1. Whose data, and who to ask
Two kinds of data pass through this service, and they are deleted by different people.
Your account data — your name, email address, billing details, sign-in records. We are the controller. Ask us, and we delete it.
Click and visitor data — what your tracking links recorded. You are the controller and we are your processor, so those decisions are yours: you can delete this data from your account, and if one of your visitors asks us to delete something, we refer them to you rather than acting on it ourselves. We cannot make that decision for you; see the Data Processing Addendum.
2. What you can delete yourself
Inside the application, without asking anyone:
- Campaigns, flows, landers and tracking domains.
- Team members and their invitations.
- Signed-in sessions, individually or all at once.
- The whole account. Closing it starts the deletion described in section 5.
Click history also expires on its own, at the end of your plan’s retention period, without anybody having to ask.
3. Asking us to delete it
Write to privacy@utmcap.com from the email address on the account, and say what you want deleted — the whole account, or something specific.
If you write from a different address we will ask you to confirm from the account address, or to answer something only the account holder would know. That is not obstruction: acting on an unverified deletion request is itself a way to lose somebody’s data.
There is no charge, and no form to fill in.
4. If you are a visitor, not a customer
If you clicked an advertisement and want the record of that click deleted, the business that ran the advertisement decides, not us — we hold the data on their behalf and are not permitted to act on it alone.
Write to them. If you do not know who they are but you know the domain the link used, tell us at privacy@utmcap.com and we will pass your request to that customer and tell you that we have. Where the law puts an obligation directly on us, we will meet it.
5. What happens, and when
- We acknowledge within a few days, and complete within one month. If a request is genuinely complicated we will say so before that month is up, rather than after.
- Closing an account starts a 30-day window. The data stays for those 30 days so that a closure made in error, or by somebody who should not have made it, can be undone. Then it is deleted.
- Ask us to skip the window and we will, once we have confirmed the request is genuine. Export anything you want to keep first — after this there is nothing to restore from.
6. What we keep, and why
Deletion means deletion, with two narrow exceptions, both of which we would rather state than have you discover:
- Invoices and payment records, which tax law requires us to keep for a fixed number of years. They contain a name, an address and amounts — not your click data.
- A minimal record that an account existed and was deleted — the identifier and the date. It is what lets us prove the deletion happened, and prevents the same address quietly re-creating something we were asked to remove.
Both are kept under the same protection as everything else, and are used for nothing else.
7. Backups
Encrypted backups are taken daily and roll off on a schedule. Deleted data disappears from live systems immediately and from backups as those age out — we do not open backups to remove individual records, because doing so reliably is not possible and claiming otherwise would be false.
Data in a backup is never restored back into service. If a restore is ever needed, deletions made since that backup are re-applied.
See also the Privacy Policy for what is held and for how long, and the Cookie Policy for what is stored in a browser.