Data Deletion Policy
Effective date: August 25, 2026
1. How to delete your account or request deletion
- Students: sign in and open Settings → Account, then select Delete account. In the mobile app, open Account → Privacy → Delete my account. You must confirm your password.
- Organization administrators: sign in and open Organization Settings → Close account. You must confirm your password and organization name. Funded escrow and open invoices must be resolved first so deletion does not strand money or records.
- Anyone, including former users: email general@sherbet.io with the subject “Data deletion request.” Tell us the email address associated with the data and what you want deleted. Do not send a password, Social Security number, or identity document by email. We will request only the additional information reasonably needed to verify the request.
2. What happens when an account is deleted
We promptly disable access, revoke active sessions and connected social-account tokens, and remove or anonymize personal information in our active systems. This includes names, email addresses, phone numbers, profile and demographic details, addresses, social handles, profile photos, device push tokens, and other information that is no longer needed.
Records that must remain connected for campaign or financial integrity are changed to non-identifying placeholders such as “Deleted User.” Anonymized information that can no longer reasonably be linked to you is not personal data.
3. What may be retained
- Payment, invoice, escrow, and related tax records are retained for at least seven years from the transaction where needed for tax, accounting, fraud-prevention, or legal obligations.
- Campaign deliverables and signed agreements may remain as anonymized business records where needed to document completed work, licenses, payment obligations, or legal claims.
- A minimal record of the request and our response may be retained to demonstrate compliance and prevent a deleted account from being silently reactivated.
- Residual copies may remain temporarily in access-restricted backups until overwritten through the provider’s ordinary backup cycle. They are not used for ordinary business purposes, and completed deletion requests are re-applied if a backup is restored.
The right to deletion is not absolute. We may deny or limit a request where retention is required or permitted by law, including to complete a transaction, protect security, comply with a legal duty, or establish, exercise, or defend legal claims. If that happens, we will explain the reason unless the law prevents us from doing so.
4. Timing and service providers
Self-service account deletion begins immediately. For emailed requests, we will acknowledge receipt within five business days and respond within the deadline that applies to you: generally one month under the GDPR or UK GDPR, 45 days under the CCPA, and 45 days elsewhere. Law may permit an extension; if we use one, we will notify you within the original response period.
Where required, we also instruct service providers and other recipients that hold the affected personal data for us to delete or update it. Their systems and legally required retention may affect when every residual copy is overwritten.
5. Questions and complaints
Contact Sherbet Solutions, Inc., the data controller, at general@sherbet.io or (650) 815-9473. You may also have the right to complain to your local privacy regulator or seek a judicial remedy.