User Data Deletion Instructions
This page describes the process, scope and timelines that apply when a user asks Nolimit Management to delete their account or data from the Nolimit Ads Management platform and the Nolimit Connection extension.
Nolimit is committed to respecting the user's control over their data and will process every deletion request in line with Meta's policies and with the personal-data protection regulations applicable to the user's operations.
1. Self-service deletion inside the workspace
Most operational data can be removed directly by the workspace owner or by any member with administrator rights through the platform UI, without contacting Nolimit.
The user can:
- Disconnect ad accounts, Business Managers, Pixels or datasets from the workspace;
- Remove members, roles and access groups managed by the organization;
- Delete audit-log entries and activity history to the extent allowed by the retention policy;
- Uninstall the Nolimit Connection extension to stop syncing new data to our systems.
Uninstalling the extension stops new data from being synced, but data that has already been synced will remain on Nolimit's systems in encrypted form. To delete that data as well, please submit a request as described in the next section.
2. Submit a deletion request
To delete the entire account and workspace from Nolimit, send an email from the address registered to the account to privacy@nolimit.dev with the subject line: "Account deletion request — [workspace name]".
The email should specify:
- The registered email and workspace ID (if known);
- The scope of the request (the entire workspace, or only the individual member account within a workspace);
- A confirmation that the user is authorized to make the request for that scope.
To protect against fraudulent requests, Nolimit may require an additional identity-verification step before processing the deletion — for example, confirmation from another workspace administrator or verification through one of the integrations already connected to the workspace.
3. Scope of data deleted
Once a deletion request has been verified and processed, Nolimit will remove the following categories of data from its operational systems:
- Identifying account information: full name, email, phone number;
- Workspace metadata and role-based access configuration;
- Audit trail and activity logs;
- System-risk signals computed for the workspace;
- OAuth tokens, session tokens and other credentials held for third-party integrations, including the Meta Graph API.
For the Nolimit Connection extension, any cookies, sessions and tokens that have been encrypted and synced to the cloud are removed from storage. Because the encryption is performed with a password the user controls, Nolimit was never able to decrypt this data — deletion simply removes the encrypted blobs from our systems.
Derived data that has been anonymized and can no longer be linked back to a specific organization may continue to be retained.
4. Processing timeline
Nolimit acknowledges deletion requests within five (5) business days of receiving a valid request and completing identity verification.
Deletion across our primary operational systems is completed within thirty (30) days of the request being confirmed. Some backup copies may persist for up to ninety (90) days before being overwritten by our regular backup-rotation policy, at which point they are also discarded.
Once the deletion is complete, the user receives a confirmation email from privacy@nolimit.dev.
5. When you disconnect Meta
If the user uninstalls the Nolimit app from their Meta account (Business Settings → Integrations → Remove), Meta will send a permission-revocation signal and a data-deletion request for the affected integration to Nolimit.
Upon receiving that signal, Nolimit revokes the related integration tokens and schedules deletion of all Meta-related data on its side — including Business Manager information, ad-account data, Pixel and dataset metadata, and the insights history that had been synced into Nolimit — within the timelines described in section 4.
If the user needs to confirm the status of a deletion or obtain evidence for an audit, please contact privacy@nolimit.dev for an official confirmation.
6. Mandatory retention
Some data may be retained beyond the 30-day window described above, only to the extent strictly necessary, in order to:
- Comply with accounting, tax, anti-money-laundering and other mandatory legal obligations;
- Respond to a request from a competent public authority;
- Protect Nolimit's legitimate rights and interests in connection with an active legal dispute.
Once the retention purpose has expired, this data is deleted or anonymized in line with Nolimit's internal retention policy.
7. Contact
All deletion requests, questions about the process and requests to confirm the status of an in-flight deletion should be sent to:
Nolimit Management
Email: privacy@nolimit.dev
Requests that are explicitly legal in nature or that relate to enterprise-contract negotiation should also be sent to: legal@nolimit.dev.
Ready to submit a deletion request?
Send an email to the Nolimit security team. We will get back to you within five business days and confirm once the deletion is complete.