Delete a Customer Permanently
What "Delete permanently" does
Delete permanently is for when a customer asks you to erase their data entirely — a GDPR "right to erasure" request, for example.
- It permanently removes the customer and their history from Passtastic: their profile, visits, points and scans are deleted outright. A few records are kept but stripped of anything personal, because we're required to retain them: message send-logs keep the fact a message went out, with the text removed, and payment records keep the transaction for tax purposes, with the email removed.
- It voids their wallet pass. The card stays in their Apple Wallet or Google Wallet but stops working and moves to the expired section — Apple and Google give us no way to delete a pass off someone's phone.
- This cannot be undone. There is no Restore button — once it's done, the data is gone.
- To confirm, you must type `DELETE` in capitals. This is deliberate friction — it stops an accidental click from erasing someone's record. The dialog shows who you're about to delete, so check that first.
Only reach for this when a customer specifically wants their data gone.
For everyday clean-up, use "Mark inactive"
If you just want to stop rewarding someone — a lapsed member, a duplicate entry, a customer who has moved away — use Mark inactive instead.
- It blocks perks at the scanner without touching their history or balance.
- Their pass shows a greyed-out "MEMBERSHIP INACTIVE" status.
- It's fully reversible with Reactivate customer.
See Mark a Customer Inactive for the full walkthrough.
Where to find "Delete permanently"
1. Open Customers from the sidebar and click the customer to open their detail panel.
2. Open the ⋯ overflow menu.
3. Choose Delete permanently.
4. Read the warning, check the name of the customer it says you're deleting, type `DELETE` to confirm, and click Delete forever.
Who can do this
Delete permanently is restricted to Admin and Owner roles — for everyone else the option isn't in the ⋯ menu at all. Mark inactive is available to Editor role and higher.
See Team Roles & Permissions for the full breakdown of what each role can do.
:::faq What's the difference between "Mark inactive" and "Delete permanently"? Mark inactive blocks the customer's perks at the scanner but keeps their history, balance, and wallet pass, and you can undo it any time with Reactivate customer. Delete permanently is an admin-only action that erases the customer and their history for good and voids their wallet pass. It cannot be undone. :::
:::faq I just need to clean up my customer list — which one do I use? Mark inactive. It stops them earning and redeeming without losing anything, and you can reactivate them later. Save Delete permanently for actual data-deletion requests. :::
:::faq A customer asked me to delete all their data. What do I do? Use Delete permanently on their profile. It removes their record and history and voids their wallet pass — this is the GDPR-erasure action. Only an Admin or Owner can do it. :::
:::faq Can I undo "Delete permanently" if I confirm by mistake? No. The record is gone. That's why it makes you type `DELETE` to confirm before it runs. :::
:::faq Why do I have to type `DELETE` to delete permanently? It's a safeguard against accidental clicks, since this action is irreversible. Type `DELETE` in capitals to enable the Delete forever button. The dialog names the customer you're deleting above the box, so you can check you have the right person before you type. :::
:::faq I'm an Editor — why don't I see "Delete permanently"? It's restricted to Admin and Owner roles because it's irreversible and removes data entirely. Editors still have full access to Mark inactive and Reactivate customer. :::