Note: Lofty is rolling out in stages. Depending on the version your account is on, some features or screens described in this article may look different or may not yet be available to you.
Introduction
The Data Subject Access Request (DSAR) feature adds privacy rights controls to your Lofty-hosted website, allowing visitors to exercise rights over their personal data. This supports compliance with privacy regulations like CCPA (California Consumer Privacy Act).
The Three DSAR Rights
Visitors to your site can exercise three rights:
Opt Out of Data Sharing
The visitor opts out of having their data shared with third parties.
How it works: - The opt-out preference is stored on the specific device and browser used when the choice was made. - If the visitor is logged in to their site account, the preference is tied to their account and follows them across devices. - If the visitor is not logged in, the preference is device/browser-specific only — it won't transfer to other devices or browsers.
Access Their Data
The visitor requests to see the data your site has collected about them.
How it works: - Email verification is required — the visitor must verify their email address before accessing their data. - Upon verification, the visitor can view their activity timeline — a log of their searches, listing views, saved favorites, and form submissions on your site.
Delete Their Account
The visitor requests that their account and associated data be deleted.
How it works: - A Delete button appears in the visitor's account settings when they are logged in. - Clicking Delete triggers an email verification step. - After verification, the visitor confirms the deletion. - What happens in Lofty: The lead is moved to a Deleted pipeline in your CRM. The lead will no longer receive automated email or text communications from Lofty.
⚠️ Important: Lofty does not automatically erase the lead's personal data from the CRM. You must manually erase the lead's information to fulfill a complete deletion request. Review the lead in the Deleted pipeline and erase their data according to your data retention policy.
DSAR Notifications in the CRM
When a visitor submits any DSAR request, Lofty logs it on the lead's timeline in the CRM. For requests that require action from you (such as manual data erasure after a deletion request), you will also receive an email notification.
Tips
- Review your deletion workflow. Because Lofty moves deleted leads to a pipeline rather than automatically erasing them, you need a documented process for reviewing and manually erasing data from deleted accounts to stay compliant.
- Communicate your privacy rights clearly. Consider adding a Privacy Policy page to your website that explains the data rights available to visitors and how to exercise them.
- Act promptly on deletion requests. CCPA and similar regulations often have response time requirements (typically 45 days). Set up a process so deletion requests don't sit unaddressed.
Frequently Asked Questions
Does the Delete request automatically remove the lead from my CRM? No. The lead is moved to a Deleted pipeline and stops receiving communications, but the personal data remains in the CRM. You must manually erase it.
What data does the Access request show the visitor? The visitor sees their activity timeline — searches, listing views, saved favorites, and form submissions on your site.
Is the Opt Out preference permanent? It persists on the specific device and browser used. If the visitor switches devices or browsers (and isn't logged in), they'd need to opt out again.
Questions?
If you have any questions regarding this topic or any others, please reach out to our Support Team via email at support@lofty.com, by phone at 1 (855) 981-7557, or by chat with us through your Lofty CRM.

Comments
0 comments
Please sign in to leave a comment.