Skip to content

Legacy user erasure routine + runbook #2359

Description

@laurenluz

Legacy user erasure routine + runbook

🎯 A small, repeatable erasure script a dev runs when support fields a deletion request, plus a short runbook saved in the repo describing the process end to end.

📋 Background

Users are asking Giveth to delete their accounts (GDPR "right to erasure"). On the legacy platform, support fields the request and a dev runs the erasure. The approach is anonymization in place, not hard deletion: donation records must survive for stats, and the database blocks deleting a user with donations, projects, or boosts anyway. The v6 stack has its own self-serve erasure (Giveth/giveth-v6-core#501), which defines the do-not-resync marker contract this routine implements.

🔨 What to build

  1. The erasure script — given a user, in one run: scrub all identity on the account in place (name, email, avatar reference, location, social handles, identity/trust scores and attestations, and the account's wallet address — the person-to-wallet link is what's being erased; wallet addresses on donation records remain). Deactivate every owned project and scrub the owner's identity from it, including verification-form (GIVbacks) personal info — never hard-delete a project, and leave free-text content untouched. Remove GIVpower boosts. Purge the contact from Ortto and the notification service. Set the erased marker per Giveth/giveth-v6-core#501 so the v6 sync never re-imports the profile.
  2. The runbook — a short reference doc committed next to the script: when to run it (a legacy user's erasure request, and any v6 self-deletion where the person also has a legacy copy), how to run it, and how to confirm completion back to support.

✅ Acceptance criteria

  • AC1 — One-run erasure — Given a legacy user, When a dev runs the erasure routine for them, Then in a single run all identity fields on the account are permanently scrubbed in place (including the account's wallet address), owned projects are deactivated with the owner's identity and verification-form personal info scrubbed, GIVpower boosts are removed, the contact is purged from the marketing/email platform (Ortto) and the notification service, and the erased marker is set so the v6 legacy sync never re-creates the profile.
  • AC2 — Donations retained — Given the erased user had donations (including recurring/streaming), Then every donation record survives with its transaction hash, amount, USD value, chain, and project intact — platform stats and project totals unchanged — but no longer points to any identifiable person.
  • AC3 — Nothing else touched — Given any erasure run, Then no donation record, project, finalized QF round result, or platform statistic is altered, recomputed, or deleted; no project is ever hard-deleted; the person's authored free-text content (descriptions, updates) is left as-is.
  • AC4 — Runbook exists — Given the routine ships, Then a short process doc lives alongside it covering: when to run it, how to run it, and confirming completion back to support.

📎 Artifacts

  • Source of truth: this backend owns erasure of the legacy database and fans out to Ortto + the notification service; the marker contract is defined in Giveth/giveth-v6-core#501.

🚫 Out of scope

  • v6 self-serve erasure and the v6 side of the sync guard → Giveth/giveth-v6-core#501
  • The delete-account UI on v6 → Giveth/giveth-v6-fe#664

🔗 Related issues

  • ⛔ Blocked by Giveth/giveth-v6-core#501 — defines the shared do-not-resync marker contract (the script itself can be built in parallel).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions