# When a customer asks you to erase their data

> Kanz makes the record anonymous instead of deleting it, and that is not a shortcut: a real delete would rewrite your verified history and your bill where nobody could see it.

- Source: https://usekanz.com/en/blog/erasing-a-customers-data
- Language: en
- Other languages: [fr](https://usekanz.com/blog/effacer-les-donnees-d-un-client), [ar](https://usekanz.com/ar/blog/mahw-bayanat-zaboon)
- Format: Markdown, generated from the same source as the page.

- Published: 2026-09-23
- Author: Kanz
- Topics: Privacy, Data, Product
- Reading time: 4 min

A customer asks to be deleted, and the honest answer is not a `DELETE`. Their first name,
email address and birthday are emptied, and their number is replaced by an opaque
identifier that leads nowhere. None of it can be recovered.

Their visits stay, with nothing left attaching them to a person: once there is no reachable
number, no name, no address and no date of birth, what remains is not personal data any
more, it is an anonymous visit in a history.

## Why not a real delete

Because a real delete would destroy things that do not belong to that person.

Visits, proofs of return, issued cards, referrals and game plays all hang off the customer
record. Delete the record and they go with it. Your verified revenue history would be
rewritten, and, more to the point, your **number of active customers** would change.

That number is a billing input. In plain terms: a business could drop a plan tier because
somebody with no connection to it exercised a right. And since the row would be gone,
nobody could see it afterwards. An invisible side effect on a bill is worse than a visible
one.

Irreversible anonymisation satisfies the right to erasure without doing any of that. It is
the correct answer, not the convenient one.

## What gets erased, precisely

| Data | What happens to it |
| --- | --- |
| Phone number | Replaced by an opaque identifier, with no link to the original |
| First name, email, birthday | Emptied |
| What Kanz had noted about them | Emptied |
| Messages sent | Recipient and content erased |
| Cards in their wallet | Invalidated; the card stops working |
| Contact status | Unsubscribed, permanently |
| Visits and proofs of return | Kept, anonymous |

Two rows of that table are worth a word of explanation.

**The number is replaced, not emptied.** It becomes an opaque identifier rather than
nothing at all, and that is not technical squeamishness. A business can hold only one
record per number. Leave the field empty and the slot stays occupied by a ghost, so the
same person could never sign up with you again. Replacing it frees the slot: if they come
back one day and sign up afresh, they start from a new record, with nothing tying it to the
old one. That is exactly what "erased" ought to mean.

**The unsubscribe is set on the way through**, and it is final for that record. Nothing can
lift it, no setting on your side and no request to Kanz. The only person who can come back
is the customer, by signing up again, which creates the fresh record described just above.
And even once anonymised, the old record keeps the mark that stops any campaign from
targeting it: the protection does not depend on the fields being empty.

## What survives, and why that is right

One row always survives: the one saying the erasure happened, when, and at whose request.

That surprises people, and it is the opposite of a contradiction. Without that trace,
nobody can answer "you were erased, and here is when" a year later. A deletion that leaves no proof
of itself is a deletion you cannot demonstrate, which is the one case where somebody will
ask you for it again.

## Before erasing: the customer is entitled to a copy

These are two different requests and they should not be run together. "Send me what you
hold on me" and "delete everything" do not call for the same answer, and the first has to
be served before the second, since afterwards there is nothing left to send.

The copy holds everything: the profile, every dated consent, every visit, every message
received, the cards, the reward codes, the referrals and the returns they left. It also
holds their number in the clear, which is the only place in the product where that is true.
That is deliberate: the document goes to the person who, by definition, already knows their
own number.

## Who presses the button, honestly

Not you. That part is done by Kanz, not from your panel, and it is better to know before
the request lands on you.

The copy of the data can be produced by support, because an access request has a legal
deadline and must not wait on an escalation. Erasure needs the highest level of
authorisation, a written reason, and the customer's **full phone number** typed in to
confirm.

That last requirement is not ceremony. Everywhere else in the admin console, numbers are
masked. So you have to hold the number already in order to erase somebody, and you only
hold it if the request came in. Nobody can erase a customer they merely came across while
scrolling through a list.

## What this means for you

Three practical things.

**Pass the request on, do not improvise.** Editing the record by hand to "erase" a customer
leaves the number in place, so it does not erase them.

**Serve the copy before the erasure** if both are asked for, because the other way round is
impossible.

**Tell your customer what stays.** Their visits stay, anonymous, and there is no way back
from them to the person. That is a more honest sentence than "everything has been deleted",
and it is the one that is true.

What Kanz collects in the first place, and what it refuses to collect, is
[in this article](/en/blog/loyalty-card-customer-data).

## Create an account

The trial runs 30 days and asks for no card.

- [Sign up](https://usekanz.com/signup)
- [Merchant panel](https://usekanz.com/panel)
