How a visitor asks for their data to be erased, what you have to do, and what we delete.
If someone who chatted with your agent asks you to delete their data, this is the path.
Open Settings, then Privacy (owners only).
Who is responsible
For conversations on your site, you are the controller and we are the processor. That means a visitor's erasure request is yours to action, and we route it to you rather than acting on it ourselves.
We deliberately do not delete a visitor's records on our own initiative. Doing so would destroy your records without your instruction, and our data processing agreement commits us to notify you rather than to respond to the visitor directly.
How a request arrives
A visitor asks at hey.support/delete-my-data.
- They enter their email address.
- We email that address a single-use confirmation link. Nothing happens until they click it, and the page only reads — the request is sent by a button, so a link scanner cannot fire it.
- We find every workspace holding data for that address and open one request against each.
- The owners of each workspace are emailed and the request appears on the Privacy tab.
The form gives the same answer to every submission — a known address, an unknown one, or a repeat. That is on purpose: a different response would turn it into a way of testing whether a given person is one of your customers.
Actioning a request
The Privacy tab lists open requests. Erasing deletes, for that person in your workspace:
- their conversations and every message in them
- any leads created from those conversations
- any bookings tied to them
We delete rather than anonymise. Visitors routinely put their name, address and order details in the message body, so blanking an email field would not actually anonymise anything.
When the last workspace holding their data has actioned the request, the visitor gets a written confirmation.
What is not covered
Some things genuinely cannot be found or are yours rather than theirs, and we say so rather than implying otherwise:
- Anonymous conversations. Someone who chatted without ever giving an email cannot be identified from an email address.
- Content you wrote. A quick answer you authored after seeing a question, or a knowledge chunk you added, belongs to your workspace and has no link back to the person who prompted it.
Backups
Backups roll on a seven-day window, so a deleted row falls out of every surviving backup well inside the timeframe we commit to. If a backup is ever restored, re-applying completed erasures is a required step of that restore.