پرش به محتوا

Account Deletion Policy

GDPR / KVKK — Right to Erasure

Last updated29 September 2026

1. How to request deletion

There are three ways to delete your account:

1. Self-service (recommended): Dashboard → Settings → Privacy → "Permanently delete account".
2. Email: Write to contact@synaltix.io from your registered email with subject "Account deletion request".
3. Post: Synaltix LLC, Albuquerque NM, USA.

We send an email verification link within 24 hours.

2. 30-day grace period

GDPR / KVKK
When you click the link in the confirmation email you are taken to a confirmation page where, after re-authenticating, you must press "Delete my account" to actually start the deletion. We deliberately separate the email link (a GET that renders a form) from the deletion action (a POST that the form submits) so email-prefetching crawlers cannot trigger unintentional deletion (RFC 9110 §9.2.1). After you press the button, a 30-day grace period begins.

Sign in again during this window and the deletion is automatically cancelled — your account is fully restored. After 30 days, deletion is irreversible.

If you are making a GDPR Art. 17 erasure request rather than voluntarily closing an account, we complete it within the one month set by Art. 12(3); the grace period does not extend that deadline. Just say so in your request.

3. Data that gets deleted

After 30 days the following is permanently erased:

• User profile (name, email, phone)
• Restaurant records (name, address, description)
• Menus, categories, products
• Product photos (including Cloudflare R2)
• Order history (except anonymized aggregate stats)
• Customer feedback, likes
• Staff records, audit log
• Stripe Customer ID (your Stripe Connect account is untouched — you close it yourself)
• Affiliate referral records

4. Data we are legally required to keep

GDPR / KVKK
The following is retained for fixed periods under law (the longest applicable period applies):

• Invoices / payment records: 7 years (US IRS / state); up to 10 years (EU VAT and Turkish TTK Art. 82 commercial books / VUK Art. 253 tax records)
• Tax documents: 7 years (W-9, W-8BEN, 1099-NEC, etc.)
• Legal-proceedings records: until any active matter is closed and the applicable statute of limitations has run
• Anonymised aggregate analytics: indefinitely (no personal data)

This data lives in an access-restricted archive and is deleted when its retention period expires.

5. Affiliate / Synaltix agreements

If you have an affiliate account: pending commissions for your referrals are settled before deletion. If you have a pending payout, deletion runs after the final payout is sent.

If there is an active contract / proposal / MoU, related data is kept until the contract expires or is terminated.

6. Third-party data deletion

When we receive your deletion request, we also trigger deletion at:

• Stripe: Customer record is deleted (Stripe keeps transaction history for 7 years — they're required to)
• Supabase Auth: User record is deleted
• Cloudflare R2: All your uploaded images are deleted
• Resend: Email send logs auto-delete in 30 days anyway
• PostHog/Sentry: User ID is anonymized

Per GDPR Article 17(2) we notify these parties of your erasure request.

7. Verification & security

Deletion requests are sensitive, so they take two independent confirmations — note this is a two-step confirmation flow, not two-factor authentication (2FA) in the security sense:

1. Request must come from the registered email
2. Email verification link (valid 24 h)
3. 30-day grace period — gives you a second chance to sign in

A third party (e.g. former co-founder) cannot delete on your behalf — you must control the registered email.

8. Children's data

The minimum age to hold a Thmenu account is 18 (or the local age of majority) because an account is a commercial contract — the full position, including the GDPR Art. 8 digital-consent ages, is in §10 of our Privacy Policy, which is canonical. We do not knowingly process personal data of anyone under 16. If you become aware that a child has registered, email contact@synaltix.io — we delete the account immediately, no verification needed.

9. Contact & complaints

Questions or complaints about deletion:

• Email: contact@synaltix.io
• EU: your local DPA (data protection authority)
• Turkey: KVKK Board — kvkk.gov.tr
• US: California residents — same address for CCPA rights.

10. Thmenu guest app (diner profile)

This section covers the Thmenu app you use to view restaurant menus, and the optional diner profile on menu.thmenu.com (email link or Google sign-in). Restaurant-owner accounts are covered by sections 1–9 above.

How to delete: in the Thmenu app or on menu.thmenu.com open Profile → sign in → "Delete my account" → type "DELETE" to confirm → confirm. Deletion takes effect immediately; there is no grace period. If you have no profile or cannot sign in, email contact@synaltix.io with the subject "Guest data deletion request".

Deleted: your diner profile, sessions, profile activity, email sign-in links, notification subscriptions tied to your orders and your feedback messages.

Anonymised: name, email and phone on reservation and loyalty-program records that match your profile's email address, and name and email on dish suggestions; contact details on allergen-incident records of orders linked to your profile (the restaurant keeps the food-safety record without personal data).

Kept by the restaurant: orders you placed are the restaurant's transaction records; the link to your profile is removed; served and cancelled orders are deleted automatically by the monthly clean-up once they are 6 months old. Product likes are anonymous records tied only to a browser fingerprint, not to your profile; because they cannot be linked to you, this action does not delete them.