Data Deletion Request
Last updated: August 1, 2026
This page explains how to delete your Anilfy.com (by Anil Kumar Kanneboina) ("Anilfy.com") account and the data we hold about you or your business. There are three ways to do it — pick whichever suits you. You do not need to give a reason, and we do not charge for it.
Choose how to request deletion
Option 1 — Delete it yourself (fastest)
If you can sign in, this is immediate and needs no email exchange.
- Sign in and go to Settings (cthe.link settings for bio-link accounts).
- Scroll to the Danger zone card and choose Delete my account.
- Confirm by typing your workspace slug and re-entering your password. We ask for both because deletion is irreversible after the grace period.
Your public pages go offline immediately. The 30-day grace period below then applies, and a Cancel deletion button appears in the same place for as long as it lasts.
Option 2 — Email us (no login needed)
Use this if you have lost access to your account, or you are a customer of a business that uses Anilfy.com rather than an account holder yourself. Email [email protected] with the subject line "Data Deletion Request" and include:
- The email address associated with the account
- Your business / workspace name
- If applicable, the Facebook or Instagram account used to sign up, so we can verify ownership
- If you are a customer of a business using Anilfy.com: the phone number or email that business holds for you, and the business's name
We verify ownership before acting — usually by asking you to reply from the account email. We acknowledge within 3 business days and complete verified requests within 30 days.
Option 3 — From Facebook or Instagram
If you connected Anilfy.com through Facebook or Instagram, you can remove it from Facebook Settings → Apps and Websites. Meta notifies us automatically and we revoke the connection and delete the associated Meta data. Meta gives you a confirmation code — you can check what we did with it at the deletion status page.
What happens after you request
| When | What happens |
|---|---|
| Immediately | Public pages (bio link, catalogue, website) go offline. Billing stops. WhatsApp and Instagram access tokens are revoked so we can no longer message on your behalf. |
| Days 1–30 | Grace period. Your data still exists and the request can be cancelled — in-app, or by replying to our confirmation email. Nothing is permanently removed yet. |
| Day 30 | An automated job permanently deletes your workspace and everything listed below. This cannot be undone. |
| After deletion | We email you a confirmation that it is done. |
What gets deleted
- Your Tenant record + all team-member links
- All contacts, leads, customers, vendors imported or created in Anilfy.com
- All inbound + outbound messages across WhatsApp, Instagram, SMS, and email
- All bookings, quotations, loyalty records, and the contact/customer records behind them. Financial records (orders, payments, refunds, and tax/GST invoices) are anonymized and retained rather than deleted where the law requires it — see "Retention exceptions" below
- All WhatsApp templates (deleted from our DB; Meta copies require separate deletion via your WABA)
- All automation rules, campaigns, audience segments
- All media uploaded via Anilfy.com (product images, business logos, broadcast media)
- All SEO pages, bio links, and public catalogue pages you created
- All integration connections (Shopify, WooCommerce, Google Sheets, Instagram, Stripe/Razorpay)
What Anilfy.com cannot delete on your behalf
- Your WhatsApp Business Account (WABA) and Instagram Business account — these are yours and live on Meta's servers. To delete them, visit business.facebook.com or use the Instagram app. Anilfy.com disconnects from them on your deletion; we do not own them.
- Payment-gateway records held by Razorpay, Stripe, or PhonePe — contact each gateway to request their own deletion. On our side, the direct identifiers we held (bank UTR / reference numbers and gateway transaction IDs) are removed when we process your deletion; only the amount, date, and invoice number are kept, and only for the statutory retention window described below.
- Meta-side conversation data that WhatsApp itself retains (24h conversation windows, template approval history). This is governed by WhatsApp's privacy policy, not ours.
Retention exceptions
We retain a minimal set of records longer than 30 days only when required by Indian law:
- Financial records — orders, payments, refunds, and tax/GST invoices. These are kept for 8 years (the longer of the Income Tax Act's 8-year and the CGST Act's 6-year requirements). We do not keep only a single invoice snapshot — the order, payment, refund, and invoice rows themselves are retained so the accounts reconcile. But before we retain them we anonymize each one: we sever its link to you, and remove the direct identifiers — customer name, phone, email, bank UTR / payment reference numbers, gateway transaction IDs, and any free-text notes — keeping only the fiscal detail the law requires (invoice number, date, GST breakdown, line items, amounts). Any payment-proof screenshots you or your customers uploaded are deleted.
- Aggregate, anonymised usage statistics (no PII)
These records are inaccessible through the app once your tenant is deleted, and are not exposed to staff except under legal compulsion. A time-based job permanently deletes the anonymized financial records once the retention window closes. Tenants operating in a jurisdiction with no such mandate can configure this window (or opt into full deletion) in their data-retention settings.
Third-party API data (Meta platform rules)
When you connect WhatsApp or Instagram via Anilfy.com, Meta sends us message events and contact metadata as you interact with your customers. Meta requires us (and we commit to):
- Delete this data within 30 days of your account deletion request
- Not use it for any purpose outside the service Anilfy.com provides to you
- Honour any user-initiated data-subject access or deletion request passed on by Meta
Your other rights
Deletion is one of several rights you hold. You may also request access to the data we hold about you, correction of anything inaccurate, a portable copy of it, or restriction of how we use it. Use the same address and subject line as Option 2 above.
Where the GDPR applies, you additionally have the right to lodge a complaint with your local supervisory authority. In India, the Digital Personal Data Protection Act, 2023 gives you the right to escalate to the Data Protection Board of India if we do not resolve your request satisfactorily. We would rather fix it first — please contact us before escalating so we have a chance to.
Contact
For any questions about this deletion process, email [email protected]. We reply within 3 business days.
Related policies: Privacy Policy · Terms of Service · Deletion status lookup