This page explains how to request deletion of data from Flow2CRM, including data received through Instagram and other connected sources. You can submit a request by email without signing in or having a Flow2CRM account. These are support request instructions, not automatic deletion at the click of a button.
Service: Flow2CRM
Support and personal data requests: support@flow2crm.com
1. Stop further data collection
If you own the connection, open the relevant source in the Flow2CRM dashboard and select Disconnect. For the official Instagram connection, this also removes the stored OAuth token in Flow2CRM. If needed, separately revoke Flow2CRM permissions in the connected app settings of Instagram or Meta. Disconnecting or revoking permissions does not delete previously saved history: send the request below for that. Not having dashboard access does not prevent you from making a request.
2. Send a request to support
Write to the email above with the subject Flow2CRM data deletion. The email link fills in this subject automatically. Include only information needed to locate your data:
- Your Flow2CRM account email, if you have one, and an email address for our reply.
- The source and its associated username, phone number, or account ID; for Instagram, the username. If known, add the connection name or a conversation link.
- What you want deleted: the entire Flow2CRM account, data from a particular source, or messages, attachments, and enquiries relating to you. For individual events, an approximate date can help.
3. Request verification
We verify that the request concerns you or an account you are authorized to manage. If needed, we ask for minimal additional verification to avoid deleting someone else's data. Do not send passwords, one-time codes, session cookies, API keys, or OAuth tokens. If you are not a Flow2CRM user, describe how and with which connected account you communicated; we will clarify a safe verification method.
4. Data covered by deletion
Within the verified scope of the request, we delete data relating to you in Flow2CRM: account or connection information, saved tokens and sessions, messages, comments, local attachments, contact information, related attribution, and operational records. A full account deletion request covers all of its sources and websites. Other people's data or accounts are not deleted solely on the basis of an unverified request.
5. Timing and completion confirmation
Requests are handled manually. After reviewing a request, we tell you about any needed clarification and the completion timeframe. We review and fulfill requests without undue delay and within the time limits set by applicable law. On completion, we send a reply confirming the scope deleted and explaining any exceptions. If you have not received a reply, contact support again with the date of your first request.
6. Exceptions and backups
Some information may be subject to mandatory legal retention. If necessary information temporarily remains in protected backups, we explain this together with the reason and further retention period. Such information must not be used for normal service operation; a completed deletion request must be reapplied if a backup is restored. We do not promise instant automatic deletion from every backup.
7. Copies in external systems
This process covers data handled by Flow2CRM. It does not delete your Instagram, Facebook, or other messenger account and does not automatically delete messages in the messenger itself. Copies already sent to Bitrix24, another CRM, or a webhook destination require separate deletion by the owner of that system. To delete data held by Instagram or Meta, use their privacy tools. For processing by Flow2CRM, use our support address.