Skip to content

Data Protection Cockpit

The cockpit answers three questions in one place: what merchantCENTRAL clears on its own, what is waiting for your decision, and how long marketplace data is kept.

Behind it runs a line that goes through the whole subject:

  • Copies the application made for its own work are cleared without asking. A retention period is not something a tenant should have to remember.
  • Your own master data is counted and explained, but not touched. You decide and you start it.
  • Posted documents are never touched. Ever.

Opening the page

Through Tell MeData Protection Cockpit, through the assisted setup (Decide on data protection and marketplace rules), or through the line Data protection decisions in the Waiting for you card on the dashboard.


Waiting for your decision

Tile What is behind it
Ready to anonymize Customers created by a marketplace import whose retention period has passed and who have no open documents.
Unclear origin Customers carrying a marketplace customer ID without a recorded origin — records from before the origin was tracked, and records matched to an ID from another import. They are never anonymized automatically.
Carriers without a limit Carriers that receive the phone number or e-mail address of the recipient on every shipment.

Why customers are not anonymized automatically

A customer is your master record, not a by-product of the import. Posted invoices and shipments hang on it, and what happens to it is a commercial decision. merchantCENTRAL tells you which records have passed the period and does it at the press of a button — but not overnight.

What anonymizing does

Cleared are name, address, phone, e-mail, VAT registration number and marketplace customer ID on the customer and their contacts.

Nothing is deleted. The customer stays so that posted invoices and shipments can keep hanging on it. The documents keep their own copy of the address — the legal retention period applies to them, and every marketplace policy grants that exception.

Anonymization is blocked while an open sales document or an unpaid entry exists. An unpaid invoice blocks it until it is settled.

Customers that existed before

A long-standing business customer who orders once through a marketplace keeps everything — their master data came from another source. Only the marketplace customer ID is removed. The buyer contact the import created on that customer is anonymized regardless: that data did come from the marketplace.


Runs by itself

Tile What happens
Labels due Shipment labels of delivered parcels past the period. A nightly job clears address, contact data and the label, return, customs and QR documents.
Order data due Marketplace orders past the period. The same job clears buyer data, raw payload and processing log.

What stays: tracking number, tracking URL, tracking history with times and locations, weights, references — and for orders the numbers, dates, amounts and status. A parcel stays traceable after its recipient can no longer be read from it.

Label PDFs are gone afterwards

Once the period has passed, no return label can be pulled from the archive any more. If you need labels longer, raise the period — that is your decision and your risk towards the marketplace policy.


Retention periods

Period Counts from Default
Master data retention last order, last posted entry or creation by the import — whichever is later 30 days
Shipment label retention delivery according to the tracking event; without one, the parcel's last sign of life 30 days
Order data retention order date of a finished order 30 days
Unfinished order retention order date, import stamp or creation timestamp 90 days

The 30 days are what marketplace policies commonly ask for, not a legal obligation. Shorter is always allowed. Longer is your decision.

Why unfinished orders are kept longer

An order stuck in import is not an exemption from the period, only a reason to wait longer before declaring it over.


Actions

Action Effect
Anonymize Customer Master Data Anonymizes every customer whose period has passed. With confirmation and a result message.
Clear Delivered Shipment Labels Now Runs the nightly job immediately. Useful for an evidence screenshot.
Carrier Settings Opens the carrier list, where you decide per carrier when recipient data may be passed on — see Shipment Provider Card.

The reminder on the dashboard

As soon as something is waiting for a decision, the dashboard says so once when it opens. The message can be postponed for 30 days, but not switched off for good: a marketplace policy is not something to tick away permanently. Until when it stays quiet is shown in the cockpit.

The labels and order data due are deliberately not counted there — they take care of themselves, and a reminder about something that happens anyway only teaches people to ignore reminders.


See also