Data Deletion Policy

Last updated: February 17, 2026

1. Overview

Drawfetti is operated by AdRific Oy (Business ID: 2811204-7, VAT ID: FI28112047), a company registered in Finland. We respect your right to control your personal data. This page explains how you can request deletion of all data associated with your Drawfetti account, what data is deleted, and how we process your request.

In accordance with the EU General Data Protection Regulation (GDPR) and Meta Platform requirements, you have the right to request erasure of your personal data at any time.

2. What Data We Store

When you use Drawfetti, we store the following types of data:

  • Account information: Your name, email address, and profile picture as provided by Facebook or Google
  • OAuth tokens: Access tokens used to connect to your Facebook Pages and YouTube channels
  • Connected pages: A list of the Facebook Pages you have connected to the Service
  • Draw data: All giveaway draws you have created, including draw configurations, filters, and results
  • Participant data: Comment data (commenter names, comment text, timestamps) fetched from your posts for running draws
  • Subscription data: Paddle customer ID, subscription status, and transaction history (we do not store credit card numbers or bank details)
  • Session data: Authentication sessions for keeping you signed in
  • Billing profile: Optional billing details you have entered (name, company, VAT ID, billing address)

3. How to Request Data Deletion

You can request deletion of all your data through any of the following methods:

Option A: Delete Your Account from Within the App

The fastest way to delete all your data is directly from your Drawfetti dashboard:

  1. Sign in to your account at drawfetti.com/login
  2. Navigate to Settings (Dashboard → Settings)
  3. Scroll down to the "Danger Zone" section
  4. Click the "Delete Account" button
  5. Type DELETE to confirm and click "Delete Everything"

This immediately and permanently deletes your account and all associated data from our systems. You will be signed out automatically.

Option B: Remove Drawfetti via Facebook Settings

You can remove Drawfetti from your Facebook account, which automatically triggers deletion of all your data through Facebook's data deletion callback:

  1. Go to your Facebook Settings → Apps and Websites
  2. Find "Drawfetti" in your list of connected apps
  3. Click "Remove"
  4. Check the box to "Delete all data posted on Facebook by Drawfetti"
  5. Confirm the removal

When you remove Drawfetti through Facebook, Facebook automatically sends us a signed data deletion request. We verify the request, delete all data associated with your Facebook user ID, and generate a confirmation code. You will be redirected to this page with a confirmation code as proof that your data has been deleted.

Option C: Email Us Directly

If you prefer, or if you are unable to sign in, you can request data deletion by emailing us at privacy@drawfetti.com with the following details:

  • Subject line: "Data Deletion Request"
  • Email body: The email address associated with your Drawfetti account, and optionally the name on your account

We will verify your identity, process the deletion, and send you a confirmation email. Manual deletion requests are processed within 30 days of receipt.

4. What Data Is Deleted

When your data deletion request is processed — regardless of which method you used — the following data is permanently removed from our systems:

  • Your Drawfetti user account and profile information
  • All connected Facebook Pages
  • All OAuth access tokens and refresh tokens
  • All giveaway draw history, configurations, and results
  • All participant data (commenter names, comments) from your draws
  • All audit log entries associated with your draws
  • All session data
  • Your billing profile information (name, address, VAT ID)

5. What Data Is NOT Deleted

The following data may be retained after account deletion:

  • Payment records held by Paddle: Our payment processor Paddle.com (Merchant of Record) retains transaction records independently for legal and tax compliance. To request deletion of payment data, contact Paddle directly via their Privacy Policy page
  • Anonymized aggregate statistics: We may retain anonymized, aggregated data (e.g., total number of draws run on the platform) that cannot be linked back to you as an individual
  • Server logs: Standard web server logs may contain IP addresses and are automatically purged within 30 days

6. How We Process Facebook Data Deletion Callbacks

When a user removes Drawfetti from their Facebook account settings, Facebook sends a signed data deletion request to our callback endpoint. Our system:

  1. Verifies the request by validating the cryptographic signature using our Facebook App Secret
  2. Identifies the user in our database using their Facebook User ID
  3. Deletes all associated data: participant records, audit entries, draws, connected pages, sessions, OAuth accounts, and the user record itself
  4. Generates a unique confirmation code for the user's records
  5. Returns a status URL (this page) where the user can verify deletion was completed

This entire process happens automatically and immediately upon receiving the request from Facebook.

7. Data Retention After Deletion

Once your data deletion request has been processed, your data is permanently removed from our active databases. We do not retain backups of deleted user data. The deletion is irreversible — if you wish to use Drawfetti again in the future, you will need to create a new account.

8. Your GDPR Rights

In addition to data deletion (the "right to erasure"), users located in the European Economic Area (EEA) have the following rights under the GDPR:

  • Right of Access: Request a copy of all data we hold about you
  • Right to Rectification: Request correction of inaccurate or incomplete data
  • Right to Data Portability: Request your data in a structured, machine-readable format
  • Right to Object: Object to certain types of data processing
  • Right to Withdraw Consent: Revoke Facebook or Google permissions at any time

To exercise any of these rights, contact us at privacy@drawfetti.com.

9. Timeframe for Processing

  • In-app deletion (Option A): Immediate — data is deleted within seconds
  • Facebook removal (Option B): Immediate — data is deleted as soon as we receive the callback from Facebook
  • Email request (Option C): Within 30 days of receiving your request

10. Contact Us

If you have any questions about data deletion or this policy, please contact us: