Data Deletion

Last updated 11 September 2026

This page explains what ALLI Recon holds from each service you connect, what disconnecting actually removes, and how to ask us to delete the rest. It is written to be checked, so where disconnecting leaves records in place, it says so.

1. The short version

There are two separate actions, and they do different things. Disconnecting a service, which you can do yourself at any time, destroys the stored credential and stops all further collection immediately. It does not delete the records already synced. To have those removed as well, email us and we will delete them.

To request deletion, write to hello@allirecon.com from the email address on your account, and say which workspace and which connected service you mean, or ask for the whole account. This is the same address named in sections 10 and 14 of our Privacy Policy, which sets out the timescale we work to and the narrow cases where Philippine tax and audit law requires us to keep specific financial records for longer.

2. How to disconnect a service yourself

Sign in, open the workspace, and go to the screen for that service: Ad spend for Meta, Setup for Xero, QuickBooks and Google, and the relevant Reconcile screen for a marketplace or courier. Each connected service has a disconnect control.

Disconnecting overwrites the stored access token with an empty value. It is destroyed, not flagged, so reconnecting later requires a fresh authorization from you. Our background jobs select connections by the presence of a token, so a disconnected service stops being read the moment the token is gone rather than at the next scheduled run.

Disconnecting inside ALLI Recon does not remove the app authorization held on the other platform. If you want that removed too, do it there: in Meta under Business settings, in Xero under Connected apps, in Intuit under the apps connected to your QuickBooks company, and in Google under your account permissions.

3. Meta

Our Meta app asks for one permission, ads_read, and it is read only. ALLI Recon cannot create, change, pause or spend on an ad. It reads one figure: the total amount an ad account spent on a given day.

What we store from Meta:

  • The ad account. Its numeric id, the name you gave it, its billing currency, and its time zone.
  • Daily totals. One total spend figure per day for the whole account, exclusive of VAT, together with the small response the platform returned for that day.
  • The access token, encrypted at rest.

What we do not store, and do not request: any Meta user id, name, email address or profile information; any audience, custom audience, pixel, conversion or lead data; any campaign, ad set or ad, and no creative content of any kind; and no demographic or placement breakdowns. We read at account level only, so there is no campaign detail to hold.

Disconnecting Meta destroys the token, marks the connection revoked, and stops the daily read. The daily spend figures already collected are kept, and so is the connection record that says which ad account they came from. Email us to have those removed.

4. Lazada and TikTok Shop

What we store from a marketplace:

  • Your seller id and the connection to it.
  • Settlement records. Payouts and their fee lines: amounts, fee names, dates, order numbers, and the settlement rows as the marketplace returned them.
  • Order records. Order number, product code, quantity, amounts, the dates an order was placed, delivered and paid, whether it was cancelled, and the name of the payment method such as cash on delivery.
  • Product records. Product codes, product names and the costs you enter yourself.

We do not store buyer personal data. No buyer name, delivery address, phone number or email address is held anywhere in ALLI Recon, in any column or in any stored payload. The order data we keep is limited to what a set of books needs: what was sold, for how much, and when. Our systems are built so that this stays true: the database function that records order status accepts a fixed set of fields and ignores every other field in what it is given, so a personal field cannot be stored even by accident.

Disconnecting a marketplace destroys both stored tokens and stops all polling. The settlement and order records already synced are kept, and the connection record is kept because posted payouts refer to it. Email us to have those removed.

5. Courier remittance files

If you upload a courier remittance file for cash on delivery reconciliation, we store the rows needed to reconcile it: waybill number, order number, the amounts and fees, the signing date, and the sending and destination city. A waybill number identifies a parcel, not a person. We do not store a recipient name, a delivery address or a phone number, and columns in your file that we do not read are not stored. The file itself is not retained; we keep a checksum of it so the same file cannot be uploaded twice.

6. Xero, QuickBooks and Google

From Xero we store your organization id, a copy of your chart of accounts, tracking categories and tax rates so the app can offer them for mapping, and the reference of every journal we posted. From QuickBooks Online we store your company id and a copy of your chart of accounts, so the app can offer those accounts for mapping by name rather than asking you to type an account number, together with the reference of every journal we posted. We do not store tracking categories or tax rates from QuickBooks, because we do not read them. From Google, if you use the spreadsheet output, we store the Google account email address you signed in with and the id and name of the spreadsheet you chose.

Disconnecting any of them destroys the stored tokens and keeps the rest, so that reconnecting does not make you map everything again. Two things are worth being plain about. Journals we posted stay in the ledger we posted them to: a posted journal is part of your books, and ALLI Recon contains no code that can void or delete one, before or after disconnecting. The permission Xero and Intuit grant for posting journals would technically allow it; our software only ever creates a journal and reads one back, and those two paths are kept separate so that stays true. If you want any of them reversed, void them in your ledger yourself. Likewise, a spreadsheet we wrote to stays in your own Google Drive with its contents intact, because it is your file and we do not delete it.

7. Deleting your whole account

If you are the owner of your organization, open the account menu in the top right and choose Delete account. You will be asked to type the organization name, because deletion cannot be undone. It is refused while anyone else is still a member and while an invoice is outstanding, so a shared workspace is never emptied by one person without the others knowing. Remove the other members first, or ask us.

What it does: your sign in is destroyed, and the name and email address on your member record are replaced with placeholders. What it leaves: the audit trail keeps your name on every action you took, the anonymised member record stays so the financial records linked to it remain intact, our hosting provider holds encrypted backups for its own retention window, and anything already posted to your ledger or written to your spreadsheet stays there because it is your file. Section 8 of the Privacy Policy sets this out, along with which financial records we are obliged to keep for longer.

If you are a member rather than an owner, or you would rather we did it, email hello@allirecon.com and ask us to close the account. We will confirm before we act.

8. Who is responsible

ALLI Recon is operated by ALLI Recon OPC. If you are not satisfied with how we handle a request, you may raise it with the National Privacy Commission.

9. Changes to this page

We will revise the date above when this page changes, and we will change it whenever what we store or what disconnecting does changes.

Questions about this document? Contact hello@allirecon.com.