Legal
Data Deletion
Last updated: July 28, 2026
How to request deletion, how requests may be verified, and how scope and necessary retained records are considered.
Request data deletion
To request deletion of information associated with a demo request, website interaction, or CODPilot workflow, use the legal contact email displayed on this page once it is configured. Describe the relationship to CODPilot and the information or account the request concerns.
If a merchant controls the relevant customer or order information, the request may need to be directed to that merchant. CODPilot can support the merchant's handling of a verified request where the applicable service arrangement requires it.
Identity and authority verification
Before acting, we may ask for information reasonably needed to confirm the requester's identity, authority, and connection to the relevant record. The verification method should be proportionate to the sensitivity of the information and should avoid collecting unnecessary additional data.
An authorized representative may need to show that they are permitted to act for the person or organization concerned.
Deletion scope
A verified request may cover information held in active CODPilot systems and, where applicable, information handled by providers supporting the relevant workflow. The practical scope depends on the request, the merchant's instructions, connected services, and the reason the information is held.
Deletion from active use may not immediately remove information from protected backups or systems with scheduled deletion cycles. Where appropriate, remaining backup copies should stay restricted until they are overwritten or otherwise removed through the applicable process.
Records that may be retained
Some information may need to be retained when deletion is not appropriate, including limited records needed for security, fraud prevention, transaction or account integrity, dispute handling, legal obligations, or documenting that a request was completed.
Any retained information should be limited to the relevant purpose and should not return to ordinary operational use solely because a deletion request was made.
Response process
After receiving a request, the operating team should acknowledge it, determine whether CODPilot or a merchant controls the relevant information, complete any necessary verification, identify affected systems and providers, and communicate the outcome or any required next step.
No fixed response deadline is promised on this page. The final process and timing must reflect the operating entity, actual service arrangements, and requirements that apply to the request.