When someone asks us to delete their data, we delete or anonymize what we can, and keep only what the law requires us to keep — mainly payment and invoice records — responding within GDPR's one-month window.
The right to erasure
Under GDPR's "right to erasure" (Article 17), individuals can ask us to delete their personal data when we no longer need it, or when they have withdrawn consent. This right is not absolute: legal obligations, such as financial record-keeping requirements, can override it.
How to make a request
Email [email protected], or ask through any of our support channels.
Our process
When we receive a deletion request, we:
- Verify the requester's identity
- Check what data exists across their account, campaign, and transaction records
- Delete or anonymize what we can
- Flag anything we are required to retain
- Confirm back to the user what was done
What we delete, and what we keep
We delete straight away the data that has no financial or legal purpose, such as marketing data, tracking cookies and optional profile details.
Payment transaction records and invoices are different. Tax law requires us to keep them for seven years in the Netherlands, where WhyDonate is based, and GDPR allows this because keeping them is a legal obligation (Article 6(1)(c)). A deletion request cannot remove them before that period has passed. Our Data Processing Agreement also states that data is deleted or returned upon termination, unless retention is required by law.
Data held by Stripe
Stripe processes the payments and verifies organizers' identities, and it is an independent controller of that data. By default it keeps identity verification data for seven years. You can also send a deletion request to Stripe directly, at [email protected]. See Stripe's guidance on verification data.
Response time
We aim to respond to deletion requests within one month, in line with GDPR requirements.