A customer asks to be deleted, and the honest answer is not a DELETE. Their first name,
email address and birthday are emptied, and their number is replaced by an opaque
identifier that leads nowhere. None of it can be recovered.
Their visits stay, with nothing left attaching them to a person: once there is no reachable number, no name, no address and no date of birth, what remains is not personal data any more, it is an anonymous visit in a history.
Why not a real delete
Because a real delete would destroy things that do not belong to that person.
Visits, proofs of return, issued cards, referrals and game plays all hang off the customer record. Delete the record and they go with it. Your verified revenue history would be rewritten, and, more to the point, your number of active customers would change.
That number is a billing input. In plain terms: a business could drop a plan tier because somebody with no connection to it exercised a right. And since the row would be gone, nobody could see it afterwards. An invisible side effect on a bill is worse than a visible one.
Irreversible anonymisation satisfies the right to erasure without doing any of that. It is the correct answer, not the convenient one.
What gets erased, precisely
| Data | What happens to it |
|---|---|
| Phone number | Replaced by an opaque identifier, with no link to the original |
| First name, email, birthday | Emptied |
| What Kanz had noted about them | Emptied |
| Messages sent | Recipient and content erased |
| Cards in their wallet | Invalidated; the card stops working |
| Contact status | Unsubscribed, permanently |
| Visits and proofs of return | Kept, anonymous |
Two rows of that table are worth a word of explanation.
The number is replaced, not emptied. It becomes an opaque identifier rather than nothing at all, and that is not technical squeamishness. A business can hold only one record per number. Leave the field empty and the slot stays occupied by a ghost, so the same person could never sign up with you again. Replacing it frees the slot: if they come back one day and sign up afresh, they start from a new record, with nothing tying it to the old one. That is exactly what "erased" ought to mean.
The unsubscribe is set on the way through, and it is final for that record. Nothing can lift it, no setting on your side and no request to Kanz. The only person who can come back is the customer, by signing up again, which creates the fresh record described just above. And even once anonymised, the old record keeps the mark that stops any campaign from targeting it: the protection does not depend on the fields being empty.
What survives, and why that is right
One row always survives: the one saying the erasure happened, when, and at whose request.
That surprises people, and it is the opposite of a contradiction. Without that trace, nobody can answer "you were erased, and here is when" a year later. A deletion that leaves no proof of itself is a deletion you cannot demonstrate, which is the one case where somebody will ask you for it again.
Before erasing: the customer is entitled to a copy
These are two different requests and they should not be run together. "Send me what you hold on me" and "delete everything" do not call for the same answer, and the first has to be served before the second, since afterwards there is nothing left to send.
The copy holds everything: the profile, every dated consent, every visit, every message received, the cards, the reward codes, the referrals and the returns they left. It also holds their number in the clear, which is the only place in the product where that is true. That is deliberate: the document goes to the person who, by definition, already knows their own number.
Who presses the button, honestly
Not you. That part is done by Kanz, not from your panel, and it is better to know before the request lands on you.
The copy of the data can be produced by support, because an access request has a legal deadline and must not wait on an escalation. Erasure needs the highest level of authorisation, a written reason, and the customer's full phone number typed in to confirm.
That last requirement is not ceremony. Everywhere else in the admin console, numbers are masked. So you have to hold the number already in order to erase somebody, and you only hold it if the request came in. Nobody can erase a customer they merely came across while scrolling through a list.
What this means for you
Three practical things.
Pass the request on, do not improvise. Editing the record by hand to "erase" a customer leaves the number in place, so it does not erase them.
Serve the copy before the erasure if both are asked for, because the other way round is impossible.
Tell your customer what stays. Their visits stay, anonymous, and there is no way back from them to the person. That is a more honest sentence than "everything has been deleted", and it is the one that is true.
What Kanz collects in the first place, and what it refuses to collect, is in this article.