Data Deletion Policy
- Last Updated: 31 July 2026
This policy explains how users can permanently remove data connected, processed, or cached through the TrustFusion WordPress plugin and its supporting Relay service (reviews.webcitylab.com).
1. Self-Service Deletion (Recommended)
You maintain control over your data through your own WordPress dashboard:
- Disconnect a business: Navigate to TrustFusion → My Businesses and click Disconnect. If you connected via the official Google OAuth flow, this instructs our Relay to stop using the associated access/refresh token, which are stored encrypted on the Relay, not in your local WordPress database.
- Revoke a Manager-based connection: If instead you added our Relay’s Google account as a Manager on your Business Profile, remove it directly from your Google Business Profile’s “People and access” settings (see Section 3) — this is the fastest way to fully cut off access for that path.
- Cached data removal: Use the plugin’s settings panel to delete downloaded profile metadata and cached review content from your own database.
- Complete cleanup on uninstall: When you delete the plugin, WordPress will prompt you to confirm whether to remove TrustFusion’s local database tables. If you confirm, all local tables (
wp_trustfusion_reviews,wp_trustfusion_profiles,wp_trustfusion_logs) and related options are permanently dropped. If you decline, your data is preserved in case you reinstall later.
2. Manual Deletion Requests & Timelines
If you no longer have access to your WordPress dashboard, or want us to remove data held on the Relay (such as an OAuth connection, or your license/account records):
- Process: Email support@webcitylab.com from the administrative email address associated with your site or purchase, with the subject line “TrustFusion — Data Deletion Request.”
- Response window: We will acknowledge your request within two (2) business days.
- Completion window: Associated tokens, Relay-held connection records, and support-cached metadata will be permanently deleted within seven (7) business days.
3. Revoking Access Directly via Google
You can cut off TrustFusion’s access at the source at any time, independent of anything in your WordPress dashboard:
- If you used the OAuth connection: Go to your Google Account → Security → Third-party apps with account access, select TrustFusion, and click Remove Access. This immediately invalidates all active tokens and prevents further API calls.
- If you used the Manager-invite method: Go to your Google Business Profile → People and access, find our Relay’s account, and remove it. This immediately stops that business from being reachable through the Relay.
4. Backups, Diagnostics, and Log Retention
- System backups: Residual operational data may persist in our secure server backups for a limited retention period (maximum 30 days) solely for disaster recovery, and is automatically overwritten on a rolling basis.
- Sync logs: The local
wp_trustfusion_sync_logtable contains short-term operational status and timestamps, not personal data, and can be emptied via your database manager at any time.
5. Scope of Stored Data
TrustFusion and the Relay process business profile metadata and review content (public, or accessed via a connection you authorized), plus the account/license data described in our Privacy Policy (license key, purchase email, site domain). We never collect, process, store, or transmit Gmail, Drive, Contacts, or other unrelated Google account data.
6. Contact & Corporate Details
- Company Name: Web City Lab
- Support Email: support@webcitylab.com
- Address: MM Tower, Rajjak Khan Shorok, Nothulladbad, Barisal Sodor, Bangladesh