Data Deletion Policy

Effective Date: January 20, 2025

Last Updated: September 20, 2025

At DASHBOARDLY INC (“Dashboardly,” “we,” “our,” or “us”), protecting user data and respecting privacy rights is a core priority. This Data Deletion Policy explains how, when, and under what conditions data is deleted, in compliance with TikTok Developer Terms, GDPR, CCPA, and other applicable laws. It applies to all TikTok Shop sellers, brands, agencies, and their authorized collaborators who use Dashboardly.

1. Scope of Data Covered

When you connect your TikTok Shop and/or TikTok Ads accounts to Dashboardly, we may access and process the following categories of data:

  • Orders: order IDs, products, timestamps, fees, refunds, discounts, shipping data.
  • Products: SKUs, product IDs, names, pricing, inventory levels, metadata.
  • Financials: TikTok commissions, payouts, promotions, and taxes.
  • Advertising data: TikTok Ads spend and performance metrics (if authorized).
  • User account data: account email, organization details, subscription plan, preferences.
  • Operational inputs: cost of goods (COGS), supplier information, purchase orders, and inventory adjustments.

This policy governs deletion of all such data, both personally identifiable and business-related.

2. Automatic Deletion After App Uninstall

  • When you uninstall Dashboardly from TikTok Shop, all TikTok-derived data imported into Dashboardly is automatically flagged for deletion.
  • Timeline:
    • Active databases: data is deleted within 30 days.
    • Encrypted backups: securely purged within 60 days.
  • Once deleted, data cannot be restored.
  • Users are notified by email confirming completion of deletion after uninstall.

3. Manual Data Deletion Requests

You may request deletion of your account and data at any time.

Process:

  1. Send an email to hello@dashboardly.io with the subject: “Data Deletion Request.”
  2. Provide:
    • Your account email.
    • Associated TikTok Shop ID(s).
  3. Dashboardly will:
    • Confirm receipt within 5 business days.
    • Complete deletion within 30 days of verification.
    • Send a written confirmation once the deletion is finalized.

Identity Verification:

  • We may require additional verification (e.g., confirming access to the account email, business information) to prevent unauthorized deletions.

4. Data Retention Exceptions

Certain categories of data are retained even after deletion requests, as required by law or operational necessity:

  • Billing records & invoices: retained for up to 7 years for compliance with tax and accounting regulations.
  • Audit logs & security logs: retained for up to 2 years for security, fraud prevention, and compliance.
  • Aggregate or anonymized analytics: retained indefinitely for improving the Service; cannot identify individuals.
  • Legal or regulatory communications: retained only as required by applicable law.

5. Data Retention for Inactive Accounts

If your subscription expires, is paused, or is canceled but your Dashboardly account remains installed, we retain your imported order history and related business data for 90 days to allow you to reactivate your subscription without losing historical insights.

If no reactivation occurs within 90 days, the account is flagged for deletion.

Users will receive at least 30 days’ advance email notice before any permanent deletion.

Billing records and audit logs remain stored as described above.

6. Programmatic Data Deletion Endpoint (TikTok Compliance)

Dashboardly provides a programmatic API endpoint to comply with TikTok Platform requirements:

Endpoint:

DELETE <https://api.dashboardly.io/v1/users/{user_id}/data>

  • Authentication: Requires a valid OAuth token.
  • Scope: Deletes TikTok-derived data, account data, and associated integrations.
  • Response: Returns JSON confirmation with timestamp and status.
  • Audit: All requests are logged and available for compliance audits.

7. Security During Deletion

All deletion tasks are conducted under strict security controls:

  • Infrastructure: hosted on DigitalOcean servers with enterprise-grade encryption.
  • Encryption: AES-256 at rest, TLS 1.2+ in transit.
  • Access Control: RBAC (Role-Based Access Control), least-privilege principle.
  • Monitoring: continuous monitoring with Sentry (error logging) and Datadog (infrastructure health).
  • Audit Trail: all deletion operations recorded in immutable logs for compliance.

8. User Rights (GDPR / CCPA)

You have the right to:

  • Access your personal data before deletion.
  • Request a deletion report showing which data was deleted and when.
  • Rectify or restrict processing of certain data.
  • Opt out of processing under CCPA.
  • File a complaint with a supervisory authority if deletion is not handled properly.

Dashboardly will respond to verified requests within 30 days as required by GDPR/CCPA.

9. Data Breach & Incident Handling

  • In case of a breach during deletion or retention, Dashboardly will notify affected users within 72 hours (per GDPR) and provide mitigation steps.
  • Logs of all deletion-related incidents are maintained for regulatory review.

10. Policy Updates

We may update this Data Deletion Policy periodically. Updates will be posted at https://dashboardly.io/data-deletion-policy with a new “Last Updated” date. Significant changes will also be communicated via email or in-app notifications.

11. Contact

For questions about this policy or to initiate a deletion request:

Dashboardly, Inc.

800 SE 4th Ave Ste 711

Hallandale Beach, FL 33009, USA

📧 hello@dashboardly.io