
If the store has enabled the optional order-tracking feature, the email you provide is used only to verify your identity at the moment of the request and is not retained by the agent beyond that check — so there's no additional record to delete in that case.
4. What we can't delete on our own
Tax and billing records processed by Stripe may need to be retained for periods set by Brazilian tax law, regardless of your deletion request — in that case, we also recommend contacting Stripe directly for payment-specific data.
If the store you spoke with is still active and the merchant keeps their own records (for example, the order itself inside the store's admin), deleting that data is the merchant's responsibility, as the controller of that data.
5. Backups
Security backups may retain a copy of data for a limited additional period, needed for continuity and disaster recovery, even after deletion from the primary database. These backups are encrypted and expire automatically; they are not used for any purpose beyond disaster recovery.
6. How we confirm your identity before deleting
To prevent third parties from requesting deletion of data that isn't theirs, we may ask for a simple confirmation (for example, replying from an email already associated with the store's account, or confirming the store domain) before processing the request.
7. Contact
Any data deletion request, whether as a merchant or as a visitor, can be sent to now@sysflow.me.