What happens when a client asks us to delete their data
A client can request deletion from their own account, confirm it by email, and change their mind for 48 hours. Here is the whole lifecycle, including what stays behind and why.
Sooner or later a client asks you to delete their data. Under GDPR they are entitled to, and in most booking tools that request lands as an email you now have to act on by hand: dig out their records, work out what you are actually allowed to remove, and remember to reply before the legal clock runs out. We built this differently. In Bookatu the whole thing runs as a proper lifecycle, and this post walks through it exactly as it happens, because if you run a salon in Europe you should know precisely what your software does in your name.
It starts in their account, not your inbox
Every client with a booking history at your salon has their own account on your booking page. Alongside their appointments and gift cards sits a Privacy section with two entries: Download my data and Delete my data. The download is instant and self-explanatory. The deletion is a bigger deal, so it starts with an explanation instead of a button.
Before anything is armed, the screen says in plain words what will be erased: their profile, visit history, photos, forms, messages and reviews. It also says what will not be erased and why, so nobody discovers the tax-law part after the fact. Then comes the first check. To submit the request, the client types their own name, exactly as it appears on their account. A typo does not pass. That is a small hurdle for someone who means it, and that is the point: it filters out the idle tap without slowing down a real decision.
The email double-check
Submitting the form deletes nothing. Bookatu emails the address on the client's file with a confirmation link, and the request only moves forward once that link is tapped. This is the identity check: whoever asked also has to hold the inbox. If the link is never tapped, the request quietly expires after 48 hours and the account stays exactly as it was.
Tapping the link opens a page that states, one more time, what is about to happen. Two buttons: confirm the deletion, or cancel the request on the spot.
48 hours to change their mind
Even after the email is confirmed, nothing runs for another 48 hours. The client's account shows the exact date the erasure will happen and a large Cancel button that works until that moment. People do change their minds. A regular who asked for deletion in a moment of frustration can undo it a day later with one tap, and nothing is lost, because nothing had been removed yet.
When the window ends, Bookatu checks the account once more before running. If something changed in the meantime, say the client booked a fresh appointment during the cooling-off, the request does not run blindly. It moves to your queue instead, with the reason stated.
The whole lifecycle at a glance
- 01They ask
From the Privacy section of their own account, typing their name to confirm they mean it.
- 02They confirm by email
A link goes to the address on their file. Nothing happens until it is tapped, and an untapped link expires after 48 hours.
- 03They can change their mind
A 48 hour cooling-off window with a Cancel button, and the exact run date shown in their account.
- 04The erasure runs
The account is checked again, personal data is removed, and financial records are kept with the personal details stripped.
- 05Everyone gets a record
The client receives a confirmation email, and the completed request stays in your dashboard with its dates.
What is erased, and what stays
When the request completes, the client's profile and contact details are permanently deleted, along with their visit history, photos, form responses, messages and reviews. Past appointments stop being about a person and become anonymous entries, so your reports still add up but no longer say who sat in the chair.
What you see on your side
Every request appears on the Privacy and security screen of your dashboard from the moment it is raised. You can see where each one stands: waiting for the email confirmation, in its cooling-off window, held for your review, completed, cancelled or expired. Each active request also carries a quiet countdown, because GDPR expects a response within a month and the screen keeps you honest about it.
Most requests never need you at all. The ones that do are held with the reason in plain words: the client still has an upcoming appointment, still owes money, or still has an active saved-card agreement with you. Once that is settled, you complete the request yourself. Before anything runs you see a preview of exactly what will be deleted and what will be kept with the personal details removed, and then you type the client's name to confirm. The same ritual the client went through, on your side of the counter.
A deletion request is not an accusation. It is a client exercising a right, and good software makes that unremarkable.
If you want the full picture of what Bookatu handles under GDPR, including the instant data download and the export of your own business, we wrote a companion piece for owners, GDPR without the panic, and the page at bookatu.com/gdpr walks through the same flows with the actual screens. The short version is simple: when a client asks to be forgotten, your software should already know what to do.