Data Deletion Instructions

How to delete data we hold about you, your organisation, or a connected platform account.

Last Updated: May 13, 2026

xTrac AI is operated by iEllipse Technologies (a partnership firm registered in India). For a full description of what data we collect and why, see the Privacy Policy. The instructions below apply to both the self-hosted (BYOG) and cloud-managed deployment models, and satisfy the data principal rights provisions of India's Digital Personal Data Protection Act, 2023.

1. Disconnect a Single Integration

If you only want to remove data for a specific connected account (for example, your Instagram Business account) without deleting your xTrac organisation:

  1. Sign in at business.xtrac.app.
  2. Open Integrations from the left navigation.
  3. Find the connected account you want to remove and click Disconnect.
  4. Confirm the disconnect dialog.

Effect:

  • Your access tokens for that platform are revoked and deleted from our key vault.
  • We stop receiving new data from that platform within minutes.
  • Cached platform data (messages, comments, insights, media metadata) is deleted within 30 days.
  • Audit logs of agent actions taken while the integration was active are retained for up to 12 months for security and compliance, then anonymised.

2. Delete Your Entire xTrac Account

If you want to delete your xTrac organisation and all associated data:

  1. Sign in at business.xtrac.app.
  2. Open SettingsOrganisation.
  3. Scroll to Danger zone and click Delete organisation.
  4. Type the organisation name to confirm.

Effect:

  • All connected integrations are disconnected and tokens revoked immediately.
  • Account data (users, agents, configuration, knowledge base) is deleted within 30 days.
  • Encrypted backups are overwritten within 35 days.
  • Audit logs are anonymised after 12 months.
  • Billing records are retained as required by tax law (typically 7 years), with personal identifiers stripped where possible.

3. Revoke Access from the Platform Side

You can also revoke xTrac's access from the connected platform itself. This is independent of the steps above and we recommend doing it as well.

📷 Instagram

  1. Visit instagram.com/accounts/manage_access/.
  2. Find xTrac in the list and click Remove.

Within 30 days of you revoking access, we delete all cached Instagram data for that account.

💬 WhatsApp Business

  1. Open Meta Business Manager → Business SettingsAccountsWhatsApp Accounts.
  2. Select your WhatsApp Business Account → People and assets → remove xTrac.

🛍️ Shopify

In your Shopify admin: Apps → find xTrac → uninstall.

✉️ Gmail / Google Workspace

Visit myaccount.google.com/permissions and remove xTrac.

4. Email-Based Deletion Request (Last Resort)

If you cannot sign in to your account or the platform self-service options do not work, email support@xtrac.app with:

  • The email address associated with your xTrac account, OR
  • The connected platform identifier you want deleted (Instagram username, WhatsApp Business Account ID, Shopify shop domain, etc.)
  • A clear statement of what you want deleted.

We will:

  1. Confirm receipt within 2 business days.
  2. Verify your identity (so we don't delete the wrong person's data).
  3. Complete the deletion within 30 days of verification.
  4. Send you written confirmation when deletion is complete.

For Meta Platform Users

Per Meta's Platform Terms, we honour data deletion callbacks initiated through Meta's Data Deletion Request infrastructure. When Meta sends us a deletion signal for your account, we delete the corresponding data automatically within 30 days, with no action required from you.

What We Cannot Delete

A few categories of data are retained by law or for system integrity:

  • Billing and tax records, retained as required by applicable tax law (typically up to 7 years).
  • Audit logs of safety-relevant or legally relevant actions, retained for the duration required by law or our incident response policy.
  • Aggregated, non-identifying analytics that cannot be traced back to you.
  • Backups already overwritten by the time we receive your request (we cannot restore them just to delete data from them; backups age out on their own retention schedule of 35 days).

Contact