returnEasier
What's new
What's newMerchant2 min read

When a shopper asks you to erase their data, every photo goes too

If a shopper exercises their right to erasure, returnEasier now deletes every photo they uploaded, including those on requests whose order Shopify keeps. Until now that case — the most common one — left photos stored until the retention period ran out.

When a shopper exercises their right to erasure (Article 17 GDPR), Shopify sends us the request and returnEasier erases their data. Until now, in one specific — and common — case, the photos that shopper had uploaded survived the erasure and stayed stored until the retention period ran out. As of today, none are left.


Every photo from that shopper is deleted

Photos are part of the commercial flow for returns and exchanges (Pro and Scale plans): your shopper attaches pictures of the product so you can assess the request. When an erasure request arrives, all of theirs are now removed: both the ones attached to a request and the ones they started uploading and never submitted.

In practice you'll see it like this: open a request from a shopper who asked for erasure and the photo section is empty. That's the correct behaviour, not a loading error.

Including those on an order Shopify keeps

Shopify does not list in the erasure request the orders still inside its retention window — it keeps them for accounting obligations. Until now, the photos on a request tied to one of those orders fell between two stools and were kept along with it.

Not any more: the order row stays (Shopify decides that) but the photos go anyway. They are personal data supplied by the shopper, and no accounting obligation requires keeping them.

If something fails, it retries until nothing is left

A photo isn't treated as deleted until deletion is confirmed. If storage fails at that moment, the request is deliberately marked as failed so Shopify retries it, and the weekly retention job later sweeps whatever is still pending. We never mark a request as clean while a single file is still standing.

There is no setting to enable and no new step in your process: if you receive an erasure request, handle it from Shopify as always and we take care of the rest.

And remember that none of this touches the legal flow — which has no photo upload: «Withdraw from contract here» works just as before, with the same mandatory wording.

Was this article helpful?