Data retention for ecommerce: how long to keep customer data and how to delete it
There is no single number, because different data has different clocks. Orders are governed by tax law, marketing profiles by necessity, and analytics by whatever you wrote in your own policy.
"How long can we keep customer data" has no single answer and shops keep asking for one. The GDPR's storage limitation principle says personal data may be kept no longer than necessary for the purposes it was collected for — which turns the question back on you, correctly, because the purposes differ.
An order record and a browsing event are both personal data and they are governed by entirely different considerations.
Four categories, four clocks
- Order and invoice records. Governed by national tax and accounting law, commonly in the range of five to eleven years depending on the country. This is a legal obligation, not a choice, and it overrides a deletion request for that data.
- Marketing profiles and behavioural data. Kept only as long as necessary for marketing. Two to three years of inactivity is a common and defensible line, and shorter is easier to defend than longer.
- Consent records. Kept for as long as a claim could be brought, which outlives the marketing relationship.
- Analytics events. Usually the shortest. Aggregate what you need and delete the row-level detail on a rolling window — 14 to 26 months is typical.
Write the schedule down and automate it
The document is small: one row per data category, with the period, the justification, and what happens at the end. The part that makes it real is a scheduled job that actually does it.
- Delete or anonymise on a schedule, not when somebody remembers.
- Log what was deleted and when, in aggregate, so you can show the policy operates.
- Include backups in the reasoning, with an honest statement of how long they persist.
- Review the schedule annually, because the data you collect changes.
For orders, deletion means anonymisation
You cannot delete an order you are legally required to retain, and you usually do not need to keep it attached to a named person to satisfy that obligation.
- Strip the identifying fields — name, email, address, phone — while keeping the financial record, the date, the amounts and the line items.
- Break the link to the marketing profile. The order remains for the accountant; the person does not remain in your marketing database.
- Make sure it is actually anonymous. If a single order can be re-identified from an unusual combination of fields, it is pseudonymised rather than anonymised, and it is still personal data.
Handling a deletion request
A request under Article 17 is not a delete button, and treating it as one causes the tax problem above. The workable process:
- Verify who is asking, proportionately. Do not demand a passport to unsubscribe somebody.
- Delete what has no other basis — marketing profile, behavioural events, preferences.
- Anonymise what you must retain, and say so in the reply, naming the obligation.
- Suppress rather than delete the email address itself where necessary to honour the objection. A hashed suppression entry is how you avoid mailing them again after a future import, and that is a legitimate purpose worth explaining.
- Propagate to processors. Every tool holding a copy has to act too, which is why the processing register exists.
- Answer within one month. Extendable, but only with an explanation.
The easiest compliance win is collecting less
Every field you do not collect is a field you do not have to retain, secure, disclose, export or delete. Shops accumulate data on the theory that it might be useful later, and it almost never is.
- Do you use date of birth? If it is not driving a real campaign, stop collecting it.
- Do you need full browsing history per person for two years, or aggregate patterns plus recent detail?
- Do you need a phone number from customers who will never be sent a message?
Reviewing this once a year takes an afternoon and reduces the size of every other obligation on this page.
Sources and further reading (4)
- GDPR Article 5 — Principles (storage limitation)
- GDPR Article 17 — Right to erasure
- EDPB — Guidelines 05/2020 on consent
- European Commission — VAT invoicing and record keeping
Checked on 23 September 2026. Provider prices, mailbox rules and legal guidance change — verify anything you plan to act on.
A store you can delete, completely
Auralata deletes everything it holds for a store when you remove it — profiles, orders, events, media — and nothing on your WooCommerce shop is touched, so your own records stay where the accountant needs them.