MuthoCommerce Data Deletion Policy
Version: 2026-08-03
Effective date: 3 August 2026
This Policy provides a public, practical route for requesting deletion. It summarises the deletion commitments in the MuthoCommerce Privacy Notice, Merchant Terms, Billing Policy, and Data Processing Addendum (DPA). Those documents and mandatory law control if this summary conflicts with them.
1. Choose the correct request route
MuthoCommerce handles two different categories of data:
- For a MuthoCommerce account, subscription, support case, security record, public-site interaction, or other data MuthoCommerce controls, send a request to privacy@muthocommerce.com.
- For shopper, order, delivery, review, loyalty, inbox, or similar data belonging to a merchant's store, contact that merchant first. The merchant ordinarily decides whether the data should be deleted, and MuthoCommerce assists the merchant under the DPA. If the merchant cannot be reached, send the storefront URL, order reference, and relevant facts to the privacy channel without sending payment credentials or one-time codes.
2. What to include
State that the message is a deletion request and identify the data or account in scope. Include the email associated with the account or order, the store name or storefront URL where relevant, and enough information to locate the record. Do not send passwords, PINs, one-time codes, full payment-card details, or unnecessary identity documents.
MuthoCommerce may request only the additional evidence reasonably needed to verify identity, authority, account ownership, or the scope of the request. An agent must show authority to act. A merchant-store deletion or deactivation instruction must come from the verified Owner or another person with equivalent authority; an ordinary staff user cannot delete the store merely by emailing support.
3. Response process
MuthoCommerce acknowledges a privacy deletion request within 3 business days and ordinarily provides its decision or completion status within 30 calendar days. If a complex or high-volume request lawfully requires more time, MuthoCommerce will explain the reason and expected date before the initial period ends.
MuthoCommerce will confirm the scope, complete deletion or irreversible anonymisation where required, or explain any data that cannot yet be deleted and the reason. A requester may ask for review of a refusal or incomplete response through the privacy channel.
4. Account and store deletion
Deleting an individual profile, closing a merchant store, and cancelling a paid subscription are different actions. A deletion request does not by itself cancel renewal or settle an unpaid amount. The verified Owner must separately cancel under the Billing, Cancellation, and Refund Policy.
When a store is deactivated, the verified Owner has a 30-day restricted recovery and available export period. After that period, MuthoCommerce deletes or irreversibly anonymises store content and Merchant Personal Data from active systems unless a limited record must be retained for law, security, a dispute, or a documented legal hold. The Owner should export records it is required to keep before the recovery period ends.
5. Backups and connected services
Deletion from active systems does not immediately rewrite every encrypted disaster-recovery copy. Residual copies are isolated from normal use and targeted for expiry within 90 additional days where MuthoCommerce controls the schedule. Where a subprocessor uses a fixed secure recovery cycle, the copy remains blocked from ordinary use until that cycle overwrites it. If a backup is restored, the valid deletion instruction is re-applied before ordinary processing resumes.
A deletion request to MuthoCommerce does not automatically delete data held by an independent payment provider, courier, social network, domain provider, or other service selected by a merchant. The requester or merchant must use that provider's deletion route unless MuthoCommerce is contractually responsible for forwarding the instruction as its subprocessor.
6. Records that may be retained
MuthoCommerce may retain only the records and fields necessary for a lawful, documented purpose, including contract and policy acceptance evidence, invoices and payment records, account tombstones, complaint records, fraud and security evidence, or material needed for a legal claim or authority order. The standard periods are listed in the Privacy Notice.
Retained records are access-restricted and are not kept for unrelated advertising. A legal hold applies only to affected data, and deletion resumes when the hold ends. MuthoCommerce will not retain an entire store merely because one invoice, complaint, or security record must remain.
7. Merchant responsibilities
A merchant remains responsible for responding to deletion requests concerning data it controls, giving lawful instructions to MuthoCommerce, and coordinating deletion with its independently selected providers. A merchant must not instruct MuthoCommerce to delete evidence it is legally required to preserve or use deletion to obstruct a refund, complaint, investigation, or legal claim.
Technical and contractual details for merchant-controlled data are in the Data Processing Addendum. Other privacy rights and complaint routes are in the Privacy Notice.