This page explains what personal data HundredFold holds, how to request its deletion, and how we handle deletion obligations that flow from the platforms our customers connect (notably Shopify and Meta). It is written to be plain and accurate; it is not marketing copy.
1. Who we are and our two roles
HundredFold is a multi-tenant business-intelligence and action platform for direct-to-consumer ecommerce brands ("merchants"). A merchant connects their store, ads, email, and inventory data; we turn it into prioritized insights and actions.
Because of how the platform works, HundredFold plays two different data-protection roles, and they determine how a deletion request is handled:
| Data category | Whose data it is | HundredFold's role | Who controls deletion |
|---|---|---|---|
| Account data | The merchant's own team members who log in to HundredFold | Controller | HundredFold (acts on the account owner's instruction) |
| End-customer data | The shoppers of the merchant's connected store | Processor | The merchant is the controller; HundredFold deletes on the merchant's (or a verified end-customer's) instruction, and on platform-mandated webhooks |
Heem Megacorp LLC, 8500 Blazyk Drive, Austin, Texas 78737 · Governed by the laws of the State of Texas, USA.
2. What data we actually hold
We deliberately store very little personal data. Knowing exactly what we hold makes deletion requests easier to scope.
Account data (we are the controller)
HundredFold accounts are invite-only — a merchant's account owner adds team members from an allowlist. There is no public self-serve signup. Authentication is passwordless (a magic link to a work email, or Google sign-in), via Supabase Auth. For each user we store:
- User email address
- Role (owner / admin / member / viewer)
- An internal Supabase user id
We do not store passwords, user phone numbers, user mailing addresses, or any payment/card data for HundredFold accounts.
End-customer personal data (we are the processor)
From a merchant's connected Shopify store, on a per-order basis, we store only:
- The customer's email address
- The shipping city, state/region, and country
That is the complete list of end-customer personal data we hold. We do not collect or store end-customer names, street addresses, phone numbers, payment or card data, or customer profiles. The stored email is used for one purpose: to export win-back audience lists to the merchant's own Klaviyo account.
What we never receive
No end-customer personal data is sent to our AI provider (Anthropic). The AI analyst and daily briefing receive business aggregates only (revenue, ROAS, AOV, inventory summaries, top-ad metrics, customer-health rates, email metrics, replenishment plans) plus the merchant's own written business-context notes — never customer names, emails, addresses, or any API keys, tokens, or secrets. Our connected ad and analytics integrations (Meta, Google, Amazon) provide aggregate metrics, not end-user personal data.
3. Scenario A — deleting an individual end-customer's data
This applies when a single shopper's data should be removed — whether the request comes from the merchant on the shopper's behalf, directly from the end-customer, or via a Shopify customers/redact webhook (see Section 5).
What gets deleted. We locate every order record associated with that customer and redact or purge the only end-customer personal data we hold for them: the customer email address and the shipping city / state / country. Where order records must be retained for the merchant's reporting integrity, the personal fields are irreversibly redacted so the order can no longer be tied to an identifiable person; otherwise the personal data is purged.
Who can request.
- The merchant (the controller of this data), through the account, or
- The end-customer directly. Because HundredFold has no relationship with the merchant's shoppers, we will, where appropriate, route or confirm a direct end-customer request with the relevant merchant, who is the controller. We will not refuse a valid erasure request, but verification may run through the merchant.
How to request. Email admin@gohundredfold.com with enough detail to identify the records — at minimum the customer email address and the store (merchant) the order belongs to.
Timeline (SLA). We complete end-customer redaction within 30 days of a verified request.
4. Scenario B — deleting a merchant account and all of its data
This applies when a merchant closes their HundredFold account, or asks us to delete their organization's data.
What gets deleted. We purge the data belonging to that organization ("org"), including:
- All account data for that org's users (emails, roles, Supabase user ids)
- All end-customer data synced from that org's connected store (the per-order emails and ship city/state/country described above)
- All synced business data for that org (catalog, inventory snapshots, orders, ads/email/analytics metrics, plans, and AI business-context notes)
- The org's integration connections and stored credentials (see Section 6 on token storage)
Because HundredFold is multi-tenant with per-org data isolation, deleting one org does not affect any other merchant's data.
Who can request. The account owner (or an authorized admin) of the org.
How to request. Email admin@gohundredfold.com from the owner/admin address on file, with the subject "Account Deletion Request" and the store/org name.
Timeline (SLA). We complete deletion of an org's data within 30 days of a verified request, excluding the limited retained categories in Section 7.
Disconnecting vs. deleting. Disconnecting an integration (e.g., revoking the Shopify or Google connection) stops new data from flowing in and revokes our access token, but does not by itself delete data already synced. To delete already-synced data, submit a deletion request as above.
5. Shopify mandatory privacy webhooks
HundredFold honors Shopify's mandatory compliance webhooks. When Shopify sends one of these to our app, we act on it automatically:
| Webhook | What Shopify is asking | What HundredFold does |
|---|---|---|
customers/redact | Delete a specific shopper's personal data (typically sent ~10 days after the customer requests erasure, or after an order's retention window) | We redact/purge that customer's stored email and ship city/state/country from all order records for that shop — the same operation as Scenario A. |
shop/redact | The merchant uninstalled the app and 48 hours have passed; delete the shop's data | We purge that shop/org's synced data and credentials — the same operation as Scenario B for that connection. |
customers/data_request | A shopper has requested the data the store holds about them | We compile the end-customer personal data we hold for that shopper (their stored email and ship city/state/country, if any) and provide it to the merchant to fulfill the request, since the merchant is the controller. |
We process these webhooks programmatically; merchants do not need to take any separate action for Shopify-originated requests.
6. A note on stored integration credentials
When an org is deleted (Scenario B / shop/redact), its stored integration credentials are removed along with its data. HundredFold's target architecture stores integration tokens in Supabase Vault by reference (encrypted at rest, with decryption locked to the server role); this is being rolled out and is not yet the active path for every provider — some credentials currently live in server environment variables or, for some OAuth providers, in database columns. Regardless of storage location, deleting an org removes that org's stored credentials, and disconnecting an integration revokes the associated access token.
7. What we retain after a deletion, and why
A deletion request removes the personal data described above. A limited set of records may be retained for a limited time:
- Backups. Our managed database provider keeps automated backups / point-in-time recovery. Deleted data may persist in encrypted backups until those backups roll off on their normal cycle, after which it is overwritten. Retained backup data is not restored into active use except for disaster recovery.
- Legal, tax, and accounting records. We may retain limited records where a legal, tax, or accounting obligation requires it.
- Security and abuse logs. Minimal operational logs may be retained for security purposes.
HundredFold does not currently apply automated, age-based deletion to data that is not the subject of a deletion request; such data is otherwise retained for as long as the account is active.
8. Meta / Facebook — data deletion instructions
This page is HundredFold's stable Data Deletion Instructions URL for the Meta platform.
HundredFold's Meta integration reads aggregate advertising metrics (spend, impressions, clicks, ROAS, placement breakdowns) and can optionally create paused draft ads for the merchant to review; it never publishes live ads and never receives end-user personal data from Meta.
To request deletion of any data associated with your HundredFold account, including data obtained via Meta login or the Meta integration:
- Email admin@gohundredfold.com with the subject line "Meta Data Deletion Request."
- Include the email address associated with your HundredFold account and, if applicable, the connected store/org name.
- We will confirm receipt, verify the request, and complete deletion within 30 days, then confirm completion to you.
9. Sub-processors involved in deletion
When we delete data, the deletion propagates to the infrastructure sub-processors that hold it on our behalf: Supabase (managed Postgres database + authentication — holds app data and user emails), Vercel (app hosting and scheduled jobs), and, where applicable, the limited operational records noted in Section 7. Our other sub-processors (Anthropic, Higgsfield, Resend) do not retain end-customer personal data: Anthropic receives only business aggregates, Higgsfield receives only product images and prompts, and Resend sends warehouse/operational email containing no end-customer personal data. Klaviyo receives customer emails that we export to build win-back lists; data already delivered into the merchant's own Klaviyo account is controlled by the merchant under Klaviyo's terms, and the merchant manages deletion there. Provider hosting region: United States (confirm per provider before publication).
The platforms a merchant connects as data sources — Shopify, Meta, Google, Amazon — are governed by their own terms and are not HundredFold infrastructure sub-processors. See our full Sub-processors list.
10. Your rights and how we verify requests
Depending on your location, you may have rights to access, correct, delete, or port your personal data (for example under GDPR or CCPA/CPRA).
To protect against unauthorized deletion, we verify the identity and authority of every requester before acting — for end-customer requests this may involve confirming with the relevant merchant (the controller). We will acknowledge a request promptly and complete it within the SLAs stated above.
Contact: admin@gohundredfold.com · Heem Megacorp LLC, 8500 Blazyk Drive, Austin, Texas 78737.