Erase your data
Spaw is a verification API. A business you dealt with may have sent us your email address to check, or reported that a message to it bounced — which means we can hold something about you without you ever having signed up here. This page deletes it. You do not need an account, and nobody is told that you asked.
Ask us to erase it
What gets deleted
- Every verification history row a customer's lookup of the address left behind.
- Every delivery outcome anyone reported about it — bounced, complained, delivered — which is what stops it counting towards the bounce ratio published for its domain.
- Any suppression list it sits on, so no account is still holding it as an address not to mail.
- The cached mailbox answer for it, so the next lookup of that address starts from nothing.
What it leaves alone, and why
- A customer's own monitored list, and the file they uploaded for a bulk run: their records, kept for them, deleted with the job after 30 days or with the monitor when they delete it.
- The seven-day repeat marker, which is a hash and a timestamp under an account's own key and expires on its own.
- A one-way hash of the address if it claimed the new-account credit bonus, which exists so the bonus cannot be claimed twice and cannot be read back.
A phone number, an address, an IP
This form takes an email address and nothing else on purpose. The only thing a stranger can prove over the web is that they receive mail at an address, and that proves control of exactly one identifier: their own. A form that also took a phone number would let anybody erase anybody else's by confirming their own mailbox — which is not a data-subject right, it is a way to clear an abuse report off a number you are abusing.
So for a phone number, a postal address or an IP address, write to [email protected]. A person checks that you are who the data is about, and then erases it exactly the same way. We answer within 30 days, which is the outer limit the GDPR allows rather than a target.
What is held about each kind of identifier, and for how long, is on the security page; who processes it is on the trust page.