Venues can flag a Contact for deletion and permanently anonymize the record. This satisfies data erasure requests, such as GDPR or CCPA, without breaking any bookings, events, invoices, or reports tied to the contact. The process is self-service, so that you can adhere to your venue's policies without requiring intervention from Momentus staff.
In this article:
- Permissions
- Configuration
- Flag a Contact for Anonymization
- Cancel a Pending Anonymization
- Use the Data Privacy Tab
Permissions
Users with Contact-edit permission can flag a contact for anonymization and cancel a pending anonymization, both from the Contact record. Users with the System Administrator role can do everything a Contact-edit user can do, plus access the Data Privacy tab and configure account-wide Data Privacy settings.
Configuration
A System Administrator sets up Data Privacy Management before anyone can flag a contact.
- In System Admin > Configuration, find the Data Privacy section, just above Alternate Language(s).
- Set Data Privacy Mode to Auto or Manual. This will be Disabled by default.
- Disabled: The feature is fully off. Flagging is not available.
- Manual: Flagging is available. No anonymization date is set automatically; a System Administrator processes flagged contacts on their own timeline from the Data Privacy tab.
- Auto: An anonymization date is computed automatically for each flagged contact, based on the Anonymization Delay (Days) value. A nightly sweep processes contacts once their date arrives. A System Administrator can still process contacts manually or early from the Data Privacy tab.
- If Data Privacy Mode is set to Auto, set the Anonymization Delay (Days) value. This defaults to 30 days. For example, at the default, a contact flagged August 1 becomes due on the nightly sweep on August 31.
- To notify contacts by email when they are anonymized, check Send anonymized email notification and select a Data Privacy Notice email template. The account needs at least one active Data Privacy email template selected; if none exists yet, a link opens the Email Templates tab with a new template pre-set to Type: Data Privacy.
Flag a Contact for Anonymization
Before you can flag a contact, the account's Data Privacy Mode must be set to Auto or Manual. Flagging is not available while the account is Disabled.
- Go to Contacts and open a contact record.
- Open the three-dot menu and select Anonymize Contact.
- The contact moves to a pending state.
- In Auto mode, an anonymization date is set automatically (today plus the account's Anonymization Delay), shown under General Information as: "Pending Anonymization on [date]."
- In Manual mode, no date is set automatically. A message of "Pending Anonymization (Date note set)" appears under General Information on the contact until a System Administrator sets a date from the Data Privacy tab.
The contact also appears in the Data Privacy tab's default view for any System Administrator to review. Flagging does not hide or restrict the contact anywhere else in the application; it remains fully visible and usable in every existing view until it is actually anonymized.
Cancel a Pending Anonymization
You can cancel a pending anonymization from either location, as long as it has not been processed yet.
- On the Contact record: open the three-dot menu and select Cancel Anonymization.
- On the Data Privacy tab: use the inline Cancel action on that contact's row, or select multiple contacts and use the Cancel anonymization bulk action.
Either path returns the contact to its normal, active state. The pending date is cleared and the "Pending Anonymization on [date]" label disappears.
Use the Data Privacy Tab
The Data Privacy tab is only visible to users with the System Administrator role.
- Go to Contacts > Data Privacy.
- Use the search field together with the two filters below to control what shows:
- Default view (neither filter checked): only contacts currently flagged for deletion.
- Show All Contacts: expands the grid to every contact in the account, each labeled marked or not marked for anonymization.
- Show Anonymized: shows the already-anonymized list, with their completion date; and any still-pending future anonymizations.
- The grid shows: Contact Name, Status, Anonymization Date, Days Until Anonymization, Email, Phone, Account. If nothing matches, the grid shows "There are no contacts to display."
- From here, use the inline Cancel anonymization action on a single row, or select multiple rows and use the bulk action bar for Anonymize contact, Cancel anonymization, or Change anonymization date. Each bulk button only enables for the rows it applies to.
Check the Last Anonymize Schedule Run timestamp at the top of the tab to see when the latest nightly sweep last ran - note that this check runs as an automated background process to check if there are contacts due for anonymization, and if so they are processed, but if not then no action is taken.