User Rights API
The User Rights API allows you to request the deletion of a user's personal data across VTEX applications, in compliance with "Right to be Forgotten" regulations.
This API provides an automated workflow for handling data erasure requests. You submit a user's email, receive a job ID, and poll that ID until the deletion is complete.
The user rights flows available in this API apply only to non-corporate shoppers. They don't apply to B2B buyers or Admin users.
For personal data stored in Master Data custom entities, follow the existing data erasure process described in Erasing customer data.
Operational behavior
- Automatic retries: If something fails internally, the system retries up to 10 times before marking the job as
Failed. You don't need to retry on your end. - Non-existent emails: If no data is found for the given email, the job completes with
Success. - Polling interval: We recommend polling with a frequency no higher than every 30 seconds.
Endpoints
Data erasure
| Summary | Method | Path |
|---|---|---|
| Create data erasure job | POST | /api/user-rights/forget/jobs |
| Get data erasure job status | GET | /api/user-rights/forget/jobs/{jobId} |