Data Deletion Instructions

For users and Facebook App Review

Last updated: 2026-01-29

For Facebook / Meta App Review

Use the information below when Facebook asks for your "Data Deletion Instructions URL" or "User Data Deletion Callback URL". This page explains how users can request deletion and how our app handles deletion requests in a way that complies with Meta's requirements.

  • Data Deletion Instructions URL (this page): use your production URL, e.g. https://yourdomain.com/data-deletion
  • User Data Deletion Callback: configure in your backend (see Section 4 below) and set it in App Dashboard → Settings → Basic → User Data Deletion.

1. Overview

Real Estate CRM ("we", "the App") allows users to request deletion of their personal data stored by our application. This includes data received from or associated with Facebook (Meta) when you use Facebook Login or our WhatsApp/Meta integrations. We process deletion requests in line with applicable law and Meta's Platform Terms and data deletion requirements.

2. How Users Can Request Data Deletion

Users can request deletion of their data in the following ways:

  • In-App (recommended): Log in to your Real Estate CRM account, go to Settings (or Account/Profile), and use the "Delete my account" or "Request data deletion" option. Follow the on-screen steps to confirm. We will process the request and send a confirmation email when the deletion is complete.
  • By email: Send a data deletion request to the contact email we publish on our website or in the App (e.g. support@yourdomain.com or the email shown in the App dashboard). Include: (1) the email address associated with your account, (2) your full name, and (3) a clear statement that you want to delete your account and all associated data. We may ask you to verify your identity before processing.
  • Via Facebook: If you originally signed in with Facebook and later request deletion through Facebook's flow (e.g. when removing our app from your Facebook account), we will receive a callback from Facebook (see Section 4). We will then process the deletion as described below.

We will process valid deletion requests within 30 days (or within the timeframe required by applicable law, e.g. 30 days under Meta's requirements). We will send a confirmation to your registered email once the deletion is complete, unless we no longer have a valid email for you.

3. What We Delete

When we process a data deletion request, we delete or anonymize the following:

  • Account data: Your account profile (name, email, organization membership), login credentials, and preferences.
  • Facebook/Meta-related data: Your Facebook User ID, name and email received from Meta, profile picture URL, and any stored Meta access tokens or refresh tokens associated with your account.
  • WhatsApp connection data: WhatsApp Business Account IDs, Phone Number IDs, and related tokens and metadata that we stored for your connected WhatsApp number(s).
  • CRM data you own: Leads, contacts, notes, and other CRM records that are linked to your user account or organization and that we can attribute to you. If you are the only member of an organization, we delete the organization and its data. If the organization has other members, we remove you from the organization and may retain organization data as needed for the remaining users.
  • Logs and caches: Where technically feasible, we purge or anonymize logs and cached data that contain your personal information, subject to retention needed for security, legal compliance, or backup (see below).

We may retain the following for a limited time where required:

  • Copies necessary to comply with legal obligations (e.g. tax, litigation).
  • Anonymized or aggregated data that no longer identifies you.
  • Backup copies that are overwritten in the normal course of our backup cycle (typically within 90 days).

After deletion, you will no longer be able to sign in or recover your data. If you use Facebook Login and we delete your data, you may need to re-authorize our app if you create a new account in the future.

4. User Data Deletion Callback (Facebook)

To comply with Meta's requirement for "User Data Deletion Callback", our backend exposes an endpoint that Facebook can call when a user requests deletion of their data from our app via Facebook's flow (e.g. when the user removes the app from their Facebook account or uses Facebook's data deletion tool).

Callback URL format: Our server implements a POST endpoint that accepts Facebook's signed request (signed_request parameter). Example (replace with your production API base URL):

https://your-api-domain.com/api/facebook/deletion-callback

We:

  • Verify the request signature using our Meta App Secret.
  • Parse the Facebook User ID (and any other identifiers) from the signed request.
  • Locate the user in our system (by linked Facebook User ID) and delete or anonymize all associated personal data as described in Section 3.
  • Return a JSON response with a confirmation URL that Facebook can show to the user (e.g. this Data Deletion page or a "Deletion complete" page).

In the Meta App Dashboard, you must add this callback URL under Settings → Basic → User Data Deletion (or the equivalent section for your app type). Facebook will send requests to this URL when users trigger data deletion from their side. Our backend documentation (for developers) contains the exact route and request/response format.

5. Contact for Deletion Requests

If you have any questions or need help with a data deletion request, contact us:

Use the contact email published on our website or in the App (e.g. support@yourdomain.com, or the email displayed in your App dashboard).

Include "Data Deletion Request" in the subject line and your account email so we can process your request quickly.

6. Summary for App Review

  • Instructions URL: This page (your production domain + /data-deletion).
  • How users request deletion: In-app option, email, or via Facebook's flow (callback).
  • What we delete: Account data, Facebook/Meta-related data, WhatsApp connection data, user-owned CRM data; logs/caches purged where feasible.
  • Timeline: Within 30 days (or as required by law/Meta).
  • Callback: We implement User Data Deletion Callback and process Facebook-sent deletion requests as described in Section 4.