Skip to main content
Version: 1.0

GDPR API

Handle your customers' right-to-erasure requests without emailing Two.

When one of your customers exercises their right to erasure under Article 17 of the GDPR, this API erases the personal data Two holds about them on your behalf. Requests are scoped to your own merchant account by your API key — you can only erase data for your own customers.

What gets erased​

Names, email addresses and phone numbers held against the customer user, their trade account contact details, and the data captured during any identity verification. The records themselves remain, with the personal data replaced by anonymised placeholders.

What cannot be erased​

Customers who have placed orders cannot be erased. Orders are financial records that Two is required to retain under applicable accounting and tax law, which is an exception to the right to erasure under Article 17(3)(b). GET /gdpr/v1/lookup reports such a customer as status: ineligible, and its message field carries a plain-language explanation you can pass on to your customer.

Shared and placeholder addresses cannot be erased automatically. Where we hold an unusually large number of records against one address, it is almost certainly not one individual's — and erasing on it could destroy data belonging to other companies. GET /gdpr/v1/lookup returns status: ineligible with reason: manual_review_required. This is not a refusal: forward the request to [email protected] with your reference and it will be handled.

  1. GET /gdpr/v1/lookup to check whether the customer can be erased. This is a read-only pre-flight check and changes nothing. It is the endpoint that answers whether a customer is eligible, so call it first.
  2. POST /gdpr/v1/erasure to request the erasure. It returns 202 Accepted with your reference: the request has been taken on, not necessarily completed. It reports no outcome, so a customer with orders and a customer we hold nothing for are both accepted in the same way — and neither is erased.

Retrying is safe: the same reference can be submitted again and nothing is erased twice.

Erasure is irreversible. There is no undo, and Two cannot restore erased personal data — so confirm the email address before you call it.

References​

Pass your own data-protection request reference on every call. It is recorded in Two's audit trail alongside the erasure and echoed back in the response, so the two sides of the paper trail line up if either of us is ever asked to demonstrate compliance.

Environments​

Testing​

https://api.sandbox.two.inc

Note: Read about our sandbox environment specific behaviour.

Production​

https://api.two.inc

Authentication​

For instructions on how to obtain API keys, visit this page. You will obtain two different keys, an initial one for testing in our sandbox environment and once ready, for production. Your API keys enables others to act on your behalf if they are able to obtain them, so make sure to keep them safe. Your API key is not to be shared with anyone, including in your version control system, client-side code, in public chatrooms and so on. The API key is applied in the request header. For example:

GET /something
X-Api-Key: secret_test_aabbccddeeff0123456789

API Keys have the following structure: secret_<env>_<key> where:

  • env is determined by the environment (prod for production, test for test environments)
  • key is a random, URL-safe, 64-bit encoded text string containing 32 random bytes.

Security Scheme Type:

apiKey

Header parameter name:

X-Api-Key