Closing a Client Account
Closing an account erases the customer's personal data, terminates their services and keeps only the billing records the law requires, each on a dated deadline.
Closing a client account is not a delete. It is a lawful erasure: the customer's personal data is destroyed immediately, the billing documents the law obliges you to keep are preserved together with the minimum identity that makes them valid, and each retained category is given a dated deadline after which the platform removes it on its own. This article describes exactly what the control does, what disappears, what stays and for how long, and what to settle before you press it.
Warning: Nothing on this page can be undone. There is no restore, no undo window, and no archive you can re-import a closed account from. Read Before you close an account first — several things the platform destroys (support history, staff notes, the credit balance, running services) are gone the moment you confirm.
Where the control is
There are two ways in.
- One account. Open the customer from Clients, then use the red Delete button in the header of the Client Details page, next to Suspend and Terminate. A confirmation dialog headed Close and erase client opens; the button that carries out the closure is labelled Erase account.
- Several accounts at once. On the Clients list, tick the checkbox on each row you want to close (or the header checkbox to take the whole page), then click Delete Selected in the blue action bar that appears. See Closing several accounts at once.
Both routes require the Delete Clients permission. Staff who only hold view or edit rights on clients do not see the button. Permissions are assigned per department — see Staff & Permissions.
The Delete button is hidden on two kinds of account: any account holding Super Admin access — the owner account and anyone else granted it — which can never be closed this way, and an account that has already been erased, because there is nothing left on it to act on.
Before you close an account
Work through this list first. Every item on it is something the closure changes irreversibly.
- Confirm the request is genuine. The closure is carried out from the admin panel by staff; customers cannot close their own account from the client portal. Satisfy yourself that the request came from the account holder before you act on it.
- Settle the money in both directions. Unpaid invoices and proformas are cancelled, not collected — whatever the customer still owes stops being collectable. Any remaining credit balance is written down to zero. If that balance is money you owe back, refund it before closing, because afterwards there is no account to refund to and no saved payment method to refund against.
- Deal with the running services. Every service that is not already terminated or cancelled is terminated as part of the closure, through the normal termination path — the machine or account behind it is torn down and any subscription held at the payment provider is cancelled. Confirm the customer has taken their data off, and take any backup you are contractually required to take, first.
- Export anything you will want later. Support tickets and every message in them, staff notes on the client, and the bodies of past emails to that address are all destroyed. If a dispute is open, or you are keeping a conversation as evidence, save it out of the platform first.
- Check the confirmation email. The customer is emailed a notice of what was deleted and what was kept, using the Account Erased template. Review and, if needed, edit its wording in Email Templates before your first closure — it is sent automatically and it quotes the retention dates back to the customer.
- Note any team relationships. If this person holds a seat on another customer's account, or has issued invitations of their own, those are removed as part of the closure. See Team Members.
- Confirm your own obligations. The retention rules described below are the ones the product applies. They are not legal advice, and they are not a substitute for it. Check with your own accountants and legal advisers which records your company must keep, and for how long, before you rely on them.
The confirmation dialog
The dialog does not simply ask “are you sure”. It states, in three blocks, what the closure will actually do:
| Block | What it says |
|---|---|
| Deleted permanently | Password, two-factor secrets, saved payment methods, SSH keys, social logins, avatar, notifications, support tickets and staff notes. Services are terminated and subscriptions at the payment provider cancelled, so no further payment can be taken. |
| Kept, because the law requires it | Invoices, proformas and payment records, plus the name, address and tax number that appear on them. They are removed automatically once the retention period ends. A client with no billing history at all is deleted outright instead. |
| Afterwards | The account can never log in or be charged again, and its email address is released so the same person can sign up as a new customer. |
Click Erase account to proceed or Cancel to back out. The closure runs immediately and can take a while on an account with several live services, because each one is torn down properly rather than just marked as gone.
Two possible outcomes
The platform decides, at the moment you confirm, which of two things to do. You do not choose; the account's own history decides.
| The account has… | What happens |
|---|---|
| No billing history at all — no invoice, no proforma, no payment, no order, no service, no credit-ledger entry, and no wholesale orders or services as a reseller | The account is deleted outright. Nothing is retained, no retention record is created, and the account disappears from the panel completely. This is the signup that never bought anything, the test account, the spam registration. |
| Any billing history — even a single payment, order or service | The account is erased. Personal data is destroyed, the documents are preserved, and a retention record is created carrying the identity those documents need and the two deadlines described below. |
When the closure finishes, the dialog switches to a result panel headed either Account erased or Account deleted, with a sentence describing what was done and, for an erasure, the two retention dates. Closing that panel returns you to the client list. If any individual step reported a problem — a service that could not be torn down, for example — the panel says so and tells you to check before you confirm completion back to the customer.
Exactly what is destroyed
All of the following happens at the moment of closure, for an erased account and for a deleted one alike.
Money and services
- Every service not already terminated or cancelled is terminated, tearing down what was provisioned and cancelling any subscription the payment provider was holding.
- Invoices, proformas and orders that were still open — unpaid, pending or on hold — are set to cancelled.
- Automatic payment attempts that were queued or in progress are cancelled.
- Saved payment methods are deleted, not deactivated. The stored card or mandate is destroyed, so there is no way to charge the customer again.
- Automatic payment and automatic credit top-up are switched off.
- Any remaining credit balance is written down to zero, through the credit ledger rather than by silently editing the number, so the ledger stays consistent. The entry is labelled as an account-erasure write-off. See Account Credit.
Access
- All active sessions are destroyed and the password is replaced with a value no login can ever match.
- Two-factor secrets, backup codes and any additional second-factor methods are cleared; so are password-reset and email-verification tokens.
- Linked social logins and stored SSH keys are deleted.
- The customer's own API keys are deleted.
- Staff department memberships, if the account held any, are dropped.
- For a reseller, wholesale orders and services are kept as billing history, but every reseller API key is revoked, the outgoing webhook address and its secret are cleared, and the reseller profile is set to terminated. See Reseller Details.
- Team seats are removed in both directions: seats this person held on someone else's account, invitations they had issued, and members and invitations on any account they owned. An account they owned is set to closed.
- The account status becomes Erased, which every login path rejects.
Personal data with no legal basis to keep it
- Support tickets and every message in them are deleted.
- Staff notes on the client are deleted.
- Notification history is deleted.
- The profile photo is deleted from storage.
- The newsletter subscription tied to that address is removed, and any pending invitation sent to that address is revoked.
- Email log entries are kept as proof that a document was dispatched, but the recipient name and address are replaced with a placeholder and the stored message bodies are removed. See Email Logs.
- Activity log entries stay — they are the audit trail of what happened on the account — but the email address, name and phone number are stripped out of their details.
The account record itself
The customer row survives only as a marker, so the retained invoices still have something to point at. It carries no personal data: the name reads Erased Client, and phone, company, address, postcode, country, tax number, profile photo and ticket signature are all cleared.
The login email address is released. It is replaced on the account with an internal, unroutable placeholder, which frees the real address — the same person can sign up again later as a brand-new customer with the same email.
Exactly what is kept, and why
Two categories survive the closure, each on its own clock. Nothing else does.
The billing identity and the documents
Invoices, proformas, payment records and credit-ledger entries are not deleted. Neither are the numbers on them: a gap in a numbered accounting series is an irregularity in itself.
Because a valid invoice has to name its buyer, the closure does one thing before it scrubs the account: any invoice or proforma that had no stored buyer details is given a frozen copy of the customer's name, company, tax number and billing address, so the document still stands on its own. Documents that already carried a buyer snapshot are left exactly as they were — overwriting them with today's data would falsify the record.
Alongside the documents, a sealed retention record is written. It holds the minimum identity those documents need — first and last name, company, tax number, street, city, county or state, postcode, country and phone, plus the account creation date and last login — together with the contact email, a non-personal summary of the documents (their numbers, statuses, totals, currencies and dates), and a written statement of the legal basis for keeping each part. That record cannot be removed while the retention deadline stands.
Connection records
Separately and for a much shorter time, the platform keeps the records that identify which customer held which address and service, and when: the addresses seen at signup and at login, the browser details of those sessions, the order origins, and the list of services with their hostnames, addresses and start and end dates. This is the bucket that lets you answer a lawful identification request from an authority. It is never displayed on the client page — only its deadline is.
The two clocks
The two categories expire on different dates, measured from different starting points. The shorter one always expires first.
| What is kept | Measured from | Period as shipped |
|---|---|---|
| Billing identity — the identity on the retained invoices, proformas and payment records | 1 July of the year following the customer's most recent billing document — the latest of their last invoice, proforma, payment, order or service, falling back to the date the account was created if there is none. Not the date you closed the account. | 120 months (ten years) from that 1 July. |
| Connection records — signup and login addresses, and which service and address the customer held and when | The moment you close the account. | 12 months from that moment, and never later than the billing-identity date. If a longer period were configured, it is trimmed back to the billing date, because connection data must not outlive the identity it belongs to. |
A worked example. A customer whose last invoice was dated 20 November 2024 has their clock start on 1 July 2025; 120 months later gives a billing-identity deadline of 1 July 2035. If you close that account today, the connection records expire twelve months from today — long before it.
Note: Both periods are company-wide and identical for every account you close; they are not chosen per customer. The period in force at the moment of closure is frozen onto that account's retention record, so a later change to the company-wide period never rewrites an account that is already closed.
What happens when each clock runs out
A job runs once a day and enforces both deadlines without any action from you.
- At the connection deadline. The connection records and the readable contact email address are deleted from the retention record, and the addresses recorded against that customer's activity entries and orders are cleared. The billing identity is untouched.
- At the billing-identity deadline. The identity and the contact address are deleted from the retention record, and the buyer block on the retained invoices and proformas is replaced with a marker saying it was redacted because the retention period expired. The documents themselves, with their numbers and totals, remain — they simply no longer identify anybody.
The retention record on the client page
Open an erased account from the client list and the usual Client Details page is replaced at the top by a read-only panel headed Personal data erased. Because everything the page normally shows about that person is gone, this panel is the account. It shows:
| Element | What it shows |
|---|---|
| Introductory sentence | That the account was closed on an erasure request, cannot log in, cannot be charged, and that its email address has been released for re-registration. |
| Erased | The date the closure was carried out. |
| Billing identity kept until | The date on which the identity behind the retained documents is removed automatically. |
| Connection records kept until | The date on which the connection records are removed automatically — or Already deleted once that has happened. |
| Retained billing identity | The name, company and tax number on one line, the billing address on the next, and the contact email below it. This is the whole of what is still held about the person; it disappears from the panel once the billing deadline passes. |
| Legal basis for what is retained | An expandable block, written at the moment of closure, stating in plain text which obligation covers each retained category and until when. This is the text to quote when a customer asks why their invoices did not vanish, or when an authority asks under what basis you hold the record. |
The header of an erased account carries a grey Data erased badge in place of the usual action buttons. Every editing action is withdrawn: the account cannot be edited, suspended, reactivated, terminated, impersonated, have its password or second factor reset, or be closed a second time. Attempting any of them returns a message explaining that the account is retained only as a billing record under a retention deadline and cannot be modified, reactivated or accessed.
Finding an erased account afterwards
Erased accounts are hidden from the default client list — they are markers, not customers, and they would otherwise clutter every search. To reach one, use the status filter on the Clients page and choose Erased. The row shows the placeholder name and a grey Erased badge; opening it takes you to the retention panel described above. They are also excluded from the client counts on the summary tiles.
The closure itself is recorded in the Activity Log, with the two retention dates and the number of services terminated. It deliberately does not record who the customer was: the log outlives the erasure, and writing the name into it would reinstate the identifier that was just removed.
What the customer receives
Unless the confirmation notice has been switched off for your company, the customer is emailed before their address is scrubbed — it is the last thing that can be sent to them. The Account Erased template restates, in their own terms, what was deleted immediately, what is retained and under which obligation, the exact date each retained category is removed automatically, that their email address is free again so they can sign up as a new customer, and where to complain if they believe their data was handled incorrectly.
Edit the wording in Email Templates if you need to name your own supervisory authority or adjust the tone. Keep the retention date placeholders in place — they are what fill in the two dates.
Closing several accounts at once
The bulk form on the Clients list runs exactly the same decision for every account you select, one at a time.
- Filter or search the list down to the accounts you mean to close.
- Tick the rows, or use the header checkbox to select the whole page. When the whole page is selected and more accounts match your filter, a prompt offers to select all matching records across every page; Clear selection undoes it.
- Click Delete Selected. The confirmation restates the same rules: services are terminated and personal data erased, billing records required by law are retained and removed automatically when the retention period ends, clients with no billing history are deleted outright, and it cannot be undone.
- Confirm. Large selections are sent in batches and the button reports its progress. When it finishes you are told how many were erased, how many were deleted outright, and how many failed.
Warning: A bulk closure terminates real infrastructure for every account in the selection. It is not a list tidy-up. Accounts holding Super Admin access cannot be selected, and an account that has already been erased is reported back as Already erased rather than processed twice, but nothing else is protected. Check the count in the confirmation before you proceed.
Messages you may see
| Message | What it means |
|---|---|
| This account has already been erased… | You are acting on an account that is already a retention record. Its personal data is gone; what remains is removed automatically on the dates the panel shows. Nothing further is needed. |
| Super admin accounts cannot be deleted | An account holding Super Admin access is protected and can never be closed from the panel. |
| This account has been erased. It is retained only as a billing record… | You tried to edit, suspend, reactivate, impersonate or reset something on an erased account. None of those actions exist any more for that account. |
| “n step(s) reported a problem” on the result panel | The closure completed, but at least one step — usually the teardown of a service — did not. Investigate the service before you confirm completion to the customer; the data erasure itself has already happened. |
| “n client(s) could not be deleted” after a bulk run | Some accounts in the selection were skipped. The most common reasons are that they were already erased or that they hold Super Admin access. |
Related pages
Clients · Client Details · Staff & Permissions · Email Templates · Activity Log · Services · Invoices
