GDPR requests: export, deletion and anonymisation

StudioFlow is built GDPR-first, so when a member asks to see, download or erase the data we hold on them, we can handle it from their record. Here is how to run each kind of request.

  1. Open their record. From Members, open the member's profile and scroll to the data and privacy (GDPR) section near the bottom.
  2. Export what we hold. Click Export data to download a file with everything on record for that member, then send it to them. An export is available any time, including the day they leave.
  3. Handle a marketing opt-out. Use the marketing consent toggle to opt a member in or out. When it is off, no marketing email goes out, but booking confirmations and receipts always send.
  4. Erase or anonymise. When a member asks to be forgotten, click Erase (anonymise), then confirm. We ask you to confirm because this cannot be undone.
  5. Know what erase does. It removes their personal details, their sign-in login and their saved card profile. Their purchase and payment history stays, now de-identified, since tax and accounting rules require us to keep it.
  6. When a member deletes in the app. Members can delete their own account from the app's profile settings. We are notified, so you can action the erasure from their record on our side.
  7. Offer the email route. A member who cannot reach the app can email us from the address they signed up with, and we pass the request on to you.

Good to know

  • Data is isolated at the database level, so one studio can never see another, and each member sees only their own record.
  • Consent is recorded per member and checked before each send, so an opt-out takes effect right away.
← All docs