Data deletion

Last updated: September 4, 2026

Waverunner is operated by Adwave Digital Inc. This page explains how to ask us to delete personal data we hold about you. Meta requires every app that can access user data to publish clear deletion instructions (or an automated callback). The same process covers Google, Reddit, TikTok, and other platforms we use to run your ads, and full Waverunner account deletion.

1. How to request deletion

  1. If you have a Waverunner login on an Individual workspace you own (no teammates), use Settings → Security → Close workspace. Type the workspace name to confirm. Unused starter credit is forfeited. If the wallet still has deposited funds, email support to return them first.
  2. Otherwise email support@adwave.com from the email address on your Waverunner account when possible.
  3. Use the subject line: Data deletion request.
  4. Include in the body:
    • Your full name
    • Your account email
    • Your organization or business name (if any)
    • Whether you want (a) platform connection data deleted (Meta / Google / Reddit / TikTok), (b) your full Waverunner account deleted, or both
    • Optional: a Meta app-scoped user id from Facebook → Settings & privacy → Settings → Apps and websites, if you have one
  5. We verify the request (we may ask for a short confirmation reply) before deleting.

The same email process applies if you only interacted with our Meta app (for example after removing the app under Facebook Apps and websites) and do not have a Waverunner login.

2. What we delete

After we verify your request, we delete or de-identify personal data associated with you and any platform connection we control. Closing a workspace runs the same erase. It covers, as applicable:

  • Account profile and contact details. Your login becomes a non-deliverable placeholder so the email address can sign up again later.
  • Authentication and connection tokens for Meta, Google, Reddit, TikTok, and any customer system you connected (QuickBooks, Stripe, Shopify, Square, Clover, HubSpot, GoHighLevel, Google Business Profile). Where the provider offers it (HubSpot, Shopify, Google) we also revoke the grant on their side; GoHighLevel has no revoke endpoint, so remove the app from your location there as well.
  • Lead contact details (name, email, phone, message), imported customer emails and names, CRM handoff records, and hashed identifiers we stored for audience matching on your behalf.
  • Visitor, session, and click identifiers on your tracking events, and the short-lived connection details held for conversion forwarding and TV household matching.
  • Mail recipient addresses from Neighborhood mail drops.
  • Files in object storage: creative files you uploaded, generated ads and renders, landing-page images, mail artwork, listing photos, and logos. Each deleted storage folder is recorded in an erase audit.
  • Website content we read to build your business profile, and chat history with the assistant.

3. What we may keep

  • Billing, ledger, tax, and other financial or transaction records we are legally required to keep, for the retention period required by law
  • Campaign, ad, and delivery records with identifiers removed (which campaigns ran, spend, impressions, and results), so money records still reconcile
  • Records needed to establish, exercise, or defend legal claims
  • Aggregated or anonymized data that cannot reasonably identify you
  • Data for which the advertiser (not Waverunner) is the controller, for example events collected by a tracking tag on an advertiser's website, which we process on the advertiser's behalf. Those requests should go to the advertiser first; we assist them with verified requests

4. What expires on its own

You do not need to ask for these. Page views and identify events expire after 180 days; clicks, interactions, ad impressions, and video playback events after 90 days; platform click ids attached to conversions 7 days after they are forwarded and no later than 90 days after the event; visitor IP addresses held for TV matching within 24 hours; and cached public-URL analyses within 24 hours. The full schedule is in the Privacy Policy.

5. Timing

We aim to acknowledge receipt and complete deletion of eligible personal data within 30 days of a verified request (sooner when practical). If we cannot delete something because of legal retention, we will say so in our reply and explain what was retained.

6. Requests from Facebook Apps and websites

You can remove our app in Facebook → Settings & privacy → Settings → Apps and websites, then request that your data be deleted. We publish this instructions URL for Meta's App Dashboard (User data deletion). Those requests are fulfilled through the email process on this page.

7. Google, Reddit, and TikTok

If you connected Google Ads, YouTube, Reddit, or TikTok assets through Waverunner, or want us to remove hashed match data we uploaded to those platforms for your campaigns, use the same email process. Hashed match data is uploaded only to Google Customer Match and Meta custom audiences; removals from those two are propagated when we delete or when an advertiser turns audience sync off, subject to each platform's processing times. We do not upload match lists to Reddit or TikTok.

8. Advertiser-site visitors

If you are a visitor to a business's website that uses Waverunner tracking or ads and want that business's data about you deleted, contact that advertised business (the controller). If an agency runs the ads and you cannot reach the business, contact the agency or email support@adwave.com. Waverunner processes that data on the advertiser's behalf and will assist the advertiser with verified requests.

9. Client users invited by an agency

If you are a client user invited by an agency, deleting your login does not delete the client organization. Ask the agency to close that workspace, or email us from the address on the account.

10. Contact

Questions about data deletion or privacy: support@adwave.com. Related: Privacy Policy · Terms of Service.