Privacy controls
Data Deletion
Use these instructions to disconnect a provider, delete your user account, remove an organization workspace, or submit a customer-data request.
1. Disconnect a provider
- Sign in at app.sonarmetrics.io.
- Select the relevant organization.
- Open Settings → Connectors.
- Open the provider and choose Disconnect.
- Choose Disconnect and keep data or Disconnect and remove data.
Both choices delete the organization’s stored credentials, remove linked advertising-account connections, and stop future synchronization. The removal choice also queues permanent deletion of that connector’s imported and derived data. Google Ads disconnect additionally attempts to revoke the stored Google authorization. You may also revoke SONARmetrics from the provider’s connected-app or security settings.
2. Delete a user account
Users who have not created an organization can choose Delete this user account during onboarding. Existing users can open account or organization settings and choose the permanent account-deletion action. Type DELETE, acknowledge the warning, and complete MFA verification.
Organization owners must first delete or transfer every organization they own. Account deletion removes the Supabase authentication identity, memberships, onboarding drafts, personal support data, and active sessions. Shared business records retained by another organization are anonymized where deletion would compromise its ledger.
3. Delete an organization
- Sign in as the organization owner.
- Open Settings → Organization.
- Choose Delete organization.
- Enter the organization name exactly and complete MFA.
Before encrypted connector records are destroyed, SONARmetrics attempts to revoke any Google Ads grants. The organization is then immediately disabled and queued for hard deletion of its isolated tenant schema, connector credentials, imported commerce and marketing data, documents, calculations, and memberships. This cannot be undone.
4. Provider-specific requests
Meta / Facebook
Disconnect Meta inside SONARmetrics to stop future access and delete the organization’s encrypted Meta grant. You can separately remove SONARmetrics under Facebook’s business integrations or connected-app settings. Provider-side removal stops the provider grant but does not by itself guarantee deletion of previously imported SONARmetrics records, so use Disconnect and remove data, organization deletion, or the verified request below for that history. This page is the public Data Deletion Instructions URL for Meta app settings.
Shopify and store-customer requests
A customer seeking access to or deletion of personal data from a Shopify or WooCommerce order should contact the merchant that operated the store. The merchant can identify the relevant orders and submit a verified request to SONARmetrics. The production Shopify app accepts Shopify’s signed customer-data and redaction webhooks for customers/data_request, customers/redact, and shop/redact. Invalid signatures are rejected before any processing. Valid customer-redaction requests remove matching customer identity fields, and valid shop-redaction requests queue complete Shopify data deletion, including after uninstall.
Google Ads and TikTok
Disconnect the relevant connector in SONARmetrics and, if desired, revoke SONARmetrics in the provider account’s connected-app or security settings. Revocation stops new access; use Disconnect and remove data, organization deletion, or the verified request below to remove imported history.
5. Submit and track a verified request
Email privacy@sonarmetrics.io from the address associated with your account. Include the organization name, the type of request, and the provider or store involved. Do not send passwords, API secrets, access tokens, identity documents, or full payment information by email.
We may request additional non-secret information to verify identity, authority, scope, and any legal retention duty. We acknowledge valid requests without undue delay and ordinarily complete them within one month where the GDPR applies, unless a lawful extension or retention duty applies. We confirm completion by email or through the provider’s required compliance-response channel.
6. What may remain
We may retain the minimum information required for fraud prevention, security, legal claims, financial compliance, or proof that a deletion request was completed. Restricted disaster-recovery backups may persist beyond live-system deletion and are not used for ordinary processing.