Resources
Data & privacy
How personal data is stored, masked, kept out of webhooks, and erased on request.
This page collects, in one place, how BreezeIQ handles personal data: what it stores, who can read it, what leaves it, and how to erase a customer. Each point links to the page with the details.
What's stored#
You never write profiles directly. BreezeIQ derives them from the events you send (Concepts). The personal data it keeps is the identifiers in those events.
| Data | How it's handled |
|---|---|
| Identifier values | Encrypted at rest. See Identifiers. |
| Identifier types | Only the types your tenant declares count. Unknown types in an event are ignored. |
email | Trimmed and lowercased before matching. |
phone | Normalised to E.164. Numbers without a country code are treated as Indian. |
| Placeholder values | Values configured as "noise" (such as [email protected]) are ignored entirely and never link anyone. Ask the BreezeIQ team to add yours. |
| Metrics, segment memberships, history | Derived per profile from events. See Profiles & identity. |
Browser events can't carry contact details#
The browser endpoint needs no token, so anyone can call it. BreezeIQ keeps only cookie and device_id from it; email and phone are dropped, because anyone could claim them. Browser events also never merge two existing profiles. Send email and phone only from your server, with the collector token. See From the browser and From your server.
Who can see what#
Data is isolated per tenant and per workspace. Each workspace (one store or brand) has its own profiles, segments and members. Identities, metrics and segments never cross workspaces: the same customer in two workspaces is two separate profiles.
| Token | Can read | Can write |
|---|---|---|
Tenant (cpt_...) | Everything in the tenant, all workspaces | Configuration, workspace tokens, profile erasure. Issued by the BreezeIQ team, not through the API. |
Workspace (cpw_...) | That workspace's profiles, segments and members, plus the tenant's event types and metric definitions | Nothing. Read-only. |
- A token can never see another tenant's data, and a workspace token can never see another workspace's data. Both return
403, as does a write with a workspace token. See Errors. - A workspace token is shown once, when it's minted, and can't be retrieved again. Listing tokens never returns their secrets. See Tokens.
- Revoking a token takes effect immediately.
- Check what a token can do with
GET /v1/whoami. See Authentication.
What leaves BreezeIQ#
Webhooks carry ids only#
Segment webhooks contain no personal data: identifiers never appear in them. A payload names the change with tenant_id, workspace_id, segment_id and profile_id. Your receiver calls the profile API for emails, phones and metrics. The webhook URL is set per environment by the BreezeIQ team. See Webhooks.
The profile API masks identifiers#
Profile views return an identifier's value in plain text only for types your environment allows (typically email and phone). For other types, value is null and only masked_value is returned. The customer table (profiles/summary) and segment member lists follow the same rule for their email and phone columns, showing the masked value where plain text isn't allowed. See Profiles API.
"identifiers": [
{
"type": "email",
"tier": "strong",
"value": "[email protected]",
"masked_value": "pr****@example.com",
"key": "9f2c…",
"status": "active"
},
{
"type": "cookie",
"tier": "weak",
"value": null,
"masked_value": "3f9a****",
"key": "52a9…",
"status": "active"
}
]Erase a customer#
To act on a deletion request (for example under GDPR), call Erase a profile (DELETE .../profiles/{profile_id}) with a tenant token. It permanently erases:
- the profile and every profile merged into it
- every identifier
- every metric
- every segment membership
- every history entry
Find the profile_id with a profile lookup by email or phone. The response counts what was deleted. See Profiles API.
curl -X DELETE "https://api.breeze.in/cdp/control-plane/v1/tenants/breeze/workspaces/my-store/profiles/9dc94bd5-31f3-855c-945b-d66a759f5c78" \
-H "Authorization: Bearer $BREEZEIQ_TOKEN"{
"deleted_root": "9dc94bd5-31f3-855c-945b-d66a759f5c78",
"deleted": {
"profiles": 1,
"identifiers": 3,
"metric_contribution": 5,
"canonical_metrics": 5,
"segment_membership": 0,
"segment_transition_log": 0
},
"redis_mappings_deleted": 3
}A deleted profile can't be restored. The call needs a tenant token; workspace tokens are read-only.