01 How to request deletion
There are three ways to ask, and any one of them is enough. You do not need to do all three.
- Email. Send one line to rocketman@mustbeagency.com with the subject Data Deletion Request, from the email address on your Ralph account or the shop owner address on your Shopify store. Say which store you mean if you have more than one. This is also the route for waitlist members: we remove your name and email from the list.
- Uninstall. Remove Ralph from your Shopify admin. Shopify sends us
shop/redact48 hours after uninstall and the purge starts on its own. No email needed. - Platform. Revoke Ralph in Meta Business Settings or at myaccount.google.com/permissions. The token stops working immediately, and for Meta the deletion callback tells us to purge the Meta-sourced data.
Whichever route you take, the timescale is the same: we acknowledge within one business day, purge the live database usually within hours and always within 30 days of verifying the request, and confirm in writing when it is done.
02 What we delete
When you ask for erasure, Ralph hard-deletes everything tied to you or your store from the live database. There is no archival tier and no "we will keep it in case". The full ledger:
Purged Gone
- Account profile, email, credentials, and any waitlist entry
- Shopify store snapshots, orders, customers
- Shopify, Meta, Google Ads, Search Console and GA4 OAuth tokens
- Conversation history & Ralph's memory of you
- Uploaded creative & generated images
- Campaign history, pipelines, briefs, drafts
- Analytics and intelligence tables for your store
- Encrypted backups (inside 30-day window)
Retained Required
- Billing & tax records, where you have paid us (7 years, HMRC)
- Payment receipts, where you have paid us (held by Stripe)
- Anonymised, aggregated usage metrics
- A single ledger line: who asked, when, confirmed
Every retained item is either a legal requirement we cannot override, or stripped of anything that could identify you. We do not hoard.
03 What (little) we keep, and why
Three boring reasons a business of our size has to retain a small amount of data:
- UK tax law. HMRC requires businesses to keep billing records for seven years. Billing is not yet open, so this applies only once you have paid us. We keep the invoice, not the person's life story.
- Stripe. Once billing opens, card receipts will live in Stripe's vault, not ours. Stripe has its own deletion process and we are happy to point you at it.
- Abuse prevention. A single ledger line, email X requested deletion on date Y, confirmed on date Z, so we can prove to an auditor or regulator that your request was honoured.
04 The purge, step by step, with timings
- 01 · Confirm receipt. A human (not a bot) replies within one business day with a case reference.
- 02 · Verify the request. We match the requesting email against the account or shop owner on file. No notarised documents are required, just enough to be sure we are erasing the right thing.
- 03 · Purge the live database. Personal data, store data, orders, conversation memory, tokens, creative, analytics snapshots: hard-deleted. Usually within hours of verification, and never later than 30 days, which is inside the one calendar month UK GDPR allows.
- 04 · Roll backups off. Encrypted backups sit on a 7-day rolling window. Your data is fully eliminated from every backup inside 30 days.
- 05 · Confirm in writing. An email lands in your inbox the moment deletion completes. Subject: Data deletion confirmed. Keep it for your records.
05 Verifying your request
To avoid deleting the wrong account, we verify that the email requesting deletion matches the one on file. If you can email us from the address associated with your Ralph account, that is usually enough. If not (lost access, changed address, and so on), we will ask for one additional signal: the shop domain, confirmation from inside the Shopify admin, or, once billing is open, the last four digits of the card on file.
No notarised documents. No ID scans. We are not a bank. The goal is to be sure, not to be obstructive.
06 Platform deletion endpoints
For platform reviewers and for users who prefer to pull the plug at the source:
Shopify
customers/data_request: subject access request relaycustomers/redact: per-customer erasureshop/redact: fired 48 hours after uninstall; full store purge
All three are HMAC-verified on every request; completion within Shopify's 30-day Protected Customer Data SLA.
Meta
Data Deletion Request Callback URL (the value to paste into Meta's developer console):
https://api.mustberalph.com/webhooks/meta/data-deletion
Returns confirmation code and status URL per Meta's data deletion callback spec.
In-app Settings → Privacy → "Delete my data", or revoke Ralph at myaccount.google.com/permissions. Tokens and Google-sourced data purged within 30 days, per Google API Limited Use policy.
07 Backups & the 7-day window
We run encrypted, off-site backups on a 7-day rolling window. When you request deletion, the live database is purged immediately; your data then rolls off every backup inside 30 days as old snapshots are overwritten by new ones. At day 30, no copy of your data exists anywhere in Ralph's systems.
08 Written confirmation
Every deletion is confirmed in writing to the email address that requested it (or to the shop-owner email on file for automated flows). If you do not receive confirmation within 30 days of your request, that is itself a bug, so please email us and we will escalate.
09 Questions & contact
Anything deletion-related:
- Email: rocketman@mustbeagency.com
- Subject line: Data Deletion Request (for a new request) or Data Deletion Question (for anything else)
- Regulator: the UK Information Commissioner's Office (ICO), ico.org.uk, if you believe we have not honoured your request under UK GDPR
We would rather lose you clean than keep you by friction. Every founder has filed a deletion request into some company's void and never heard back. Not here. The door out is the same size as the door in.
Ralph