Developer
Data deletion API
Two ways in. A public request that the person confirms from their own inbox, or a server-to-server call from a system you trust. Both erase that person's data from DataCops and give you a status link as proof.
What it does
The data deletion API handles GDPR right-to-erasure and CCPA deletion requests for one email on one website. The public endpoint never deletes on the spot: it emails the person a confirmation link, and the erasure runs when they click it. The private endpoint, called with your x-dc-key, runs the erasure straight away because the caller is already trusted. For the product overview, see DSAR automation and data deletion.What gets deleted
For that email, on that website only:
- Identified user records (the email, its risk scores and its device link) are deleted.
- Email, phone, first name and last name are removed from every visit record, along with the stored identity used to match conversions.
- Conversions held for the qualification gate are deleted, since they keep the full original details.
Anonymous visit data that is not tied to the email, such as page views and bot scores, stays, because it no longer identifies the person. Only data on the website the key belongs to is touched; your other websites need their own request.
Each request also gets a hard purge date 30 days after it is received, shown on the status page.
Public request
POST /public/data-deletion/request
No private key. Pass your public cop_key in the body, so you can call this from a browser or your server. The answer is the same whether or not DataCops holds data for that email, so nobody can use it to check who is in your system.
curl -X POST https://api.joindatacops.com/public/data-deletion/request \
-H "Content-Type: application/json" \
-d '{
"email": "person@example.com",
"cop_key": "YOUR_COP_KEY",
"pageUrl": "https://yourstore.com/privacy"
}'{
"success": true,
"message": "Please check your email and click the link to confirm your deletion request."
}- DataCops records the request and emails the person a confirmation link, plus a link to their status page.
- They click the link. The erasure runs once, then they land on the status page. Later clicks just show the status.
One request per email per website per 24 hours. A repeat inside that window gets the same success answer but no new email. pageUrl is optional and only stored for your records.
Server-to-server
POST /api/v1/data-deletion
For a CRM, helpdesk or privacy tool you control. Authenticate with your private key in x-dc-key (see Authentication). There is no email step: the erasure runs during the call and the response tells you what changed.
curl -X POST https://api.joindatacops.com/api/v1/data-deletion \
-H "x-dc-key: dcp_your_private_api_key" \
-H "Content-Type: application/json" \
-d '{ "email": "person@example.com" }'{
"success": true,
"accepted": true,
"confirmation_code": "9f2c...e41a",
"session_records_anonymised": 3,
"status_url": "https://joindatacops.com/data-deletion/status?id=9f2c...e41a"
}Store the confirmation_code or status_url as your proof that the request was handled.
Check status
GET /public/dsar/proof/:code
No auth. Returns a masked record, never the raw email or any personal data.
{
"status": "completed",
"maskedEmail": "pe***@example.com",
"received_at": "2026-10-01T09:00:00.000Z",
"completed_at": "2026-10-01T09:02:00.000Z",
"hard_purge_at": "2026-10-31T09:00:00.000Z",
"integrations_affected": 0,
"session_records_anonymised": 3,
"completion_email_sent_at": null,
"merchant_log": []
}status moves from received to processing to completed. An unknown code returns 404.
Drop-in form
Rather not build the form? Put this tag on your privacy page. It renders an email box where the tag sits and calls the public endpoint for you.
<script
src="https://cdn.joindatacops.com/dsar-embed.js"
data-cop-key="YOUR_COP_KEY"></script>Errors
| Code | Public request | Server-to-server |
|---|---|---|
| 200 | Request recorded, email sent | Erasure done |
| 400 | Invalid email, missing or invalid cop_key | Invalid email |
| 401 | Not used | Missing or invalid x-dc-key |
| 403 | Data deletion requests are switched off for this site | Not used |
| 500 | Unexpected error, retry | Unexpected error, retry |