Legal

Data Deletion Policy

How to delete Vertex CRM data and how Meta / Facebook data deletion callbacks are handled.

Reviewed August 2026

1. Overview

This Data Deletion Policy explains how Vertex CRM handles requests to delete personal data, including Meta / Facebook data deletion requests required for App Review. It should be read with our Privacy Policy and Data Retention Policy.

2. Roles

  • Customer organization (tenant): typically the data controller for CRM business records (leads, contacts, deals) entered or ingested into their workspace.
  • Vertex CRM / OctaVertex Media: processes tenant data to provide the Service, and operates the Meta application that customers authorize.

3. How to request deletion

3.1 End users inside a customer workspace

Contact your organization’s Vertex CRM administrator first. Administrators can deactivate users, remove records they control, and disconnect Meta integrations under Setup → Integrations.

3.2 Organization / account deletion

Organization admins (or contractual contacts) may request workspace closure and deletion of tenant data by contacting us via /contact. We will confirm identity/authority, export options if contractually available, then delete or anonymize tenant data subject to legal retention needs (billing, security logs, dispute records).

3.3 Meta / Facebook “Apps and websites” deletion

If you remove Vertex CRM from your Facebook settings and request data deletion, Meta sends a signed request to our callback. We:

  1. Verify the signed request with our Meta App Secret
  2. Delete OAuth tokens and Meta-connected account rows associated with that Facebook user id
  3. Delete synced Meta campaign cache linked to those connections
  4. Return a confirmation code and status URL

Status URL pattern: /meta/data-deletion/status?code={confirmation_code}

Callback URL (configure in Meta App Dashboard): https://vertexcrm.in/meta/data-deletion (or your deployed origin + /meta/data-deletion)

4. What Meta deletion removes vs keeps

Removed: Meta access tokens, Page/Ad Account connection records for that Facebook user, synced Meta ads campaign cache for those connections.

Not automatically removed: CRM business records the tenant already stored (for example a lead created from a Lead Ad or WhatsApp message). Those remain under the tenant’s control and retention policy until the tenant deletes them or requests organization-level deletion. This is intentional: in a B2B CRM, deleting a Facebook user’s app authorization must not silently wipe another company’s sales pipeline.

5. Disconnecting Meta without full account deletion

Tenant administrators can disconnect Meta Ads / Pages / WhatsApp credentials at any time from Setup → Integrations (or WhatsApp setup). Disconnecting revokes stored tokens for that organization connection.

6. Timelines

Meta callback processing is typically immediate for token/connection wipe. Organization-wide deletion requests are acknowledged promptly and completed within a reasonable period (target: 30 days) unless a longer retention period is required by law or contract.

7. Contact

Email/web: vertexcrm.in/contact. Include confirmation codes for Meta deletion status questions.

Last updated: August 2026.