How to start it
- 1. Sign in. On the app, or in any browser on this website. You do not need the app installed.
- 2. Open Settings, then Account. Delete account is the last control in that group.
- 3. Clear anything still open. Your wallet has to be empty, your bookings and table reservations finished or cancelled, any withdrawal settled, and any listing of yours unpublished or handed to another agent. The screen names whichever of those applies to you and links straight to the control that clears it.
- 4. Confirm it is you, then type the phrase. Your password, or a code we email you if you signed up with Google or Apple.
What happens next, and when
The moment you confirm, your account is signed out everywhere and deactivated. You cannot sign in and nobody can reach your profile. Nothing has been destroyed yet.
We email you straight away with the date and a restore code. 30 days later a scheduled job runs the deletion, and we email you again when it has finished. After that it cannot be undone.
What is destroyed
Your profile, your photograph and cover picture, your posts, comments, stories and drafts, your saved items, interests and searches, your devices and notifications, your saved cards and bank accounts, and every file you have uploaded, including any identity, agency or host documents. The files are removed from storage, not just the records that point at them.
- their posts and replies, emptied instead of deleted where somebody else had replied under them
- the pictures on those posts
- what they liked
- what they reposted
- their stories
- their comments, emptied instead of deleted where somebody else had replied under them
- what they liked on a story
- what they liked on a comment
- saved properties
- saved stays and restaurants
- saved searches and their alerts
- who they followed and who followed them
- blocks in both directions
- mutes
- every notification
- their conversations with the assistant
- what they asked the assistant in a thread
- area membership
- moderator applications
- events they said they were coming to
- support tickets they raised, and the replies on them
- badges
- roles
- saved cards
- saved bank accounts
- payout accounts
- identity and agency documents, rows and objects
- host and business documents, rows and objects
- photographs they uploaded
- films they uploaded
- pictures they sent in a thread
What is kept, and why
Vallo is registered with the Special Control Unit against Money Laundering, and Nigerian anti-money-laundering rules require a platform that moves money to retain its transaction records. So bookings, reservations, wallet entries, payments, payout records, inspection requests and reviews are kept, with your name, email address and telephone number removed from every one of them. What is left is an amount, a date and a reference that no longer points at a person.
Messages you have sent stay in the other person’s conversation with an anonymous sender, so their side of the thread is still readable. Nobody can see who wrote them.
- bookings: guest name, telephone number and address removed, because a booking is a financial record and the foreign key onto it is on delete restrict.
- reservations: the note left for the restaurant removed, because the restaurant's own record of a table it held.
- wallet_entries: any address, name or account number left in the metadata removed, because the movements themselves are the record the law requires.
- transactions: nothing: the row names a booking, not a person removed, because the processor's side of the same record.
- ledger_entries: nothing: the row names a booking, not a person removed, because how a payment was split.
- platform_revenue: nothing: the row names a reference, not a person removed, because what the platform earned.
- escrows: nothing: both parties are uuids removed, because money held between two people, and the foreign keys are on delete restrict.
- rent_payments: nothing: both parties are uuids removed, because a tenancy payment, and the foreign keys are on delete restrict.
- booking_refunds: nothing: the row is amounts and a reason code removed, because what came back and why.
- booking_state_events: nothing: the actor is a uuid removed, because the trail of how a booking reached its state.
- inspection_requests: the note they wrote removed, because the other side's record of an inspection that was arranged.
- inspection_confirmations: nothing: the row is a uuid and a timestamp removed, because the confirmation an escrow release was decided on.
- reviews: the author label, which becomes Deleted account removed, because a review belongs to the property as much as to its author.
- messages: nothing: the sender becomes an anonymous reference removed, because the other person's thread must stay readable, and sender_id is NOT NULL.
- agent_applications: name, telephone number, address, identity document type and number, bank details removed, because the record that a verification check happened.
- agents: the agency display name removed, because listings hang off it and bookings hang off those.
- businesses: the representative's name and number, CAC number, registered name and tax identifier removed, because the business keeps trading under its own name, and it may not reach this point still on the market: owning one that a stranger can transact against is a precondition, cleared by transferring it to somebody who accepted it or by closing it.
- events: nothing: the host becomes an anonymous reference, exactly as a message sender does removed, because a meetup that already happened is history, and the evening belongs to everybody who was there; the host name every surface draws comes from profiles, which this purge scrubs to Deleted account.
- profiles: first name, surname, nickname, telephone number, photograph, place, occupation, interests and every preference removed, because the row is the anonymous reference every retained record points at.
- social_profiles: handle, biography, pronouns, link, cover, banner and photograph removed, because the row carries counts other people's timelines are drawn from.
How long those records are kept for is set out in the privacy policy, section 7.
Stop a deletion you have started
Your account is deactivated while the 30 days run, so you cannot sign in to change your mind. Use the code from the email we sent instead. It puts everything back exactly as it was, and it is the only thing it can do.
If you cannot get in at all
If you have lost access to the email address on the account and cannot sign in, write to us at the contact form and we will verify who you are before we do anything. This is the exception, not the route: the control in Settings works for everybody who can sign in, and it does not need us.