Data Deletion
This page is the data deletion instruction required by Meta and by Shopify. It explains what BulkMsg deletes automatically, and how to ask us to delete the rest.
Deletion that happens automatically
Most deletion needs no request at all. BulkMsg listens for the mandatory Shopify privacy webhooks and acts on each one:
| Event | When it fires | What we do |
|---|---|---|
app/uninstalled | The moment you uninstall BulkMsg | All sending stops immediately and the stored WhatsApp and SMS credentials are revoked, so we can no longer message anyone on your behalf |
shop/redact | 48 hours after uninstall, sent by Shopify | Your store’s data — profile, automations, templates, broadcasts and message history — is erased from our systems |
customers/redact | When a shopper asks a store to erase their data | That individual’s phone number and message records are erased |
customers/data_request | When a shopper asks a store for a copy of their data | We compile what we hold about that person and return it to the merchant |
Disconnecting WhatsApp inside the app, without uninstalling, also revokes the access token we hold for your WhatsApp Business Account. The account and phone number stay yours.
If you are a merchant
To have everything deleted, uninstall BulkMsg from your Shopify admin. Shopify will send the redaction request and your data is erased on receipt.
If you want deletion sooner than that, or you want to confirm it has happened, email info@panthercodx.com from the address on the store account, with your .myshopify.com domain. We will confirm within 30 days and usually much sooner.
If you received a message from a store
BulkMsg sent that message on behalf of the store, and the store decides what happens to your data. Two things you can do:
- Stop the messages. Reply STOP to the message. Opt-outs are actioned on receipt and that number is not messaged again.
- Delete the data. Ask the store to erase your details. Their request reaches us through Shopify and we erase what we hold about you.
You can also write to us directly at info@panthercodx.com with the phone number that was messaged and, if you know it, the name of the store. We will forward the request to the merchant and delete our copy of your data. We may ask for something that verifies the number is yours before acting, so that no one else can delete or retrieve your records.
If you connected through Facebook or Meta
Merchants connect their WhatsApp Business Account to BulkMsg through Meta’s Embedded Signup, which issues us an access token scoped to that account. To remove it:
- Disconnect WhatsApp on the Connections page in BulkMsg, or uninstall the app, and we revoke the token; or
- Remove BulkMsg from your Meta Business Settings under Business Integrations, which revokes it from Meta’s side; or
- Email us at info@panthercodx.com and we will revoke it and delete the associated records.
What survives deletion
Two narrow categories are kept after a deletion request, because keeping them is a legal obligation rather than a choice:
- Billing and tax records — invoices and the usage totals behind them, retained for the period tax law requires, typically seven years. These do not contain your customers’ phone numbers or message content.
- Suppression records — where someone has opted out, we keep the minimum needed to make sure they are not messaged again. Deleting that record entirely would defeat the opt-out.
Encrypted backups roll off on their normal schedule, within 35 days, after which deleted data is gone from those too.
Contact
Data deletion requests, and any question about this page:
PantherCodx
info@panthercodx.com
See also our Privacy Policy and Terms of Service.