Developer

Data deletion API

Two ways in. A public request that the person confirms from their own inbox, or a server-to-server call from a system you trust. Both erase that person's data from DataCops and give you a status link as proof.

What it does

The data deletion API handles GDPR right-to-erasure and CCPA deletion requests for one email on one website. The public endpoint never deletes on the spot: it emails the person a confirmation link, and the erasure runs when they click it. The private endpoint, called with your x-dc-key, runs the erasure straight away because the caller is already trusted. For the product overview, see DSAR automation and data deletion.

What gets deleted

For that email, on that website only:

  • Identified user records (the email, its risk scores and its device link) are deleted.
  • Email, phone, first name and last name are removed from every visit record, along with the stored identity used to match conversions.
  • Conversions held for the qualification gate are deleted, since they keep the full original details.

Anonymous visit data that is not tied to the email, such as page views and bot scores, stays, because it no longer identifies the person. Only data on the website the key belongs to is touched; your other websites need their own request.

Each request also gets a hard purge date 30 days after it is received, shown on the status page.

Public request

POST /public/data-deletion/request

No private key. Pass your public cop_key in the body, so you can call this from a browser or your server. The answer is the same whether or not DataCops holds data for that email, so nobody can use it to check who is in your system.

cURL
curl -X POST https://api.joindatacops.com/public/data-deletion/request \
  -H "Content-Type: application/json" \
  -d '{
    "email": "person@example.com",
    "cop_key": "YOUR_COP_KEY",
    "pageUrl": "https://yourstore.com/privacy"
  }'
200 OK
{
  "success": true,
  "message": "Please check your email and click the link to confirm your deletion request."
}
  1. DataCops records the request and emails the person a confirmation link, plus a link to their status page.
  2. They click the link. The erasure runs once, then they land on the status page. Later clicks just show the status.

One request per email per website per 24 hours. A repeat inside that window gets the same success answer but no new email. pageUrl is optional and only stored for your records.

Server-to-server

POST /api/v1/data-deletion

For a CRM, helpdesk or privacy tool you control. Authenticate with your private key in x-dc-key (see Authentication). There is no email step: the erasure runs during the call and the response tells you what changed.

cURL
curl -X POST https://api.joindatacops.com/api/v1/data-deletion \
  -H "x-dc-key: dcp_your_private_api_key" \
  -H "Content-Type: application/json" \
  -d '{ "email": "person@example.com" }'
200 OK
{
  "success": true,
  "accepted": true,
  "confirmation_code": "9f2c...e41a",
  "session_records_anonymised": 3,
  "status_url": "https://joindatacops.com/data-deletion/status?id=9f2c...e41a"
}

Store the confirmation_code or status_url as your proof that the request was handled.

Check status

GET /public/dsar/proof/:code

No auth. Returns a masked record, never the raw email or any personal data.

200 OK
{
  "status": "completed",
  "maskedEmail": "pe***@example.com",
  "received_at": "2026-10-01T09:00:00.000Z",
  "completed_at": "2026-10-01T09:02:00.000Z",
  "hard_purge_at": "2026-10-31T09:00:00.000Z",
  "integrations_affected": 0,
  "session_records_anonymised": 3,
  "completion_email_sent_at": null,
  "merchant_log": []
}

status moves from received to processing to completed. An unknown code returns 404.

Drop-in form

Rather not build the form? Put this tag on your privacy page. It renders an email box where the tag sits and calls the public endpoint for you.

HTML
<script
  src="https://cdn.joindatacops.com/dsar-embed.js"
  data-cop-key="YOUR_COP_KEY"></script>

Errors

CodePublic requestServer-to-server
200Request recorded, email sentErasure done
400Invalid email, missing or invalid cop_keyInvalid email
401Not usedMissing or invalid x-dc-key
403Data deletion requests are switched off for this siteNot used
500Unexpected error, retryUnexpected error, retry
Was this page helpful?