Draft — pre-launch. These legal documents are under revision and are not yet in force. Hail Pilot is a pre-launch service; the legal entity responsible for it will be identified here, with its registered name, before the Service accepts customer sign-ups. No account may be opened, and no data processing agreement executed, in reliance on this draft.

Data Deletion

Version: 2026-09-18.v1. Effective date: 18 September 2026. Operator: ABSOLUTE SERVICES (UEN 53464936W), a sole proprietorship registered in Singapore and owned by LEE KOK WAN. "Hail Pilot" is the name of the product and service operated by ABSOLUTE SERVICES ("Hail Pilot", "we", "us"). Registered address: 60 Paya Lebar Road, #06-28, Paya Lebar Square, Singapore 409051.

This page explains how to ask Hail Pilot to delete personal data, what happens when you do, and when data from each Platform is deleted automatically without a request. The periods are set out in full in the Retention Schedule at /legal/retention; if this page and the Retention Schedule differ, the Retention Schedule applies. Terms in capitals have the meaning given in the Terms of Service at /legal/terms.

1. Who this is for

1.1 Merchant Users: people who use Hail Pilot on behalf of a Merchant. For your own account data, we are the organisation responsible under the Privacy Policy at /legal/privacy.

1.2 Buyers: customers of a Merchant that uses Hail Pilot. This includes people who bought from the Merchant on Shopee, Lazada, TikTok Shop or Shopify, and people who sent a message to the Merchant's WhatsApp Business Account or Instagram professional account. For Buyer Data we act on the Merchant's behalf, so the Merchant decides on your request (section 3.2). The Notice to Buyers at /legal/buyers explains this in more detail.

2. How to ask

2.1 Email business@hailpilot.com. There is no self-service deletion control in the Service; requests are made by email.

2.2 Tell us what we need to find your data: (a) Merchant Users: the email address of your Hail Pilot account and the name of the workspace; (b) Buyers: the name of the shop you dealt with and the Platform (Shopee, Lazada, TikTok Shop, Shopify, WhatsApp or Instagram); (c) if you messaged the shop on WhatsApp, the phone number you used; if on Instagram, your Instagram username; (d) if you bought from a Shopify store, the name or web address of the store.

2.3 We may ask you to verify your identity before we act.

3. What happens and when

3.1 Merchant Users. We act on your request ourselves. We respond as soon as reasonably possible. If we cannot respond in full within 30 days of receiving your request, we tell you in writing within those 30 days when we will. Where the Personal Data Protection Act 2010 (Malaysia) applies to you, we respond within the time it allows, which is 21 days unless we tell you in writing that we need longer. When your account is closed or you are removed as a user, your account data is deleted within 90 days, except the records described in section 5.1.

3.2 Buyers. We forward your request to the Merchant within five business days and tell you we have done so. On the Merchant's instruction, we delete your Buyer record (your name, phone number, email address and address) and de-identify your other records in the same way as automatic deletion (Retention Schedule 2.2 and 2.6). We then confirm in writing to you that this has been done.

3.3 What de-identification removes. Email addresses and phone numbers written into free text, such as messages and case notes, are redacted. Names and street addresses written into free text are not reliably removed. If this concerns you, say so in your request.

3.4 Disconnecting a source. A Merchant can also have the Buyer Data from a source removed by disconnecting it. The connection's access credentials are deleted 7 days after disconnection, and Buyer records linked to the Merchant only through that connection are deleted 30 days after disconnection.

3.5 Other systems. Deleting data from Hail Pilot does not delete it from a Platform's or from Meta's own systems. Those systems are governed by their own terms.

4. Automatic deletion by Platform

4.1 A daily job deletes Buyer Data on four clocks, each using the period for the source in the table below: (a) Buyer record: the period after the Buyer's first order through that source, or 30 days after the source is disconnected if no other live connection links the Buyer, whichever is earlier; (b) order copies (delivery address, Buyer note, raw order data and tracking number held on an order): the period after the order was placed; (c) messages: the period after each message, when its text is replaced with "[deleted]" and the sender's name, picture and raw message data are removed; (d) raw data a Platform sent us: the period after we received it, and in any case in a monthly batch once it is 180 days old.

4.2 Steps (a) to (c) wait while the Buyer or the order has an open case, dispute, refund request or chargeback, and run at the next daily run after it closes. Records of full webhook requests received from Platforms are deleted 90 days after receipt.

PlatformWhat we holdWhen it is deletedPlatform rule
ShopeeBuyer name, contact details and address; orders; chat messages; raw order and message data90 days on each clock in 4.1Shopee Open Platform Data Protection Policy, cl. 10.6: no longer than 90 days
LazadaBuyer name, contact details and address; orders; chat messages; raw order and message data90 days on each clock in 4.1Lazada Open Platform Terms, cl. 9.11(c): no longer than 90 days after an order is shipped
TikTok ShopBuyer name, contact details and address; orders; chat messages; raw order and message data90 days on each clock in 4.1TikTok Shop Seller Terms: delete as soon as reasonably possible after the transaction is complete; 90 days covers returns, refunds and disputes
ShopifyBuyer name, contact details and address; orders; dispute and chargeback notices; raw order data180 days on each clock in 4.1. After you uninstall the app, Shopify sends a shop/redact request 48 hours later and we delete all data for that store within 30 days of it. On a customers/redact request, that Buyer's data within 30 daysShopify: keep only as long as needed; card chargebacks can arrive months after a charge
WhatsAppPhone number, profile name, message content and delivery status; the raw data Meta sends. No Buyer record is created90 days after each message (4.1(c)) and after receipt (4.1(d))Meta Platform Terms: delete when no longer necessary, and explain how to request deletion
InstagramInstagram-scoped identifier and message content; the raw data Meta sends. No Buyer record is created90 days after each message (4.1(c)) and after receipt (4.1(d))Meta Platform Terms: delete when no longer necessary, and explain how to request deletion
CSV import and manual entryBuyer name, contact details and address; orders180 days on each clock in 4.1No Platform rule; this is our own limit

5. What we keep and why

5.1 Records we must keep. Hail Pilot's own records of its relationship with a Merchant, including records of privacy requests and how they were handled, are kept for 6 years under Part 6 of the Retention Schedule. They include Buyer Data only where a record of a request or an incident necessarily refers to a specific Buyer.

5.2 De-identified business records. Order, case, dispute and outcome records remain after a Buyer's personal data is removed, de-identified as described in section 3.3, so that the Merchant's case history and statistics stay consistent.

5.3 Network Signals. Network Signals are pseudonymised tokens and counts. They hold no names, contact details or images. They are derived only from Shopee, Shopify, CSV import and manual entry sources, and never from Lazada, TikTok Shop, WhatsApp, Instagram or Amazon. For Network Signals we are the responsible organisation. They are kept indefinitely and are not deleted or nullified on request; a Buyer may ask what we hold about them and ask for it to be corrected (Retention Schedule 7.3).

5.4 Backups. Deleted data may remain in encrypted backups until they expire: weekly backups after 56 days and monthly backups after 12 months. Backups are used only to restore the Service after a failure. If a restore brings back a Buyer record whose period has ended, the daily runs delete it again (Retention Schedule 1.5).

6. Contact

6.1 Deletion requests and questions about this page: business@hailpilot.com.

6.2 If you are not satisfied with our response, you may complain to the Personal Data Protection Commission, Singapore (pdpc.gov.sg) or, for matters under the Personal Data Protection Act 2010 (Malaysia), to the Personal Data Protection Department, Malaysia (pdp.gov.my).