> ## Documentation Index
> Fetch the complete documentation index at: https://docs-pos.solya.app/llms.txt
> Use this file to discover all available pages before exploring further.

# Erase a customer's personal data (GDPR)

> IRREVERSIBLY anonymizes one customer in place for a GDPR erasure request: the name becomes a placeholder, every contact field is cleared and marketing consent is withdrawn. The record and its id SURVIVE so past sales stay resolvable, and the loyalty ledger is untouched. Idempotent, and audited with the acting actor. Only call this on an explicit, verified erasure request — never to 'clean up' data. 404s for an unknown id.



## OpenAPI

````yaml /openapi.json post /v1/customers/{id}/erasure
openapi: 3.0.3
info:
  title: Solya POS API
  version: 1.0.0
  description: >-
    The Solya POS backend HTTP surface. Every documented operation is
    agent-ready: it carries an `operationId`, an agent-facing `description`, the
    `pos.*` scopes it enforces (`x-required-permissions`) and an `x-agent-tier`.
    Success responses return the payload as raw JSON; failures return the
    `ErrorResponse` envelope (`{ error: { code, message, statusCode } }`).
servers:
  - url: /
    description: The backend, relative to its deployed origin.
security: []
paths:
  /v1/customers/{id}/erasure:
    post:
      tags:
        - Customers
      summary: Erase a customer's personal data (GDPR)
      description: >-
        IRREVERSIBLY anonymizes one customer in place for a GDPR erasure
        request: the name becomes a placeholder, every contact field is cleared
        and marketing consent is withdrawn. The record and its id SURVIVE so
        past sales stay resolvable, and the loyalty ledger is untouched.
        Idempotent, and audited with the acting actor. Only call this on an
        explicit, verified erasure request — never to 'clean up' data. 404s for
        an unknown id.
      operationId: eraseCustomerData
      parameters:
        - schema:
            type: string
            minLength: 1
          in: path
          name: id
          required: true
      responses:
        '200':
          description: >-
            The anonymized customer: PII scrubbed, id and loyalty ledger
            preserved.
          content:
            application/json:
              schema:
                type: object
                properties:
                  id:
                    type: string
                    minLength: 1
                  name:
                    type: string
                    minLength: 1
                  email:
                    type: string
                    format: email
                    pattern: >-
                      ^(?!\.)(?!.*\.\.)([A-Za-z0-9_'+\-\.]*)[A-Za-z0-9_+-]@([A-Za-z0-9][A-Za-z0-9\-]*\.)+[A-Za-z]{2,}$
                  phone:
                    type: string
                  tier:
                    type: string
                    minLength: 1
                  postalCode:
                    type: string
                  addressLine:
                    type: string
                  points:
                    default: 0
                    type: integer
                    minimum: 0
                    maximum: 9007199254740991
                  spend:
                    default: 0
                    type: number
                    minimum: 0
                  orders:
                    default: 0
                    type: integer
                    minimum: 0
                    maximum: 9007199254740991
                  optIn:
                    default: false
                    type: boolean
                required:
                  - id
                  - name
                  - tier
                  - points
                  - spend
                  - orders
                  - optIn
                additionalProperties: false
                description: >-
                  The anonymized customer: PII scrubbed, id and loyalty ledger
                  preserved.
                example:
                  id: cust-1
                  name: Client anonymisé
                  tier: Or
                  points: 1240
                  spend: 842.5
                  orders: 17
                  optIn: false
        '400':
          description: >-
            The request failed schema validation; `error.fieldErrors` lists the
            fields.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ValidationErrorResponse'
        '401':
          description: No valid credential was presented — send a bearer token.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '403':
          description: The actor is authenticated but lacks the required `pos.*` scope.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '404':
          description: No resource matches the addressed identifier.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '500':
          description: An unexpected server error — safe to retry idempotent requests.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
      security:
        - bearerAuth: []
components:
  schemas:
    ValidationErrorResponse:
      type: object
      required:
        - error
      additionalProperties: false
      description: >-
        A `VALIDATION_FAILED` envelope carrying the offending fields in
        `fieldErrors`.
      properties:
        error:
          type: object
          required:
            - code
            - message
            - statusCode
          additionalProperties: false
          properties:
            code:
              type: string
              enum:
                - VALIDATION_FAILED
            message:
              type: string
            statusCode:
              type: integer
            fieldErrors:
              type: array
              description: >-
                One entry per rejected field: the field path and why it was
                rejected.
              items:
                type: object
                required:
                  - field
                  - message
                additionalProperties: false
                properties:
                  field:
                    type: string
                    description: Dot-path of the offending field.
                  message:
                    type: string
                    description: Why the field was rejected.
    ErrorResponse:
      type: object
      required:
        - error
      additionalProperties: false
      description: The uniform failure envelope every non-2xx response returns.
      properties:
        error:
          type: object
          required:
            - code
            - message
            - statusCode
          additionalProperties: false
          properties:
            code:
              type: string
              enum:
                - VALIDATION_FAILED
                - UNAUTHORIZED
                - FORBIDDEN
                - NOT_FOUND
                - CONFLICT
                - BUSINESS_RULE_VIOLATION
                - INTERNAL_ERROR
              description: >-
                Machine-readable kernel `ResultCode` — branch on this, not on
                `message`.
            message:
              type: string
              description: >-
                Human-readable explanation. Safe to surface; never leaks server
                internals.
            statusCode:
              type: integer
              description: >-
                The HTTP status, mirrored into the body so a client need not
                read headers.
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >-
        `Authorization: Bearer <token>`. Accepts EITHER a Keycloak access token
        (scopes-in-token) OR an opaque POS session token; both resolve to the
        same `pos.*` scope vocabulary the route guards enforce.

````